DJB's description of "anonymization" while talking[1] about his job as the man in the middle at Verizon:
>> Hashing is magic crypto pixie-dust, which takes personally identifiable information and makes it incomprehensible to the marketing department. When a marketing person looks at random letters and numbers they have no idea what it means. They can't imagine that anybody could possibly understand the information, reverse the hash, correlate the hashes, track them, save them, record them.
> lots of industry standard analyses unachievable with those identifiers out of the picture.
Calling something "standard" doesn't mean it's ethical. If someone wants use that type of identifier, they need to get explicit informed consent from everyone involved, and they need to be liable for any damages that derive from their database of identified records.
[1] https://projectbullrun.org/surveillance/2015/video-2015.html...
I'm fine with this.
>As long as there is no Personally Identifiable Information (which, no, metadata, location history, medical claims, transaction details, don't count).
Currently. Hopefully the stroke of a pen will eventually change this, and soon.
This is also often the case with location data as well. Spoiler alert: this is absolutely not sufficient to anonymize location data.