数据隐私见解

关于人工智能安全、GDPR 合规、医疗数据保护和 PII 匿名化最佳实践的专家文章。

所有文章

人工智能安全

自动高亮个人信息:为何技术手段胜过合规培训

62%使用AI工具处理客户数据的员工「有时」或「经常」忘记在粘贴前删除个人信息。了解为何自动高亮能从根本上消除这一合规漏洞,而培训无法做到。

March 6, 20267 分钟
法律科技

PDF遮黑陷阱:视觉遮盖如何让敏感数据裸奔

司法部艾普斯坦文件、马纳福特案和NSA泄露事件有一个共同的失败根源:表面遮黑实则保留了可提取的底层文本。了解如何避免这一高风险失误。

March 6, 20268 分钟
技术

文档格式碎片化:个人信息匿名化的隐藏合规漏洞

一份数据主体访问请求(DSAR)回应可能横跨Word合同、PDF发票、Excel客户列表和CSV导出文件。使用不同工具处理不同格式,会产生难以发现的合规漏洞。

March 6, 20267 分钟
GDPR 与合规

Excel与GDPR:如何匿名化数百列个人信息

Excel是企业运营中个人信息密度最高的文件类型之一。了解为何标准文本分析在电子表格上会失效,以及列上下文感知分析如何破解这一难题。

March 6, 20268 分钟
技术

GDPR合规日志匿名化:在保护隐私的同时保留调试能力

应用程序日志会悄悄积累用户电子邮件、IP地址和账号信息。了解如何在与第三方、承包商和可观测性平台共享日志时,在合规的前提下保留其全部调试价值。

March 6, 20267 分钟
GDPR 与合规

CSV自由文本中的个人信息:超越列删除的研究数据共享

调查CSV不仅在结构化列中包含个人信息,自由文本回答中同样如此。标准的列删除操作会遗漏违反GDPR匿名化标准的个人信息,导致数据共享合规失败。

March 6, 20267 分钟
法律科技

混合格式电子取证:合规漏洞与应对之道

电子取证生产请求与 GDPR 数据主体访问请求横跨 PDF、Word 文档、Excel 及 JSON 导出等多种格式。不同工具分开处理,必然产生一致性漏洞。

March 6, 20267 分钟
技术

应用日志中的 GDPR 合规:JSON PII 脱敏实践

应用日志中包含客户邮箱地址、IP 地址和账户号码,GDPR 第 5 条第 1 款 (e) 项对此有明确的管理要求。

March 6, 20266 分钟
GDPR 与合规

GDPR 与遗留扫描文件:OCR 识别 PII 的合规实践

GDPR 的删除权适用于「无论何种格式」的个人数据。基于图像的 PDF 纸质档案并不例外。

March 6, 20267 分钟
人工智能安全

截图 PII:内部工具中被忽视的数据泄露风险

Slack、Teams、Jira 和邮件每天都在接收含有客户 PII 的截图,这一访问控制漏洞绕过了所有 DLP 工具。

March 6, 20266 分钟
医疗保健

手写表单 OCR 与 PII 检测:医疗保险行业实践

某中型医院每年处理 5 万份手写入院表单,按此规模人工脱敏 PII 需要 0.5 个全职人力。

March 6, 20267 分钟
GDPR 与合规

学术研究 PII:截图与 GDPR 合规风险

学术论文中常用含有真实患者记录的 pandas DataFrame 和 R 输出截图作为方法论示例,这构成 GDPR 违规。

March 6, 20267 分钟
人工智能安全

内部 Wiki 中的 PII:Confluence 客户数据风险

支持团队用含客户账户截图记录操作流程,三年下来,您的知识库中可能已积累数千次 GDPR 数据最小化违规。

March 6, 20266 分钟
人工智能安全

AI 编程助手泄露生产环境个人数据

单元测试夹具中存有真实客户记录,调试时调取生产数据写入日志文件。GitHub 报告显示 2024 年开发者在公共代码库中泄露了 3900 万条密钥。

March 6, 20268 分钟
GDPR 与合规

个人数据工具碎片化导致合规审计失败

四种不同的工具对应四种不同的工作流,意味着四套不同的实体覆盖范围和四条独立的审计追踪记录。

March 6, 20267 分钟
技术

跨应用个人数据保护:Word、Chrome 与 AI 工具的全链路防护

客户数据在日常工作中流转于浏览器调研、Word 草稿与 Claude 提示词之间,每次应用切换都是潜在的泄露节点。

March 6, 20266 分钟
GDPR 与合规

一套工具应对 GDPR、CCPA 与 PDPA

欧盟员工受 GDPR 约束,美国员工处理 CCPA 数据,亚太员工遵守 PDPA。三套法律框架,一支分布式团队。

March 6, 20268 分钟
GDPR 与合规

GDPR 审计失败:个人数据工具碎片化之殇

审计人员追问个人数据检测管控措施,「我们使用五种不同工具」并非他们想要的答案。本文揭示跨平台一致性为何至关重要。

March 6, 20266 分钟
GDPR 与合规

远程办公与 GDPR:平台不一致性合规挑战

办公室员工使用功能完整的桌面软件,远程员工使用设置可能不同的网页应用。欧盟法院明确指出,政策本身不构成 GDPR 第 32 条规定的技术管控。

March 6, 20266 分钟
技术

跨平台个人数据合规:Mac、Linux 与 Windows

隐私官使用 Mac,法律团队使用 Windows,数据工程师使用 Linux——处理的却是同一份合规义务。本文解释为何操作系统无关的检测方案至关重要。

March 6, 20266 分钟
GDPR 与合规

BfDI 德国:数据保护合规技术指南

德国2024年申报了27,829起GDPR违规事件,超过其他任何欧盟成员国。BfDI的执法重点对技术团队的个人信息处理意味着什么?

March 6, 20268 分钟
GDPR 与合规

CNIL 法国:GDPR 技术合规指南

CNIL在2023年处理了16,433起投诉,自2019年以来累计开出逾1.5亿欧元罚款。其AI指导意见要求对训练数据进行有据可查的匿名化处理。

March 6, 20267 分钟
GDPR 与合规

ICO 英国:脱欧后的 GDPR 合规差异

ICO于2025年12月因加密机制不当对LastPass处以120万英镑罚款,该裁定确立了客户端加密属于法定要求的原则。

March 6, 20267 分钟
GDPR 与合规

意大利 Garante:AI 与个人信息合规指南

意大利Garante于2024年12月对OpenAI处以1,500万欧元罚款,并曾于2023年临时封禁ChatGPT。欧盟最强硬的AI监管机构究竟要求什么?

March 6, 20267 分钟

今天就开始保护您的数据

267+ 种实体类型,48 种语言,企业级安全,初创公司定价。

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022, held by our hosting provider.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.

Hetzner holds ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

Automated checks run on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We test detection against sample documents before each release.

A failing unit or integration run stops the release.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

Paid plans can buy top-up credits.

Credits reset at the end of each cycle.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.