Lupta · Consent-Fit Decision Memo

Secondary research use permitted after age + pincode generalization

De-identification decisioning under India's DPDP framework · 2026-07-08
Your control — this memo assesses a proposed release; the data fiduciary decides. Every number here came from a deterministic tool, not the model.
Approve with transforms Release permitted only after the transforms below.

Consent analysis

Specified purpose
The original cardiac-outcomes study only.
Lawful basis
Research exemption (§17(2)(b))
Fit
exceeds consent

The proposed cross-institution model exceeds the study-specific consent; it may proceed only under the §17(2)(b) research exemption, and only if no decision is taken specific to an individual.

Identifiers

Direct
patient_namemrn
Quasi
agesexpincodeadmission_date
Sensitive
diagnosis

Risk findings — every figure from a tool

MetricValueSource tool
k (raw QI set)1compute_k
records at risk (k<2)7compute_k
prosecutor max risk1.0reidentification_risk
k after age->band, pincode->district6compute_k

Linkage reasoning

An 89-year-old female with a rare restrictive cardiomyopathy (I42.5) in a low-population pincode is population-unique against the electoral roll even though the sample shows k=1.

Recommended transforms

ColumnActionRationale
agegeneralize to 5-year bandscollapses rare elderly singletons
pincodetruncate to district prefixremoves sub-district uniqueness

DPDP citations

AssertionProvision
Proposed use exceeds the consented purpose§6(1) read with §2(za)
Research exemption applies subject to standards§17(2)(b); Rule 16 + Second Schedule

Residual risk. Journalist risk not computed for the raw set; assess against Census priors before release.

Your control

DPDP provisions cited here are notified but enforceable from 13 May 2027. Anonymization under DPDP is a definitional question (§2(t)) with no prescribed statutory standard — re-identification risk above is assessed per the stated k-anonymity methodology, not against a legal threshold.

Lupta · consent-aware de-identification decisioning · generated 2026-07-08
Claude reasons; a deterministic engine owns every number. No figure in this memo was produced by the model.