データプライバシーの洞察
AIセキュリティ、GDPR準拠、医療データ保護、PII匿名化のベストプラクティスに関する専門的な記事。
すべての記事
コピペ忘れ: 自動PII強調表示とコンプライアンス
ペーストボード(クリップボード)に貼り付けられたテキストのリアルタイムPII検出と自動強調表示。
PDF墨消しの罠: ブラックボックス墨消し
PDF墨消し機能(Adobe Acrobat等)が完全でない理由。「見えない」が「消えていない」リスク。
ドキュメント形式の分散: PII匿名化
PDF、Word、Excel、Confluence、Slack、ChatGPT など複数の形式に分散したドキュメントのPII検出と匿名化。
Excel GDPR: スプレッドシートのPII匿名化
MicrosoftExcelスプレッドシートに含まれたPIIの自動検出と匿名化。ビジネスユーザー向けツール実装。
GDPR準拠JSONログ匿名化: DevOps
DevOps環境におけるログ処理でのPIIの自動検出と匿名化。ログ集約とGDPR準拠の両立。
CSV自由テキスト: PII研究データ共有GDPR
CSV形式で共有される研究データに含まれた自由テキストフィールド内のPIIの検出と管理。
複合形式 eDiscovery: GDPR準拠
e-discovery(電子証拠開示)プロセスにおける複数形式ファイルのGDPR準拠な処理。法的文書のPII検出。
API ログのJSON内PIIマスキングとGDPR監視可能性
APIサーバーログに含まれるJSON形式のPIIを自動的に検出・マスキングする実装。GDPR監視可能性要件との両立。
レガシースキャン文書: GDPR OCR匿名化
過去にスキャンされたレガシー文書のOCR処理と、その結果に含まれたPIIのGDPR準拠な匿名化。
スクリーンショット PII流出: 内部ツール GDPR
Slack、Confluence、メールなど内部ツールで共有されたスクリーンショットからのPII流出防止。
手書き形式 OCR: PII検出 医療保険
医療・保険業界での手書き形式のOCR処理と、OCR結果に含まれたPIIの検出・保護。
研究出版: PII データ分析 スクリーンショット
学術研究論文やホワイトペーパー出版時のスクリーンショット内PII検出・黒塗り。
Confluence Wiki: 顧客PIIとスクリーンショット GDPR
AtlassianのConfluenceなどの内部Wikiに保存されたスクリーンショット内のPIIの自動検出と保護。
AI コーディングアシスタント: 本番環境でのPIIデータ漏洩
GitHub CopilotやGitHub Copilot X、Claude for Businessなどのコーディングアシスタントが、ソースコードに含まれた個人情報(PII)をどのように学習・処理するかの分析。
PIIツール分散: コンプライアンス監査失敗
複数のPII検出ツールが分散していることによるGDPR監査での一貫性問題と失敗事例。
クロスアプリケーションPII保護: Word、Chrome、AI
Word文書、Chrome、コーディングアシスタントなど複数のアプリケーション間でのPIIの流出防止メカニズム。
国際プライバシー準拠: GDPR、CCPA、PDPA 統一ツール
GDPR、CCPA、PDPA、LGPD など複数の規制に対応する統一的なPII検出・匿名化ツールの設計。
GDPR監査: PIIツール分散とクロスプラットフォーム
複数のPII検出ツールがクロスプラットフォーム環境に分散している際のGDPR監査ガイドライン。
リモートワーク: GDPR プラットフォーム非一貫性
リモートワーク環境での複数プラットフォーム(Slack, Zoom, Teams等)間のGDPR準拠の不一貫性。
クロスプラットフォームPII準拠: macOS、Linux、Windows
Windows、macOS、Linuxなど複数のOSで一貫したPII検出と保護を実現するための技術アーキテクチャ。
BfDI ドイツ: GDPR準拠技術ガイド
ドイツ連邦データ保護オンブズマン(BfDI)によるGDPR実装ガイド。ドイツ企業向けの技術的要件と運用ガイドライン。
CNIL フランス: GDPR AI匿名化準拠
フランスのデータ保護局(CNIL)によるAI技術の匿名化要件。GDPR第36条の事前相談ガイドライン。
ICO UK GDPR: AI LastPass技術準拠
英国情報コミッショナー(ICO)によるAI技術企業への規制。LastPass侵害事件から学ぶGDPR技術準拠。
Garante イタリア: ChatGPT禁止とAI PII準拠
イタリアのデータ保護局(Garante)によるChatGPT禁止と、AI技術利用企業への要件。
About this page
We update this page when our platform or the law changes.
Read our founder note for how we work.
Each change shows up in the timestamp at the top.
Related reading
We follow these rules
- GDPR (EU 2016/679).
- ISO/IEC 27001:2022, held by our hosting provider.
- NIS2 (EU 2022/2555).
- HIPAA safe harbor under 45 CFR § 164.514(b)(2).
Our promise
We do not sell your data.
We do not train models on your text.
We store your files in Germany.
You can delete your account at any time.
You own your work.
Where we run
Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.
Hetzner holds ISO 27001 certification.
All data stays in the EU.
Backups run every day.
Need help?
Email support@anonym.legal.
We reply within one business day.
How we test
Automated checks run on every release.
Each surface gets its own sweep script and report.
Human reviewers spot-check the output each week.
We test detection against sample documents before each release.
A failing unit or integration run stops the release.
What we never do
- We never sell your information to third parties.
- We never train models on what you upload.
- We never keep your work after you delete it.
- We never share keys with any outside firm.
- We never run ads inside the product.
Plans in plain words
We sell credits, not seats.
One credit covers one short job.
Long jobs use a few credits each.
Paid plans can buy top-up credits.
Credits reset at the end of each cycle.
Read the plans page for current rates.
Who built this
A small team of engineers and lawyers built this.
We ship from Europe and work in the open.
Our founder note spells out why we started.
Where to start
- Open the web app and try a sample file.
- Learn how credits get counted.
- See current plans and limits.
- Meet the team behind the product.
How the parts fit
A browser add-on cleans text inside Chrome.
A Word plug-in handles drafts in Office.
A small desktop tool works on whole folders.
An agent protocol link feeds large models safely.
All four share one core engine and one rule set.
Words from our team
We started this work after a lunch about cookies.
One friend kept getting odd ads on her phone.
We asked why a court file leaked through a draft.
We sketched the first build on a napkin that week.
By month three we had a tiny demo for a friend.
She used it on her first case the next day.
Common questions we hear
Can the tool read scanned PDFs? Yes, with OCR.
Does it work on long files? Yes, in small chunks.
Can I roll my own rule set? Yes, save it as a preset.
Does it run offline? The desktop build runs offline.
Do you keep my files? No, the cloud build wipes after each run.
Will it learn from my work? No, we never train on inputs.
A short tour of the workflow
Upload a file or paste a snippet of prose.
Pick the entities you want gone from the draft.
Choose a method: replace, mask, hash, encrypt, or redact.
Press run and watch the side panel show each hit.
Skim the result and tweak any rule that misfired.
Save the cleaned file or send it to a teammate.