数据隐私见解
关于人工智能安全、GDPR 合规、医疗数据保护和 PII 匿名化最佳实践的专家文章。
所有文章
PII自动检测降低电子取证成本
律师主导的电子取证PII编辑每页费用1至2美元。一起涉及5万份文件的诉讼案件,仅编辑费用就超过37.5万美元。自动化预筛可将律师工时削减70%。
HIPAA安全港去标识化的规模化实施
HIPAA安全港要求删除18类特定的PHI标识符。学术医疗中心需要规模化去标识化,但现有工具价格高昂,远超研究经费预算。
大规模 GDPR DSAR 合规:每月处理 200 份请求
GDPR 第 15 条数据主体访问请求每年增长 40% 至 60%,各机构每月收到数百份请求。批量 PII 脱敏可将 DSAR 处理速度提升 10 倍,助力大规模合规。
批量脱敏助力 FOIA 处理效率提升 80%
美国联邦机构在 2024 财年收到 150 万件 FOIA 申请,平均每件处理成本 $482。批量 PII 脱敏可将处理时间从数月压缩至数周,大幅降低人力成本。
隐私软件中的透明定价如何建立信任
67% 的 B2B 采购者更倾向于定价透明的供应商,43% 的采购者会淘汰需要联系销售才能获取定价信息的供应商。
自由职业数据从业者 GDPR 匿名化实操指南
自由职业者和独立数据承包商面临合规盲区:专为企业设计的订阅定价无法适配每月处理 3 个客户数据集的工作模式。本指南提供可落地的解决方案。
以创业预算实现企业级 PII 合规
企业级数据匿名化工具起价 €800/月,开源方案需要 Python 专业知识。这一价格鸿沟让数百万中小企业、个人从业者和创业公司陷入合规困境。
NGO 的 GDPR 合规:免费隐私工具指南
NGO 和人道主义组织与商业企业承担着同等的 GDPR 义务,却往往面临零技术预算的现实困境。本文介绍可行的免费工具与实用方案。
Presidio 与 anonym.legal:自建还是购买?
Microsoft Presidio 技术上免费,但正确部署需要 40 至 80 个工程工时。anonym.legal 以托管 SaaS 的形式提供同等机器学习精度,无需任何工程投入。
初创公司的 PII 匿名化工具:如何告别天价企业许可费
Informatica、BigID 等企业级 PII 工具专为财富 500 强企业设计,年授权费动辄六位数。而欧盟 99% 的企业都是中小企业,GDPR 对所有规模的企业一视同仁。
ISO 27001 如何帮助企业通过安全问卷审查并赢得大额合同
Gartner 2024 年研究显示,52% 的大型企业安全采购流程要求供应商持有 ISO 27001 认证。在金融、医疗、法律等强监管行业,这一比例高达 80% 至 90%。
政府采购中的 ISO 27001:SaaS 供应商入门指南
美国联邦云服务合同需要 FedRAMP 授权,审批周期长达 12 至 24 个月。对于欧盟和英国政府机构而言,ISO 27001 通常是被广泛接受的等效认证标准。
DORA 法规下的 ICT 供应商管理与 ISO 27001
DORA 于 2025 年 1 月正式生效,要求金融机构对每家科技供应商进行年度审查。ISO 27001 认证可将每家供应商的审查工时从 40 至 80 小时大幅压缩至数小时以内。
ISO 27001 与医疗行业 HIPAA 业务伙伴协议的合规证明
HIPAA 业务伙伴协议要求提供「充分保证」,证明已采取适当的数据保护措施。ISO 27001 与 HIPAA 164 条款的控制要求高度契合,可直接用于满足合规举证需求。
ISO 27001 在供应链下游合规中的价值
没有 ISO 27001 认证,小型供应商每填写一份企业问卷需耗费 40 到 80 小时。企业订单的流失,往往并非因为产品不安全,而是因为无法及时提供合规证明。
ISO 27001 如何缩短企业级销售周期
一家全球金融服务公司要求供应商统一采用 ISO 27001 后,调查问卷填写时间缩短了 52%。77% 的企业采购团队将 ISO 27001 列为首要认证要求。
DSAR 请求量激增:GDPR 合规的批量处理方案
爱尔兰数据保护委员会 2024 年分别对 LinkedIn 和 Meta 开出 3.1 亿欧元和 2.51 亿欧元罚单,执法力度的显著提升正在推动数据主体访问请求量急剧增加。
DPO 合规必备:匿名化工具 GDPR 第 28 条供应商评估清单
GDPR 第 35 条要求对高风险处理活动进行数据保护影响评估(DPIA)。ISO 27001 认证可将安全调查问卷的处理时间缩短 73%。
匿名化 vs 假名化:2000 万欧元罚款背后的关键区别
GDPR 对匿名化数据与假名化数据的处理截然不同。真正的匿名化可使数据完全脱离 GDPR 管辖;假名化则不能。混淆两者,可能触发高达 2000 万欧元的最高罚款。
EDPB 01/2025 指南:假名化的合规新要求
EDPB 01/2025 指南明确指出:假名化数据在 GDPR 框架下仍属于个人数据,只有真正意义上的匿名化才能脱离 GDPR 管辖范围。
GDPR 合规悖论:你的匿名化工具本身是否违规?
荷兰数据保护局 2024 年对 Uber 开出 2.9 亿欧元罚单,原因正是将欧洲驾驶员数据传输至美国服务器。大多数设在美国的匿名化工具面临同样的合规风险。
匿名化工具是否构成 GDPR 违规?TikTok 5.3 亿欧元罚款的警示
爱尔兰数据保护委员会对 TikTok 开出 5.3 亿欧元罚单,原因是将欧洲用户数据传输至中国。这一裁决确立了明确先例:使用境外工具处理欧盟个人数据本身即可构成违规。
GDPR 被遗忘权:EDPB 2025 执法行动
EDPB 2025 年协调执法框架针对「被遗忘权」合规情况展开调查,32 个数据保护机构同步参与,其中 9 个已启动正式调查程序。
MiCA与GDPR:加密钱包地址的个人信息检测
欧盟MiCA法规将加密货币钱包地址视为金融标识符。与个人关联的钱包地址适用GDPR,而标准个人信息工具完全无法识别这类地址格式。
About this page
We update this page when our platform or the law changes.
Read our founder note for how we work.
Each change shows up in the timestamp at the top.
Related reading
We follow these rules
- GDPR (EU 2016/679).
- ISO/IEC 27001:2022, held by our hosting provider.
- NIS2 (EU 2022/2555).
- HIPAA safe harbor under 45 CFR § 164.514(b)(2).
Our promise
We do not sell your data.
We do not train models on your text.
We store your files in Germany.
You can delete your account at any time.
You own your work.
Where we run
Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.
Hetzner holds ISO 27001 certification.
All data stays in the EU.
Backups run every day.
Need help?
Email support@anonym.legal.
We reply within one business day.
How we test
Automated checks run on every release.
Each surface gets its own sweep script and report.
Human reviewers spot-check the output each week.
We test detection against sample documents before each release.
A failing unit or integration run stops the release.
What we never do
- We never sell your information to third parties.
- We never train models on what you upload.
- We never keep your work after you delete it.
- We never share keys with any outside firm.
- We never run ads inside the product.
Plans in plain words
We sell credits, not seats.
One credit covers one short job.
Long jobs use a few credits each.
Paid plans can buy top-up credits.
Credits reset at the end of each cycle.
Read the plans page for current rates.
Who built this
A small team of engineers and lawyers built this.
We ship from Europe and work in the open.
Our founder note spells out why we started.
Where to start
- Open the web app and try a sample file.
- Learn how credits get counted.
- See current plans and limits.
- Meet the team behind the product.
How the parts fit
A browser add-on cleans text inside Chrome.
A Word plug-in handles drafts in Office.
A small desktop tool works on whole folders.
An agent protocol link feeds large models safely.
All four share one core engine and one rule set.
Words from our team
We started this work after a lunch about cookies.
One friend kept getting odd ads on her phone.
We asked why a court file leaked through a draft.
We sketched the first build on a napkin that week.
By month three we had a tiny demo for a friend.
She used it on her first case the next day.
Common questions we hear
Can the tool read scanned PDFs? Yes, with OCR.
Does it work on long files? Yes, in small chunks.
Can I roll my own rule set? Yes, save it as a preset.
Does it run offline? The desktop build runs offline.
Do you keep my files? No, the cloud build wipes after each run.
Will it learn from my work? No, we never train on inputs.
A short tour of the workflow
Upload a file or paste a snippet of prose.
Pick the entities you want gone from the draft.
Choose a method: replace, mask, hash, encrypt, or redact.
Press run and watch the side panel show each hit.
Skim the result and tweak any rule that misfired.
Save the cleaned file or send it to a teammate.