By · Last updated 2026-06-05

Späť na blogGDPR a Dodržiavanie

APD Belgicko: IAB, financny sektor a NIS2

Belgicky APD vydal prelomove rozhodnutie IAB Europe tykajuce sa digitalneho reklamneho priemyslu v hodnote 220 miliard eur. V roku 2024 vydal 82 vymozitelnych rozhodnuti.

June 5, 20268 min čítania
Belgium APDIAB EuropeGDPR financial sectorNIS2 complianceEU data protection

APD Belgicko: IAB, financny sektor a NIS2

Belgicky dozorny organ pre ochranu dat zaujima v EU jedinecne postavenie. Krajina je sidlom EU a NATO. Ma viac globalnych bank a financnych institutov ako akykolvek iny stat EU okrem Luxemburska. To dava Autorite de protection des donnees/Gegevensbeschermingsautoriteit (APD/GBA) siroke moznosti a vplyv.

Rozhodnutie vo veci IAB Europe

Vo februari 2022 belgicky regulator rozhodol proti IAB Europe. Pripad sa tykal Ramca transparentnosti a suhlasu (TCF). TCF roci priblizne 220 miliard eur v digitalnej reklame v EU.

Co dozorny organ zistil: Retazec suhlasu TCF je osobny udaj. Je prepojeny s pseudonymnym ID pouzivatela. IAB Europe bol oznaceny za spolocneho spravcu. To ho robilo zodpovednym za to, ako vydavatelia a reklamne spolocnosti tieto data vyuzivaju.

Pokuta 250 000 eur bola mala. Skutocny dopad bol omnoho vacsi. Urad pozadoval plny redesign TCF. Kazdy vydavatel v EU, ktory pouziva nastroj suhlasu, to pocitil. Rovnako aj kazdy reklamny kupcup.

Poucenie: technologia celého sektora moze porusit GDPR. Nie su ohrozene iba jednotlive spolocnosti. K zodpovednosti mozno volat cely retazec. Ziadny clanek tohto retazca nie je mimo dohlĺdu.

Financny sektor: NIS2 a GDPR spolocne

Belgicko je domom Europskej bankovej organu (EBA), EIOPA a globalneho uzla SWIFT. Banky a poistovne musia spĺnat ako GDPR Clanek 32, tak NIS2 Clanek 21. Tieto dva zakony sa z velke casti prekryvaju.

NIS2 Clanek 21 stanovuje tieto pravidla:

  • Kontrola rizik v oblasti ludskych, fyzickych a digitalnych faktorov
  • Nahlasenie incidentov do 24 hodin
  • Plany obnovy podnikania
  • Kontroly bezpecnosti dodavatelskych retazcov
  • Sifrovanie dat pri prenose a v klade
  • Viacfaktorove riadenie pristupu

GDPR Clanek 32 stanovuje tieto pravidla:

  • Maskovanie a sifrovanie osobnych zaznamov
  • Schopnost obnovit pristup po incidente
  • Pravidelne testovanie bezpecnostnych kontrol
  • Technicke ochranne opatrenia zalozene na riziku

Tieto kontroly sa objavuju v oboch zakonoch: sifrovanie, riadenie pristupu, reakcia na incidenty a kontroly dodavatelskych retazcov. Silne programy podla GDPR Clanku 32 splnaju vetsinu poziadaviek NIS2 Clanku 21. Jeden konsolidovany subor kontrol je najefektivnejsou cestou. Pozri nasu prirucku pre sulad s GDPR s podrobnym prehlad oboch zakonov.

Vymozitelnost v roku 2024: hlavne temy

Belgicky regulator vydal v roku 2024 82 rozhodnuti. Pocet pripadov z financneho sektora vzrastol oproti roku 2023 o 56 %. Vyniknaju styri temy.

Profilovanie bez suhlasu: Banky, ktore pouzivaju transakne data na analyzu vydavkov alebo ponuky produktov, musia dodrzovat pravidla GDPR. Dozorny organ odmietol "zlepsenie sluzieb" ako platny dovod, ked profilovanie stavi na takychto datach.

Skórovanie uvieru pomocou AI: GDPR Clanek 22 upravuje automatizovane rozhodnutia o uvere. Vyzaduje ludsky prehlad a jasne odovodnenie. Niekolko fintech spolocnosti tieto zaruky nemalo. To bolo klucovym zameriavanim.

Zlucovanie dat po fusich: Banky, ktore po akviziciach zlucili zaznamy, casto porusili pravidla o uceloch. Povodny suhlas nepokryval novy kombinovany pouzitok.

Outsourcing bez nastrojov na prenos: Spolocnosti, ktore posielali IT prace do tretich krajin bez spravnych pravnych nastrojov, celia postihom. Pripady sa tykali Indie, Maroka a Filipin.

Pre firmy s belgickymi bankovymi operaciami: konsolidovane kontroly GDPR a NIS2 su najlepsou obranon pred auditom. Nase prehladne informacie o bezpecnosti a sulade ukazuju, ako design zero-knowledge znizuje expozíciu pri zdroji.

Zdroje

Pripravení chrániť vaše údaje?

Začnite anonymizovať PII s 285+ typmi entít v 48 jazykoch.

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

Related reading

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our servers live in Falkenstein, Germany.

We use Hetzner. They hold ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.