Zum Inhalt

Image Anonymization and Consent Process for EPPA

Research document for GitHub issue #93. Date: 2026-05-19


Table of Contents

  1. Applicable Norms and Regulations
  2. Common Practices in Biomechanics Literature
  3. Recommended Approach for EPPA
  4. Implementation Plan
  5. Consent Workflow
  6. Sources

1. Applicable Norms and Regulations

1.1 HIPAA (United States) — Safe Harbor Method

HIPAA provides two de-identification pathways: Expert Determination and Safe Harbor. The Safe Harbor method enumerates 18 identifier categories that must be removed, and explicitly lists:

"Full-face photographs and any comparable images"

as protected health information (PHI). For EPPA's clinical photography:

  • All facial photographs are PHI — even when not accompanied by a name or medical record number.
  • The Safe Harbor standard requires removal or obscuration of facial features that could permit identification.
  • The NCI (National Cancer Institute) launched the MIDI-B Challenge (Medical Image De-Identification Benchmark, 2024) to standardize and benchmark de-identification tools conformant to HIPAA Safe Harbor, signaling that regulatory bodies consider this an active area of evolving standards.

Key takeaway: Eye bars alone are considered insufficient by HIPAA standards. Full-face obscuration or defacing that prevents identification is required.

1.2 GDPR (European Union)

Under GDPR, medical images are personal data (and often special category data under Article 9):

  • Anonymization is itself considered data processing, requiring a legal basis (consent, legitimate interest, etc.).
  • Once truly anonymized (irreversible), the data exits GDPR scope entirely.
  • Pseudonymized data (reversible mapping) remains within GDPR scope.
  • For clinical research photography, the French CNIL and the University of Malta Research Ethics Committee (UREC) both specify that facial images require either:
  • Written informed consent for publication, OR
  • Anonymization that renders the individual not reasonably identifiable by any means.
  • Even with full anonymization, best practice is to inform the patient that images were taken and anonymized.

Key takeaway: GDPR demands a higher bar than HIPAA in some respects — the anonymization must be irreversible for the data to fall outside regulation. A simple overlay that could theoretically be reversed (e.g., a semi-transparent blur) would not qualify.

1.3 ISO Standards

Standard Scope Relevance
ISO 25237:2017 — Health Informatics: Pseudonymization Defines principles for pseudonymization services, including organizational/technical aspects and controlled re-identification Directly applicable. Establishes that pseudonymization must have documented policies for when/if re-identification is permitted. For EPPA, anonymization (irreversible) is preferred over pseudonymization (reversible).
ISO 27799 — Information Security Management in Health Extends ISO/IEC 27002 for health organizations Referenced by ISO 25237. Provides the security management framework within which image anonymization policies should operate.
ISO/IEC 29100 — Privacy Framework General privacy architecture Provides the vocabulary and principles (consent, purpose limitation, data minimization) that inform any health data anonymization design.

Key takeaway: ISO 25237 distinguishes clearly between pseudonymization (reversible, key-managed) and anonymization (irreversible, no key). EPPA should implement anonymization (destructive masking) on exported images, not pseudonymization.

1.4 Argentine Regulations

Ley 25.326 — Proteccion de Datos Personales

Argentina's comprehensive data protection law (2000, with updates) classifies health data as sensitive data (Art. 2 and Art. 7):

  • Sensitive data can only be processed with explicit consent or when authorized by law for specific purposes.
  • Art. 28 (exemption): The law's provisions do not apply to scientific or medical research activities as long as the collected data cannot be attributed to a determined or determinable person. If anonymity cannot be maintained during collection, a dissociation technique must be applied so that no individual is identifiable.
  • Medical data exchange is permitted for treatment or epidemiological research, under the law's terms.

This means: EPPA images that retain facial identity are sensitive personal data under Argentine law. They must be either: 1. Processed with explicit consent, or 2. Anonymized via dissociation technique so the person is not determinable.

ANMAT Disposiciones

  • Disposicion 6677/2010 — Good Clinical Practices for pharmacological studies. Mandates informed consent and CEI (Comite de Etica en Investigacion) approval for any research involving human subjects. While focused on drug trials, it establishes the consent framework that ethics committees apply to all health research.
  • Disposicion 7516/2025 — Updated Good Clinical Practices (effective December 2025). Reinforces the CEI oversight requirements.
  • Resolucion Ministerial 1480/2011 — Guide for Health Research in Humans. Broad mandate: any research involving human subjects requires ethics committee approval and informed consent.

Practical Implications for EPPA

Since EPPA is a postural evaluation tool used in clinical/academic settings (not a drug trial), it falls under: - Ley 25.326 for data protection. - Res. 1480/2011 for general health research ethics. - The institutional CEI of the university or hospital where evaluations occur.

The CEI will require evidence that the software either: - Obtains informed consent for image capture AND storage, or - Applies a validated anonymization process that renders subjects non-identifiable in any exported output.


2. Common Practices in Biomechanics Literature

2.1 Published Research on Anonymization in Posture/Biomechanics

Paper 1: "Effect of Face Blurring on Human Pose Estimation: Ensuring Subject Privacy for Medical and Occupational Health Applications" - Permusic et al., Sensors (MDPI), Vol. 22, Issue 23, Article 9376, December 2022. - Findings: Face blurring has a negligible effect on human pose estimation accuracy (< 1 degree difference in joint angles). This validates that face blurring does not degrade biomechanical analysis when the analysis concerns body landmarks below the face. - Relevance to EPPA: Confirms that masking the face region will not affect postural angle calculations for trunk, limbs, and pelvis. However, EPPA also uses facial landmarks (Eminencia Frontal Media, Espina Nasal, Tragus, Punto Mentoniano) — these must remain visible/usable during analysis but can be masked in exported images.

Paper 2: "Standardization of Guidelines for Patient Photograph Deidentification" - Bared et al., Annals of Plastic Surgery, Vol. 76, Issue 6, pp. S305-S308, June 2016. - Findings: 87% of de-identified images in medical journals were inadequately concealed. The most common technique (eye-bar only) was found insufficient. The paper recommends that both eyebrows and eyes must be concealed to ensure anonymity. - Relevance to EPPA: The standard eye-bar is not enough. EPPA must mask from forehead to below the nose at minimum to be defensible.

Paper 3: "Anonymizing Facial Images to Improve Patient Privacy" - Schwarz et al., Nature Medicine, Vol. 28, pp. 1902-1903, September 2022. - Findings: A "digital mask" approach was developed to erase identifiable features while preserving disease-relevant features. However, a subsequent correspondence (Schwarz & Bhandarkar, Nature Medicine, 2023) raised concerns that digital masks may not irreversibly erase identity, making them potentially insufficient for rigorous privacy standards. - Relevance to EPPA: Reinforces that destructive masking (solid fill, heavy pixelation) is safer than generative/smoothing approaches that might be reversed.

2.2 What Posturography Papers Typically Do

In the posture analysis literature (e.g., Ferreira et al., "Photographic analysis of human posture: A literature review," Journal of Bodywork and Movement Therapies, 2014):

  • Subjects are typically photographed in minimal clothing with reflective markers on anatomical landmarks.
  • Published images most commonly use:
  • Full body silhouettes (black outline on white background)
  • Heavy pixelation/blur of the entire face region
  • Black rectangles over eyes + nose + mouth
  • Some papers show unblurred faces with explicit written consent referenced in the methods section.
  • The trend since ~2020 is increasing scrutiny from ethics committees, with many now requiring either full face anonymization OR proof of explicit photo-release consent.

3.0 Scope and Legal/Regulatory Limit

The EPPA anonymization workflow is intended to reduce operational sharing risk by producing a separate anonymized export while preserving the clinical working image and measurements. It is not a legal or regulatory certification, and it does not replace patient consent, institutional ethics review, data-protection assessment, or site-specific policy approval.

3.1 Core Principle

Anonymize at export time, not during analysis.

The evaluator needs to see the full face to place markers on Eminencia Frontal Media, Espina Nasal, Tragus, and Punto Mentoniano. But the exported image (PNG capture) and any shared reports should have the face region masked.

3.2 What to Mask

For the anterior view (where facial markers exist):

+---------------------------+
|                           |
|   [MASK ZONE - Solid]     |  <- From top of forehead (above Eminencia Frontal Media)
|   Eyes, eyebrows, nose,   |     to below chin (below Punto Mentoniano)
|   mouth, ears (if visible) |     Width: ear-to-ear (Tragus to Tragus)
|                           |
+---------------------------+

Mask zone definition: - Top edge: 15% above the highest facial marker (Eminencia Frontal Media) to cover forehead/hairline. - Bottom edge: 10% below Punto Mentoniano to cover the chin fully. - Left/Right edges: 10% beyond Tragus Izq./Der. to cover ears and cheek contour.

What is preserved: - The marker points themselves (small colored dots) remain visible on the masked region — they show anatomical position without revealing identity. - Reference lines and angle annotations drawn over the mask zone remain visible. - All body landmarks below the neck are unaffected.

For lateral views (Lateral Izquierda, Lateral Derecha): - Mask the head profile from forehead to chin, preserving the Tragus marker point.

For posterior view: - Typically no facial features visible; mask the back of the head if hair/ear profile could identify the subject.

3.3 Mask Style

Recommended: Solid opaque rectangle (black or dark gray) with marker dots overlaid.

Rationale: - Solid fill is irreversible — no algorithm can recover the underlying pixels. This satisfies GDPR irreversibility and HIPAA Safe Harbor requirements. - Blur/pixelation is NOT recommended as primary method — research has shown that heavy pixelation can sometimes be reversed, and it does not meet the GDPR irreversibility standard. - Marker dots overlaid on the solid fill preserve the analytical value (you can see where Eminencia Frontal Media, Espina Nasal, etc. are positioned relative to body landmarks).

Alternative (user-configurable): Gaussian blur with radius >= 40px as a secondary option, with a warning that blur is considered less robust than solid masking.

3.4 Summary Matrix

View Markers in Face Zone Mask Region Mask Type
Anterior Eminencia Frontal Media, Espina Nasal, Punto Mentoniano, Tragus Izq., Tragus Der. Forehead to below chin, ear to ear Solid + marker dots overlaid
Lateral Izq. Tragus Izq. Full head profile Solid + marker dot overlaid
Lateral Der. Tragus Der. Full head profile Solid + marker dot overlaid
Posterior None typically Back of head (optional) Solid (if enabled)

4. Implementation Plan: JavaScript Canvas-Based Face Region Masking

4.1 Architecture Overview

The anonymization should be applied at the moment of image export (the handleCaptureClick function that already uses html2canvas). It should NOT modify the live UI — the evaluator works with the unmasked image during analysis.

[Live Analysis UI] --> evaluator places markers, runs analysis
                   |
                   v
[Export Button] --> html2canvas captures the element
                   |
                   v
[Anonymization Layer] --> canvas post-processing: draw mask over face region
                   |
                   v
[Consent Check] --> modal: "Has the subject consented to image capture? Anonymization will be applied."
                   |
                   v
[Download PNG] --> anonymized image saved

4.2 Step-by-Step Implementation

Step 1: Define Face Region from Markers

The facial markers already placed by the evaluator define the face zone. Use them to compute the mask rectangle:

// In a new utility: src/lib/anonymization.ts

interface FaceRegion {
  top: number;    // y-coordinate: min of facial markers - padding
  bottom: number; // y-coordinate: max of facial markers + padding
  left: number;   // x-coordinate: min of facial markers - padding
  right: number;  // x-coordinate: max of facial markers + padding
}

const FACIAL_MARKER_IDS = {
  anterior: ['12', '13', '14', '15', '16'], // EFM, EN, PM, TI, TD
  lateralIzq: ['52'],                        // Tragus Izq
  lateralDer: ['32'],                        // Tragus Der
};

function computeFaceRegion(
  markers: Map<string, { x: number; y: number }>,
  view: 'anterior' | 'lateralIzq' | 'lateralDer' | 'posterior',
  imageWidth: number,
  imageHeight: number
): FaceRegion | null {
  const facialIds = FACIAL_MARKER_IDS[view];
  if (!facialIds) return null;

  const facialPoints = facialIds
    .map(id => markers.get(id))
    .filter(Boolean) as { x: number; y: number }[];

  if (facialPoints.length === 0) return null;

  const xs = facialPoints.map(p => p.x);
  const ys = facialPoints.map(p => p.y);

  const minX = Math.min(...xs);
  const maxX = Math.max(...xs);
  const minY = Math.min(...ys);
  const maxY = Math.max(...ys);

  // Padding: expand beyond outermost markers
  const width = maxX - minX || imageWidth * 0.15;
  const height = maxY - minY || imageHeight * 0.15;
  const padX = width * 0.35;  // 35% horizontal padding
  const padY = height * 0.25; // 25% vertical padding (more above for forehead)

  return {
    top: Math.max(0, minY - padY * 1.5),     // Extra padding above for forehead
    bottom: Math.min(imageHeight, maxY + padY),
    left: Math.max(0, minX - padX),
    right: Math.min(imageWidth, maxX + padX),
  };
}

Step 2: Apply Mask to Canvas

After html2canvas generates the canvas, apply the mask before converting to data URL:

function applyAnonymizationMask(
  canvas: HTMLCanvasElement,
  faceRegion: FaceRegion,
  markerPositions: Array<{ x: number; y: number; label: string }>,
  options: {
    maskColor?: string;      // default: '#1a1a1a'
    maskOpacity?: number;    // default: 1.0
    showMarkerDots?: boolean; // default: true
    markerDotRadius?: number; // default: 4
    markerDotColor?: string;  // default: '#00ff00'
  } = {}
): void {
  const ctx = canvas.getContext('2d');
  if (!ctx) return;

  const {
    maskColor = '#1a1a1a',
    maskOpacity = 1.0,
    showMarkerDots = true,
    markerDotRadius = 4,
    markerDotColor = '#00ff00',
  } = options;

  // Draw solid mask rectangle
  ctx.save();
  ctx.globalAlpha = maskOpacity;
  ctx.fillStyle = maskColor;
  ctx.fillRect(
    faceRegion.left,
    faceRegion.top,
    faceRegion.right - faceRegion.left,
    faceRegion.bottom - faceRegion.top
  );
  ctx.restore();

  // Re-draw marker dots on top of mask
  if (showMarkerDots) {
    ctx.save();
    ctx.fillStyle = markerDotColor;
    for (const marker of markerPositions) {
      ctx.beginPath();
      ctx.arc(marker.x, marker.y, markerDotRadius, 0, Math.PI * 2);
      ctx.fill();
      // Optional: label next to dot
      ctx.fillStyle = '#ffffff';
      ctx.font = '10px sans-serif';
      ctx.fillText(marker.label, marker.x + markerDotRadius + 2, marker.y + 3);
      ctx.fillStyle = markerDotColor;
    }
    ctx.restore();
  }
}

Step 3: Integrate into Export Flow

Modify the existing handleCaptureClick in each analysis page:

// In anterior/page.tsx (and similar for lateral views)

const handleCaptureClick = async () => {
  // ... existing html2canvas capture ...

  const canvas = await html2canvas(targetElement, { /* existing options */ });

  // NEW: Compute face region from placed markers
  const faceRegion = computeFaceRegion(
    placedMarkers,  // existing state: Map<string, {x, y}>
    'anterior',
    canvas.width,
    canvas.height
  );

  // NEW: Apply anonymization if face region was detected
  if (faceRegion && anonymizationEnabled) {
    const facialMarkerPositions = FACIAL_MARKER_IDS.anterior
      .map(id => {
        const pos = placedMarkers.get(id);
        const def = anteriorMarkers.find(m => m.value === id);
        return pos ? { x: pos.x, y: pos.y, label: def?.label || id } : null;
      })
      .filter(Boolean);

    applyAnonymizationMask(canvas, faceRegion, facialMarkerPositions);
  }

  // Existing: convert to data URL and download
  const dataUrl = canvas.toDataURL('image/png');
  // ... rest of existing download logic ...
};

Step 4: Add UI Toggle

Add an anonymization toggle in the analysis toolbar, defaulting to ON:

// State
const [anonymizationEnabled, setAnonymizationEnabled] = useState(true);

// UI element (in the toolbar/button area)
<div className="flex items-center gap-2">
  <Switch
    checked={anonymizationEnabled}
    onCheckedChange={setAnonymizationEnabled}
    id="anonymization-toggle"
  />
  <Label htmlFor="anonymization-toggle" className="text-sm">
    Anonimizar rostro en exportacion
  </Label>
</div>

Step 5: Fallback — Manual Region Selection

If no facial markers have been placed (e.g., the evaluator only placed body markers), the system should:

  1. Show a warning: "No se detectaron marcadores faciales. La region de anonimizacion no puede calcularse automaticamente."
  2. Offer a manual rectangle-draw tool on the canvas preview before download.
  3. Alternatively, use a fixed proportional region (top 25% of image, full width) as a conservative fallback.

4.3 File Structure

src/
  lib/
    anonymization.ts          # NEW: computeFaceRegion, applyAnonymizationMask
    anonymization.test.ts     # NEW: unit tests for region computation
  app/
    analysis/
      anterior/page.tsx       # MODIFIED: integrate anonymization into export
      lateral-izquierda/page.tsx  # MODIFIED: same
      lateral-derecha/page.tsx    # MODIFIED: same
      posterior/page.tsx          # MODIFIED: optional head-back mask
  components/
    anonymization-toggle.tsx  # NEW: reusable toggle component
    consent-dialog.tsx        # NEW: consent confirmation modal

4.4 Testing Plan

Test Type Description
Region computation with all markers Unit Verify FaceRegion bounds are correct given known marker positions
Region computation with missing markers Unit Verify graceful degradation when some facial markers are absent
Mask covers face pixels Integration Capture canvas, verify pixel values in face zone are mask color
Marker dots visible on mask Integration Verify marker dot pixels are present on top of mask
No mask when toggle is off Integration Verify export produces unmasked image when anonymization is disabled
Consent dialog blocks export E2E Verify the consent modal appears and must be confirmed before download

5.1 Rationale

Even with anonymization, Argentine law (Ley 25.326) and international best practices require that the evaluator confirms consent for image capture. The consent workflow serves three purposes:

  1. Legal compliance: Documents that the subject (or their representative) consented to the evaluation process including photography.
  2. Audit trail: Creates a record that can be presented to a CEI (ethics committee) if challenged.
  3. Evaluator awareness: Forces the evaluator to explicitly consider privacy before exporting data.

When the evaluator clicks "Capturar Imagen" or "Exportar", a modal dialog appears:

+----------------------------------------------------------+
|  Confirmacion de Consentimiento y Privacidad              |
|                                                          |
|  Antes de exportar, confirme lo siguiente:               |
|                                                          |
|  [ ] El sujeto evaluado (o su representante legal)       |
|      ha dado consentimiento informado para la            |
|      captura de imagenes durante esta evaluacion.        |
|                                                          |
|  [ ] La anonimizacion facial esta activada.              |
|      (o) Se exportara con rostro visible porque el       |
|      sujeto firmo un consentimiento especifico para      |
|      el uso de su imagen identificable.                  |
|                                                          |
|  [ ] La imagen exportada sera utilizada unicamente       |
|      para los fines declarados en el consentimiento      |
|      (evaluacion clinica / investigacion academica).     |
|                                                          |
|  Evaluador: [nombre autocompletado si esta logueado]     |
|  Fecha/hora: 2026-05-19 14:30:00 (autogenerado)         |
|                                                          |
|  [Cancelar]                    [Confirmar y Exportar]    |
+----------------------------------------------------------+
Anonymization Toggle Consent Checkbox 1 (General) Consent Checkbox 2 (Image Use) Result
ON Checked "Anonymization active" Export with mask. Standard case.
OFF Checked "Explicit image consent signed" Export without mask. Requires explicit photo-release consent.
ON Unchecked Any Blocked. Cannot export without general consent confirmation.
OFF Unchecked Any Blocked. Cannot export without general consent confirmation.

5.4 Metadata in Exported Files

The exported PNG should include EXIF/metadata (via canvas or post-processing):

{
  "eppa_version": "1.0.0",
  "anonymization_applied": true,
  "anonymization_method": "solid_mask_with_marker_overlay",
  "consent_confirmed_by_evaluator": true,
  "export_timestamp": "2026-05-19T14:30:00-03:00",
  "view": "anterior",
  "facial_markers_preserved": ["Eminencia Frontal Media", "Espina Nasal", "Punto Mentoniano", "Tragus Izq.", "Tragus Der."]
}

For CSV exports, append a metadata row or header comment with the same information.

EPPA should provide a downloadable consent form template (PDF) that institutions can adapt. Key elements:

  1. Purpose of image capture — postural evaluation for clinical/academic purposes.
  2. What is captured — full-body photographs in anatomical position with visible markers.
  3. Anonymization guarantee — facial features will be obscured in any exported or shared images.
  4. Data retention — images are processed in-browser and not uploaded to any server (EPPA is client-side).
  5. Right to withdrawal — the subject can request deletion of images at any time.
  6. Signature lines — subject (or representative), evaluator, date.

This template should be bilingual (Spanish/English) given the academic context.


Sources

Regulations and Standards

Published Research

Technical References