Articulo de referencia

Five safes

The Five Safes is a framework for helping make decisions about making effective use of data which is confidential or sensitive. It is mainly used to describe or design research ...

The Five Safes is a framework for helping make decisions about making effective use of data which is confidential or sensitive. It is mainly used to describe or design research access to statistical data held by government and health agencies, and by data archives such as the UK Data Service.[1] It is not an internationally accepted standard.

Two of the Five Safes refer to statistical disclosure control, and so the Five Safes is usually used to contrast statistical and non-statistical controls when comparing data management options.

Concept

The Five Safes proposes that data management decisions be considered as solving problems in five 'dimensions': projects, people, settings, data and outputs. The combination of the controls leads to 'safe use'. These are most commonly expressed as questions, for example:[2][3]

These dimensions are scales, not limits. That is, solutions can have a mix of more or fewer controls in each dimension, but the overall aim of 'safe use' independent of the particular mix. For example, a public use file available for open download cannot control who uses it, where or for what purpose, and so all the control (protection) must be in the data itself. In contrast, a file which is only accessed through a secure environment with certified users can contain very sensitive information: the non-statistical controls allow the data to be 'unsafe'. One academic likened the process to a graphic equalizer,[4] where bass and treble can be combined independently to produce a sound the listener likes, which has proven to be a very useful metaphor. This 2023 Data Foundationwebinar is an expert discussion of how the elements interact, including an excellent introductory representation.[5]

There is no 'order' to the Five Safes, in that one is necessarily more important than the others. However, Ritchie[6] argued that the 'managerial' controls (projects, people, setting) should be addressed before the 'statistical' controls (data, output).

The Five Safes concept is associated with other topics which developed from the same programme at ONS, although these are not necessarily implemented. Safe people is associated with 'active researcher management',[7] while safe outputs is linked with principles-based output statistical disclosure control.

The Five Safes is a positive framework, describing what is and is not. The EDRU ('evidence-based, default-open, risk-managed, user-centred') attitudinal model[8] is sometimes used to give a normative context

The 'data access spectrum'

From 2003 the Five Safes was also represented in a simpler form as a 'Data Access Spectrum'.[9] The non-data controls (project, people, setting, outputs) tend to work together, in that organisations often see these as a complementary set of restrictions on access. These can then be contrasted with choices about data anonymisation to present a linear representation of data access options. This presentation is consistent with the idea of 'data as a residual',[6] as well as data protection laws of the time which often characterised data simply as anonymous or not anonymous.

A similar idea had already been developed independently in 2001 by Chuck Humphrey of the Canadian RDC network, the 'continuum of access'.[10] More recently, The Open Data Institute has developed a 'Data Spectrum toolkit'[11] which includes industry-specific examples.

History and terminology

The Five Safes was devised in the winter of 2002/2003 by Felix Ritchie at the UK Office for National Statistics (ONS) to describe its secure remote-access Virtual Microdata Laboratory (VML).[12] It was described at this time as the 'VML Security Model'. This was adopted by the NORC data enclave,[13] and more widely in the US, as the 'portfolio model' (although this is now also used to refer to a slightly different legal/statistical/educational breakdown).[14] In 2012 the framework as was still being referred to as the 'VML security model',[15] but its increasing use among non-UK organisations led to the adoption of the more general and informative phrase 'Five Safes'.[2]

The original framework only had four safes (projects, people, settings and outputs): the framework was used to describe highly detailed data access through a secure environment, and so the 'data' dimension was irrelevant. From 2007 onwards, 'safe data' was included as the framework was used to a describe a wider range of ONS activities. As the US version was based upon the 2005 specification, some US iterations uses have the original four dimensions (eg[13]).

Some discussions, such as the OECD,[16] use the term 'secure' instead 'safe'. However, the use of both these terms can cause presentational problems: less control in a particular dimension could be seen to imply 'unsafe users' or 'insecure settings', for example, which distracts from the main message. Hence, the Australian government uses the term "five data sharing principles".

The 'Anonymisation Decision-Making Framework'[17] uses a framework based on the Five Safes but relabelling "projects", "people", and "settings" as "governance", "agency" and "infrastructure", respectively; "Output" is omitted, and "safe use" becomes "functional anonymisation". There is no reference to the Five Safes or any associated literature. The Australian version[18] was required to include references to the Five Safes, and presented it as an alternative without comment.

Application

The framework has had three uses: pedagogical, descriptive, and design. Since 2016, it has also been used, directly and indirectly in legislation. See [19] for more detailed examples.

Pedagogy

The first significant use of the framework, other than internal administrative use, was to structure researcher training courses at the UK Office for National Statistics from 2003. UK Data Archive, Administrative Data Research Network, Eurostat, Statistics New Zealand, the Mexican National Institute of Statistics and Geography, NORC, Statistics Canada and the Australian Bureau of Statistics, amongst others, have also used this framework. Most of these courses are for researchers using restricted-access facilities; the Eurostat courses[20] are unusual in that they are designed for all users of sensitive data.

Description

El marco se utiliza a menudo para describir soluciones de acceso a datos existentes (por ejemplo, UK HMRC Data Lab, [ 21 ] UK Data Service, [ 22 ] Statistics New Zealand [ 23 ] ) o planificadas/conceptualizadas (por ejemplo, Eurostat en 2011 [ 24 ] ). Un uso inicial [ 25 ] fue ayudar a identificar áreas donde la ONS todavía tenía "riesgos irreducibles" en su provisión de acceso remoto seguro.

El marco se utiliza principalmente para datos confidenciales de ciencias sociales. Hasta la fecha, parece haber tenido poco impacto en la planificación de la investigación médica, [ 26 ] aunque ahora está incluido en las directrices revisadas sobre la implementación de las regulaciones HIPAA [ 27 ] en los EE. UU., y por Cancer Research UK y la Health Foundation en el Reino Unido. [ 28 ] También se ha utilizado para describir un modelo de seguridad para el Programa de Informática Sanitaria de Escocia . [ 29 ]

Diseño

En general, el modelo de las Cinco Cajas de Seguridad se ha utilizado para describir soluciones a posteriori y para explicar/justificar las decisiones tomadas, pero cada vez más organizaciones lo emplean para diseñar soluciones de acceso a datos. Por ejemplo, la Agencia Estadística Helénica desarrolló una estrategia de datos basada en las Cinco Cajas de Seguridad en 2016; la Fundación de Salud del Reino Unido las utilizó para diseñar sus programas de gestión de datos y formación. [ 28 ] Su uso en el sector privado es menos frecuente, pero algunas organizaciones lo han incorporado a sus servicios de consultoría.

En 2015, el Servicio de Datos del Reino Unido organizó un taller [ 22 ] para animar a los usuarios de datos de los sectores académico y privado a pensar en cómo gestionar los datos de investigación confidenciales, utilizando las Cinco Cajas Fuertes para demostrar opciones alternativas y mejores prácticas .

Los primeros en adoptar el diseño estratégico se encontraban en Australia: tanto la Oficina Australiana de Estadística como el Departamento Australiano de Servicios Sociales utilizaron los Cinco Principios de Seguridad como herramienta de diseño ex ante. [ 3 ] [ 8 ] En 2017, la Comisión Australiana de Productividad recomendó [ 30 ] adoptar una versión del marco para apoyar el intercambio y la reutilización de datos entre gobiernos. Esto fue objeto de una amplia consulta y culminó en la Ley DAT de 2022.

Since 2020 the Five Safes has been the overriding framework for the design of new secure facilities and data sharing arrangements in the UK for public health and social sciences. This has been promoted by the Office for Statistics Regulation, the UK Statistics Authority, NHS DIgital, and the research funding bodies Administrative Data Research UK and DARE UK.

Regulation and legislation

Three laws have incorporated the Fives Safes. They are explicit in the South Australian Public Sector (Data Sharing) Act 2016, and implicit in the research provisions of the UK Digital Economy Act 2017. The Australian Data Availability and Transparency Act 2022 renames the Five Safes as the Five Data Sharing Principles.A 2025 statutory review of the DAT Act 2022 found "that the DAT Act has not been effective in achieving its objectives."[31]. The review includes specific references to the challenges associated with the Safes model being implemented in practice "The DAT Act’s current approach to the Five Safes is not strictly a principles-based approach, noting that they are embedded within and enabled through the DAT Act’s very prescriptive, rules-based approach."

Public engagement

The UK Data Service has produced a blog[32] and video[33] for the general public about the use of Five Safes in re-using administrative data. Statistics New Zealand produced a non-technical description,[34] as did ONS for Data Privacy Day 2017. [35] The Australian Federal Government has produced several videos on data sharing, including the Data Sharing Principles. [36]

Criticism

In the 2020 paper, "Not fit for Purpose: A critical analysis of the ‘Five Safes’", [37] the authors argue that Five Safes is fundamentally flawed due to its disconnection from existing legal protections, its appropriation of safety notions without strong technical measures, and its static view of disclosure risk. Others have argued that the Five Safes has too little content to be useful, or is a box-ticking exercise, or that more 'safes' are needed. Green and Ritchie (2023)[19] provide an extensive review of these critiques and proposals. International standards (such as ISO/IEC/JTC1) for data sharing and use should be considered for robust data sharing frameworks.

References

  1. ^"What is the Five Safes framework?". www.ukdataservice.ac.uk. UK Data Service. Retrieved 2017-01-25.
  2. ^ abDesai, Tanvi; Ritchie, Felix; Welpton, Richard (2016). "Five Safes: designing data access for research"(PDF). Bristol Business School Working Papers in Economics: Footnote 1.
  3. ^ ab"1015.0 - Information Paper: Transforming Statistics for the Future". www.abs.gov.au. Australian Bureau of Statistics. 2016. Retrieved 2017-01-25.
  4. ^McEachern, Steve (2015). "Implementation of the Trusted Access Model"(PDF). Australian Data Archive.
  5. ^Hawes, Michael (2023). The Five Safes Framework. Conference presentation: The Vision of Privacy under the Evidence Act. Data Foundation.
  6. ^ abRitchie, Felix (2017). The 'Five Safes': a framework for planning, designing and evaluating data access solutions. Data for Policy. doi:10.5281/zenodo.897821.
  7. ^Desai, Tanvi; Ritchie, Felix (2009). "Effective Researcher Management"(PDF). www.unece.org. Eurostat. Retrieved 2017-01-25.
  8. ^ abGreen, Elizabeth; Ritchie, Felix (2016). "Department of Social Services data access project final report. Project Report".
  9. ^Ritchie, Felix (2009). "Designing a national model for data access". Comparative Analysis of Enterprise (Micro)Data 2009. Retrieved 16 April 2020.
  10. ^Humphrey, Charles (Chuck) (2001). "The Data Liberation Initiative Orientation Session".
  11. ^"ODI Data Spectrum". Open Data Institute. 26 September 2020.
  12. ^Ritchie, Felix (2008). "Secure access to confidential microdata: four years of the Virtual Microdata Laboratory"(PDF). Economic and Labour Market Statistics. 2 (5): 29–34. doi:10.1057/elmr.2008.73. S2CID 154673912.
  13. ^ abLane, Julia; Bowie, Chet; Scheuren, Fritz; Mulcahy, Tim (2009). "NORC Data Enclave:Providing Secure Remote Access to Sensitive Microdata". UNECE/EU Workshop on Statistical Confidentiality 2009.
  14. ^Lane, Julia; Heus, Pascal; Mulcahy, Tim (2008). "Data Access in a Cyber World: Making Use of Cyberinfrastructure". Transactions in Data Privacy: 2–16. S2CID 16923006.
  15. ^Felix, Ritchie (2013-01-01). "International access to restricted data: A principles-based standards approach". Statistical Journal of the IAOS. 29 (4): 289–300. doi:10.3233/sji-130780. ISSN 1874-7655.
  16. ^Volkow, Natalia. "OECD Expert Group For International Collaboration On Microdata Access, Chapter 6. Standardised Application Process For Microdata Access"(PDF). www.oecd.org. OECD. pp. 73–79. Retrieved 2017-01-25.
  17. ^Elliot, Mark; Mackey, Elaine; O'Hara, Kieran; Tudor, Caroline (2016). Anonymisation Decision-Making Framework(PDF). University of Manchester. Archived from the original(PDF) on 2020-09-20. Retrieved 2020-04-16.
  18. ^O'Keefe, Christine; Otorepec, Stephanie; Elliot, Mark; Mackay, Elaine; O'Hara, Kieran (2017). De-identification decision-making framework. CSIRO. doi:10.4225/08/59c169433efd4.
  19. ^ abGreen, Elizabeth; Ritchie, Felix (2023-11-30). "The present and future of the Five Safes framework". Journal of Privacy and Confidentiality. 13 (2). doi:10.29012/jpc.831. ISSN 2575-8527.
  20. ^"Self-study material for the users of European microdatasets". ec.europa.eu. European Commission. Retrieved 2017-01-25.
  21. ^Hawkins, Mike (2011). "The HMRC Datalab". slideserve.com. Retrieved 2017-01-25.
  22. ^ ab"The 5 safes of access to confidential data". www.ukdataservice.ac.uk. UK Data Service. Archived from the original on 2017-02-02. Retrieved 2017-01-25.
  23. ^Camden, Mike (2011). "Confidentiality for integrated data"(PDF). www.unece.org. Eurostat. Retrieved 2017-01-25.
  24. ^Bujnowska, Aleksandra; Museux, Jean-Marc (2011). "The Future of Access to European Confidential Data for Scientific Purposes"(PDF). www.unece.org. Eurostat. Retrieved 2017-01-25.
  25. ^Ritchie, Felix (2005). "Access to business microdata in the UK: dealing with the irreducible risks"(PDF). UNECE/Eurostat Workshop on Statistical Data Confidentiality 2005.
  26. ^Green, Elizabeth (2015). "Enabling data linkage to maximise the value of public health research data"(PDF). Public Health Research Data Forum Commissioned Reports. et al. Wellcome Trust.
  27. ^Council, National Research (2014-01-09). Proposed Revisions to the Common Rule for the Protection of Human Subjects in the Behavioral and Social Sciences. doi:10.17226/18614. ISBN 9780309298063. PMID 25032406.
  28. ^ abWolters, Arne (2015). "Governance and the HSCIC's IG toolkit"(PDF). ukdataservice.ac.uk. Retrieved 2017-01-25.
  29. ^Sullivan, Frank. "The Scottish Health Informatics Programme". www.rss.org.uk. Retrieved 2017-01-25.
  30. ^Data Availability and Use: Australian Productivity Commission Inquiry Report. Productivity Commission. 2017. ISBN 978-1-74037-617-4.
  31. ^Department of Finance (2025). "Statutory Review of the Data Availability and Transparency Act 2022 – Final Report"(PDF). Commonwealth Department of Finance website. Retrieved 1 April 2026.
  32. ^Welpton, Richard; Corti, Louise. "Access to sensitive data for research: the five safes". blog.ukdataservice.ac.ukpublisher=UK Data Service. Retrieved 2017-01-25.
  33. ^"Five Safes video". www.youtube.com. UK Data Service. Retrieved 2017-01-25.
  34. ^"How we keep IDI data safe". www.stats.govt.nzpublisher=Statistics New Zealand. Retrieved 2017-01-25.
  35. ^Stokes, Pete (2017). "The Five Safes: data privacy at ONS". blog.ons.gov.uk. Office for National Statistics. Retrieved 2017-01-28.
  36. ^Office of the National Data Commissioner (2022). "Sharing data safely". ONDC.
  37. ^Culnane, Chris; Rubinstein, Benjamin I. P.; Watts, David (2020). "Not fit for Purpose: A critical analysis of the 'Five Safes'". arXiv:2011.02142 [cs.CR].
Retrieved from "https://en.wikipedia.org/w/index.php?title=Five_safes&oldid=1346499934"