Also wanted to add, since this is a common question: does PGPP protect all identifiers or just some? As with most privacy systems, just some. Our aim is twofold: 1) to decouple a user's human identity from their network identities (mobile and Internet) and 2) randomize their network identities. We view decoupling as pretty fundamental to practical privacy -- to decouple who you are from what you do. Who you are in the context of the network is your human identity, often associated with the main point of contact you have with the network and billing -- your subscription and SIM, your broadband connection and its IP address and your home address, etc. That information has been used as the key upon which datasets can be attached. The goal then is to decouple across entities -- the different parties who have data -- and across uses -- the different mechanisms of a network protocol, such as authentication and connectivity.
Other identifiers such as hardware identifiers aren't inherently attached to a person and aren't always used by networks, but even when they are, removing them is insufficient -- as our colleagues at UCSD found in recent work, phones can be identified at the PHY, without even using a unique hardware identifier.