数据隐私见解
关于人工智能安全、GDPR 合规、医疗数据保护和 PII 匿名化最佳实践的专家文章。
所有文章
AEPD 西班牙:AI 与员工数据保护法规
AEPD在2023年作出847项处罚决定,数量居欧盟之首,并要求对所有处理个人数据的AI系统开展数据保护影响评估。
荷兰 AP:2.9亿欧元 Uber 罚款与跨境数据传输合规
荷兰AP就数据跨境传输开出迄今欧盟最大的单项罚款——针对Uber的2.9亿欧元。跨境传输合规究竟要求什么?
爱尔兰 DPC:欧盟 GDPR 巨额罚款的主要来源
TikTok被罚5.3亿欧元、LinkedIn被罚3.1亿欧元、Meta被罚2.51亿欧元——均来自爱尔兰DPC。为什么科技巨头将欧盟总部设在爱尔兰?这对SaaS企业意味着什么?
波兰UODO:罚款数量超过法国的GDPR执法机构
波兰数据保护局UODO的人均罚款率超过法国、德国及大多数西欧同类机构。对于在波兰运营的企业而言,这是切实存在的合规风险,而非单纯的文书要求。
瑞典IMY:北欧GDPR匿名化标准指南
瑞典数据监管机构IMY发布了欧盟最详尽的匿名化技术标准文件,已有12个成员国数据保护局将其列为核心参考。本指南解析IMY的四项匿名化测试方法及其对企业合规实践的影响。
丹麦Datatilsynet:医疗数据GDPR执法指南2024
丹麦数据保护局2024年处理的31起GDPR案件中,45%涉及医疗系统。全球领先的数字化医疗体系带来的不仅是研究优势,更是严苛的合规要求。本文解析CPR号码识别难题与患者数据复用规则。
奥地利DSB:Schrems诉讼与跨境数据传输合规
奥地利数据保护局是NOYB的主场监管机构。从Schrems I到Schrems II,再到预期中的Schrems III,这一系列诉讼持续重塑欧盟数据传输法律格局。本文解析DSB对Google Analytics的裁定及有效的跨境传输技术措施。
比利时APD:IAB裁定、金融行业与NIS2双轨合规
比利时数据保护局以其对IAB Europe的历史性裁定和金融行业的严格执法著称。本文解析APD 2024年执法主题,以及GDPR第32条与NIS2第21条联动合规的最优路径。
捷克ÚOOÚ:制造业GDPR合规与「出生号码」识别挑战
捷克数据保护局2024年发布的58项执法决定中,34%针对制造业和汽车行业。跨国集团将外国配置的PII工具强推给本地机构,却未能覆盖捷克特有身份标识符,这是最常见的合规失效模式。
罗马尼亚ANSPDCP:BPO行业GDPR风险与CNP号码识别
罗马尼亚数据保护局正在加大GDPR执法力度,BPO和外包企业是主要执法对象。78%的外包企业PII工具无法正确检测CNP号码,这一缺口在数据泄露的事后审查中反复暴露。
葡萄牙CNPD:GDPR与LGPD个人信息合规要点
葡萄牙CNPD是连接欧盟GDPR与巴西LGPD的关键桥梁,覆盖全球逾2.15亿葡语使用者。一家医院因病历匿名化不足被罚款250万欧元。
匈牙利NAIH:人工智能治理与GDPR合规规则
NAIH要求所有处理个人数据的AI系统事先完成数据保护影响评估(DPIA)。匈牙利文本NER准确率仅为67%,远低于欧盟82%的平均水平。
希腊HDPA:旅游业与航运业的GDPR合规
希腊HDPA于2024年作出89项执法决定,较2022年增加162%。旅游业占案例总数的38%。AFM和AMKA等身份标识符需要专门处理。
美国FTC:第5条款AI隐私执法
FTC于2024年发起19项AI执法行动,亚马逊Alexa被罚8.75亿美元。美国已有25部州隐私法生效。零知识架构与FTC监管重点高度契合。
HIPAA OCR:2024年725起数据泄露,2.75亿条记录受影响
HHS OCR报告显示,2024年共发生725起HIPAA数据泄露事件,涉及2.75亿条患者记录,创历史最高纪录。医疗数据泄露平均损失高达1022万美元。
CCPA/CPRA 2025:加州AI隐私合规指南
加州隐私保护局(CPPA)2024年开出逾1亿美元罚款。CPRA覆盖加州4000万居民,对全球大多数企业均适用。法律规定19类敏感数据,并对自动化决策提出告知要求。
巴西ANPD:2024年LGPD执法指南
巴西数据保护局ANPD于2024年开出首批重大罚款。LGPD覆盖2.15亿巴西人,体量超过德国、法国和英国的总和。
印度DPDPA 2023:全球隐私影响
印度《数字个人数据保护法》覆盖14亿人口,数据保护委员会已于2025年正式运营。违规罚款最高达₹250亿卢比(约€2700万)。包含Aadhaar身份证号检测支持。
加拿大OPC:从PIPEDA到C-27法案
加拿大隐私专员办公室(OPC)依据PIPEDA执法,同时议会正在审议C-27法案的AI与数据法规。加拿大在2026年审查期间维持欧盟GDPR充分性认定。
日本PPC与APPI:AI训练数据合规
日本个人信息保护委员会(PPC)执行2022年修订版APPI,覆盖240万家日本企业。我的号码(My Number)12位身份证号须进行Verhoeff算法校验。
脱欧后英国GDPR:与欧盟的技术差异
《2025年数据保护与数字信息法》(DPDI)与欧盟GDPR产生14处分歧。欧英充分性认定将于2026年接受审查。LastPass £120万罚款案将加密标准确立为法律要求。
德语PII检测与DSGVO合规
BfDI报告显示,2024年德国共发生27,829起数据泄露通报,创历史新高。65%的德国企业使用对德语个人身份信息支持不足的检测工具。
法国CNIL:数据保护机构对PII工具的技术要求
CNIL 2023年处理16,433件投诉(同比增长43%)。63%的CNIL通知指出AI匿名化不足。78%的通用工具无法检测NIR/法国社会保障号码。
西班牙AEPD:DNI、NIE与拉丁美洲身份标识
AEPD 2023年发出847项处罚决议——数量居欧盟之首。通用工具对DNI/NIE的检测准确率仅为34%。
About this page
We update this page when our platform or the law changes.
Read our founder note for how we work.
Each change shows up in the timestamp at the top.
Related reading
We follow these rules
- GDPR (EU 2016/679).
- ISO/IEC 27001:2022, held by our hosting provider.
- NIS2 (EU 2022/2555).
- HIPAA safe harbor under 45 CFR § 164.514(b)(2).
Our promise
We do not sell your data.
We do not train models on your text.
We store your files in Germany.
You can delete your account at any time.
You own your work.
Where we run
Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.
Hetzner holds ISO 27001 certification.
All data stays in the EU.
Backups run every day.
Need help?
Email support@anonym.legal.
We reply within one business day.
How we test
Automated checks run on every release.
Each surface gets its own sweep script and report.
Human reviewers spot-check the output each week.
We test detection against sample documents before each release.
A failing unit or integration run stops the release.
What we never do
- We never sell your information to third parties.
- We never train models on what you upload.
- We never keep your work after you delete it.
- We never share keys with any outside firm.
- We never run ads inside the product.
Plans in plain words
We sell credits, not seats.
One credit covers one short job.
Long jobs use a few credits each.
Paid plans can buy top-up credits.
Credits reset at the end of each cycle.
Read the plans page for current rates.
Who built this
A small team of engineers and lawyers built this.
We ship from Europe and work in the open.
Our founder note spells out why we started.
Where to start
- Open the web app and try a sample file.
- Learn how credits get counted.
- See current plans and limits.
- Meet the team behind the product.
How the parts fit
A browser add-on cleans text inside Chrome.
A Word plug-in handles drafts in Office.
A small desktop tool works on whole folders.
An agent protocol link feeds large models safely.
All four share one core engine and one rule set.
Words from our team
We started this work after a lunch about cookies.
One friend kept getting odd ads on her phone.
We asked why a court file leaked through a draft.
We sketched the first build on a napkin that week.
By month three we had a tiny demo for a friend.
She used it on her first case the next day.
Common questions we hear
Can the tool read scanned PDFs? Yes, with OCR.
Does it work on long files? Yes, in small chunks.
Can I roll my own rule set? Yes, save it as a preset.
Does it run offline? The desktop build runs offline.
Do you keep my files? No, the cloud build wipes after each run.
Will it learn from my work? No, we never train on inputs.
A short tour of the workflow
Upload a file or paste a snippet of prose.
Pick the entities you want gone from the draft.
Choose a method: replace, mask, hash, encrypt, or redact.
Press run and watch the side panel show each hit.
Skim the result and tweak any rule that misfired.
Save the cleaned file or send it to a teammate.