By · Last updated 2026-05-04

返回博客GDPR 与合规

GDPR 被遗忘权:EDPB 2025 执法行动

EDPB 2025 年协调执法框架针对「被遗忘权」合规情况展开调查,32 个数据保护机构同步参与,其中 9 个已启动正式调查程序。

May 4, 20269 分钟阅读
GDPR right to erasureEDPB coordinated enforcement 2025Article 17 compliancedata minimizationanonymization vs deletion

GDPR 被遗忘权:EDPB 2025 年调查结果

2026 年更新版

EDPB 2025 年被遗忘权专项行动

2025 年,欧洲数据保护委员会启动了一项重大专项行动,聚焦 GDPR 第 17 条——数据主体的被遗忘权。欧盟及欧洲经济区共 32 个数据保护机构(DPA)同步参与,形成联动态势。此次行动旨在发现系统性合规漏洞,而非追究个别案例。

此次行动属于协调执法框架(CEF)机制。根据调查结果,目前已有 9 个 DPA 启动正式调查程序。

七类普遍性违规

CEF 报告在受查机构中发现了七类普遍问题:

  1. 处理删除请求的流程存在明显缺陷
  2. 过度拒绝合规请求
  3. 向申请人设置不合理的举证负担
  4. 无法跨系统定位所有个人数据
  5. 超出 GDPR 规定的 30 天响应期限
  6. 未能向申请人提供有效反馈
  7. 以有缺陷的「匿名化」代替删除——机构声称已完成匿名化,但数据仍可溯源至真实个人

第七类问题最为复杂,直接影响所有将匿名化作为减少个人数据留存手段的机构。

匿名化与删除的根本区别

GDPR 的被遗忘权并非在任何情况下都要求彻底删除。第 65 条序言允许在删除不可行时采用匿名化方式,备份磁带和分析系统是常见适用场景。

然而,CEF 调查显示,这一例外正在被滥用。部分机构将某个流程冠以「匿名化」之名,以规避真正的删除义务,但该流程仍可将数据追溯至真实个人。

EDPB 对此划定了明确的红线。

真正的匿名化意味着数据与个人之间的关联无法被重建——无论是数据控制者还是任何第三方,均无法完成重新关联。满足这一条件的数据方可脱离 GDPR 管辖范围,删除请求视为已执行完毕。

假名化则不同。持有对应密钥仍可实现重新关联,个人数据依然存在,删除请求并未得到满足——相关数据必须被删除,或其密钥必须被销毁。

双层架构方案

在分析场景中使用匿名化手段的机构,应建立双层数据架构。

**第一层——数据摄入层:**原始个人数据进入此层,受删除请求约束。当数据主体行使第 17 条权利时,此层数据予以删除。

**第二层——分析层:**仅允许匿名化后的输出结果进入此层。若匿名化流程完整且不可逆,这些输出不构成个人数据,删除请求到来时无需对其进行处理。

该架构成立的前提是,脱敏处理步骤须通过三项检验。

其一:单向性。可逆令牌和加密替换均不符合要求。

其二:完整性。所有类型的标识符必须全部处理,仅处理姓名远远不够。

其三:可记录性。机构必须能够向 DPA 说明所用方法的具体机制。

将客户姓名替换为加密令牌的零售商,执行的是假名化——而非真正意义上的删除。分析层仍存储个人数据,删除请求依然适用。

我们的 GDPR 合规指南 涵盖了各类方法的法律依据,安全合规概览 列明了所需的技术控制措施。如需分步骤操作指引,请参阅我们的 GDPR 匿名化审计指南

参考来源

准备好保护您的数据了吗?

开始使用 285 种实体类型在 48 种语言中匿名化 PII。

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

Related reading

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our servers live in Falkenstein, Germany.

We use Hetzner. They hold ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.