Anonymity Protection System for Survey Data Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional digital survey systems fail to adequately protect the anonymity of respondents, as they often associate identifying information with responses, lack flexibility in data analysis, and allow data manipulation that can compromise anonymity, leading to breaches in respondent identity.
Innovation Solution
An anonymity protection system that determines and applies anonymity thresholds based on data sensitivity, respondent number, and predefined settings, modifies data output to maintain anonymity, and dynamically updates filtering options to prevent identity exposure, ensuring anonymity for both presented and filtered-out data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If conventional survey systems display survey responses with identifying information, then data analysis capability is improved, but respondent anonymity is compromised
Solution Approach 1:
The system extracts and removes identifying information from survey responses before display. PII redaction components scan and remove names, addresses, phone numbers, and other identifiers from response text, allowing analysts to access response content without exposure to identifying details.
Solution Approach 2:
The system applies different levels of anonymity protection to different data elements. Respondent identifiers are completely removed, while response content is preserved for analysis. This selective processing maintains data utility while protecting anonymity at the appropriate locations in the data structure.
2Measurement precision
If conventional systems filter survey responses to small groups, then data analysis precision is improved, but respondent anonymity is compromised
Solution Approach 1:
The system preemptively prevents anonymity breaches by monitoring filter application in real-time. When a filter would reduce a group to a size that compromises anonymity (e.g., fewer than 5 respondents), the system automatically blocks the filter application or aggregates the data to maintain sufficient group size, preventing the harmful outcome before it occurs.
Solution Approach 2:
The system provides feedback to analysts when attempted filters would compromise anonymity. The interface displays warnings about group sizes and prevents application of filters that would create identifiable groups, allowing analysts to adjust their analysis approach while maintaining anonymity protections.
3Manufacturing precision
If conventional systems provide verbatim text responses, then data accuracy is improved, but respondent anonymity is compromised
Solution Approach 1:
The system extracts and removes identifying language from verbatim text responses while preserving the substantive content. PII redaction components scan response text for names, locations, organizations, and other identifiers, removing only these elements to maintain data accuracy while eliminating anonymity risks.
Solution Approach 2:
The system applies targeted redaction to specific identifying elements within text responses rather than removing entire responses. This selective processing preserves the accuracy and analytical value of response content while removing only the portions that compromise anonymity.
4Adaptability or versatility
If survey systems collect detailed respondent information, then data utility is improved, but anonymity protection difficulty increases
Solution Approach 1:
The system segments respondent data into distinct categories: identifiers (completely removed), quasi-identifiers (aggregated or suppressed), and response content (preserved). This segmentation allows the system to collect and utilize detailed information for analysis while applying appropriate anonymity protections to each data type independently.
Solution Approach 2:
The system introduces an intermediary processing layer between data collection and data display. Anonymization components process the detailed respondent information through multiple stages (identification, redaction, aggregation) before presenting data to analysts, mediating between the need for detailed data and the need for anonymity protection.
Data Source
AI summary
The present disclosure relates to systems, non-transitory computer-readable media, and methods for maintaining the anonymity of survey respondents while providing useful data to an analyst. In particular, in one or more embodiments, the disclosed systems utilize various anonymity protections based on various anonymity thresholds. For example, the presently disclosed systems and methods may disallow or modify potentially identifying data filters, including generating alternate data groupings. Further, the systems and methods may modify text responses to reduce identification risk.


