Related Experiment Video
Updated: Sep 25, 2026

Generation of Comprehensive Thoracic Oncology Database - Tool for Translational Research
Published on: January 22, 2011
[What are anonymized data? : Options for providing cancer registry data for research in compliance with the General
Joachim Hübner1, Jana Johne2, Maria Heil3
1Klinische Landesauswertungsstelle Niedersachsen (KLast), Industriestr. 9, 26121, Oldenburg, Deutschland.
Abstract:
Every day, large amounts of patient-related data are collected in the healthcare system. The prerequisite for using such data for research purposes is usually that the consent of the persons concerned has been obtained or that the data are provided in anonymized form. Both researchers and data holders are often uncertain about what anonymization means and how it can be achieved. Is it sufficient to remove directly identifying information such as name and address? If not, what additional information that could enable identification must be considered? And can a dataset only be considered anonymized if it can be made available to the general public without risk?This article highlights the tension between the needs of research and the data protection interests of the individuals concerned, using the example of cancer registry data. Based on the definition of personal data in Art. 4 No. 1 of the General Data Protection Regulation (GDPR) and current case law of the European Court of Justice (ECJ), it is argued that anonymity is not a property solely inherent to the data. Rather, it depends on the specific risk of re-identification, which is also influenced by the context in which the data are to be provided. The article highlights ways in which the probability of re-identifying a data subject can be minimized, both through data pre-processing and through legal and contractual restrictions on data use. If the remaining risk is judged to be-in the words of the ECJ-"de facto negligible," the pre-requisites for providing data in anonymized form have been met.

