anonym.legal

By · Last updated 2026-05-02

Nazaj na blogGDPR in skladnost

Globalna skladnost osebnih podatkov: GDPR, LGPD in DPDP

Brazilska CPF, indijska Aadhaar in americanska SSN imajo temeljno razlicne formate in logiko preverjanja. LGPD in indijski zakon DPDP dodajata CPF in Aadhaar na seznam zascitenih identifikatorjev.

May 2, 20268 min branja
global PII complianceBrazilian CPF detectionIndian Aadhaar DPDPLGPD compliancemulti-regulatory PII

Globalna skladnost osebnih podatkov: trije zakoni, trije formati ID

Britansko trzisce obravnava dokumente prodajalcev iz 80 drzav. Hkrati veljajo trije zakoni: GDPR za prodajalce iz EU, LGPD za brazilske prodajalce in indijski zakon DPDP za indijske prodajalce. Vsak zakon imenuje razlicne nacionalne ID-je kot zascitene. Vsak format ima svojo kontrolno logiko.

Brazilska CPF: format in status LGPD

CPF (Cadastro de Pessoas Fisicas) je brazilska stevilka zavezanca za davek. Ima 11 stevk v formatu XXX.XXX.XXX-XX. Zadnji dve stevki sta kontrolni. Matematicni algoritem na prvih devetih stevkah ju ustvari.

Brazilski LGPD obravnava CPF kot zasciteni osebni identifikator, podobno po obcutljivosti americanski SSN. Orodje, ki ne pozna formata CPF, ga ne more najti. Tisto, ki preskoci kontrolno vsoto, bo oznacilo lazne zadetke.

Indijska Aadhaar: format in pravila DPDP

Aadhaar je 12-mestna stevilka, ki jo izda indijska UIDAI. Stevilke so dodeljene nakljucno. Zadnja stevka je Verhoeffova kontrolna stevka.

Indijski zakon DPDP ustvarja dolznosti za vsako skupino, ki obravnava podatke povezane z Aadhaar. Zaznavanje potrebuje dva koraka. Najprej ujemite 12-mestni format in preverite Verhoeffovo stevko. Nato filtrirajte po kontekstu. Ni vsak 12-mestni niz Aadhaar.

Americanska SSN: znana struktura

SSN ima devet stevk. Prve tri so stevilka obmocja. Naslednji dve sta stevilka skupine. Zadnje stiri so serijska stevilka. Vsak segment ima dolocena pravila. Preverjanje je dobro dokumentirano.

Vrzel med orodji za eno drzavo in globalnimi pravili

Ti trije ID-ji ne delijo nobenega formata in nobenega pravila preverjanja. Orodje, zgrajeno za americansko uporabo, bo ujelo SSN. CPF in Aadhaar bo morda v celoti zamudilo.

Vecina ekip to vrzel odkrije, ko regulator vprasuje - ne prej. Vrzel ustvarja resnicno tveganje po vsakem zakonu:

  • Clen 28 GDPR zahteva pisni sporazum o obdelavi podatkov z vsakim obdelovalcem. DPIA, ki navaja "zaznavanje SSN" kot glavni nadzor - ko nabor podatkov vsebuje tudi stevilke CPF - ima dokumentirano vrzel. Revizor jo lahko najde.
  • LGPD globe lahko dosezejo 2% brazilskega prihodka, do R$50M na krsitev. CPF, ki ostane neodkrit, je neposredna krsitev LGPD.
  • Izvrsevalnost DPDP je se nova. Ekipe, ki zdaj dokumentirajo svojo pokritost, bodo v boljsem polozaju, ko bodo zgodnje odlocbe postavile standard.

Tri ureitve glob hkrati ustvarjajo plastno tveganje. Orodja za eno drzavo pustijo globalne ekipe izpostavljene.

Kaj zahteva popolna pokritost

Orodje potrebuje format, kontrolni algoritem in pravni kontekst vsakega ID-ja. CPF potrebuje modularno kontrolno vsoto. Aadhaar potrebuje Verhoeffovo preverjanje in kontekstno filtriranje. SSN potrebuje obmocna in skupinska pravila. To so trije loceni problemi. Noben enoten iskalny vzorec ne pokriva vseh.

Glejte tudi: globalna vrzel identifikatorjev osebnih podatkov: SSN, CPF, Aadhaar, vodnik za izvrsevalnost brazilskega LGPD ANPD in tehnicna skladnost indijskega zakona o zasebnosti DPDPA.

Viri

Ste pripravljeni zaščititi svoje podatke?

Začnite z anonimizacijo PII z več kot 285 tipi entitet v 48 jezikih.

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

Related reading

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our servers live in Falkenstein, Germany.

We use Hetzner. They hold ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.