データプライバシーの洞察
AIセキュリティ、GDPR準拠、医療データ保護、PII匿名化のベストプラクティスに関する専門的な記事。
すべての記事
AEPD スペイン: AI DPIAとGDPR準拠 (2025)
スペインのデータ保護局(AEPD)がAI技術に対するデータ保護影響評価(DPIA)の実施方法を詳述しています。GDPRおよびスペイン有機法第3/2018号の要件を満たすためのフレームワーク。
Dutch AP Uber: GDPR罰金とクロスボーダー転送
オランダがUberに課した€390,000の罰金から学ぶGDPR国際転送ルール。
Irish DPC TikTok LinkedIn Meta: GDPR執行
アイルランドのデータ保護委員会(DPC)によるTikTok、LinkedIn、Metaへの大規模罰金。GDPR執行の最前線。
UODO ポーランド: GDPR執行 中央ヨーロッパ
ポーランドのUODOによるGDPR執行。中央・東ヨーロッパ地域の最大の経済圏での準拠要件。
IMy スウェーデン: GDPR匿名化 北欧ガイド
スウェーデンのIMy(Integritetsskyddsmyndigheten)によるGDPR匿名化ガイド。北欧諸国の標準実装。
Datatilsynet デンマーク: ヘルスケアデータGDPR
デンマークの医療機関向けGDPR準拠ガイド。北欧地域の医療データ保護の標準。
DSB オーストリア: NOYB Schrems GDPR転送
オーストリア・ヨーロッパデータ保護局(DSB)とNOYB、MaxSchrems氏によるGDPR国際譲渡ガイドライン。
APD ベルギー: 金融セクターのGDPR要件
ベルギーのデータ保護当局(APD - Autorité de Protection des Données)による金融機関向けGDPR準拠ガイド。
ÚOOÚ チェコ共和国: GDPR 製造業準拠
チェコ個人情報保護局(ÚOOÚ)による製造業向けGDPR準拠ガイド。中央ヨーロッパの産業データ保護。
ANSPDCP ルーマニア: 業務委託とBPO向けGDPR
ルーマニア企業がBPO(ビジネスプロセスアウトソーシング)を利用する際のGDPR準拠。データプロセッサーの要件。
CNPD ポルトガル: LGPD-GDPR架橋
ポルトガル国家データ保護委員会(CNPD)によるLGPDとGDPRの両規制対応。ラテンアメリカとEUの橋渡し企業向け。
NAIH ハンガリー: AI GDPR準拠
ハンガリーのNAIH(Nemzeti Adatvédelmi és Információszabadság Hatóság)によるAI技術企業への規制ガイドライン。
HDPA ギリシャ: 観光・海運 GDPR
ギリシャの観光・海運産業におけるGDPR準拠ガイド。高度に国際的なセクターでのデータ保護。
FTC 米国: AI プライバシー Section 5 執行
米国連邦取引委員会(FTC)によるAI技術企業への規制。Section 5(不公正慣行)による執行事例。
HIPAA OCR HHS: PHI匿名化執行
HHS(米国厚生労働省)Office for Civil Rights(OCR)によるHIPAA違反執行。PHI匿名化の実装ガイドライン。
CCPA/CPRA カリフォルニア州プライバシー法準拠ガイド
カリフォルニア州のCCPA(Consumer Privacy Act)およびCPRA(California Privacy Rights Act)の企業向け実装ガイド。
ANPD ブラジル: LGPD執行ガイド (2025)
ブラジル国家データ保護局(ANPD)によるLGPD(Lei Geral de Proteção de Dados)の執行と罰金基準。企業の準拠手順。
DPDPA インド: プライバシー法技術準拠
インドのDPDPA(Digital Personal Data Protection Act)の企業向け技術実装ガイド。14億人市場への対応。
OPC カナダ: PIPEDA Bill C-27 プライバシー
カナダのプライバシーコミッショナー(OPC)によるPIPEDA(個人情報保護電子文書法)と新Bill C-27ガイドライン。
PPC 日本: APPI プライバシー準拠ガイド
日本個人情報保護委員会(PPC)によるAPPI(Act on Protection of Personal Information)準拠ガイド。
UK ICO GDPR: ポストブレグジット発散
ブレグジット後の英国GDPRとEU GDPRの乖離。英国のデータ移転規制の独自進化。
Datenschutz Deutsch: PII検出 BfDI DSGVO
ドイツ語での詳細なPII検出テクニック。BfDIガイドラインに基づくDSGVO準拠実装。
CNIL フランス: GDPR PII技術準拠
フランスCNILが要求するPII処理のセキュリティ技術的要件。データセキュリティデクリーのフランス版。
AEPD スペイン: PII準拠ガイド (ラテンアメリカ対応)
スペインから見たラテンアメリカ地域のPII検出要件。スペイン企業がラテンアメリカで事業展開する際の個人情報保護対応。
About this page
We update this page when our platform or the law changes.
Read our founder note for how we work.
Each change shows up in the timestamp at the top.
Related reading
We follow these rules
- GDPR (EU 2016/679).
- ISO/IEC 27001:2022, held by our hosting provider.
- NIS2 (EU 2022/2555).
- HIPAA safe harbor under 45 CFR § 164.514(b)(2).
Our promise
We do not sell your data.
We do not train models on your text.
We store your files in Germany.
You can delete your account at any time.
You own your work.
Where we run
Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.
Hetzner holds ISO 27001 certification.
All data stays in the EU.
Backups run every day.
Need help?
Email support@anonym.legal.
We reply within one business day.
How we test
Automated checks run on every release.
Each surface gets its own sweep script and report.
Human reviewers spot-check the output each week.
We test detection against sample documents before each release.
A failing unit or integration run stops the release.
What we never do
- We never sell your information to third parties.
- We never train models on what you upload.
- We never keep your work after you delete it.
- We never share keys with any outside firm.
- We never run ads inside the product.
Plans in plain words
We sell credits, not seats.
One credit covers one short job.
Long jobs use a few credits each.
Paid plans can buy top-up credits.
Credits reset at the end of each cycle.
Read the plans page for current rates.
Who built this
A small team of engineers and lawyers built this.
We ship from Europe and work in the open.
Our founder note spells out why we started.
Where to start
- Open the web app and try a sample file.
- Learn how credits get counted.
- See current plans and limits.
- Meet the team behind the product.
How the parts fit
A browser add-on cleans text inside Chrome.
A Word plug-in handles drafts in Office.
A small desktop tool works on whole folders.
An agent protocol link feeds large models safely.
All four share one core engine and one rule set.
Words from our team
We started this work after a lunch about cookies.
One friend kept getting odd ads on her phone.
We asked why a court file leaked through a draft.
We sketched the first build on a napkin that week.
By month three we had a tiny demo for a friend.
She used it on her first case the next day.
Common questions we hear
Can the tool read scanned PDFs? Yes, with OCR.
Does it work on long files? Yes, in small chunks.
Can I roll my own rule set? Yes, save it as a preset.
Does it run offline? The desktop build runs offline.
Do you keep my files? No, the cloud build wipes after each run.
Will it learn from my work? No, we never train on inputs.
A short tour of the workflow
Upload a file or paste a snippet of prose.
Pick the entities you want gone from the draft.
Choose a method: replace, mask, hash, encrypt, or redact.
Press run and watch the side panel show each hit.
Skim the result and tweak any rule that misfired.
Save the cleaned file or send it to a teammate.