By · Last updated 2026-04-14

返回博客GDPR 与合规

数据主权:云端PII工具的局限性

2011年至2025年间,拥有数据保护法的国家从76个增至120个以上。德国SGB V规定医疗数据必须保存在受德国管控的系统中。

April 14, 20269 分钟阅读
data sovereigntylocal-first processingSwiss banking secrecyGerman healthcare lawHIPAA local compliance

数据主权:云端PII工具为何难以满足需求

2026年更新版

2011年至2025年间,拥有隐私保护法律的国家从76个增至120个以上。各法律管辖区并未走向统一,而是愈发分化。每部新法律都在全球基准线之上叠加本地规则。依托中央服务器运营的云端工具越来越难以跟上步伐。

GDPR为欧盟隐私保护设定了基准门槛。将数据传输至欧盟以外需要充分性决定或有效保障措施。但GDPR只是门槛,而非上限。医疗、银行和公共部门的规定更为严格。在某些情况下,这些规定使云端数据处理根本无从实现。

德国:SGB V与医疗记录

德国《社会法典》第五卷(SGB V)规范法定医疗保险制度。它对患者记录的处理方式作出明确限制。受SGB V约束的医疗档案必须保存在受德国管控的系统中。这一规定使美国云服务商——即便是在欧盟境内托管的——也无法处理最敏感的患者档案。

美国卫生与公众服务部下属的公民权利办公室(HHS OCR)在2024年共征收超过1亿美元的HIPAA罚款,创历史新高。德国与美国的趋势指向同一结论:医疗记录需要最严格的管控措施,薄弱的管控只会引来罚款。

瑞士:银行保密制度与FINMA监管

瑞士银行保密制度受《瑞士银行法》第47条约束,属于刑事法律,而非民事法律。未经同意披露客户信息——包括在数据处理过程中与云服务商共享——可能构成刑事犯罪。

FINMA外包规定要求在向任何第三方提供瑞士银行记录之前获得批准并取得客户同意。本地化处理从根本上消除了这一问题。如果记录从不离开银行自有系统,则无需办理任何传输审批手续。

本地处理模式

LocalLLaMA社区已记录企业选择本地AI的原因:「如果微调数据包含个人或敏感信息,在本地进行可避免复杂的法律合规工作。」同样的逻辑适用于数据脱敏。在本地处理记录,便可跳过整个类别的法律分析。

基于Tauri 2.0和Rust构建的工具可通过网络监控进行审查。安全团队可以确认运行过程中没有任何网络请求离开本机。这种可验证性对受监管行业至关重要。SaaS服务商的隐私承诺无法以同样方式得到验证。更多关于本地处理如何支持医疗合规审计的内容,请参见我们的HIPAA云合规指南

为何碎片化趋势将持续

120多个国家拥有隐私法律,这并非稳定状态。更多法律正在陆续出台。GDPR基准线与行业专项规定之间的差距正在扩大,而非缩小。每部新法律增加的本地限制,都会给将文件发送至中央服务器的工具带来更多阻力。

本地优先工具颠覆了这一模式。软件在文件所在之处运行,数据不经由任何网络传输。合规性成为设计的内在特性,而非合同条款中的一句承诺。对于德国、瑞士及其他严格监管市场的团队而言,这一转变消除了整整一类风险。关于多司法管辖区需求的更宏观视角,请参见我们的全球隐私合规指南

参考资料

准备好保护您的数据了吗?

开始使用 285 种实体类型在 48 种语言中匿名化 PII。

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

Related reading

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our servers live in Falkenstein, Germany.

We use Hetzner. They hold ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.