Dashboard Structural Analysis anonym.plus SD2 IRREVERSIBILITY Case Study
← Previous Next →
anonym.plus SD2 IRREVERSIBILITY
Case Study 20 of 30

GDPR Fine: Mercadona S.A. — Spanish Data Protection Authority (aepd) (Spain)

Spanish Data Protection Authority (aepd) · GDPR DPA: Spanish Data Protection Authority (aepd) (2021-07-26)

Research Source

GDPR Fine: Mercadona S.A. — Spanish Data Protection Authority (aepd) (Spain)
Spanish Data Protection Authority (aepd) · GDPR DPA: Spanish Data Protection Authority (aepd) · 2021-07-26 · Source: GDPR Enforcement Tracker

Fine: €2,520,000 | Articles: Art. 5 (1) c) GDPR, Art. 6 GDPR, Art.

Executive Summary

This research paper examines a critical privacy challenge related to IRREVERSIBILITY — once pii propagates, it cannot be un-propagated.

anonym.plus addresses this through 100% local processing with AES-256-GCM encrypted vault — PII processed and stored locally, never touching any external server.

Root Cause: SD2 — IRREVERSIBILITY

Once PII propagates, it cannot be un-propagated. The arrow of data only points one direction. PII exposure is a one-way function with no inverse.

Irreducible truth: Information entropy only increases. You cannot recall a broadcast signal. You cannot un-train a neural network. You cannot selectively erase a backup tape. Every deletion mechanism is an approximation — and the original exposure persists.

The Solution: How anonym.plus Addresses This

Detection Capabilities

anonym.plus identifies 200+ entity types including advertising IDs, browsing history, location data, interest profiles, bid parameters. The local Presidio 2.2.357 + spaCy 3.8.11 architecture uses Presidio 2.2.357 deterministic recognizers with 121 built-in presets for structured identifiers and spaCy 3.8.11 with 23 language models, all running locally via FastAPI sidecar for contextual references.

Anonymization Methods

Redact is recommended for this pain point: removing identifiers before data enters advertising systems prevents permanent surveillance records. Replace provides an alternative — substituting advertising identifiers with non-trackable alternatives enables aggregate analytics without surveillance. For scenarios requiring reversibility, Encrypt (AES-256-GCM) enables authorized recovery of original values.

Architecture & Deployment

The local sidecar REST API (port 5002-5003) provides programmatic access to Presidio detection for local development workflow integration.

Compliance Mapping

This pain point intersects with GDPR Article 6 lawful basis, ePrivacy consent requirements, Article 21 right to object.

anonym.plus’s GDPR (data never leaves device), HIPAA (local processing) compliance coverage, combined with 100% local — data never leaves device hosting, provides documented technical measures organizations can reference in their compliance documentation and regulatory submissions.

Product Specifications

SpecificationValue
App Versionv8.10.5
Entity Types200+ built-in, up to 50 custom
Detection EnginePresidio 2.2.357 + spaCy 3.8.11 (23 models)
Languages48 UI, 23 NLP models
Document FormatsPDF, DOCX, XLSX, TXT, CSV, JSON, XML + Image OCR
Anonymization MethodsReplace, Redact, Mask, Hash (SHA-256/512/MD5), Encrypt (AES-256-GCM)
ArchitectureTauri 2.x (Rust + React) + FastAPI sidecar (~370 MB)
PlatformsWin/Mac/Linux
LicensingEd25519 signed, machine-fingerprinted, max 5 machines
Processing100% local — data never leaves device
ComplianceGDPR, HIPAA (data residency guaranteed by local processing)
← Previous Next →