Preview

Digital Solutions and Artificial Intelligence Technologies

Advanced search

Depersonalization of personal data in the banking sector: Analysis of methods and selection of an implementation strategy

https://doi.org/10.26794/3030-7097-2026-2-3-26-33

Abstract

This article examines the pressing issue of personal data anonymization in credit and financial institutions (CFIs) in the context of tightening regulatory requirements, in particular, Roskomnadzor Order No. 140. It analyzes classic and modern anonymization methods (masking, pseudonymization, synthetic data generation, etc.) for their applicability in a banking environment where preserving data formats, referential integrity, and high performance are critical. A comparative assessment of three modern domestic solutions is provided: DataMask, Garda Data Masking, and N1 AI. Their systemic limitations are identified, including potential non-compliance with new regulations, insufficient flexibility for unique banking entities, and high cost of ownership. Based on this analysis, the strategic feasibility of developing a specialized internal anonymization tool is substantiated. This tool guarantees full regulatory compliance, maximum adaptability to the bank’s business processes, and long-term economic efficiency. A credit and financial institution is characterized by processing an extensive array of structured personal data (PD), which combines the features of general, other data, and information that constitutes bank secrecy. This information is typically stored in relational databases in a formalized format (separate fields for passport number, phone number, account number, etc.), which, on the one hand, simplifies their automated search, but on the other hand, requires strict protection measures, including secure anonymization for use in non-production environments. This determines the key requirements for the system under consideration: the need to accurately detect fields of various categories of financial and identifying information, and the use of masking algorithms that ensure irreversible conversion while preserving the structural integrity and data format for the correct operation of test systems.

About the Authors

E. K. Baranova
Financial University under the Government of the Russian Federation
Russian Federation

Elena K. Baranova — Assoc. Prof., Department of Information Security

Moscow



Ya. V. Lebedkina
Financial University under the Government of the Russian Federation
Russian Federation

Yana V. Lebedkina — bachelor student, Department of Information Security

Moscow



References

1. Almukhametova E. I., Shaimardanov I. F. Relevance and methods of depersonalization of personal data. In: Advanced engineering solutions in oil refining and petrochemistry. Salavat: Ufa State Petroleum Technical University; 2025:261-263. URL: https://elibrary.ru/ffypro (In Russ.).

2. Alekseev D. V., Tumbinskaya M. V. Modern methods of depersonalization of personal data: analysis of effectiveness and development directions. In: Digital Systems and Models: theory and practice of design, development and use. Kazan: Kazan State Power Engineering University; 2025:2036-2039. URL: https://elibrary.ru/wldthv (In Russ.).

3. Kolbasov V.V. Personal data: depersonalization of personal data processed in personal data information systems. Non-profit organizations in Russia. 2017;1:59-62. URL: https://elibrary.ru/zegwvv (In Russ.).

4. Kuchin I. Y. Protection of the confidentiality of personal data through depersonalization. Bulletin of the Astrakhan State Technical University. Series: Management, Computer Engineering and Computer Science. 2010;2:158-162. URL: https://elibrary.ru/muyqhf (In Russ.).

5. Poluyanova E.V. Topical issues related to depersonalization of personal data in the Russian Federation. Trends in the Development of Science and Education. 2024;114-6:36-38. (In Russ.). URL: https://doi.org/10.18411/trnio-10-2024-243

6. Chepik P. I. Depersonalization of personal data as a way to increase their protection during processing in information systems. In: Secure Information technologies. Moscow: Bauman Moscow State Technical University; 2023;150-153. URL: https://elibrary.ru/tktuem (In Russ.).

7. Alekseev D. V., Tumbinskaya M. V. Modern methods of depersonalization of personal data: analysis of effectiveness and development directions. In: Digital Systems and Models: Theory and practice of design, development and use. Kazan; 2025:2036-2039. URL: https://elibrary.ru/wldthv (In Russ.).

8. Borisov A.V. Application of simulation computer modeling to the problem of depersonalization of personal data. Assessment of the condition and the main provisions. Programming. 2023;4:58-74. (In Russ.). URL: https://doi.org/10.31857/S0132347423040040

9. Besov V.V., Danilova E. Z., Mekuria D.V. Methods of depersonalization of user data: an analysis of applicability in the context of modern privacy requirements. Telecommunications and Information Technology. 2025;12(1):84-89. URL: https://elibrary.ru/xjkqtn (In Russ.).

10. Mishchenko E.Yu., Sokolov A. N. Algorithms for implementing methods of depersonalization of personal data in distributed information systems. Reports of Tomsk State University of Control Systems and Radio Electronics. 2019;22(1):66-70. (In Russ.). URL: https://doi.org/10.21293/1818-0442-2019-22-1-7-66-70

11. Malyavko A. A., Reutov V. V., Korotkov I. V., Shperling V. K. Algorithms, methods and approaches to depersonalization and enrichment of data, including personal data. Digital Technology Security. 2022;4(107):9-26. (In Russ.). URL: https://doi.org/10.17212/2782-2230-2022-4-9-26

12. Guseva T. M., Karabanova A. N., Blimgotov T. K. Protection of personal data by depersonalization. In: Theory and practice of the application of new information technologies. Stavropol: AGRUS Publishing House; 2020:103-106. URL: https://elibrary.ru/jssuvn (In Russ.).

13. Marshalko G. B., Dali F.A., Savinykh A. N. Comparative analysis of methods of depersonalization of personal data. In: Methods and technical means of ensuring information security. St. Petersburg; 2022:161-163. URL: https://elibrary.ru/wppbqj (In Russ.).

14. Uchaeva E. S., Fot Yu. D. Research of methods of depersonalization of personal data. In: Current issues of ensuring integrated security. Orenburg; 2025:1570-1574. URL: https://elibrary.ru/eevaeh (In Russ.).


Review

For citations:


Baranova E.K., Lebedkina Ya.V. Depersonalization of personal data in the banking sector: Analysis of methods and selection of an implementation strategy. Digital Solutions and Artificial Intelligence Technologies. 2026;2(3):26-33. (In Russ.) https://doi.org/10.26794/3030-7097-2026-2-3-26-33

Views: 133

JATS XML


Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.


ISSN 3033-7097 (Online)