数据隐私见解

关于人工智能安全、GDPR 合规、医疗数据保护和 PII 匿名化最佳实践的专家文章。

所有文章

人工智能安全

氛围编程与个人信息泄露:被忽视的安全隐患

AI 生成的代码鲜少包含个人信息处理逻辑。73% 的氛围编程应用在处理敏感数据时缺乏匿名化机制。开发者必须了解这一风险。

March 16, 20267 分钟
法律科技

COPPA 2026 年 4 月新规:教育科技平台须在截止日期前完成的合规工作

COPPA 更新规则将于 2026 年 4 月 22 日生效。Reddit 因儿童数据违规被罚款 1,447 万英镑。教育科技平台面临同等风险。

March 16, 20266 分钟
技术

LangChain CVE-2025-68664:个人信息如何通过 RAG 管道泄露及修复方案

CVSS 9.3。LangChain 的序列化函数将环境变量和密钥暴露给攻击者控制的 LLM。如何检测并修复个人信息泄露问题。

March 16, 20268 分钟
人工智能安全

MCP 服务器安全 2026:8,000 台公网暴露,492 台零认证

8,000+ 台模型上下文协议服务器公开暴露在互联网上,492 台完全没有认证机制,36.7% 存在 SSRF 漏洞。如何在 MCP 工具中保护个人信息。

March 16, 20267 分钟
GDPR 与合规

欧盟《人工智能法》2026年8月:依据第10条对训练数据进行匿名化处理

欧盟《人工智能法》将于2026年8月2日全面执法。罚款上限为3500万欧元或全球营业额的7%。第10条要求对训练数据进行匿名化处理。

March 16, 20269 分钟
法律科技

永久匿名化:证据灭失风险

34.8%的ChatGPT输入包含敏感数据(Cyberhaven)。解决方案——永久匿名化——本身会带来新的法律风险:证据灭失。GDPR第4(5)条也有相关规定。

March 15, 202610 分钟
法律科技

8万美元的遮盖账单:Word插件解决方案

以每小时200-400美元计算,10,000份文件的提交在律师时间上花费26,000至80,000美元(RAND研究所)。Bloomberg Law 2024年研究发现自动化将该时间线大幅压缩。

March 14, 20269 分钟
人工智能安全

浏览器DLP:拦截 vs 匿名化——2026年方案对比

浏览器DLP有两种路线:拦截方案阻止个人信息提交至AI工具;匿名化方案在发送前对数据进行变换处理。本文提供客观对比分析。

March 14, 202610 分钟
人工智能安全

三星三度将源代码泄露给ChatGPT

2023年4月,三星半导体的三支独立工程师团队在一个月内将专有代码和机密数据粘贴到了ChatGPT中。每次事件都揭示了不同的风险维度。

March 13, 20269 分钟
法律科技

电子证据开示制裁:AI遮盖过度的法律风险

在Athletics Investment Group诉Schnitzer Steel案(2024年)中,不当遮盖引发了证据开示制裁。AI工具精确率仅为22.7%,法律团队面临真实的法律责任。

March 12, 202610 分钟
GDPR 与合规

SaaS泄露激增300%:零知识成必选项

Conduent暴露2590万条记录,NHS Digital影响900万名患者,攻击者在9分钟内攻破SaaS供应商。当您的供应商成为攻击面时。

March 11, 20269 分钟
医疗保健

云端HIPAA:PHI的零知识保护

业务伙伴协议无法在您的云端AI供应商以明文处理PHI时防止HIPAA违规。了解零知识架构能做什么。

March 10, 20269 分钟
技术

LibreOffice个人信息匿名化扩展

使用anonym.legal扩展在LibreOffice文档中匿名化个人信息的分步指南,支持Writer、Calc和Impress,覆盖267种以上实体类型。

March 10, 202610 分钟
技术

LibreOffice 与 Office:个人信息脱敏对比

LibreOffice(anonym.legal 扩展)与 Microsoft Office(Office 加载项)个人信息匿名化功能的详细对比。

March 10, 20268 分钟
GDPR 与合规

开源文档匿名化:LibreOffice 实践指南

公共部门机构如何借助 LibreOffice 与 anonym.legal 扩展实现符合 GDPR 合规要求的文档匿名化。

March 10, 20269 分钟
法律科技

跨平台个人信息保护:Office 与 LibreOffice 统一方案

混合使用 Microsoft Office 和 LibreOffice 的机构如何借助 anonym.legal 实现一致的个人信息匿名化处理。

March 10, 20267 分钟
人工智能安全

企业AI封禁:生产力与风险的博弈

27.4%的企业AI聊天机器人内容包含敏感数据,同比增长156%。然而71.6%的员工仍通过个人账户继续使用AI。

March 9, 20269 分钟
人工智能安全

2026年:安全的AI隐私扩展程序指南

2026年1月,两个拥有90万以上用户的恶意Chrome扩展程序被发现每隔30分钟就窃取一次ChatGPT和DeepSeek对话记录。

March 8, 20268 分钟
人工智能安全

ChatGPT、Claude和Gemini的浏览器DLP防护指南

传统企业DLP是为文件传输和电子邮件而设计的,并非针对AI聊天机器人。本指南详述2026年面向ChatGPT、Claude和Gemini的浏览器原生数据防泄漏方案。

March 8, 202612 分钟
医疗保健

CISO拒绝云端PHI处理的内幕

2024年725起医疗行业数据泄露影响2.75亿条记录。面对平均1022万美元的泄露成本——行业最高——医疗机构CISO正在重新审视云端AI工具。

March 7, 20269 分钟
GDPR 与合规

5.3亿欧元TikTok罚款:GDPR数据主权

TikTok因欧盟-中国数据传输被处以5.3亿欧元GDPR罚款,标志着数据主权执法进入新纪元。

March 6, 20269 分钟
医疗保健

HHS 2025:AI 临床记录必须拦截 PHI

AI 转录系统可能在无意间将 A 患者的 PHI 写入 B 患者的病历。实时 PHI 检测在 EHR 写入前进行拦截,是关闭这一合规漏洞的关键控制措施。

March 6, 20269 分钟
技术

二值 PII 检测为何无法满足合规要求

「已检测 / 未检测」的判断对于需要人工裁量的合规场景远远不够。置信度评分将 PII 匿名化从二元猜测转变为可审计的合规控制。

March 6, 20268 分钟
GDPR 与合规

GDPR数据最小化:实时API拦截

GDPR第5(1)(c)条要求企业仅收集必要数据。在表单提交阶段集成实时API,可在数据进入系统前阻止过度收集,从源头杜绝合规违规。

March 6, 20267 分钟

今天就开始保护您的数据

267+ 种实体类型,48 种语言,企业级安全,初创公司定价。

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022, held by our hosting provider.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.

Hetzner holds ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

Automated checks run on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We test detection against sample documents before each release.

A failing unit or integration run stops the release.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

Paid plans can buy top-up credits.

Credits reset at the end of each cycle.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.