データプライバシーの洞察

AIセキュリティ、GDPR準拠、医療データ保護、PII匿名化のベストプラクティスに関する専門的な記事。

すべての記事

GDPRおよびコンプライアンス

AEPD スペイン: AI DPIAとGDPR準拠 (2025)

スペインのデータ保護局(AEPD)がAI技術に対するデータ保護影響評価(DPIA)の実施方法を詳述しています。GDPRおよびスペイン有機法第3/2018号の要件を満たすためのフレームワーク。

March 6, 20267
GDPRおよびコンプライアンス

Dutch AP Uber: GDPR罰金とクロスボーダー転送

オランダがUberに課した€390,000の罰金から学ぶGDPR国際転送ルール。

March 6, 20267
GDPRおよびコンプライアンス

Irish DPC TikTok LinkedIn Meta: GDPR執行

アイルランドのデータ保護委員会(DPC)によるTikTok、LinkedIn、Metaへの大規模罰金。GDPR執行の最前線。

March 6, 20268
GDPRおよびコンプライアンス

UODO ポーランド: GDPR執行 中央ヨーロッパ

ポーランドのUODOによるGDPR執行。中央・東ヨーロッパ地域の最大の経済圏での準拠要件。

March 6, 20269
GDPRおよびコンプライアンス

IMy スウェーデン: GDPR匿名化 北欧ガイド

スウェーデンのIMy(Integritetsskyddsmyndigheten)によるGDPR匿名化ガイド。北欧諸国の標準実装。

March 6, 20268
GDPRおよびコンプライアンス

Datatilsynet デンマーク: ヘルスケアデータGDPR

デンマークの医療機関向けGDPR準拠ガイド。北欧地域の医療データ保護の標準。

March 6, 20268
GDPRおよびコンプライアンス

DSB オーストリア: NOYB Schrems GDPR転送

オーストリア・ヨーロッパデータ保護局(DSB)とNOYB、MaxSchrems氏によるGDPR国際譲渡ガイドライン。

March 6, 20268
GDPRおよびコンプライアンス

APD ベルギー: 金融セクターのGDPR要件

ベルギーのデータ保護当局(APD - Autorité de Protection des Données)による金融機関向けGDPR準拠ガイド。

March 6, 20268
GDPRおよびコンプライアンス

ÚOOÚ チェコ共和国: GDPR 製造業準拠

チェコ個人情報保護局(ÚOOÚ)による製造業向けGDPR準拠ガイド。中央ヨーロッパの産業データ保護。

March 6, 20268
GDPRおよびコンプライアンス

ANSPDCP ルーマニア: 業務委託とBPO向けGDPR

ルーマニア企業がBPO(ビジネスプロセスアウトソーシング)を利用する際のGDPR準拠。データプロセッサーの要件。

March 6, 20268
GDPRおよびコンプライアンス

CNPD ポルトガル: LGPD-GDPR架橋

ポルトガル国家データ保護委員会(CNPD)によるLGPDとGDPRの両規制対応。ラテンアメリカとEUの橋渡し企業向け。

March 6, 20268
GDPRおよびコンプライアンス

NAIH ハンガリー: AI GDPR準拠

ハンガリーのNAIH(Nemzeti Adatvédelmi és Információszabadság Hatóság)によるAI技術企業への規制ガイドライン。

March 6, 20268
GDPRおよびコンプライアンス

HDPA ギリシャ: 観光・海運 GDPR

ギリシャの観光・海運産業におけるGDPR準拠ガイド。高度に国際的なセクターでのデータ保護。

March 6, 20269
GDPRおよびコンプライアンス

FTC 米国: AI プライバシー Section 5 執行

米国連邦取引委員会(FTC)によるAI技術企業への規制。Section 5(不公正慣行)による執行事例。

March 6, 20269
医療

HIPAA OCR HHS: PHI匿名化執行

HHS(米国厚生労働省)Office for Civil Rights(OCR)によるHIPAA違反執行。PHI匿名化の実装ガイドライン。

March 6, 202610
GDPRおよびコンプライアンス

CCPA/CPRA カリフォルニア州プライバシー法準拠ガイド

カリフォルニア州のCCPA(Consumer Privacy Act)およびCPRA(California Privacy Rights Act)の企業向け実装ガイド。

March 6, 202610
GDPRおよびコンプライアンス

ANPD ブラジル: LGPD執行ガイド (2025)

ブラジル国家データ保護局(ANPD)によるLGPD(Lei Geral de Proteção de Dados)の執行と罰金基準。企業の準拠手順。

March 6, 202610
GDPRおよびコンプライアンス

DPDPA インド: プライバシー法技術準拠

インドのDPDPA(Digital Personal Data Protection Act)の企業向け技術実装ガイド。14億人市場への対応。

March 6, 202610
GDPRおよびコンプライアンス

OPC カナダ: PIPEDA Bill C-27 プライバシー

カナダのプライバシーコミッショナー(OPC)によるPIPEDA(個人情報保護電子文書法)と新Bill C-27ガイドライン。

March 6, 202610
GDPRおよびコンプライアンス

PPC 日本: APPI プライバシー準拠ガイド

日本個人情報保護委員会(PPC)によるAPPI(Act on Protection of Personal Information)準拠ガイド。

March 6, 202610
GDPRおよびコンプライアンス

UK ICO GDPR: ポストブレグジット発散

ブレグジット後の英国GDPRとEU GDPRの乖離。英国のデータ移転規制の独自進化。

March 6, 202610
GDPRおよびコンプライアンス

Datenschutz Deutsch: PII検出 BfDI DSGVO

ドイツ語での詳細なPII検出テクニック。BfDIガイドラインに基づくDSGVO準拠実装。

March 6, 20269
GDPRおよびコンプライアンス

CNIL フランス: GDPR PII技術準拠

フランスCNILが要求するPII処理のセキュリティ技術的要件。データセキュリティデクリーのフランス版。

March 6, 20269
GDPRおよびコンプライアンス

AEPD スペイン: PII準拠ガイド (ラテンアメリカ対応)

スペインから見たラテンアメリカ地域のPII検出要件。スペイン企業がラテンアメリカで事業展開する際の個人情報保護対応。

March 6, 20269

今日からデータを保護し始めましょう

267以上のエンティティタイプ、48言語、スタートアップ価格でのエンタープライズグレードのセキュリティ。

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022, held by our hosting provider.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.

Hetzner holds ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

Automated checks run on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We test detection against sample documents before each release.

A failing unit or integration run stops the release.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

Paid plans can buy top-up credits.

Credits reset at the end of each cycle.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.