<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">10</article-id>
      <title-group>
        <article-title>Personal data depersonalization algorithm for transfer to test development environments in government bodies and organizations</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Алгоритм обезличивания персональных данных при передаче в тестовые среды разработки в государственных органах и организациях</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0002-8319-8237</contrib-id>
          <name>
            <surname>Baryshnikova</surname>
            <given-names>Alena</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>baryshnikova1309@yandex.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0002-9304-3757</contrib-id>
          <name>
            <surname>Morozov</surname>
            <given-names>Ilya</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
          <email>morozowilui@gmail.com</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">National University of Oil and Gas “Gubkin University”</aff>
      <aff id="aff2">National University of Oil and Gas "Gubkin University"</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-10-09">
        <day>09</day>
        <month>10</month>
        <year>2026</year>
      </pub-date>
      <issue>3</issue>
      <fpage>131</fpage>
      <lpage>144</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/images/oblozhki/3_2026.png"/>
      <abstract xml:lang="en">
        <p>The digital transformation of public administration is accompanied by the intensive development of automated information systems that process significant amounts of personal data of citizens. The practice of preparing test environments by copying records from operational databases creates serious risks of unauthorized dissemination of personal data, primarily from internal intruders with legitimate access to information resources. The article analyzes the problem of personal data protection when they are transferred to test development environments in government agencies and organizations. The analysis of the typical organizational structure and information flows is carried out, the model of the internal violator is formalized, the target threat of homicide is considered.096 (“Copying”) according to the Basic Threat Document of the FSTEC of Russia. An irreversible deconstruction algorithm is proposed that combines deterministic hashing with a unique salt based on the Keccak‑256 algorithm and context-sensitive masking. The algorithm complies with the requirements of Federal Law No. 152-FZ “On Personal Data”, Federal Law No. 187-FZ “On the Security of Critical Information Infrastructure”, GOST R57700.34–2017 and the Basic Threat Document of the FSTEC of Russia. The integrability of the solution into CI/CD pipelines is shown without reducing the flexibility of development. The results demonstrate the applicability of the proposed approach both in educational and other government organizations operating information systems with arrays of structured personal data.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Personal data</kwd>
        <kwd>depersonalization</kwd>
        <kwd>test environment</kwd>
        <kwd>information security</kwd>
        <kwd>internal intruder</kwd>
        <kwd>Keccak‑256</kwd>
        <kwd>CI/CD</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
