What problem does it solve?
This Skill applies reversible pseudonymization to clinical and personal data so organizations can protect working datasets while retaining a separately controlled ability to re-link records when legally authorized. It preserves the distinction between pseudonymization and irreversible anonymization under GDPR.
Core Features & Use Cases
- GDPR-aligned pseudonymization: Use OpenMed replacement surrogates with the GDPR pseudonymization policy and a retained mapping.
- Separate key management: Route pseudonymized text to ordinary processing systems while storing the re-linkage mapping in a separate, access-controlled key vault.
- Authorized re-linkage: Restore original values only when a lawful basis exists, with audit logging that avoids recording restored plaintext.
- Retention and risk controls: Apply independent retention to the mapping, protect it as a high-sensitivity secret, and assess residual quasi-identifier risk.
- Use Case: Prepare EU clinical notes for analytics while preserving a controlled ability to reconnect records for an authorized patient request or longitudinal study.
Quick Start
Use the pseudonymizing-for-gdpr skill to pseudonymize the attached clinical text under GDPR, keep the re-linkage mapping in a separate key vault, and check the output for residual identifiers.