The takeaway
Ask how privacy risk is assessed across the full dataset, including free text, attachments, and combinations of fields.
Start with the intended use and recipient
Before preparing a dataset for sharing, define who would receive it, what they need it for, and which details the task actually requires. That makes the privacy conversation specific. A high-level study of issue categories may need a different set of fields from an evaluation of complete troubleshooting sequences.
Ask your review team to separate the information needed for the proposed task from information that happens to be available. The first decision is scope. Preparation should follow that decision rather than assume everything must be included.
Look beyond obvious identifiers
NIST's guidance on de-identification describes both direct identifiers and other attributes that can contribute to identification. It also emphasizes evaluating disclosure risk and the chosen sharing model. Its guidance is written for government datasets, but those concepts are useful questions for a business review.
In an illustrative service record, deleting a customer's name might still leave a precise address, an unusual job description, or a detailed incident narrative. A reviewer should consider what the remaining information reveals in combination.
Review free text and attachments deliberately
Create a checklist of the places information can hide: ticket bodies, email signatures, quoted replies, file names, screenshots, document properties, and attachment contents. Ask whether the proposed review actually covers these areas or only the structured table columns.
Also separate personal information from other sensitive business material. Credentials, confidential pricing, proprietary designs, and customer commitments may require different handling. A process focused on names and email addresses may not address those concerns.
Preserve useful relationships carefully
A workflow can depend on knowing that two records concern the same case. Ask whether the preparation process can preserve the necessary relationship without preserving unnecessary identity details. Document which references were transformed and who, if anyone, can reverse or reconnect them.
NIST cautions that tools which merely mask information may be insufficient for de-identification. Avoid treating a completed automated scan as the entire review. Agree on how outputs will be inspected and how uncertain cases will be handled.
Ask for a review you can understand
Before approving a proposed release, request a plain-language explanation of the included data, exclusions, transformations, residual concerns, and access conditions. Identify who signs off and what triggers another review, such as a new field or a refreshed export.
Keep privacy preparation and permission review connected. An altered dataset still needs an appropriate basis for the proposed use. For your first assessment, a description of systems and record types is usually a better discussion document than an unsolicited sample of real records.
Sources & further reading
Sources checked October 2, 2026.