OAIC Decision Provides Guidance on De-Identifying Personal Information for AI Model Training

The recent OAIC decision into I-MED Radiology Network Limited's disclosure of de-identified patient data to Annalise.ai serves as a valuable guide for businesses on techniques for de-identifying personal information, particularly for the purpose of training AI models. The Office of the Australian Information Commissioner (OAIC) concluded its preliminary inquiries into I-MED's data practices without taking regulatory action, determining that the de-identified patient data was sufficiently de-identified and no longer constituted 'personal information' under the Privacy Act 1988 (Cth). The decision highlights the importance of good governance and planning for privacy when commencing new initiatives involving new technology.

Key Takeaways:

  • Businesses should develop a robust de-identification methodology using recognised standards and techniques (e.g., hashing, redaction, aggregation) to ensure data is no longer reasonably identifiable.
  • Mitigate risk of re-identification by imposing contractual obligations on data recipients to prevent re-identification and using technical controls to prevent linkage with other datasets.
  • Strengthen data governance by establishing clear internal policies and procedures for de-identification and data sharing, aligned with frameworks like the 5-Safes Principles.
  • Inform customers about how their de-identified data may be used to mitigate reputational risks.
  • Consider consumer law risks, including false, misleading or deceptive conduct, unfair contract terms, and unfair trading practices when using customer data for AI model training.

Statistics:

  • 90% of individuals in a data set of 1.1 million users' credit-card transactions can be identified with just four fairly vague pieces of information (MIT study, 2015).
  • The OAIC found that I-MED's de-identification process, which included technical, contractual, and governance measures, was sufficient to de-identify the patient data and exempt it from the application of the Privacy Act.
  • I-MED used two hashing techniques, time-shifting dates, aggregating certain fields, and redacting text to de-identify the patient data.
  • Annalise.ai was prohibited from disclosing or publishing the patient data for any purpose, and required to store the data in a secure environment.

Sources:

  • OAIC report on preliminary inquiries into I-MED Radiology Network Limited's disclosure of de-identified patient data to Annalise.ai.
  • National Institute of Standards and Technology practices on de-identification.
  • MIT study, 2015, on re-identification risks.
  • Privacy Act 1988 (Cth).
  • 5-Safes Principles.