By · Last updated 2026-05-07

返回博客GDPR 与合规

EDPB 01/2025 指南:假名化的合规新要求

EDPB 01/2025 指南明确指出:假名化数据在 GDPR 框架下仍属于个人数据,只有真正意义上的匿名化才能脱离 GDPR 管辖范围。

May 7, 20269 分钟阅读
EDPB 2025 pseudonymizationanonymization vs pseudonymization GDPRGDPR scope personal dataDPO compliance gappseudonymization domain

EDPB 2025:假名化指南详解

2026 年更新版

2025 年 1 月的政策变化

2025 年 1 月,欧洲数据保护委员会发布了 01/2025 号指南,主题聚焦于假名化。核心结论简明扼要:假名化后的数据仍属于个人数据,依然受法律管辖。许多机构此前认为假名化数据已脱离法律约束,新指南对此予以明确否定。

关键原则是:只要你的机构持有可逆转该过程的密钥,GDPR 的全部义务依然适用于你。

「假名化域」的新概念

指南引入了一个新概念:假名化域(pseudonymization domain)。这一概念指代所有能够将假名化数据关联回真实个人的主体。

凡落入该域内的主体,均受法律约束。持有密钥或能够推导出密钥的主体,即属于该域——所有法律义务对其全面适用。

两个概念,一道关键分界

以下两个术语含义截然不同,不可混用。

真正的匿名化不可逆转。任何主体在任何时候都无法还原原始数据。真正匿名化的数据脱离法律管辖范围。

假名化可以逆转。通过密钥、查找表或附属文件均可还原原始值。持有密钥的主体对相应数据仍负有完整的法律义务。

以下三类工具产生的是假名化输出,而非真正意义上的匿名化输出:

  • 令牌系统:以固定令牌替换个人数据并保留查找表
  • 加密工具:对个人数据加密并保留解密密钥
  • 保留格式加密工具

哈希处理更接近真正意义上的匿名化——但前提是输入值难以被猜测。对于常见姓名或短位数身份代码,查表攻击可以还原哈希结果。EDPB 对此明确提示风险:对容易猜测的值进行哈希处理,可能不符合真正匿名化的标准。

DPO 的实操步骤

逐一审查每一批标注为「已匿名化」的数据集,核心问题只有一个:是否有任何主体能够逆转这一过程?若答案是肯定的,该数据集属于假名化数据,法律义务依然适用。

必须脱离法律管辖范围的数据——分析结果、存档文件、汇总统计——需要采用真正不可逆的处理方式。可选方案包括:永久性编辑删除、使用不可恢复值进行遮蔽,或对高熵值输入进行哈希处理。务必记录所用方法及其合理依据。

必须保留可逆性的数据——研究项目的重新联系场景、审计追踪、法律保全——必须明确标注为假名化个人数据,保留所有法律义务,并按 EDPB 密钥管理要求记录密钥托管情况。

五种处理方法对应上述两类场景:替换、遮蔽和加密产生假名化输出;编辑删除和哈希(仅限高熵值输入)在满足完整性审查的前提下可达到真正匿名化的标准。

务必核实你的工具实际产生的是什么类型的输出。以「匿名化工具」名义销售的产品,若保留了任何查找表或密钥,其实际输出仍是假名化数据。我们的 GDPR 合规指南 涵盖全部分类规则,安全合规概览 说明了 DPO 必须记录在案的技术控制措施。有关工具选型指导,请参阅我们的匿名化预设与审计指南

参考来源

准备好保护您的数据了吗?

开始使用 285 种实体类型在 48 种语言中匿名化 PII。

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

Related reading

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our servers live in Falkenstein, Germany.

We use Hetzner. They hold ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.