数据隐私见解

关于人工智能安全、GDPR 合规、医疗数据保护和 PII 匿名化最佳实践的专家文章。

所有文章

GDPR 与合规

全球个人信息合规:GDPR、LGPD与DPDP

巴西CPF、印度Aadhaar和美国SSN在格式和验证逻辑上存在根本差异。LGPD和印度DPDP法案分别将CPF和Aadhaar列为受保护数据,单一国家工具无法满足全球合规要求。

May 2, 20268 分钟
GDPR 与合规

内部员工编号同样属于个人信息

每个大型组织都有专有的内部标识,可将匿名记录与真实人员关联起来。34%的GDPR罚款涉及技术措施不足问题,而遗漏内部标识是一个被普遍忽视的合规盲区。

May 1, 20268 分钟
医疗保健

无需编码:HIPAA管道中的自定义MRN检测

医疗记录号因医院而异——每家医疗系统都有自己独特的格式。HIPAA安全港要求移除MRN,而无代码工作流让合规团队无需工程师支持即可完成这项工作。

April 30, 20268 分钟
GDPR 与合规

欧盟标识缺口:Steuer-ID、NIR、Personnummer

通用个人信息工具以美国标识为基础构建。德国Steuer-ID、法国NIR、瑞典Personnummer和挪威Fødselsnummer在这些工具中完全无法识别。

April 29, 20268 分钟
医疗保健

您的工具遗漏了18项HIPAA标识中的哪些?

HIPAA列出了18类受保护健康信息(PHI)标识,而大多数匿名化工具只能检测其中约6类。各医院的医疗记录号格式各不相同,美国也没有统一的国家标准。

April 28, 20269 分钟
GDPR 与合规

全球个人信息标识:SSN、CPF、Aadhaar及更多

GDPR适用于德国税务识别号(Steuer-ID)、法国国民身份证号(NIR)、瑞典个人号码(Personnummer)及267多种其他标识类型,而大多数工具从未涉及这些格式。

April 27, 20268 分钟
医疗保健

研究中的可逆加密重新识别协议

你无法联系「Patient_001」进行随访。IRB 现在要求记录在案的重新识别协议——证明你在符合伦理条件时「能够」重新识别。

April 26, 20268 分钟
GDPR 与合规

GDPR AI 工作流中的令牌映射

客户姓名在 AI 处理前已匿名化,AI 的回复中包含匿名令牌。最终发送给客户的回复必须还原真实姓名——而非令牌占位符。

April 25, 20268 分钟
法律科技

匿名 HR 调查与可逆个人信息保护

匿名调查能鼓励员工举报骚扰和违规行为。但当严重指控出现时,HR 需要展开调查——而匿名恰恰阻断了调查路径。

April 24, 20268 分钟
中小企业安全

财务审计中的可逆加密

2026 年 2 月南区联邦法院裁定:AI 处理的文件若未在处理前进行匿名化,将丧失律师-客户特权保护。

April 23, 20268 分钟
法律科技

法律证据开示中的可逆加密

文件已经脱敏,法官却命令你提交原件。该怎么办?2024 年 GDPR 罚款总额达 12 亿欧元,创历史新高。

April 22, 20269 分钟
医疗保健

临床研究中的可逆去标识化

当研究在 5,000 名受试者中发现 47 人存在意外的生物标志物风险时,研究人员需要联系真实患者。然而仅有 23% 的匿名化工具支持这一功能。

April 21, 20269 分钟
医疗保健

HIPAA 合规的 ChatGPT:浏览器端 PHI 防护

77% 的员工每周至少向 AI 工具分享一次敏感工作信息。实时浏览器 PHI 拦截可将泄露事件减少 94%。

April 20, 20268 分钟
人工智能安全

您的AI隐私工具是否正在窃取您的数据?

67%的AI Chrome扩展程序会收集用户数据。2025年12月的事件中,90万用户因伪装成隐私保护工具的扩展程序而遭受损失。

April 19, 20268 分钟
人工智能安全

客服团队每日平均发生3.8次个人信息泄露

每位使用ChatGPT的客服人员每天平均进行3.8次敏感数据粘贴操作。对于一个100人的团队,这意味着每天发生380起GDPR合规风险事件。

April 18, 20268 分钟
GDPR 与合规

GDPR与ChatGPT:即时脱敏保护客服数据

意大利数据保护机构Garante于2024年12月对OpenAI处以1500万欧元罚款。63%的意大利企业缺乏符合GDPR的AI使用政策。2024年一项欧盟审计发现,63%的ChatGPT账户存在合规问题。

April 17, 20268 分钟
人工智能安全

90万用户数据泄露事件后的安全反思

2026年1月,两款恶意Chrome扩展程序在拥有90万以上用户的情况下,每30分钟向外泄露一次完整的ChatGPT和DeepSeek对话记录。

April 16, 20268 分钟
人工智能安全

为何制度规范无法阻止ChatGPT泄露个人信息

77%的企业AI用户会将数据直接复制粘贴到聊天机器人中。上传的文件中近40%包含个人身份信息或支付卡数据。HIPAA安全规则拟议更新。

April 15, 20268 分钟
GDPR 与合规

数据主权:云端PII工具的局限性

2011年至2025年间,拥有数据保护法的国家从76个增至120个以上。德国SGB V规定医疗数据必须保存在受德国管控的系统中。

April 14, 20269 分钟
技术

气隙网络隐私保护:完全离线的个人信息匿名化

FedRAMP和ITAR环境有一个共同点——云端根本不是选项。GDPR第4条第5款规定的可逆假名化、EDPB指南要求的令牌分离……本文介绍气隙环境下的合规解决方案。

April 13, 20269 分钟
中小企业安全

交易大厅:离线匿名化合规实践

交易大厅无法使用云端SaaS提交合规文件。美国律师协会第512号正式意见要求防止电子发现中的意外信息泄露,并保留完整的数据处理记录。

April 12, 20268 分钟
医疗保健

本地批量处理5万份临床记录:HIPAA合规指南

2026年2月南纽约联邦地区法院裁定,未经匿名化处理便通过AI处理的文件将丧失律师-委托人特权。

April 11, 20268 分钟
法律科技

面向GDPR与CCPA的电子表格结构化数据匿名化

Excel公式会引用包含客户姓名的单元格,数据透视表缓存敏感数据,67%的政府采购合同要求气隙环境。本文介绍如何在原生Excel格式中实现合规级匿名化。

April 10, 20268 分钟
法律科技

FOIA积压危机:政府文件自动化脱敏实践

2024财年美国FOIA申请量达150万件,同比增长25%,积压量增长33%至267,056件待处理请求,政府为此耗资7.23亿美元。

April 9, 20268 分钟

今天就开始保护您的数据

267+ 种实体类型,48 种语言,企业级安全,初创公司定价。

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022, held by our hosting provider.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.

Hetzner holds ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

Automated checks run on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We test detection against sample documents before each release.

A failing unit or integration run stops the release.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

Paid plans can buy top-up credits.

Credits reset at the end of each cycle.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.