データプライバシーの洞察
AIセキュリティ、GDPR準拠、医療データ保護、PII匿名化のベストプラクティスに関する専門的な記事。
すべての記事
Garante イタリア: GDPR PII技術準拠
イタリアのGaranteが要求するPII処理のセキュリティ技術要件。イタリア特有の識別子(コッディスフィスカーレなど)への対応。
ANPD LGPD: ブラジルポルトガル語での匿名化技術ガイド
ブラジル企業向けのLGPD準拠な匿名化実装。ブラジルポルトガル語での詳細な技術ガイド。
Dutch AP ABP: PII検出 BSN準拠
オランダのデータ保護局(AP)によるBSN(Burgerservicenummer)検出とAVG(GDPR)準拠ガイド。
UODO PESEL: ポーランドPII RODO準拠
ポーランド個人データ保護局(UODO)によるPESEL(個人識別番号)の検出・保護とRODO(ポーランド版GDPR)準拠ガイド。
ANSPDCP ルーマニア: CNPとGDPR技術ガイド
ルーマニア国家データ保護局(ANSPDCP)によるCNP(Cod Numeric Personal)の検出と保護。GDPRテクニカルガイド。
IMy スウェーデン: personnummer GDPR技術ガイド
スウェーデンのIMy による personnummer(スウェーデン個人識別番号)の検出・保護技術ガイド。
Datatilsynet デンマーク: CPR GDPR技術ガイド
デンマークのデータ保護局(Datatilsynet)によるCPR(Central Person Register)番号の検出と保護。
ÚOOÚ チェコ: rodné číslo GDPR技術
チェコのÚOOUによるrodné číslo(チェコ個人識別番号)の検出・保護技術ガイド。数学的検証アルゴリズム解説。
NAIH ハンガリー: TAJ GDPR技術ガイド
ハンガリーのNAIHによるTAJ(社会保障番号)の検出・保護技術ガイド。
HDPA ギリシャ: AFM AMKA GDPR技術
ギリシャのデータ保護局(HDPA)によるAFM(税務ID)とAMKA(社会保障番号)の検出・保護技術ガイド。
PPC 日本: My Number APPI技術ガイド
日本のPPCによるMy Number(マイナンバー)とAPPI準拠技術ガイド。特別な識別番号の厳格な保護要件。
エプスタインファイルの後: ブラックボックスハイライトは真の赤actionではない理由
2025年12月のDOJエプスタインファイルの公開は、重要な赤actionの失敗を暴露しました: 黒くハイライトされたPDFテキストはコピー&ペーストを通じて読み取ることができます。法律チームの71%がAIツールを使用している中、真の赤actionが何を意味するのかを理解することはこれまでになく緊...
弁護士-クライアント特権とAI:すべての法律事務所がAIツールを使用する方法を変えるべき2026年の裁判所の判決
2026年2月、連邦裁判所はAIとの通信が弁護士-クライアント特権を持たないと判決を下しました。79%の弁護士がAIを使用しているが、正式なポリシーを持つ事務所はわずか10%。リスクは体系的です。法律事務所がAIの生産性を維持しながらクライアントの機密性を保護する方法を紹介します。
ゼロ知識対ゼロ信頼:あなたの「暗号化された」クラウドツールが実際にデータを保護しない理由
LastPassはユーザーのデータを暗号化しましたが、$438Mが盗まれました。サーバーサイド暗号化と真のゼロ知識アーキテクチャの違い、そしてすべての企業セキュリティチームが尋ねるべき質問について説明します。
エアギャップPII匿名化:防衛と政府がオフラインファーストツールを必要とする理由
41%の企業セキュリティポリシーは、機密文書のクラウド処理を禁止しています。防衛請負業者、政府機関、規制された企業がオフラインファーストのPII匿名化を用いてGDPRおよびITARコンプライアンスを達成する方法を紹介します。
なぜあなたのPII検出ツールは英語話者に対してのみGDPR準拠なのか
ドイツのSteuer-ID、フランスのNIR、スウェーデンのPersonnummerはすべて異なる検出ロジックを必要とします。英語のみのツールは、非英語のPIIの40-60%を見逃し、23のEU公用語にわたってGDPRのリスクを生じさせます。
可逆と永久:あなたのレダクションツールの選択が重要な理由
GDPRは匿名化と擬似匿名化を区別します。裁判所は元の文書を要求します。研究には再識別が必要です。それぞれのアプローチを使うべき時を学びましょう。
多言語NER:英語で訓練されたモデルがアラビア語で失敗する理由
英語のNERモデルは85-92%の精度を達成します。アラビア語や中国語では?しばしば50-70%。技術的な課題について学び、真に多言語のPII検出を構築する方法を見つけましょう。
2024年に94%の中小企業が攻撃を受けた—ほとんどが保護を受けられない
中小企業は大企業と同じ脅威に直面していますが、月額800ドル以上のセキュリティツールを購入する余裕がありません。月額€3でエンタープライズグレードの保護を得る方法を紹介します。
PHI検出精度: John Snow Labs 96% 対 GPT-4o 79%
すべての非識別化ツールが同じではありません。ECIR 2025のベンチマークは、F1スコアが79%から96%までの範囲であることを示しています。精度がなぜ重要なのか、ツールをどのように評価するかを学びましょう。
なぜ裁判所は「赤acted」文書に対して弁護士に制裁を科しているのか
Wordでテキストをハイライトすることは赤actionではありません。裁判所は特権情報を露呈させる技術的な失敗に対して弁護士に制裁を科しています。適切な赤action技術を学びましょう。
クラウドとChatGPTを使って会社の秘密を漏らさずに使用する方法
AIアシスタントを安全に使用するための開発者ガイド。Claude Desktop、Cursor、VS Codeでの透明なPII保護のためにMCPサーバー統合を設定します。
90万人のユーザーがAIチャットを盗まれた—あなたのもその一つでしたか?
2つの悪意のあるChrome拡張機能が90万人以上のユーザーからChatGPTの会話を盗みました。そのうちの1つはGoogleの「注目」バッジを持っていました。何が起こったのか、そして自分を守る方法は?
$7.42M: なぜ医療データ侵害は他の業界よりも高額なのか
医療業界は14年連続でデータ侵害のコストが最も高い業界です。PHIがなぜそれほど価値があるのか、そしてそれをどのように保護するかを学びましょう。
About this page
We update this page when our platform or the law changes.
Read our founder note for how we work.
Each change shows up in the timestamp at the top.
Related reading
We follow these rules
- GDPR (EU 2016/679).
- ISO/IEC 27001:2022, held by our hosting provider.
- NIS2 (EU 2022/2555).
- HIPAA safe harbor under 45 CFR § 164.514(b)(2).
Our promise
We do not sell your data.
We do not train models on your text.
We store your files in Germany.
You can delete your account at any time.
You own your work.
Where we run
Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.
Hetzner holds ISO 27001 certification.
All data stays in the EU.
Backups run every day.
Need help?
Email support@anonym.legal.
We reply within one business day.
How we test
Automated checks run on every release.
Each surface gets its own sweep script and report.
Human reviewers spot-check the output each week.
We test detection against sample documents before each release.
A failing unit or integration run stops the release.
What we never do
- We never sell your information to third parties.
- We never train models on what you upload.
- We never keep your work after you delete it.
- We never share keys with any outside firm.
- We never run ads inside the product.
Plans in plain words
We sell credits, not seats.
One credit covers one short job.
Long jobs use a few credits each.
Paid plans can buy top-up credits.
Credits reset at the end of each cycle.
Read the plans page for current rates.
Who built this
A small team of engineers and lawyers built this.
We ship from Europe and work in the open.
Our founder note spells out why we started.
Where to start
- Open the web app and try a sample file.
- Learn how credits get counted.
- See current plans and limits.
- Meet the team behind the product.
How the parts fit
A browser add-on cleans text inside Chrome.
A Word plug-in handles drafts in Office.
A small desktop tool works on whole folders.
An agent protocol link feeds large models safely.
All four share one core engine and one rule set.
Words from our team
We started this work after a lunch about cookies.
One friend kept getting odd ads on her phone.
We asked why a court file leaked through a draft.
We sketched the first build on a napkin that week.
By month three we had a tiny demo for a friend.
She used it on her first case the next day.
Common questions we hear
Can the tool read scanned PDFs? Yes, with OCR.
Does it work on long files? Yes, in small chunks.
Can I roll my own rule set? Yes, save it as a preset.
Does it run offline? The desktop build runs offline.
Do you keep my files? No, the cloud build wipes after each run.
Will it learn from my work? No, we never train on inputs.
A short tour of the workflow
Upload a file or paste a snippet of prose.
Pick the entities you want gone from the draft.
Choose a method: replace, mask, hash, encrypt, or redact.
Press run and watch the side panel show each hit.
Skim the result and tweak any rule that misfired.
Save the cleaned file or send it to a teammate.