Use this url to cite publication: https://cris.mruni.eu/cris/handle/007/26276
Options
Personal Data Processing in Educational Institutions: Anonymisation and Pseudonymisation
Type of publication
Straipsnis konferencijos medžiagoje kitoje duomenų bazėje / Article in conference proceedings in other databases (P1c)
Title
Personal Data Processing in Educational Institutions: Anonymisation and Pseudonymisation
Date Issued
2020
Extent
p. 9989-9997
Is part of
ICERI 2020: 13th international conference of education,research and innovation, 9th-11th November 2020 : proceedings. [Valencia] : IATED Academy, 2020. ISBN 9788409242320.
Series/Report no.
ICERI Proceedings, ISSN 2340-1095
Field of Science
Abstract
Educational institutions collect vast amounts of personal data from students and staff. This personal data is vital for schools and universities to operate. Therefore, clear and well-documented processes need to be in place. The General Data Protection Regulation (GDPR) provides the regulation to manage and protect this data while creating consistent policies and practices. The GDPR applies to organisations in all sectors including educational institutions. With the GDPR in place, organisations need to determine the lawful basis for processing personal data, so it is essential properly to identify the type of personal data. Personal data anonymisation or pseudonymisation can bring some considerable benefits and play an important role in facilitating the implementation of GDPR in the organisation. Pseudonymisation does not remove all identifying information from the data but merely reduces the linkability of a dataset with the original identity of an individual. Anonymisation is definitely one of the best ways to ensure the safety of data collected. This extra measure of security lets freely exploit data collection in ways that wouldn’t be legally permissible when it comes to non-anonymised data. Both pseudonymisation and anonymisation are encouraged in the GDPR and enable its constraints to be met. Non-compliance with the GDPR poses financial, legal and reputational risks to organisations. The main purpose of this article is to develop a theoretical model of personal data processing after anonymisation and pseudonymisation under the GDPR. This model could help organisations to understand the application of the GDPR requirements for the processing of personal data including their anonymisation and pseudonymisation. It is very important for educational institutions to ensure adequate protection of personal data. The research methods used in this academic article include comparative analysis, systematic analysis and generalisation analysis. A conceptual framework is grounded in the literature review. Based on the generalisation method, conclusions are drawn.
Is Referenced by
Type of document
type::text::conference output::conference proceedings::conference paper
ISBN (of the container)
9788409242320
eLABa
76255219
Coverage Spatial
Ispanija / Spain (ES)
Language
Anglų / English (en)
Bibliographic Details
0