Pseudonymisation and De-Identification - Maryland MODPA
Maryland Online Data Privacy Act of 2024 MD-MODPA-Pseudonymisation-De-Identification-Section-14-4610-4611-Internal-Research-Aggregated: Maryland MODPA Pseudonymisation + De-Identification + Section 14-4610 + 14-4611 + Internal Research + Aggregated
Apply pseudonymisation and de-identification under Sections 14-4610 and 14-4611 to enable lawful internal research + product improvement + aggregated reporting while protecting consumer privacy. Pseudonymised Data definition (Section 14-4601(V)) - personal data that cannot be attributed to specific consumer without use of additional information kept separately and subject to technical and organisational measures preventing re-identification. De-Identified Data definition - cannot reasonably be linked to consumer or household + technical safeguards + business processes preventing re-identification + publicly commit to maintain without re-identifying + contractually bind recipients. Aggregated Consumer Information - statistical de-identified about group/category from which individual identities removed + not linked to any consumer. Internal research exemption (Section 14-4611) permits processing without consent for internal product improvement + bug repair + security maintenance + scientific research in public interest under privacy-by-design + research ethics review board + data destruction post-research timeline. Maryland Consumer Health Information Act (separate) interaction. HIPAA Safe Harbor / Expert Determination cross-walk for health data.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 261 controls across 75 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
MY-PDPA-DPO-Designation-Class-Data-User-Registration-DPIA-Code-Practice-Section-43A-2024-Amendment Malaysia PDPA Governance + DPO Section 43A + Class of Data User Registration + DPIA + Code of Practice
MY-PDPA-Data-Subject-Rights-Access-Correction-Portability-Withdraw-Consent-Prevent-Marketing-Sections-30-43 Malaysia PDPA Subject Rights + Access + Correction + Portability + Withdraw Consent + Prevent Marketing + Sections 30 to 43
MY-PDPA-Seven-Personal-Data-Protection-Principles-General-Notice-Choice-Disclosure-Security-Retention-Data-Integrity-Access Malaysia PDPA Seven Principles + General + Notice and Choice + Disclosure + Security + Retention + Data Integrity + Access
PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37