![èŠåºãç»å](https://assets.st-note.com/production/uploads/images/172461660/rectangle_large_type_2_a8c69ab68f37c05472212bae3bd5973e.png?width=1200)
ðªðºGDPRã®éèŠæ³æïŒãã©ã€ãã·ãŒãŽãŒã«ãåºé¡ç¯å²â ¡ ã®æãåºãã¡ã¢ïŒ
ããã«ã¡ã¯ïŒ
å æ¥ããã©ã€ãã·ãŒãŽãŒã«ãè©Šéšãå§ãŸããšã®noteãæžããŸããã
ããããã©ã€ãã·ãŒãã¯ã€ãããšç°ãªããGDPRã®è©Šéšç¯å²ã¯ãå ¬åŒæç§æžããªããããç¬ç¿ããå¿ èŠããããŸããã(æ¶ïŒ
ããã§ããã®èšäºã§ã¯ã
ãã®ïŒç§ç®ã®ãã¡ãGDPRã®è©Šéšç¯å²ã®é
ç®ããšã®æŠèŠããã³ã該åœæ¡æãæãåºããè©Šéšé
ç®ãšæ¡æã®å¯Ÿå¿ã¥ããããŠã¿ãããšæããŸãã
ïŒçè
ã®å匷ç®çã§æ¡æãåŒçšããŠããããå匷ããå
容ããã€ãã§ã«å
¬éãããã®ã§ãã確èªã¯ããŠããŸãããå
¬åŒã§ã¯ãããŸããã®ã§ãã泚æãã ãããïŒ
GDPRã«é¢ããè©Šéšç¯å²
ãŸããè©ŠéšæŠèŠããGDPRã«é¢ããè©Šéšç¯å²ãåºé¡ç¯å²ãæ¯ãè¿ããŸãã
ïŒè©Šéšç¯å²ã®é ç®ã»å 容ïŒ
II.ã欧å·é£åïŒEU: European UnionïŒã®äžè¬ããŒã¿ä¿è·èŠåïŒGDPR: General Data Protection RegulationïŒ
2.1ãé©çšç¯å²
GDPRã®å°ççé©çšç¯å²
2.2ãåºæ¬æŠå¿µ
å®çŸ©ïŒå人ããŒã¿ãç¹å¥ãªçš®é¡ã®å人ããŒã¿ãåŠçã移転ã管çè ãåŠçè ãå ±å管çè ãåæçïŒ
2.3ã管çè ã»åŠçè ã®çŸ©å
â å人ããŒã¿åŠçã®è«žååã
â¡åŠçã®æ³çæ ¹æ ïŒå人ããŒã¿ã®åŠçãç¹å¥ãªçš®é¡ã®å人ããŒã¿ã®åŠçïŒãâ¢åŠç掻åã®èšé²ã
â£ããŒã¿äž»äœãžã®æ å ±éç¥ã»æš©å©è¡äœ¿å¯Ÿå¿ã
â€é©åãªæè¡çã»çµç¹çæªçœ®ã®å®æœã
â¥å人ããŒã¿äŸµå®³ãžã®å¯Ÿå¿ã
âŠããŒã¿åŠçå¥çŽã®ç· çµã»æŽæ°ã
â§EU代ç人ã
âšããŒã¿ä¿è·è²¬ä»»è ã®éžä»»çŸ©åã
â©ããŒã¿ä¿è·åœ±é¿è©äŸ¡ã®å®æœçŸ©åã
âªåå€ç§»è»¢èŠå¶ç
ïŒåºé¡ç¯å²ïŒ
ã»äžè¬ããŒã¿ä¿è·èŠåïŒGDPR: General Data Protection RegulationïŒåæïŒ1é ã26é ã75é ã76é ïŒ
ã»GDPRæ¡æïŒ2æ¡ïœ10æ¡ã12æ¡ïœ22æ¡ã24æ¡ïœ39æ¡ã44æ¡ïœ49æ¡ã84æ¡ïŒ
欧å·ããŒã¿ä¿è·äŒè°ïŒEDPB: European Data Protection BoardïŒã¬ã€ãã©ã€ã³
ã»ç®¡çè åã³åŠçè ã®æŠå¿µã«é¢ããã¬ã€ãã©ã€ã³
ã»ããŒã¿ããŒã¿ããªãã£ã®æš©å©ã«é¢ããã¬ã€ãã©ã€ã³
ã»ããŒã¿ä¿è·ãªãã£ãµãŒïŒDPOïŒã«é¢ããã¬ã€ãã©ã€ã³
ã»ç®¡çè åã¯åŠçè ã®äž»ç£ç£æ©é¢ã®ç¹å®ã«é¢ããã¬ã€ãã©ã€ã³8 2022
ã»å人ããŒã¿äŸµå®³éç¥ã«é¢ããã¬ã€ãã©ã€ã³09_2022
ã»å人ããŒã¿äŸµå®³éç¥ã®äºäŸã«é¢ããã¬ã€ãã©ã€ã³01_2021
ã»åæã«é¢ããã¬ã€ãã©ã€ã³
ã»éææ§ã«é¢ããã¬ã€ãã©ã€ã³
ã»èŠå第49æ¡ã®äŸå€ã«é¢ããã¬ã€ãã©ã€ã³
ç¶ããŠãè©Šéšç¯å²ã®é ç®ããšã«ãæå®ææžïŒPPCæ¥æ¬èªç¿»èš³çïŒãããæŠèŠãšè©²åœæ¡æãåãããŠã¿ãŠãããŸãã
è©Šéšç¯å²ã®æ³ä»€æŠèŠ
2.1 é©çšç¯å²ãscope
該åœæ¡æ: 第2æ¡ïŒå®äœçé©çšç¯å²ïŒç¬¬3æ¡ïŒå°ççé©çšç¯å²ïŒ
æŠèŠ:
GDPRã¯ãEUå ã«æ ç¹ãããäŒæ¥ã ãã§ãªããEUåå€ã®äŒæ¥ã以äžã®å Žåã«é©çšãããïŒ
EUå± äœè ã«å¯ŸããŠååããµãŒãã¹ãæäŸããå ŽåãïŒæåã»ç¡åãåããªãïŒã
EUå ã®ããŒã¿äž»äœã®è¡åãç£èŠããå ŽåïŒäŸ: è¡å远跡ããããã¡ã€ãªã³ã°ïŒã
é©çšç¯å²ãåºãããåœå¢ãè¶ ããããŒã¿ä¿è·èŠå¶ãç®æããŠããã
GDPRã¯ãå人ããŒã¿ã®åŠçãèªååãããæ段ã«ãã£ãŠè¡ãããå Žåããéšåçã«èªååãããå Žåã«ãé©çšãããã
å人ããŒã¿ãå«ããã¡ã€ã«ç®¡çã·ã¹ãã ã察象ãšãªãã
2æ¡ãå®äœçé©çšç¯å²ã
1. æ¬èŠåã¯ããã®å šéšåã¯äžéšãèªåçãªæ段ã«ããå人ããŒã¿ã®åæ±ãã«å¯Ÿãã䞊ã³ã«ãèªåçãªæ段以å€ã®æ¹æ³ã«ããå人ããŒã¿ã®åæ±ãã§ãã£ãŠããã¡ã€ãªã³ã°ã·ã¹ãã ã®äžéšãæ§æãããã®ãåã¯ããã¡ã€ãªã³ã°ã·ã¹ãã ã®äžéšãšããŠæ§æããããšãäºå®ãããŠãããã®ã«å¯Ÿããé©çšãããã
2. æ¬èŠåã¯ã以äžã®å人ããŒã¿ã®åæ±ãã«ã¯é©çšãããªãïŒïŒä»¥äžç¥ïŒ
3æ¡ãå°ççé©çšç¯å²ãArticle 3 Territorial scope
1. æ¬èŠåã¯ããã®åæ±ããEUåå ã§è¡ããããã®ã§ãããåŠããåãããEUåå ã®ç®¡çè åã¯åŠçè ã®æ ç¹ã®æŽ»åã®éçšã«ãããå人ããŒã¿ã®åæ±ãã«é©çšãããã
2. åæ±æŽ»åã以äžãšé¢é£ããå Žåãæ¬èŠåã¯ãEUåå ã«æ ç¹ã®ãªã管çè åã¯åŠçè ã«ããEUåå ã®ããŒã¿äž»äœã®å人ããŒã¿ã®åæ±ãã«é©çšãããïŒ
ã(a) ããŒã¿äž»äœã®æ¯æããèŠæ±ããããåŠããåãããEUåå ã®ããŒã¿äž»äœã«å¯Ÿããç©ååã¯ãµãŒãã¹ã®æäŸãåã¯
ã(b) ããŒã¿äž»äœã®è¡åãEUåå ã§è¡ããããã®ã§ããéãããã®è¡åã®ç£èŠã
3. æ¬èŠåã¯ãEUåå ã«æ ç¹ã®ãªã管çè ã«ãããã®ã§ãã£ãŠããåœéå ¬æ³ã®å¹åã«ããå çåœã®åœå æ³ã®é©çšã®ããå Žæã«ãããŠè¡ãããå人ããŒã¿ã®åæ±ãã«é©çšãããã
é¢é£åæ:åæ1é
GDPRã®ç®çããåœå¢ãè¶ ããããŒã¿ä¿è·ã確ä¿ããå人ããŒã¿ä¿è·ã®äžè²«æ§ãä¿é²ããããšã«ããããšã匷調ã
(1) å人ããŒã¿ã®åæ±ããšé¢é£ããèªç¶äººã®ä¿è·ã¯ãåºæ¬çãªæš©å©ã®äžã€ã§ããã欧å·é£ååºæ¬æš©æ²ç« ïŒä»¥äžãæ²ç« ããšãããïŒã®ç¬¬8æ¡ç¬¬1é åã³æ¬§å·é£åã®æ©èœã«é¢ããæ¡çŽïŒä»¥äžãTFEUããšãããïŒã®ç¬¬16æ¡ç¬¬1é ã¯ãå šãŠã®è ãèªå·±ã«é¢ããå人ããŒã¿ã®ä¿è·ã®æš©å©ãæãããšå®ããŠããã
é¢é£ã¬ã€ãã©ã€ã³:ãGDPRã®å°ççé©çšç¯å²ïŒç¬¬3æ¡ïŒã«é¢ããã¬ã€ãã©ã€ã³ 03_2018 â ããŒãžã§ã³2.1ïŒ
GDPR第3æ¡ã«åºã¥ããEUåå€ã®äŒæ¥ãGDPRã®é©çšå¯Ÿè±¡ãšãªãããå€æããåºæºãæäŸãïŒEUå± äœè ã«ãååããµãŒãã¹ãæäŸããããšããèŠä»¶ã®å ·äœäŸã
ãè¡åç£èŠãã®å ·äœäŸãšè©²åœåºæºã
2.2 åºæ¬æŠå¿µãdefinition
該åœæ¡æ:ã第4æ¡ïŒå®çŸ©ïŒã第9æ¡ïŒç¹å¥ãªçš®é¡ã®å人ããŒã¿ã®åæ±ãïŒ
å人ããŒã¿ãpersonal data
該åœæ¡æ:ã第4æ¡ïŒå®çŸ©ïŒç¬¬1é
æŠèŠ:
èå¥ãããããŸãã¯èå¥å¯èœãªèªç¶äººïŒããŒã¿äž»äœïŒã«é¢ããæ å ±ãæãã
ååãäœæãIDãäœçœ®æ å ±ããªã³ã©ã€ã³èå¥åïŒäŸ: IPã¢ãã¬ã¹ïŒãªã©ãå«ãŸããã
ã(1) ãå人ããŒã¿ããšã¯ãèå¥ãããèªç¶äººåã¯èå¥å¯èœãªèªç¶äººïŒãããŒã¿äž»äœãïŒã«é¢ããæ å ±ãæå³ããã
èå¥å¯èœãªèªç¶äººãšã¯ãç¹ã«ãæ°åãèå¥çªå·ãäœçœ®ããŒã¿ããªã³ã©ã€ã³èå¥åã®ãããªèå¥åãåç §ããããšã«ãã£ãŠãåã¯ãåœè©²èªç¶äººã®èº«äœçãçççãéºäŒçã粟ç¥çãçµæžçãæåçåã¯ç€ŸäŒçãªåäžæ§ã瀺ãäžã€åã¯è€æ°ã®èŠçŽ ãåç §ããããšã«ãã£ãŠãçŽæ¥çåã¯éæ¥çã«ãèå¥ããããè ãããã
é¢é£åæ:åæ26é
å¿ååãããããŒã¿ã¯é©çšå€ãèå¥å¯èœæ§ãããå Žåã¯GDPRç¯å²å ã
(26) ããŒã¿ä¿è·ã®åºæ¬ååã¯ãèå¥ãããèªç¶äººåã¯èå¥å¯èœãªèªç¶äººã«é¢ããå šãŠã®æ å ±ã«å¯ŸããŠé©çšãããªããã°ãªããªããè¿œå æ å ±ã䜿çšããŠã®å©çšã«ãã£ãŠèªç¶äººã«å±ããããšã瀺ããããä»®ååãçµãå人ããŒã¿ã¯ãèå¥å¯èœãªèªç¶äººã«é¢ããæ å ±ãšããŠèããããªããã°ãªããªããããèªç¶äººãèå¥å¯èœã§ãããã©ãããå€æããããã«ã¯ãéžå¥ã®ãããªãèªç¶äººãçŽæ¥åã¯éæ¥ã«èå¥ããããã«ç®¡çè åã¯ãã以å€ã®è ã«ãã£ãŠçšããããåççãªå¯èœæ§ã®ããå šãŠã®æ段ãèæ ®ã«å ¥ããªããã°ãªããªããèªç¶äººãèå¥ããããã«æ段ãçšããããåççãªå¯èœæ§ããããåŠãã確èªããããã«ã¯ãåæ±ãã®æç¹ã«ãããŠå©çšå¯èœãªæè¡åã³æè¡ã®çºå±ãèæ ®ã«å ¥ããäžã§ãèå¥ã®ããã«èŠããè²»çšåã³æééã®ãããªãå šãŠã®å®¢èŠ³çãªèŠçŽ ãèæ ®ã«å ¥ããªããã°ãªããªãããããããããŒã¿ä¿è·ã®åºæ¬ååã¯ãå¿åæ å ±ãããªãã¡ãèå¥ãããèªç¶äººåã¯èå¥å¯èœãªèªç¶äººãšã®é¢ä¿ããããªãæ å ±ãåã¯ãããŒã¿äž»äœãèå¥ã§ããªãããã«å¿ååãããå人ããŒã¿ã«å¯ŸããŠã¯ãé©çšãããªããæ¬èŠåã¯ããããããçµ±èšã®ç®çåã¯èª¿æ»ç 究ã®ç®çãå«ãããã®ãããªå¿åæ å ±ã®åæ±ãã«é¢ãããã®ã§ã¯ãªãã
ç¹å¥ãªçš®é¡ã®å人ããŒã¿ special categories of personal data
該åœæ¡æ:第9æ¡ïŒç¹å¥ãªçš®é¡ã®å人ããŒã¿ã®åæ±ãïŒã第10æ¡ æ眪å€æ±ºåã³ç¯çœªãšé¢é£ããå人ããŒã¿ã®åæ±ã
æŠèŠ:
人皮ãæ°æãæ¿æ²»çæèŠãå®æãå¥åº·æ å ±ãéºäŒããŒã¿ããã€ãªã¡ããªã¯ã¹ããŒã¿ãæ§çæåãªã©ã
ç¹å¥ãªä¿è·ãå¿ èŠã§ãåŠçã«ã¯éå®çãªæ¡ä»¶ãé©çšãããã
第9æ¡ãç¹å¥ãªçš®é¡ã®å人ããŒã¿ã®åæ±ã
ã1. 人皮çè¥ããã¯æ°æçãªåºèªãæ¿æ²»çãªæèŠãå®æäžè¥ããã¯ææ³äžã®ä¿¡æ¡ãåã¯ãåŽåçµåãžã®å å ¥ãæããã«ããå人ããŒã¿ã®åæ±ãã䞊ã³ã«ãéºäŒåããŒã¿ãèªç¶äººãäžæã«èå¥ããããšãç®çãšããçäœããŒã¿ãå¥åº·ã«é¢ããããŒã¿ãåã¯ãèªç¶äººã®æ§ç掻è¥ããã¯æ§çæåã«é¢ããããŒã¿ã®åæ±ãã¯ãçŠæ¢ãããã
第10æ¡ æ眪å€æ±ºåã³ç¯çœªãšé¢é£ããå人ããŒã¿ã®åæ±ã
ã第6æ¡ç¬¬1é ã«åºã¥ãæ眪å€æ±ºåã³ç¯çœªè¡çºåã¯ä¿è·æªçœ®ãšé¢é£ããå人ããŒã¿ã®åæ±ãã¯ãå ¬çæ©é¢ã®ç®¡çã®äžã«ããå Žåãåã¯ãããŒã¿äž»äœã®æš©å©åã³èªç±ã®ããã®é©åãªä¿è·æªçœ®ãå®ããEUæ³åã¯å çåœã®åœå æ³ã«ãã£ãŠãã®åæ±ããèªããããå Žåã«éãããããè¡ãããšãã§ãããæ眪å€æ±ºã®å æ¬çãªèšé²ã¯ãå ¬çæ©é¢ã®ç®¡çã®äžã«ããå Žåã«éãããããä¿ç®¡ã§ããã
é¢é£åæ:åæ75é ïŒ
äžé©åãªåŠçãç¹å¥ãªæ害ãäžãããªã¹ã¯ã«èšåã
(75) èªç¶äººã®æš©å©åã³èªç±ã«å¯Ÿãããªã¹ã¯ã¯ãæ§ã ãªèç¶æ§ãšæ·±å»åºŠã§ãå人ããŒã¿ã®åæ±ãããçãããã
ããã¯ãç©çãªæ倱ã財ç£çãªæ倱è¥ããã¯é財ç£çãªæ倱ãçºçãããããã®ã§ãããç¹ã«
ïŒãã®åæ±ãããå·®å¥ãIDçååã¯IDè©æ¬ºãééäžã®æ倱ãä¿¡çšã®æ¯æãè·åäžã®å®ç§çŸ©åã«ãã£ãŠä¿è·ãããŠããå人ããŒã¿ã®æ©å¯æ§ã®åªå€±ãç¡æš©éã«ããä»®ååã®åŸ©å ãåã¯ãããã以å€ã®é倧ãªçµæžçåã¯ç€ŸäŒçãªäžå©çãçãããããå ŽåïŒããŒã¿äž»äœããã®æš©å©åã³èªç±ã奪ãããåã¯ããã®å人ããŒã¿ã«å¯Ÿããã³ã³ãããŒã«ã®å®è¡ã劚ããããå Žå
ïŒäººçš®çè¥ããã¯æ°æçãªåºèªãæ¿æ²»çãªæèŠãä¿¡æåã¯ææ³äžã®ä¿¡æ¡ãåŽåçµåã®å å ¥ãæããã«ããå人ããŒã¿ã®åæ±ãã䞊ã³ã«ãéºäŒåããŒã¿ãå¥åº·ãšé¢ä¿ããããŒã¿è¥ããã¯æ§ç掻ãšé¢ä¿ããããŒã¿ãåã¯ãæ眪å€æ±ºåã³ç¯çœªè¡çºè¥ããã¯é¢é£ããä¿è·æªçœ®ãšé¢ä¿ããããŒã¿ã®åæ±ãã®å Žå
ïŒå人çåŽé¢ãè©äŸ¡ãããå Žåãç¹ã«ãå人ãããã¡ã€ã«ã®äœæè¥ããã¯ãã®äœ¿çšã®ããã«ãè·åéè¡èœåãçµæžç¶æ ãå¥åº·ãå人çãªå奜è¥ããã¯èå³ãä¿¡é Œæ§è¥ããã¯è¡åãäœçœ®è¥ããã¯ç§»åã«é¢ããåŽé¢ãåæåã¯äºæž¬ãããå Žå
ïŒè匱æ§ã®ããèªç¶äººã®å人ããŒã¿ãç¹ã«ãåã©ãã®å人ããŒã¿ãåæ±ãããå Žå
ïŒåã¯ãåæ±ããè«å€§ãªéã®å人ããŒã¿ãå«ãã§ãããå€æ°ã®ããŒã¿äž»äœã«å¯ŸããŠåœ±é¿ãåãŒãå Žåãããã§ããã
åŠçãprocessing
該åœæ¡æ:ã第4æ¡ïŒå®çŸ©ïŒç¬¬2é
æŠèŠ:
ããŒã¿ã®åéãä¿åãå©çšãåé€ãªã©ãå人ããŒã¿ã«å¯Ÿããããããæäœã
ã(2) ãåæ±ãããšã¯ãèªåçãªæ段ã«ãããåŠããåãããåéãèšé²ãç·šéãæ§æãèšé²ä¿åãä¿®æ£è¥ããã¯å€æŽãæ€çŽ¢ãåç §ã䜿çšãéä¿¡ã«ããé瀺ãé åžãåã¯ãããã以å€ã«å©çšå¯èœãªãã®ãšããããšãæŽåè¥ããã¯çµåãå¶éãæ¶å»è¥ããã¯ç Žå£ã®ãããªãå人ããŒã¿è¥ããã¯äžçŸ€ã®å人ããŒã¿ã«å®æœãããæ¥åéè¡åã¯äžçŸ€ã®æ¥åéè¡ãæå³ããã
管çè controller ã»åŠçè Processor ã»å ±å管çè Joint controllers
該åœæ¡æ: 第4æ¡ïŒå®çŸ©ïŒã第26æ¡ïŒå ±å管çè ïŒã第28æ¡ïŒåŠçè ïŒ
æŠèŠ
管çè : åŠçç®çã»æ段ã決å®ã
åŠçè : 管çè ã®æ瀺ã«åŸããããŒã¿ãåŠçã
å ±å管çè : åŠçç®çã»æ段ãå ±åã§æ±ºå®ã
第4æ¡ïŒå®çŸ©ïŒ
(7) ã管çè ããšã¯ãèªç¶äººåã¯æ³äººãå ¬çæ©é¢ãéšå±åã¯ãã®ä»ã®çµç¹ã§ãã£ãŠãåç¬ã§åã¯ä»ã®è ãšå ±åã§ãå人ããŒã¿ã®åæ±ãã®ç®çåã³æ¹æ³ã決å®ããè ãæå³ããã
ãã®åæ±ãã®ç®çåã³æ¹æ³ãEUæ³åã¯å çåœã®åœå æ³ã«ãã£ãŠæ±ºå®ãããå Žåã管çè åã¯ç®¡çè ãæå®ããããã®ç¹å¥ã®åºæºã¯ãEU æ³åã¯å çåœã®åœå æ³ã«ãã£ãŠå®ããããšãã§ããã
(8) ãåŠçè ããšã¯ã管çè ã®ä»£ããã«å人ããŒã¿ãåæ±ãèªç¶äººè¥ããã¯æ³äººãå ¬çæ©é¢ãéšå±åã¯ãã®ä»ã®çµç¹ãæå³ããã
第26æ¡ïŒå ±å管çè ïŒ
1. äºè 以äžã®ç®¡çè ãå ±åããŠåæ±ãã®ç®çåã³æ¹æ³ã決å®ããå Žåããããã®è ã¯ãå ±å管çè ãšãªãã管çè ããæãã¹ãããããã®ç®¡çè ã®è²¬ä»»ãEUæ³åã¯å çåœã®åœå æ³ã«ãã£ãŠå®ããããŠããªãå Žåããã®ç¯å²å ã«ãããŠã管çè ã¯ãæ¬èŠåã«åºã¥ã矩åããšããããããŒã¿äž»äœã®æš©å©ã®è¡äœ¿ã«é¢ãã矩åã䞊ã³ã«ã第13 æ¡åã³ç¬¬ 14 æ¡ã«èŠå®ããæ å ±ãæäŸãã¹ã管çè ããããã®çŸ©åãéµå®ããããã®ç®¡çè ããããã®è²¬ä»»ã«ã€ããŠã管çè ã®éã§ã®åæã«ãããéææ§ã®ããæ æ§ã§å®ããããã®åæã«ãããŠã¯ãããŒã¿äž»äœã®ããã®é£çµ¡å ãæå®ã§ããã
2. 第 1 é ã«èŠå®ããåæã¯ãå ±å管çè åèªãšããŒã¿äž»äœãšã®ããããã®éã«ããã圹å²åã³é¢ä¿ãé©æ£ã«åæ ãããã®ãšããããã®åæã®èŠç¹ã¯ãããŒã¿äž»äœã«å©çšå¯èœãªãã®ãšãããã
3. 第1é ã«èŠå®ããåæã«å®ããæ¡ä»¶ã«ããããããããŒã¿äž»äœã¯ãåã ã®ç®¡çè ãšã®é¢ä¿ã«ãããŠãåã³ãåã ã®ç®¡çè ã«å¯ŸããŠãæ¬èŠåã«åºã¥ãèªå·±ã®æš©å©ãè¡äœ¿ã§ããã
é¢é£ã¬ã€ãã©ã€ã³: 管çè åã³åŠçè ã®æŠå¿µã«é¢ããã¬ã€ãã©ã€ã³*
GDPR第4æ¡ïŒå®çŸ©ïŒã«åºã¥ããã管çè ããåŠçè ããå ±å管çè ãã®æŠå¿µãæ確åãã圹å²ãšè²¬ä»»ãå®çŸ©ããŒã¿åŠçã«é¢ãã責任ã®ç¯å²ãã管çè ã»åŠçè éã®é¢ä¿ãæŽçããå¥çŽèŠä»¶ã矩åã解説ã
管çè åã¯åŠçè ã®äž»ç£ç£æ©é¢ã®ç¹å®ã«é¢ããã¬ã€ãã©ã€ã³8 2022
GDPR第56æ¡(äž»ç£ç£æ©é¢ã®è·åæš©é)ã«åºã¥ããEUåå ã§è€æ°åœã«æ ç¹ãæã€çµç¹ã®ãäž»ç£ç£æ©é¢ïŒLead Supervisory AuthorityïŒãã®ç¹å®åºæºã解説ãçµç¹ã®äž»èŠæ ç¹ïŒMain EstablishmentïŒã®å€ææ¹æ³ããç£ç£æ©é¢éã®ååã¡ã«ããºã ã説æã
åæãconsent
該åœæ¡æ:ã第4æ¡ïŒå®çŸ©ïŒ11é ã第7æ¡ïŒåæã®èŠä»¶ïŒã第8æ¡ïŒåã©ãã®åæïŒ
æŠèŠ:
èªç±ãç¹å®ãæ瀺çãã€ç¥èã«åºã¥ããææ衚瀺ãæ€åå¯èœã
第4æ¡ïŒå®çŸ©ïŒ
ã(11) ããŒã¿äž»äœã®ãåæããšã¯ãèªç±ã«äžããããç¹å®ãããäºåã«èª¬æãåããäžã§ã®ãäžæçã§ã¯ãªããããŒã¿äž»äœã®ææã®è¡šç€ºãæå³ããããã«ãã£ãŠãããŒã¿äž»äœãããã®é³è¿°åã¯æ確ãªç©æ¥µçè¡çºã«ãããèªèº«ã«é¢é£ããå人ããŒã¿ã®åæ±ãã®åæãè¡šæãããã®ãæå³ããã
第7æ¡ åæã®èŠä»¶
ã1. åæ±ããåæã«åºã¥ãå Žåã管çè ã¯ãããŒã¿äž»äœãèªå·±ã®å人ããŒã¿ã®åæ±ãã«åæããŠããããšã蚌æããããã«ããªããã°ãªããªãã
ã2. å¥ã®äºé ãšãé¢ä¿ããæžé¢äžã®å®£èšã®äžã§ããŒã¿äž»äœã®åæãäžããããå Žåããã®åæã®èŠæ±ã¯ãå¥ã®äºé ãšæ確ã«åºå¥ã§ããç解ãããã容æã«ã¢ã¯ã»ã¹ã§ããæ¹æ³ã§ãæ確ãã€å¹³æãªæèšãçšããŠã衚瀺ãããªããã°ãªããªãããã®ãããªæžé¢äžã®å®£èšäžã®æ¬èŠåã®éåè¡çºãæ§æããéšåã¯ããããªãéšåã«ã€ããŠãææåããªãã
ã3. ããŒã¿äž»äœã¯ãèªå·±ã®åæãããã€ã§ããæ€åããæš©å©ãæãããåæã®æ€åã¯ããã®æ€ååã®åæã«åºã¥ãåæ±ãã®é©æ³æ§ã«åœ±é¿ãäžããªããããŒã¿äž»äœã¯ãåæãäžããåã«ããã®ããšã«ã€ããŠæ å ±æäŸãåãããã®ãšããªããã°ãªããªããåæã®æ€åã¯ãåæãäžããã®ãšåãããã«ã容æãªãã®ã§ãªããã°ãªããªãã
ã4. åæãèªç±ã«äžãããããåŠããå€æããå Žåãç¹ã«ããµãŒãã¹ã®æäŸãå«ããåœè©²å¥çŽã®å±¥è¡ã«å¿ èŠã®ãªãå人ããŒã¿ã®åæ±ãã®åæãå¥çŽã®å±¥è¡ã®æ¡ä»¶ãšããŠãããåŠãã«ã€ããŠãæ倧éã®èæ ®ãæãããªããã°ãªããªãã
第8æ¡ æ å ±ç€ŸäŒãµãŒãã¹ãšã®é¢ä¿ã«ãããŠåã©ãã®åæã«é©çšãããèŠä»¶
ã1. åã©ãã«å¯ŸããçŽæ¥çãªæ å ±ç€ŸäŒãµãŒãã¹ã®æäŸãšã®é¢ä¿ã«ãããŠç¬¬6æ¡ç¬¬1é (a)ãé©çšãããå Žåããã®åã©ãã16æ³ä»¥äžã§ãããšãã¯ããã®åã©ãã®å人ããŒã¿ã®åæ±ãã¯é©æ³ã§ããããã®åã©ãã16æ³æªæºã®å Žåããã®ãããªåæ±ãã¯ããã®åã©ãã®èŠªæš©äžã®è²¬ä»»ã®ããè ã«ãã£ãŠåæãäžããããå Žåãåã¯ããã®è ã«ãã£ãŠãããæ¿èªãããå Žåã«éãããã€ããã®ç¯å²å ã«éããé©æ³ã§ããã å çåœã¯ããã®å¹Žéœ¢ã13 æ³ãäžåããªãéããæ³åŸã«ãã£ãŠããããã®ç®çã®ããã®ããäœã幎霢ãå®ããããšãã§ããã
ã2. 管çè ã¯ãå©çšå¯èœãªæè¡ãèæ ®ã«å ¥ããäžã§ããã®åã©ãã«ã€ããŠèŠªæš©äžã®è²¬ä»»ã®ããè ã«ãã£ãŠåæãäžããããããšãåã¯ããã®è ã«ãã£ãŠãããæ¿èªãããããšã確èªããããã®åççãªåªåããããã®ãšããã
ã3. 第1é ã¯ãåã©ããšé¢ä¿ããå¥çŽã®æå¹æ§ãç· çµåã¯æ³åŸå¹æã«é¢ããèŠå®ã®ãããªå çåœã®äžè¬çãªå¥çŽæ³ã«å¯ŸããŠåœ±é¿ãäžããªãã
é¢é£ã¬ã€ãã©ã€ã³: åæã«é¢ããã¬ã€ãã©ã€ã³
GDPR第4æ¡å®çŸ©(11)åæã»ç¬¬7æ¡åæã®èŠä»¶ã«åºã¥ããé©åãªãåæãã®ååŸèŠä»¶ãå®çŸ©ããèªç±ææã»ç¹å®æ§ã»æ瀺æ§ã»æ€åå¯èœæ§ããæºããåæã®æ¡ä»¶ãéåãªã¹ã¯ãé©çšäŸã解説ã
2.3 管çè ã»åŠçè ã®çŸ©å
ïŒå šè¬ïŒ
該åœæ¡æ:
第24æ¡ ç®¡çè ã®è²¬ä»»ã
第25æ¡ ããŒã¿ä¿è·ãã€ãã¶ã€ã³åã³ããŒã¿ä¿è·ãã€ããã©ã«ãã
第28æ¡ïŒåŠçè ïŒïŒãïŒäžéšâŠåç §ïŒ
第29æ¡ ç®¡çè åã¯åŠçè ã®æš©éã®äžã«ãããåæ±ãã
第31æ¡ ç£ç£æ©é¢ãšã®ååæŠèŠ:
第24æ¡ ç®¡çè ã®è²¬ä»»
ã1. åæ±ãã®æ§è³ªãç¯å²ãéçšåã³ç®ç䞊ã³ã«èªç¶äººã®æš©å©åã³èªç±ã«å¯Ÿããæ§ã ãªèç¶æ§ãšæ·±å»åºŠã®ãªã¹ã¯ãèæ ®ã«å ¥ããäžã§ã管çè ã¯ãæ¬èŠåã«åŸã£ãŠåæ±ããéè¡ãããããšã確ä¿ãããã€ããã®ããšã説æã§ããããã«ããããã®é©åãªæè¡äžåã³çµç¹äžã®æªçœ®ãå®è£ ãããã®ãšããããããã®æªçœ®ã¯ãã¬ãã¥ãŒããããŸããå¿ èŠããããšãã¯ãææ°ã®ãã®ã«æ¹ãããããã®ãšããã
ã2. åæ±æŽ»åãšé¢é£ããŠæ¯äŸçã§ããå Žåã第1é ã«èŠå®ããæªçœ®ã¯ã管çè ã«ããé©åãªããŒã¿ä¿è·æ¹éã®å®è£ ãå«ããã®ãšããã
ã3. 第40 æ¡ã«èŠå®ããæ¿èªãããè¡åèŠç¯åã³ç¬¬ 42 æ¡ã«èŠå®ããæ¿èªãããèªèšŒæ¹æ³ã®éµå®ã¯ã管çè ã®çŸ©åãå±¥è¡ãããŠããããšã蚌æããããã®èŠçŽ ãšããŠçšããããšãã§ããã
第25æ¡ ããŒã¿ä¿è·ãã€ãã¶ã€ã³åã³ããŒã¿ä¿è·ãã€ããã©ã«ã
ã1. æè¡æ°Žæºãå®è£ è²»çšãåæ±ãã®æ§è³ªãç¯å²ãéçšåã³ç®ç䞊ã³ã«åæ±ãã«ãã£ãŠåŒãããããèªç¶äººã®æš©å©åã³èªç±ã«å¯Ÿããæ§ã ãªèç¶æ§ãšæ·±å»åºŠã®ãªã¹ã¯ãèæ ®ã«å ¥ããäžã§ã管çè ã¯ãæ¬èŠåã®èŠä»¶ã«é©åãããã®ãšãããã€ãããŒã¿äž»äœã®æš©å©ãä¿è·ãããããåæ±ãã®æ¹æ³ã決å®ããæç¹åã³åæ±ãããèªäœã®æç¹ã®äž¡æç¹ã«ãããŠãããŒã¿ã®æå°åã®ãããªããŒã¿ä¿è·ã®åºæ¬ååãå¹æçãªæ æ§ã§å®è£ ãããã®åæ±ãã®äžã«å¿ èŠãªä¿è·æªçœ®ãçµ±åããããã«èšèšããããä»®ååã®ãããªãé©åãªæè¡çæªçœ®åã³çµç¹çæªçœ®ãå®è£ ããã
ã2. 管çè ã¯ããã®åæ±ãã®åã ã®ç¹å®ã®ç®çã®ããã«å¿ èŠãªå人ããŒã¿ã®ã¿ãåæ±ãããããšãããã©ã«ãã§ç¢ºä¿ããããã®é©åãªæè¡çæªçœ®åã³çµç¹çæªçœ®ãå®è£ ããããã®çŸ©åã¯ãåéãããå人ããŒã¿ã®åéããã®åæ±ãã®ç¯å²ããã®èšé²ä¿åæéåã³ã¢ã¯ã»ã¹å¯èœæ§ã«é©çšãããããšãããããã®ãããªæªçœ®ã¯ãå人ããŒã¿ãããã®å人ã®é¢äžãªããäžç¹å®ã®èªç¶äººããã¢ã¯ã»ã¹å¯èœãªãã®ãšãããªãããšãããã©ã«ãã§ç¢ºä¿ããã
ã3. 第42æ¡ã«ããæ¿èªãããèªèšŒæ¹æ³ã¯ãæ¬æ¡ã®ç¬¬1é åã³ç¬¬2é ã«å®ããèŠä»¶ã®å 足ã蚌æããããã®èŠçŽ ãšããŠçšããããšãã§ããã
第28æ¡ïŒåŠçè ïŒ
ã1. 管çè ã®ä»£ããã®è ã«ãã£ãŠåæ±ããè¡ãããå Žåããã®ç®¡çè ã¯ãåœè©²åæ±ããæ¬èŠåã«å®ãã矩åã«é©åãããããªæ æ§ã§é©åãªæè¡äžåã³çµç¹äžã®ä¿è·æªçœ®ãå®è£ ããããšã«ã€ããŠååãªä¿èšŒãæäŸããåŠçè ã®ã¿ãçšãããã®ãšãããã€ãããŒã¿äž»äœã®æš©å©ã®ä¿è·ã確ä¿ãããã®ãšããã
ã2. 以äžâŠåŠçå¥çŽã®é åç §
第29æ¡ ç®¡çè åã¯åŠçè ã®æš©éã®äžã«ãããåæ±ã
ãåŠçè åã³ç®¡çè ã®æš©éåã¯åŠçè ã®æš©éã®äžã§è¡çºããè ã§ãã£ãŠãå人ããŒã¿ãžã®ã¢ã¯ã»ã¹ããã€è ã¯ãEU åã¯å çåœã®åœå æ³ã«ããæ±ããããŠããå Žåãé€ãã管çè ããæ瀺ããªãéããåœè©²å人ããŒã¿ãåæ±ã£ãŠã¯ãªããªãã
第31æ¡ ç£ç£æ©é¢ãšã®åå
管çè åã³åŠçè ã䞊ã³ã«ã該åœããå Žåã¯ãããã®è ã®ä»£ç人ã¯ãèŠæ±ã«å¿ããŠããã®è·åã®éè¡ã«ãããŠç£ç£æ©é¢ãšååãããã®ãšããã
é¢é£ã¬ã€ãã©ã€ã³: 管çè åã³åŠçè ã®æŠå¿µã«é¢ããã¬ã€ãã©ã€ã³*
ïŒè©³çŽ°ã¯2.2åç §ïŒ
â å人ããŒã¿åŠçã®è«žåå Principles relating to processing of personal data
該åœæ¡æ: 第5æ¡ïŒå人ããŒã¿ã®åæ±ããšé¢é£ããåºæ¬åå ïŒ
Article 5 Principles relating to processing of personal dataæŠèŠ:
å ¬æ£æ§ãéææ§ãç®çéå®ãããŒã¿æå°åãæ£ç¢ºæ§ãä¿åæéã®å¶éãã»ãã¥ãªãã£ç¢ºä¿ã
第5æ¡ïŒå人ããŒã¿ã®åæ±ããšé¢é£ããåºæ¬åå ïŒ
1. å人ããŒã¿ã¯ïŒ
ã(a) ãã®ããŒã¿äž»äœãšã®é¢ä¿ã«ãããŠãé©æ³ã§ãããå ¬æ£ã§ããããã€ãéææ§ã®ããæ æ§ã§åæ±ãããªããã°ãªããªããïŒãé©æ³æ§ãå ¬æ£æ§åã³éææ§ãïŒ
ã(b) ç¹å®ãããæ確ã§ããããã€ãæ£åœãªç®çã®ããã«åéããããã®ãšãããã€ããã®ç®çã«é©åããªãæ æ§ã§è¿œå çåæ±ããããŠã¯ãªããªããå ¬å ±ã®å©çã«ãããä¿ç®¡ã®ç®çãç§åŠçç 究è¥ããã¯æŽå²çç 究ã®ç®çåã¯çµ±èšã®ç®çã®ããã«è¡ãããè¿œå çåæ±ãã¯ã第89æ¡ç¬¬1é ã«åŸããåœåã®ç®çãšé©åããªããã®ãšã¯ã¿ãªãããªããïŒãç®çã®éå®ãïŒ
ã(c) ãã®å人ããŒã¿ãåæ±ãããç®çãšã®é¢ä¿ã«ãããŠãååã§ãããé¢é£æ§ãããããã€ãå¿ èŠã®ãããã®ã«éå®ãããªããã°ãªããªããïŒãããŒã¿ã®æå°åãïŒ
ã(d) æ£ç¢ºã§ããããã€ããããå¿ èŠãªå Žåãææ°ã®ç¶æ ã«ç¶æãããªããã°ãªããªãããã®å人ããŒã¿ãåæ±ãããç®çãèæ ®ããäžã§ãé æ»ãªããäžæ£ç¢ºãªå人ããŒã¿ãæ¶å»åã¯èšæ£ãããããšã確ä¿ããããã®å šãŠã®æç«ãŠãè¬ããããªããã°ãªããªããïŒãæ£ç¢ºæ§ãïŒ
ã(e) ãã®å人ããŒã¿ãåæ±ãããç®çã®ããã«å¿ èŠãªæéã ããããŒã¿äž»äœã®èå¥ã蚱容ããæ¹åŒãç¶æãããã¹ãã§ãããããŒã¿äž»äœã®æš©å©åã³èªç±ã®å®å šæ§ã確ä¿ããããã«æ¬èŠåã«ãã£ãŠæ±ããããé©åãªæè¡äžåã³çµç¹äžã®æªçœ®ã®å®è£ ã®äžã§ã第89æ¡ç¬¬1é ã«åŸããå ¬å ±ã®å©çã«ãããä¿ç®¡ã®ç®çãç§åŠçç 究è¥ããã¯æŽå²çç 究ã®ç®çåã¯çµ±èšã®ç®çã®ã¿ã®ããã«åæ±ãããå人ããŒã¿ã§ããéãããã®å人ããŒã¿ãããé·ãæéèšé²ä¿åã§ãããïŒãèšé²ä¿åã®å¶éãïŒ
ã(f) ç¡æš©éã«ããåæ±ãè¥ããã¯éæ³ãªåæ±ãã«å¯ŸããŠã䞊ã³ã«ãå¶çºçãªåªå€±ãç Žå£åã¯æå£ã«å¯ŸããŠãé©åãªæè¡äžåã¯çµç¹äžã®æªçœ®ãçšããŠè¡ãããä¿è·ãå«ããå人ããŒã¿ã®é©åãªå®å šæ§ã確ä¿ããæ æ§ã«ãããåæ±ããããïŒãå®å šæ§åã³æ©å¯æ§ãïŒ
2. 管çè ã¯ã第 1 é ã«ã€ããŠè²¬ä»»ãè² ãããã€ãåé éµå®ã蚌æã§ããããã«ããªããã°ãªããªããã®ãšãããïŒãã¢ã«ãŠã³ã¿ããªãã£ãïŒ
é¢é£åæ: åæ26é ã75é ã76é
(76) ããŒã¿äž»äœã®æš©å©åã³èªç±ã«å¯Ÿãããªã¹ã¯ã®èç¶æ§åã³ãã®æ·±å»åºŠã¯ããã®åæ±ãã®æ§è³ªãç¯å²ãéçšåã³ç®çã«ç §ãããŠå€æãããªããã°ãªããªãããªã¹ã¯ã¯ãããŒã¿åæ±æ¥åããªã¹ã¯åã¯é«åºŠãªãªã¹ã¯ãå«ããã®ãåŠãã決ããããšã®ã§ãã客芳çãªè©äŸ¡ã«åºã¥ããŠæ±ºå®ãããªããã°ãªããªãã
ïŒ26é ã¯å人ããŒã¿ã75é ã¯ç¹å¥ã«ããŽãªããŒã¿ãåç §ïŒ
â¡ åŠçã®æ³çæ ¹æ Lawfulness of processing
該åœæ¡æ:
第6æ¡ïŒåæ±ãã®é©æ³æ§ ïŒArticle 6 Lawfulness of processing
第9æ¡ïŒç¹å¥ãªçš®é¡ã®å人ããŒã¿ã®åæ±ã ïŒArticle 9 Processing of special categories of personal data
æŠèŠ:
ã»åŠçã¯æ£åœãªæ³çæ ¹æ ïŒåæãå¥çŽå±¥è¡ãæ³ç矩åãªã©ïŒã«åºã¥ããªããã°ãªããªãã
ã»ç¹å¥ãªçš®é¡ã®å人ããŒã¿ã®åŠçã¯ãäŸå€ä»¥å€ã¯ååçŠæ¢ã
第6æ¡ïŒåæ±ãã®é©æ³æ§ ïŒ
1. åæ±ãã¯ã以äžã®å°ãªããšãäžã€ãé©çšãããå Žåã«ãããŠã®ã¿ããã®ç¯å²å ã§ãé©æ³ã§ããïŒ
ã(a) ããŒã¿äž»äœããäžã€åã¯è€æ°ã®ç¹å®ã®ç®çã®ããã®èªå·±ã®å人ããŒã¿ã®åæ±ãã«é¢ããåæãäžããå Žåã
ã(b) ããŒã¿äž»äœãå¥çŽåœäºè ãšãªã£ãŠããå¥çŽã®å±¥è¡ã®ããã«åæ±ããå¿ èŠãšãªãå Žåãåã¯ãå¥çŽç· çµã®åã«ãããŒã¿äž»äœã®èŠæ±ã«éããŠæ段ãè¬ããããã«åæ±ããå¿ èŠãšãªãå Žåã
ã(c) 管çè ãæããæ³ç矩åãéµå®ããããã«åæ±ããå¿ èŠãšãªãå Žåã
ã(d) ããŒã¿äž»äœåã¯ä»ã®èªç¶äººã®çåœã«é¢ããå©çãä¿è·ããããã«åæ±ããå¿ èŠãšãªãå Žåã
ã(e) å ¬å ±ã®å©çã«ãããŠãåã¯ã管çè ã«äžããããå ¬çãªæš©éã®è¡äœ¿ã«ãããŠè¡ãããè·åã®éè¡ã®ããã«åæ±ããå¿ èŠãšãªãå Žåã
ã(f) 管çè ã«ãã£ãŠãåã¯ã第äžè ã«ãã£ãŠæ±ããããæ£åœãªå©çã®ç®çã®ããã«åæ±ããå¿ èŠãšãªãå Žåããã ãããã®å©çããããå人ããŒã¿ã®ä¿è·ãæ±ããããŒã¿äž»äœã®å©ç䞊ã³ã«åºæ¬çãªæš©å©åã³èªç±ã®ã»ããåªå ããå Žåãç¹ã«ããã®ããŒã¿äž»äœãåã©ãã§ããå Žåãé€ãã
ïŒä»¥äžç¥ïŒ
第9æ¡ ç¹å¥ãªçš®é¡ã®å人ããŒã¿ã®åæ±ã
1. 人皮çè¥ããã¯æ°æçãªåºèªãæ¿æ²»çãªæèŠãå®æäžè¥ããã¯ææ³äžã®ä¿¡æ¡ãåã¯ãåŽåçµåãžã®å å ¥ãæããã«ããå人ããŒã¿ã®åæ±ãã䞊ã³ã«ãéºäŒåããŒã¿ãèªç¶äººãäžæã«èå¥ããããšãç®çãšããçäœããŒã¿ãå¥åº·ã«é¢ããããŒã¿ãåã¯ãèªç¶äººã®æ§ç掻è¥ããã¯æ§çæåã«é¢ããããŒã¿ã®åæ±ãã¯ãçŠæ¢ãããã
2. 第1é ã¯ã以äžã®ããããã®å Žåã«ã¯é©çšãããªãã
ã(a) ããŒã¿äž»äœããäžã€åã¯è€æ°ã®ç¹å®ãããç®çã®ããã®ãã®å人ããŒã¿ã®åæ±ãã«é¢ããæ確ãªåæãäžããå Žåããã ããEUæ³åã¯å çåœã®åœå æ³ã第1é ã«å®ããçŠæ¢ãããŒã¿äž»äœã解é€ã§ããªãããšãå®ããŠããå Žåãé€ãã
ã(b) EU æ³è¥ããã¯å çåœã®åœå æ³ã«ããèªããããŠããç¯å²å ãåã¯ãããŒã¿äž»äœã®åºæ¬çãªæš©å©åã³å©çã®ããã®é©åãªä¿è·æªçœ®ãå®ããå çåœã®åœå æ³ã«ããå£äœåçŽã«ãã£ãŠèªããããç¯å²å ã§ãéçšåã³ç€ŸäŒä¿é䞊ã³ã«ç€ŸäŒçä¿è·ã®æ³åŸã®åéã«ããã管çè åã¯ããŒã¿äž»äœã®çŸ©åãå±¥è¡ããç®çã®ãããåã¯ããããã®è ã®ç¹å¥ã®æš©å©ãè¡äœ¿ããç®çã®ããã«åæ±ããå¿ èŠãšãªãå Žåã
ã(c) ããŒã¿äž»äœãç©ççåã¯æ³çã«åæãäžããããšãã§ããªãå Žåã§ãããŒã¿äž»äœåã¯ãã®ä»ã®èªç¶äººã®çåœã«é¢ããå©çãä¿è·ããããã«åæ±ããå¿ èŠãšãªããšãã
ã(d) æ¿æ²»ãææ³ãå®æåã¯åŽåçµåã®ç®çã«ããå£äœãåäŒãã®ä»ã®éå¶å©çµç¹ã«ããé©åãªä¿è·æªçœ®ãå ·åããæ£åœãªæŽ»åã®éçšã«ãããŠãåœè©²åæ±ããããã®çµç¹ã®æ§æå¡è¥ããã¯å æ§æå¡ãåã¯ããã®çµç¹ã®ç®çãšé¢ä¿ããŠãã®çµç¹ãšç¶ç¶çã«æ¥è§Šããã€è ã®ã¿ã«é¢ãããã®ã§ããããšãæ¡ä»¶ãšãããã€ãããŒã¿äž»äœã®åæãªããã®å人ããŒã¿ãåœè©²çµç¹ã®å€éšã«é瀺ãããªãããšãæ¡ä»¶ãšããŠãåæ±ããè¡ãããå Žåã
ã(e) ããŒã¿äž»äœã«ãã£ãŠæçœã«å ¬éã®ãã®ãšãããå人ããŒã¿ã«é¢ããåæ±ãã®å Žåã
ã(f) 蚎ãã®æèµ·è¥ããã¯æ»æé²åŸ¡ã®ãããåã¯ãè£å€æããã®åžæ³äžã®æš©èœãè¡äœ¿ããéã«åæ±ããå¿ èŠãšãªãå Žåã
ã(g) æ±ããããç®çãšæ¯äŸçã§ãããããŒã¿ä¿è·ã®æš©å©ã®æ¬è³ªçéšåãå°éãããŸããããŒã¿äž»äœã®åºæ¬çãªæš©å©åã³å©çã®å®å šæ§ã確ä¿ããããã®é©åãã€åå¥ã®æªçœ®ãå®ããEUæ³åã¯å çåœã®åœå æ³ã«åºã¥ããéèŠãªå ¬å ±ã®å©çãçç±ãšããåæ±ããå¿ èŠãšãªãå Žåã
ã(h) EU æ³åã¯å çåœã®åœå æ³ã«åºã¥ããåã¯ãå»çå°é家ãšã®å¥çŽã«ããããã€ã第3é ã«å®ããæ¡ä»¶åã³ä¿è·æªçœ®ã«åŸããäºé²å»åŠè¥ããã¯ç£æ¥å»åŠã®ç®çã®ããã«ãåŽåè ã®æ¥åéè¡èœåã®è©äŸ¡ãå»çäžã®èšºæãå»çè¥ããã¯ç€ŸäŒçŠç¥åã¯æ²»çã®æäŸãåã¯ãå»çå¶åºŠè¥ããã¯ç€ŸäŒçŠç¥å¶åºŠåã³ãã®ãµãŒãã¹æäŸã®ç®¡çã®ããã«åæ±ããå¿ èŠãšãªãå Žåã
ã(i) ããŒã¿äž»äœã®æš©å©åã³èªç±ãç¹ã«ãè·åäžã®ç§å¯ãä¿è·ããããã®é©åãã€åå¥ã®æªçœ®ã«é¢ããŠå®ããEU æ³åã¯å çåœã®åœå æ³ã«åºã¥ããå¥åº·ã«å¯Ÿããåœå¢ãè¶ããé倧ãªè åšããä¿è·ããããšãåã¯ãå»çåã³å»è¬åè¥ããã¯å»çæ©åšã®é«ãæ°Žæºã®å質åã³å®å šæ§ã確ä¿ããããšã®ãããªãå ¬è¡è¡çã®åéã«ãããŠãå ¬å ±ã®å©çãçç±ãšããåæ±ããå¿ èŠãšãªãå Žåã
ã(j) æ±ããããç®çãšæ¯äŸçã§ãããããŒã¿ä¿è·ã®æš©å©ã®æ¬è³ªçéšåãå°éãããŸããããŒã¿äž»äœã®åºæ¬çãªæš©å©åã³å©çã®å®å šæ§ã確ä¿ããããã®é©åãã€åå¥ã®æªçœ®ãå®ããEUæ³åã¯å çåœã®åœå æ³ã«åºã¥ãã第89æ¡ç¬¬1é ã«åŸããå ¬å ±ã®å©çã«ãããä¿ç®¡ã®ç®çãç§åŠçç 究è¥ããã¯æŽå²çç 究ã®ç®çåã¯çµ±èšã®ç®çã®ããã«åæ±ããå¿ èŠãšãªãå Žåã
ïŒïŒä»¥éç¥ïŒ
⢠åŠç掻åã®èšé² Records of processing activities
該åœæ¡æ:ã第30æ¡ïŒåŠç掻åã®èšé²ïŒArticle 30 Records of processing activities
æŠèŠ:
åŠçã®ç®çãããŒã¿ã®çš®é¡ã管çè ã»åŠçè ã®æ å ±ãªã©ã詳现ã«èšé²ãã矩åã
1. åã ã®ç®¡çè ãåã³ã該åœããå Žåã管çè ã®ä»£ç人ã¯ããã®è²¬ä»»ã«ãããŠãåæ±æŽ»åã®èšé²ãä¿ç®¡ããããã®èšé²ã¯ã以äžã®æ å ±ã®å šãŠãå«ããïŒãã(a) 管çè ãåã³ã該åœããå Žåãå ±å管çè ã管çè ã®ä»£ç人䞊ã³ã«ããŒã¿ä¿è·ãªãã£ãµãŒã®åååã³é£çµ¡å ïŒ
(b) åæ±ãã®ç®çïŒ
(c) ããŒã¿äž»äœã®é¡åã®èšè¿°åã³å人ããŒã¿ã®çš®é¡ã®èšè¿°ïŒ
(d) 第äžåœåã¯åœéæ©é¢å ã®ååŸè ãå«ããå人ããŒã¿ãé瀺ããããåã¯ãé瀺ãããååŸè ã®é¡åïŒ
(e) 該åœããå Žåãåœè©²ç¬¬äžåœè¥ããã¯åœéæ©é¢ã®èå¥ãå«ãã第äžåœåã¯åœéæ©é¢ã«å¯Ÿããå人ããŒã¿ã®ç§»è»¢ãåã³ã第49æ¡ç¬¬1é 第2å¯é ã«èŠå®ãã移転ã®å Žåãé©æ£ãªä¿è·æªçœ®ã瀺ãææžïŒ
(f) å¯èœãªãšãã¯ãç°ãªãçš®é¡æ¯ã®ããŒã¿ã®åé€ã®ããã«äºå®ãããŠããæéïŒ
(g) å¯èœãªãšãã¯ã第32æ¡ç¬¬1é ã«èŠå®ããæè¡çåã³çµç¹çå®å šç®¡çæªçœ®ã®æŠèŠã
2. åã ã®åŠçè ãåã³ã該åœããå ŽåãåŠçè ã®ä»£ç人ã¯ã管çè ã®ä»£ããã«è¡ãããå šãŠã®çš®é¡ã®åæ±ãã®èšé²ãä¿ç®¡ããã以äžã®äºé ãå«ããïŒ
(a) åŠçè åã³åŠçè ã代ããã«æŽ»åããŠããåã ã®ç®¡çè ã®åååã³é£çµ¡å ã䞊ã³ã«ã該åœããå Žåã管çè åã¯åŠçè ã®ä»£ç人åã³ããŒã¿ä¿è·ãªãã£ãµãŒã®åååã³é£çµ¡å ïŒ
(b) åã ã®ç®¡çè ã®ä»£ããã«è¡ãããåæ±ãã®çš®é¡ïŒ
(c) 該åœããå Žåãåœè©²ç¬¬äžåœè¥ããã¯åœéæ©é¢ã®èå¥ãå«ãã第äžåœåã¯åœéæ©é¢ã«å¯Ÿããå人ããŒã¿ã®ç§»è»¢ãåã³ã第49æ¡ç¬¬1é 第2å¯é ã«èŠå®ãã移転ã®å Žåãé©åãªä¿è·æªçœ®ã瀺ãææžïŒ
(d) å¯èœãªãšãã¯ã第32æ¡ç¬¬1é ã«èŠå®ããæè¡çåã³çµç¹çå®å šç®¡çæªçœ®ã®äžè¬çãªèšè¿°ã
3. 第1é åã³ç¬¬2é ã«èŠå®ããèšé²ã¯ãæžé¢ã«ãããã®ãšããé»åçæ¹åŒãå«ããã®ãšããã
4. 管çè åã¯åŠçè ãåã³ã該åœããå Žåã管çè ã®åã¯åŠçè ã®ä»£ç人ã¯ãèŠè«ã«å¿ããŠãç£ç£æ©é¢ããã®èšé²ãå©çšã§ããããã«ããã
5. å®æœããåæ±ããããŒã¿äž»äœã®æš©å©åã³èªç±ã«å¯ŸããŠãªã¹ã¯ãçºçãããå¯èœæ§ãããå Žåããã®åæ±ããäžæçãªãã®ã§ã¯ãªãå Žåãåã¯ããã®åæ±ãã第 9æ¡ç¬¬ 1é ã«èŠå®ããç¹å¥ãªçš®é¡ã®ããŒã¿ãå«ãã§ãããè¥ããã¯ã第10æ¡ã«èŠå®ããæ眪å€æ±ºåã³ç¯çœªè¡çºãšé¢é£ãããã®ã§ããå Žåãé€ãã第1é åã³ç¬¬2é ã«èŠå®ãã矩åã¯ãåŸæ¥è ã®æ°ã250åæªæºã®äŒæ¥åã¯çµç¹ã«å¯ŸããŠã¯ãé©çšãããªãã
⣠ããŒã¿äž»äœãžã®æ å ±éç¥ã»æš©å©è¡äœ¿å¯Ÿå¿ã
該åœæ¡æ:
第12æ¡ïœ22æ¡ïŒéç¥çŸ©åãã¢ã¯ã»ã¹æš©ãããŒã¿ããŒã¿ããªãã£ãªã©ïŒ
Article 12 Transparent information, communication and modalities for the exercise of the rights of the data subject
æŠèŠ:
ããŒã¿äž»äœã®æš©å©ïŒã¢ã¯ã»ã¹æš©ãèšæ£æš©ãåé€æš©ãªã©ïŒãé©åã«éç¥ã察å¿ã
第12æ¡ ããŒã¿äž»äœã®æš©å©è¡äœ¿ã®ããã®éææ§ã®ããæ å ±æäŸãé£çµ¡åã³æžåŒ
1. 管çè ã¯ãããŒã¿äž»äœã«å¯Ÿããç°¡æœã§ãéææ§ããããç解ããããã容æã«ã¢ã¯ã»ã¹ã§ããæ¹åŒã«ãããæ確ãã€å¹³æãªæèšãçšããŠãåæ±ãã«é¢ãã第13æ¡åã³ç¬¬14æ¡ã«å®ããæ å ±äžŠã³ã«ç¬¬15æ¡ãã第22æ¡åã³ç¬¬34 æ¡ã«å®ããé£çµ¡ãæäŸããããã«ãç¹ã«ãåã©ãã«å¯ŸããŠæ Œå¥ã«å¯ŸåŠããæ å ±æäŸã®ããã«ãé©åãªæªçœ®ãè¬ããããã®æ å ±ã¯ãæžé¢ã«ãããåã¯é©åã§ãããšãã¯é»åçãªæ段ãå«ããã®ä»ã®æ¹æ³ã«ãããæäŸããããããŒã¿äž»äœããæ±ãããããšãã¯ãåœè©²ããŒã¿äž»äœã®èº«å ãä»ã®æ段ã«ãã£ãŠèšŒæãããããšãæ¡ä»¶ãšããŠããã®æ å ±ãå£é ã§æäŸã§ããã
ïŒä»¥äžç¥ïŒ
第13æ¡ ããŒã¿äž»äœããå人ããŒã¿ãååŸãããå Žåã«ãããŠæäŸãããæ å ±
1. ããŒã¿äž»äœãšé¢é£ããå人ããŒã¿ããã®ããŒã¿äž»äœããåéãããå Žåã管çè ã¯ããã®å人ããŒã¿ãååŸããæç¹ã«ãããŠããã®ããŒã¿äž»äœã«å¯Ÿãã以äžã®å šãŠã®æ å ±ãæäŸããïŒ
ïŒä»¥äžç¥ïŒ
第14æ¡ å人ããŒã¿ãããŒã¿äž»äœããååŸããããã®ã§ã¯ãªãå Žåã«ãããŠæäŸãããæ å ±
1. å人ããŒã¿ãããŒã¿äž»äœããååŸããããã®ã§ã¯ãªãå Žåã管çè ã¯ãããŒã¿äž»äœã«å¯Ÿãã以äžã®æ å ±ãæäŸããïŒ
ïŒä»¥äžç¥ïŒ
第15æ¡ ããŒã¿äž»äœã«ããã¢ã¯ã»ã¹ã®æš©å©
1. ããŒã¿äž»äœã¯ã管çè ãããèªå·±ã«é¢ä¿ããå人ããŒã¿ãåæ±ãããŠãããåŠãã®ç¢ºèªãåŸãæš©å©ã䞊ã³ã«ããããåæ±ãããŠãããšãã¯ããã®å人ããŒã¿åã³ä»¥äžã®æ å ±ã«ã¢ã¯ã»ã¹ããæš©å©ãæããïŒ
ïŒä»¥äžç¥ïŒ
第16æ¡ èšæ£ã®æš©å©
ããŒã¿äž»äœã¯ã管çè ãããäžåœã«é æ»ããããšãªããèªå·±ãšé¢ä¿ããäžæ£ç¢ºãªå人ããŒã¿ã®èšæ£ãåŸãæš©å©ãæãããåæ±ãã®ç®çãèæ ®ã«å ¥ããäžã§ãããŒã¿äž»äœã¯ãè£è¶³ã®é³è¿°ãæäŸããæ¹æ³ã«ããå Žåãå«ããäžå®å šãªå人ããŒã¿ãå®å šãªãã®ãšãããæš©å©ãæããã
ïŒä»¥äžç¥ïŒ
第17æ¡ æ¶å»ã®æš©å©ïŒãå¿ããããæš©å©ãïŒ
1. 以äžã®æ ¹æ äžã®ãããããé©çšãããå ŽåãããŒã¿äž»äœã¯ã管çè ãããäžåœã«é æ»ããããšãªããèªå·±ã«é¢ããå人ããŒã¿ã®æ¶å»ãåŸãæš©å©ããã¡ããŸãã管çè ã¯ãäžåœã«é æ»ããããšãªããå人ããŒã¿ãæ¶å»ãã¹ã矩åãè² ãã
ïŒä»¥äžç¥ïŒ
第18æ¡ åæ±ãã®å¶éã®æš©å©
1. ããŒã¿äž»äœã¯ã以äžã®ãããããé©çšãããå Žåã管çè ãããåæ±ãã®å¶éãåŸãæš©å©ãæããïŒ
ïŒä»¥äžç¥ïŒ
第19æ¡ å人ããŒã¿ã®èšæ£è¥ããã¯æ¶å»åã¯åæ±ãã®å¶éã«é¢ããéç¥çŸ©å
管çè ã¯ããããäžå¯èœã§ããããåã¯ãé倧ãªè² æ ãèŠããããšãæããã§ããå Žåãé€ãããã®ããŒã¿ã®é瀺ãåããåã ã®ååŸè ã«å¯Ÿãã第16æ¡ã第17æ¡ç¬¬1é åã³ç¬¬18æ¡ã«åŸã£ãŠè¡ãããå人ããŒã¿ã®èšæ£è¥ããã¯æ¶å»åã¯åæ±ãã®å¶éãéç¥ããã管çè ã¯ãããŒã¿äž»äœã«å¯Ÿãããã®ããŒã¿äž»äœããããæ±ããå Žåããã®ååŸè ã«é¢ããæ å ±æäŸããã
第20æ¡ ããŒã¿ããŒã¿ããªãã£ã®æš©å©
1. ããŒã¿äž»äœã¯ã以äžã®å Žåã«ãããŠã¯ãèªå·±ã管çè ã«å¯ŸããŠæäŸããèªå·±ãšé¢ä¿ããå人ããŒã¿ããæ§é åãããäžè¬çã«å©çšããæ©æ¢°å¯èªæ§ã®ãã圢åŒã§åãåãæš©å©ããã¡ããŸãããã®å人ããŒã¿ã®æäŸãåãã管çè ãã劚ããããããšãªããå¥ã®ç®¡çè ã«å¯Ÿãããããã®å人ããŒã¿ã移è¡ããæš©å©ãæããã
ïŒä»¥äžç¥ïŒ
第21æ¡ ç°è°ãè¿°ã¹ãæš©å©
1. ããŒã¿äž»äœã¯ãèªå·±ã®ç¹å¥ãªç¶æ³ãšé¢é£ããæ ¹æ ã«åºã¥ãã第6æ¡ç¬¬1é (e)åã¯(f) ã«åºã¥ããŠè¡ãããèªå·±ãšé¢ä¿ããå人ããŒã¿ã®åæ±ãã«å¯Ÿãããããã®æ¡é ã«åºã¥ããããã¡ã€ãªã³ã°ã®å Žåãå«ãããã€ã§ããç°è°ãè¿°ã¹ãæš©å©ãæããã管çè ã¯ãããŒã¿äž»äœã®å©çãæš©å©åã³èªç±ãããåªå ããåæ±ãã«ã€ããŠãåã¯ã蚎ãã®æèµ·åã³æ»æé²åŸ¡ã«ã€ããŠããããããªãæ£åœãªæ ¹æ ãããããšããã®ç®¡çè ã蚌æããªãéãã以åŸããã®å人ããŒã¿ã®åæ±ããããªãã
ïŒä»¥äžç¥ïŒ
第22æ¡ ãããã¡ã€ãªã³ã°ãå«ãå人ã«å¯Ÿããèªååãããææ決å®
1. ããŒã¿äž»äœã¯ãåœè©²ããŒã¿äž»äœã«é¢ããæ³çå¹æãçºçããããåã¯ãåœè©²ããŒã¿äž»äœã«å¯ŸããŠåæ§ã®é倧ãªåœ±é¿ãåãŒããããã¡ã€ãªã³ã°ãå«ããã£ã±ãèªååãããåæ±ãã«åºã¥ãã決å®ã®å¯Ÿè±¡ãšãããªãæš©å©ãæããã
ïŒä»¥äžç¥ïŒ
é¢é£ã¬ã€ãã©ã€ã³:
ããŒã¿ããŒã¿ããªãã£ã®æš©å©ã«é¢ããã¬ã€ãã©ã€ã³
GDPR第20æ¡ããŒã¿ããŒã¿ããªãã£ã®æš©å©ã«åºã¥ããããŒã¿äž»äœãèªèº«ã®ããŒã¿ãå¥ã®ãµãŒãã¹ã«ç§»è¡ããæš©å©ãå ·äœåãããããŒã¿ã®æ§é åã»äžè¬çã«äœ¿çšããã圢åŒã§ã®æäŸçŸ©åããæè¡çå®è£ ã®èæ ®äºé ã説æã
éææ§ã«é¢ããã¬ã€ãã©ã€ã³
GDPR第12ïœ14æ¡ã«åºã¥ããããŒã¿äž»äœãžã®æ å ±æäŸçŸ©åãæ確åããã©ã€ãã·ãŒããªã·ãŒã®èŠä»¶ãããŒã¿äž»äœã«åãããããæ å ±æäŸã®æ¹æ³ãäŸå€èŠå®ã説æã
†é©åãªæè¡çã»çµç¹çæªçœ® Security of processing
該åœæ¡æ:
第32æ¡ïŒç¬¬32æ¡ åæ±ãã®å®å šæ§ ïŒArticle 32 Security of processing
æŠèŠ:
æå·åãæ¬ååãã¢ã¯ã»ã¹å¶åŸ¡ãªã©ã®ã»ãã¥ãªãã£å¯Ÿçãè¬ããã
第32æ¡ïŒç¬¬32æ¡ åæ±ãã®å®å šæ§ ïŒ
1. ææ°æè¡ãå®è£ è²»çšãåæ±ãã®æ§è³ªãç¯å²ãéçšåã³ç®ç䞊ã³ã«èªç¶äººã®æš©å©åã³èªç±ã«å¯Ÿããæ§ã ãªèç¶æ§ãšæ·±å»åºŠã®ãªã¹ã¯ãèæ ®ã«å ¥ããäžã§ã管çè åã³åŠçè ã¯ããªã¹ã¯ã«é©åã«å¯Ÿå¿ããäžå®ã®ã¬ãã«ã®å®å šæ§ã確ä¿ããããã«ãç¹ã«ã以äžã®ãã®ãå«ããé©åãªæè¡äžåã³çµç¹äžã®æªçœ®ããããã¹ãå®è£ ããã
(a) å人ããŒã¿ã®ä»®åååã¯æå·åïŒ
(b) åæ±ã·ã¹ãã åã³åæ±ãµãŒãã¹ã®çŸåšã®æ©å¯æ§ãå®å šæ§ãå¯çšæ§åã³å埩æ§ã確ä¿ããèœåïŒ
(c) ç©çåã¯æè¡çãªã€ã³ã·ãã³ããçºçããéãé©æãªæ æ§ã§ãå人ããŒã¿ã®å¯çšæ§åã³ããã«å¯Ÿããã¢ã¯ã»ã¹ã埩æ§ããèœåïŒ
(d) åæ±ãã®å®å šæ§ã確ä¿ããããã®æè¡äžåã³çµç¹äžã®æªçœ®ã®æå¹æ§ã®å®æçãªãã¹ããè©äŸ¡åã³è©å®ã®ããã®æé ã
2. å®å šæ§ã®é©åãªã¬ãã«ãè©äŸ¡ããéãåæ±ãã«ãã£ãŠç€ºããããªã¹ã¯ãç¹ã«ãéä¿¡ãããèšé²ä¿åãããåã¯ããã以å€ã®åæ±ãããªãããå人ããŒã¿ã®ãå¶çºçåã¯éæ³ãªãç Žå£ãåªå€±ãæ¹å€ãç¡æš©éã®é瀺ãåã¯ãã¢ã¯ã»ã¹ããçãããªã¹ã¯ãç¹ã«èæ ®ã«å ¥ããã
3. 第40æ¡ã§å®ããè¡åèŠç¯åã¯ç¬¬42æ¡ã§å®ããæ¿èªãããèªèšŒã¡ã«ããºã ã«å¿ å®ã§ããããšã¯ãæ¬æ¡ç¬¬1é ã«å®ããèŠä»¶ã®éµå®ã説æããããã®èŠçŽ ãšããŠçšããããšãã§ããã
4. 管çè åã³åŠçè ã¯ã管çè åã¯åŠçè ã®æš©éã®äžã§è¡åããå人ããŒã¿ã«ã¢ã¯ã»ã¹ããèªç¶äººãã管çè ã®æ瀺ã«åºã¥ãå Žåãé€ããEU æ³åã¯å çåœã®åœå æ³ã«ãã£ãŠãã®ããã«ããããšãæ±ããããªãéãããã®å人ããŒã¿ãåæ±ããªãããšã確ä¿ããããã®æç«ãŠãè¬ããã
⥠å人ããŒã¿äŸµå®³ãžã®å¯Ÿå¿ãpersonal data breach
該åœæ¡æ:
第33æ¡ïŒç£ç£æ©é¢ã«å¯Ÿããå人ããŒã¿äŸµå®³ã®éç¥ ïŒArticle 33 Notification of a personal data breach to the supervisory authority ã
第34æ¡ïŒããŒã¿äž»äœã«å¯Ÿããå人ããŒã¿äŸµå®³ã®é£çµ¡ ïŒArticle 34 Communication of a personal data breach to the data subject
æŠèŠ:
䟵害çºçåŸã72æé以å ã«ç£ç£æ©é¢ã«éç¥ãé倧ãªå Žåã¯ããŒã¿äž»äœã«ãéç¥ã
第33æ¡ïŒç£ç£æ©é¢ã«å¯Ÿããå人ããŒã¿äŸµå®³ã®éç¥ ïŒ
1. å人ããŒã¿äŸµå®³ãçºçããå Žåã管çè ã¯ããã®å人ããŒã¿äŸµå®³ãèªç¶äººã®æš©å©åã³èªç±ã«å¯Ÿãããªã¹ã¯ãçºçããããããããªãå Žåãé€ããäžåœãªé æ»ãªãããã€ããããå®æœå¯èœãªãšãã¯ããã®äŸµå®³ã«æ°ã¥ããæããé ããšã72æé以å ã«ã第55æ¡ã«åŸã£ãŠæèœç£ç£æ©é¢ã«å¯Ÿãããã®å人ããŒã¿äŸµå®³ãéç¥ããªããã°ãªããªããç£ç£æ©é¢ã«å¯Ÿããéç¥ã72æé以å ã«è¡ãããªãå Žåããã®éç¥ã¯ããã®é 延ã®çç±ãä»ããªããã°ãªããªãã
2. åŠçè ã¯ãå人ããŒã¿äŸµå®³ã«æ°ã¥ããåŸãäžåœãªé æ»ãªãã管çè ã«å¯ŸããŠéç¥ããªããã°ãªããªãã
ïŒä»¥äžç¥ïŒ
第34æ¡ïŒããŒã¿äž»äœã«å¯Ÿããå人ããŒã¿äŸµå®³ã®é£çµ¡ ïŒ
1. å人ããŒã¿äŸµå®³ãèªç¶äººã®æš©å©åã³èªç±ã«å¯Ÿããé«ããªã¹ã¯ãçºçãããå¯èœæ§ãããå Žåã管çè ã¯ããã®ããŒã¿äž»äœã«å¯Ÿããäžåœãªé æ»ãªãããã®å人ããŒã¿äŸµå®³ãé£çµ¡ããªããã°ãªããªãã
ïŒä»¥äžç¥ïŒ
é¢é£ã¬ã€ãã©ã€ã³:
å人ããŒã¿äŸµå®³éç¥ã«é¢ããã¬ã€ãã©ã€ã³09_2022
GDPR第33æ¡ã»34æ¡ã«åºã¥ããããŒã¿äŸµå®³ã®éç¥çŸ©åã«é¢ããæç¶ããšèŠä»¶ãæ確åãç£ç£æ©é¢ããã³ããŒã¿äž»äœãžã®éç¥åºæºã72æé以å ã®å ±å矩åãäŸå€äºé ã説æã
å人ããŒã¿äŸµå®³éç¥ã®äºäŸã«é¢ããã¬ã€ãã©ã€ã³01_2021
å人ããŒã¿äŸµå®³ãçºçããéãå ·äœçãªäºäŸããšã«éç¥çŸ©åã®æç¡ãå€æããããã®æéãæäŸãå žåçãªããŒã¿äŸµå®³ã®ã·ããªãªã瀺ããããããã®ã±ãŒã¹ã§ç£ç£æ©é¢ã»ããŒã¿äž»äœãžã®éç¥èŠåŠãæŽçã
⊠ããŒã¿åŠçå¥çŽã®ç· çµãProcessorïŒDPAïŒ
該åœæ¡æ:ã第28æ¡ïŒåŠçè ïŒã*(ïŒæ ¡ã¯å šè¬åç §ïŒ
æŠèŠ:
管çè ãšåŠçè éã§ãããŒã¿ä¿è·ã«é¢ããæ³çå¥çŽãç· çµã
第28æ¡ïŒåŠçè ïŒ
1.ïŒå šè¬ã®é åç §ïŒ
2. åŠçè ã¯ã管çè ããäºåã«åå¥çåã¯äžè¬çãªæžé¢ã«ããæ¿èªãåŸãªãã§ãå¥ã®åŠçè ãæ¥åã«åŸäºãããŠã¯ãªããªããäžè¬çãªæžé¢ã«ããæ¿èªã®å ŽåãåŠçè ã¯ã管çè ã«å¯Ÿããå¥ã®åŠçè ã®è¿œå åã¯äº€ä»£ã«é¢ããå€æŽã®äºå®ãéç¥ããããã«ãã£ãŠã管çè ã«ããã®ãããªå€æŽã«å¯ŸããŠç°è°ãè¿°ã¹ãæ©äŒãäžãããã®ãšããã
3. åŠçè ã«ããåæ±ãã¯ã管çè ãšã®é¢ä¿ã«é¢ããŠåŠçè ãææãããã€ãåæ±ãã®å¯Ÿè±¡åã³æéãåæ±ãã®æ§è³ªåã³ç®çãå人ããŒã¿ã®çš®é¡åã³ããŒã¿äž»äœã®é¡åã䞊ã³ã«ã管çè ã®çŸ©ååã³æš©å©ãå®ãããå¥çŽåã¯ãã®ä»ã®EUæ³è¥ããã¯å çåœã®åœå æ³ã«åºã¥ãæ³åŸè¡çºã«ãã£ãŠèŠåŸããããå¥çŽåã¯ãã®ä»ã®æ³åŸè¡çºã¯ãç¹ã«ãåŠçè ãã以äžã®ãšããè¡ãããšãå®ããïŒ
ã(a) åŠçè ãæãã EU åã¯å çåœã®åœå æ³ããã®ããã«ããããšãèŠæ±ããå Žåãé€ããå人ããŒã¿ã®ç¬¬äžåœåã¯åœéæ©é¢ã«å¯Ÿãã移転ãšé¢é£ãããã®ãå«ãã管çè ããã®ææžåãããæ瀺ã®ã¿ã«åºã¥ããŠå人ããŒã¿ãåæ±ãããšããã®ãããªå Žåãåœè©²ã®æ³åŸããã®ãããªå ¬å ±ã®å©çäžã®éèŠãªæ³çæ ¹æ ã«é¢ããæ å ±æäŸãçŠæ¢ããªãéããåŠçè ã¯ã管çè ã«å¯Ÿããåæ±ãã®åã«ãåœè©²æ³åŸäžã®èŠä»¶ã«ã€ããŠæ å ±æäŸãããã®ãšããã
ã(b) å人ããŒã¿ã®åæ±ããæ¿èªãããè ãèªãå®ç§çŸ©åã課ããåã¯ãé©åãªæ³åŸäžã®å®ç§çŸ©åã®äžã«ããããšã確ä¿ããããšã
ã(c) 第32 æ¡ïŒåæ±ãã®å®å šæ§ ïŒã«ãã£ãŠæ±ããããå šãŠã®æªçœ®ãè¬ããããšã
ã(d) å¥ã®åŠçè ãæ¥åã«åŸäºãããããã«ã第2é åã³ç¬¬4é ã«èŠå®ããèŠä»¶ãå°éããããšã
ã(e) 第 3 ç« ã«å®ããããŒã¿äž»äœã®æš©å©ãè¡äœ¿ããããã®èŠæ±ã«å¯ŸåŠãã¹ã管çè ã®çŸ©åãå 足ãããããã«ããããå¯èœãªç¯å²å ã§ãåæ±ãã®æ§è³ªãèæ ®ã«å ¥ããäžã§ãé©åãªæè¡äžåã³çµç¹äžã®æªçœ®ã«ãã£ãŠã管çè ãæ¯æŽããããšã
ã(f) åæ±ãã®æ§è³ªåã³åŠçè ãå©çšå¯èœãªæ å ±ãèæ ®ã«å ¥ããäžã§ã第32æ¡ãã第36æ¡ã«ãã矩åã®éµå®ã®ç¢ºä¿ã«ãããŠã管çè ãæ¯æŽããããšã
ã(g) åæ±ããšé¢ä¿ãããµãŒãã¹ã®æäŸãçµäºããåŸãEUæ³åã¯å çåœã®åœå æ³ãå人ããŒã¿ã®èšé²ä¿åãèŠæ±ããŠããªãéãã管çè ã®éžæã«ãããå šãŠã®å人ããŒã¿ãæ¶å»ããåã¯ãããã管çè ã«è¿åŽããããšã䞊ã³ã«ãååšããŠããè€è£œç©ãæ¶å»ããããšã
ã(h) æ¬æ¡ã«å®ãã矩åã®éµå®ã説æãããããåã³ã管çè ã«ãã£ãŠè¡ãããæ€æ»è¥ããã¯ç®¡çè ããå§ä»»ãããå¥ã®ç£æ»äººã«ãã£ãŠè¡ãããæ€æ»ãå«ããç£æ»ãåãå ¥ããè¥ããã¯ãç£æ»ã«è³ããããã«ããããã«å¿ èŠãªå šãŠã®æ å ±ãã管çè ãå©çšã§ããããã«ããããšã
ïŒä»¥äžç¥ïŒ
⧠EU代ç人ãRepresentatives
該åœæ¡æ:
第27æ¡ïŒEUåå ã«æ ç¹ã®ãªã管çè åã¯åŠçè ã®ä»£ç人 ïŒArticle 27 Representatives of controllers or processors not established in the Union
æŠèŠ:
EUåå€ã®ç®¡çè ã»åŠçè ã¯EUå ã®ä»£ç人ãæå®ã
第27æ¡ïŒEUåå ã«æ ç¹ã®ãªã管çè åã¯åŠçè ã®ä»£ç人 ïŒ
1. 第3æ¡ç¬¬2é ãé©çšãããå Žåã管çè åã¯åŠçè ã¯ãæžé¢ã«ãããEUåå ã«ããã代ç人ãæå®ãããã®ãšããã
(以äžç¥ïŒ
âš ããŒã¿ä¿è·è²¬ä»»è ïŒDPOïŒ ãdata protection officer
該åœæ¡æ:
第37æ¡ïœ39æ¡ïŒDPOã®éžä»»çŸ©åã圹å²ãä»»åïŒArticle 37 Designation of the data protection officer
æŠèŠ:
å ¬å ±æ©é¢ã倧èŠæš¡åŠçãè¡ãå Žåã«éžä»»çŸ©åããã
第37æ¡ ããŒã¿ä¿è·ãªãã£ãµãŒã®æå
1. 管çè åã³åŠçè ã¯ã以äžã®å Žåã«ãããŠãããŒã¿ä¿è·ãªãã£ãµãŒãæåããªããã°ãªããªãïŒ
(a) å ¬çæ©é¢åã¯å ¬ççµç¹ã«ãã£ãŠè¡ãããå Žåããã ããè£å€æããã®åžæ³äžã®æš©éãè¡äœ¿ããïŒacting in their judicial capacityïŒå Žåãé€ãåæ±ãïŒ
(b)管çè åã¯åŠçè ã®äžå¿çæ¥åãã ãã®åæ±ãã®æ§è³ªãç¯å²åã³åã¯ç®çã®ããã«ãããŒã¿äž»äœã®å®æçãã€ç³»çµ±çãªç£èŠã倧èŠæš¡ã«èŠããåæ±æ¥åã«ãã£ãŠæ§æãããå ŽåïŒåã¯ã
(c) 管çè åã¯åŠçè ã®äžå¿çæ¥åãã第9æ¡ã«ããç¹å¥ãªçš®é¡ã®ããŒã¿åã³ç¬¬10æ¡ã§å®ããæ眪å€æ±ºåã³ç¯çœªè¡çºãšé¢é£ããå人ããŒã¿ã®å€§èŠæš¡ãªåæ±ãã«ãã£ãŠæ§æãããå Žåã
2. äŒæ¥ã°ã«ãŒãã¯ãããŒã¿ä¿è·ãªãã£ãµãŒãåæ ç¹ãã容æã«ã¢ã¯ã»ã¹å¯èœãªå Žåã«éãã1åã®ããŒã¿ä¿è·ãªãã£ãµãŒãæåã§ããã
3. 管çè åã¯åŠçè ãå ¬çæ©é¢åã¯å ¬ççµç¹ã§ããå Žåããã®çµç¹äžã®æ§é åã³èŠæš¡ãèæ ®ã«å ¥ããäžã§ãè€æ°ã®å ¬çæ©é¢åã¯å ¬ççµç¹ã«å¯ŸããŠåäžã®ããŒã¿ä¿è·ãªãã£ãµãŒãæåã§ããã
4. 第1é ã§å®ããå Žå以å€ã«ãããŠã¯ã管çè è¥ããã¯åŠçè ãåã¯ãæ§ã ãªçš®é¡ã®ç®¡çè è¥ããã¯åŠçè ã代衚ããå£äœãã®ä»ã®çµç¹ã¯ãããŒã¿ä¿è·ãªãã£ãµãŒãæåããããšãã§ããåã¯ãEUæ³åã¯å çåœã®åœå æ³ã«ãã£ãŠèŠæ±ãããå ŽåãããŒã¿ä¿è·ãªãã£ãµãŒãæåããªããã°ãªããªãããã®ããŒã¿ä¿è·ãªãã£ãµãŒã¯ããã®ãããªå£äœãã®ä»ã®çµç¹ã代衚ãã管çè åã¯åŠçè ã®ããã«è¡åã§ããã
5. ããŒã¿ä¿è·ãªãã£ãµãŒã¯ãå°é家ãšããŠã®è³è³ªãåã³ãç¹ã«ãããŒã¿ä¿è·ã®æ³ä»€åã³å®åã«é¢ããå°éç¥è䞊ã³ã«ç¬¬39æ¡ã§å®ããè·åãå 足ããããã®èœåã«åºã¥ããŠæå®ãããã
6. ããŒã¿ä¿è·ãªãã£ãµãŒã¯ã管çè åã¯åŠçè ã®è·å¡ãšããããšãã§ããåã¯ãæ¥åå¥çŽã«åºã¥ããŠãã®è·åãæããããšãã§ããã
7. 管çè åã¯åŠçè ã¯ãããŒã¿ä¿è·ãªãã£ãµãŒã®é£çµ¡å ã®è©³çŽ°ãå ¬è¡šãããã€ãç£ç£æ©é¢ã«å¯Ÿãããããé£çµ¡ããªããã°ãªããªãã
第38æ¡ ããŒã¿ä¿è·ãªãã£ãµãŒã®å°äœ
1. 管çè åã³åŠçè ã¯ãå人ããŒã¿ã®ä¿è·ã«é¢é£ããå šãŠã®åé¡ã«ãé©æ£ãã€é©æã«ãããŒã¿ä¿è·ãªãã£ãµãŒãé¢äžããããšã確ä¿ããªããã°ãªããªãã
ïŒä»¥äžç¥ïŒ
第39æ¡ ããŒã¿ä¿è·ãªãã£ãµãŒã®è·å
1. ããŒã¿ä¿è·ãªãã£ãµãŒã¯ãå°ãªããšãã以äžã®è·åãè¡ããªããã°ãªããªãïŒ
(a) 管çè åã¯åŠçè åã³åæ±ããè¡ãåŸæ¥è ã«å¯Ÿããæ¬èŠååã³ãã以å€ã® EU è¥ããã¯å çåœã®ããŒã¿ä¿è·æ¡é ã«ãã矩åãéç¥ãããã€ãå©èšããããšïŒ
(b) åæ±æ¥åã«é¢äžããè·å¡ã®è²¬ä»»ã®å²åœãŠãæèåäžåã³èšç·Žã䞊ã³ã«ãé¢é£ããç£æ»ãå«ããæ¬èŠåã®éµå®ããã以å€ã®EUåã¯å çåœã®å人ããŒã¿ä¿è·æ¡é éµå®ã䞊ã³ã«ãå人ããŒã¿ä¿è·ãšé¢é£ãã管çè åã¯åŠçè ã®ä¿è·æ¹éã®éµå®ãç£èŠããããšïŒ
(c) èŠè«ããã£ãå Žåã第35æ¡ã«ããããŒã¿ä¿è·åœ±é¿è©äŸ¡ã«é¢ããŠå©èšãæäŸãããã®éè¡ãç£èŠããããšïŒ
(d) ç£ç£æ©é¢ãšååããããšïŒ
(e) åæ±ããšé¢é£ããåé¡ã«é¢ããç£ç£æ©é¢ã®é£çµ¡å ãšããŠè¡åããããšã第 36 æ¡ã«èŠå®ããäºååè°ãé©åãªå Žåããã以å€ã®é¢é£äºé ã«ã€ããŠåè°ããããšãå«ãã
2. ããŒã¿ä¿è·ãªãã£ãµãŒã¯ããã®è·åãéè¡ããéãåæ±ãã®æ§è³ªãç¯å²ãéçšåã³ç®çãèæ ®ã«å ¥ããäžã§ãåæ±æ¥åãšé¢ä¿ãããªã¹ã¯ã«é¢ããé©æ£ã«æ³šæãæãã
é¢é£ã¬ã€ãã©ã€ã³:
ããŒã¿ä¿è·ãªãã£ãµãŒïŒDPOïŒã«é¢ããã¬ã€ãã©ã€ã³
GDPR第37ïœ39æ¡ã«åºã¥ããDPOïŒããŒã¿ä¿è·è²¬ä»»è ïŒã®ä»»åœåºæºã圹å²ã矩åãæ確åãDPOã®ç¬ç«æ§ãçµç¹å ã§ã®äœçœ®ä»ããæ¥åéè¡äžã®èŠä»¶ã«ã€ããŠå ·äœçã«èª¬æã
â© ããŒã¿ä¿è·åœ±é¿è©äŸ¡ïŒDPIAïŒãData protection impact assessment
該åœæ¡æ:
第35æ¡ïŒããŒã¿ä¿è·åœ±é¿è©äŸ¡ ïŒArticle 35 Data protection impact assessmentã第36æ¡ äºååè°ãArticle 36 Prior consultationæŠèŠ:
é«ãªã¹ã¯ã䌎ãåŠçã«é¢ããŠå®æœçŸ©åãããã
第35æ¡ïŒããŒã¿ä¿è·åœ±é¿è©äŸ¡ ïŒ
ã1. åæ±ãã®æ§è³ªãç¯å²ãéçšåã³ç®çãèæ ®ã«å ¥ããäžã§ãç¹ã«æ°ããªæè¡ãçšãããããªçš®é¡ã®åæ±ãããèªç¶äººã®æš©å©åã³èªç±ã«å¯Ÿããé«ããªã¹ã¯ãçºçãããããããããå Žåã管çè ã¯ããã®åæ±ãã®éå§åã«ãäºå®ããŠããåæ±æ¥åã®å人ããŒã¿ã®ä¿è·ã«å¯Ÿãã圱é¿ã«ã€ããŠã®è©äŸ¡ãè¡ããªããã°ãªããªããé¡äŒŒã®é«åºŠã®ãªã¹ã¯ã瀺ãäžé£ã®é¡äŒŒããåæ±æ¥åã¯ãåäžã®è©äŸ¡ã®å¯Ÿè±¡ãšããããšãã§ããã
ã2. 管çè ã¯ãããŒã¿ä¿è·åœ±é¿è©äŸ¡ãè¡ãå Žåããã®æå®ãããŠãããšãã¯ãããŒã¿ä¿è·ãªãã£ãµãŒã«å¯ŸããŠå©èšãæ±ããªããã°ãªããªãã
ã3. 第1é ã«èŠå®ããããŒã¿ä¿è·åœ±é¿è©äŸ¡ã¯ããšãããã以äžã®å Žåã«æ±ããããïŒ
(a) ãããã¡ã€ãªã³ã°ãå«ããèªåçãªåæ±ãã«åºã¥ããã®ã§ããããã€ãããã«åºã¥ãå€æãèªç¶äººã«é¢ããŠæ³çå¹æãçºçãããåã¯ãèªç¶äººã«å¯ŸããŠåæ§ã®é倧ãªåœ±é¿ãåãŒããèªç¶äººã«é¢ããäººæ ŒçåŽé¢ã®äœç³»çãã€åºç¯å²ãªè©äŸ¡ã®å ŽåïŒ
(b) 第 9 æ¡ç¬¬ 1é ã«èŠå®ããç¹å¥ãªçš®é¡ã®ããŒã¿åã¯ç¬¬10æ¡ã«èŠå®ããæ眪å€æ±ºåã³ç¯çœªè¡çºãšé¢é£ããå人ããŒã¿ã®å€§èŠæš¡ãªåæ±ãã®å ŽåïŒåã¯ã
(c) å ¬è¡ãã¢ã¯ã»ã¹å¯èœãªå Žæã®ãã·ã¹ãã ã«ããç£èŠã倧èŠæš¡ã«è¡ãããå Žåã
ã4. ç£ç£æ©é¢ã¯ã第1é ã«ããããŒã¿ä¿è·åœ±é¿è©äŸ¡ã®çŸ©åã«æããåæ±æ¥åã®çš®é¡ã®ãªã¹ããäœæãããããå ¬è¡šããªããã°ãªããªããç£ç£æ©é¢ã¯ã第68æ¡ã«èŠå®ãã欧å·ããŒã¿ä¿è·äŒè°ã«å¯Ÿãããã®ãªã¹ããéä»ãããã®ãšããã
ã5. ç£ç£æ©é¢ã¯ãããŒã¿ä¿è·åœ±é¿è©äŸ¡ãèŠããªãåæ±æ¥åã®çš®é¡ã®ãªã¹ããäœæãããããå ¬è¡šããããšãã§ãããç£ç£æ©é¢ã¯ã欧å·ããŒã¿ä¿è·äŒè°ã«å¯Ÿãããã®ãªã¹ããéä»ãããã®ãšããã
ïŒä»¥äžç¥ïŒ
第36æ¡ äºååè°
ã1. ãã®ãªã¹ã¯ã軜æžãããããã«ç®¡çè ã«ãã£ãŠè¬ããããæªçœ®ãååšããªãç¶æ³äžã§ãèªç¶äººã®æš©å©åã³èªç±ã«å¯ŸããŠé«ããªã¹ã¯ããããããããããããšããããšã第35æ¡ã«åºã¥ãããŒã¿ä¿è·åœ±é¿è©äŸ¡ã瀺ããŠããå Žåã管çè ã¯ããã®åæ±ããéå§ããåã«ãç£ç£æ©é¢ãšåè°ããªããã°ãªããªãã
ã2. 第1é ã§å®ããäºå®ãããŠããåæ±ããæ¬èŠåã«éåããããšã®èŠè§£ãç£ç£æ©é¢ããã€ãšãã¯ããšãããã管çè ããªã¹ã¯ã®ç¹å®åã³åæžã«ã€ããŠäžååã§ãããšãã¯ããã®ç£ç£æ©é¢ã¯ãåè°ã®èŠè«ãåçããæãã8é±é以å ã«ããã®ç®¡çè ã«å¯Ÿããåã³ã該åœããå ŽåãåŠçè ã«å¯Ÿããæžé¢ã«ããå©èšãæäŸãããŸãã第58 æ¡ã«èŠå®ããæš©éäžã®ãããããçšããããšãã§ããããã®æéã¯ãäºå®ãããŠããåæ±ãã®è€éæ§ãèæ ®ã«å ¥ããäžã§ã6é±éãŸã§å»¶é·ã§ããããã®ç£ç£æ©é¢ã¯ããã®ç®¡çè ã«å¯Ÿããåã³ã該åœããå Žåã¯ãåŠçè ã«å¯Ÿããåè°ã®èŠè«ãåé ããæãã1ãæ以å ã«ããã®é 延ã®çç±ãä»ããŠããã®ãããªæé延é·ãéç¥ãããã®ãšããããããã®æéã¯ãç£ç£æ©é¢ãåè°ã®ããã«æ±ããæ å ±ãå ¥æãããŸã§ã®éãåæ¢ãããããšãã§ããã
ã3. 第 1 é ã«ããç£ç£æ©é¢ãšåè°ããå Žåã管çè ã¯ãç£ç£æ©é¢ã«å¯Ÿãã以äžã®æ å ±ãæäŸããªããã°ãªããªãïŒ
ã (a) 該åœããå Žåãåæ±ãã«é¢äžãã管çè ãå ±å管çè åã³åŠçè ã®ããããã®è²¬ä»»ãç¹ã«äŒæ¥ã°ã«ãŒãå ã®åæ±ãã«é¢é£ãã責任ïŒ
ã(b) äºå®ãããŠããåæ±ãã®ç®çåã³æ¹æ³ïŒ
ã(c) æ¬èŠåã«ããããŒã¿äž»äœã®æš©å©åã³èªç±ãä¿è·ããããã«æäŸãããæªçœ®åã³ä¿è·æªçœ®ïŒ
ã(d) 該åœããå ŽåãããŒã¿ä¿è·ãªãã£ãµãŒã®è©³çŽ°ãªé£çµ¡å ïŒ
ã(e) 第35 æ¡ã«å®ããããŒã¿ä¿è·åœ±é¿è©äŸ¡ïŒäžŠã³ã«ã
ã(f) ç£ç£æ©é¢ããæ±ãããããã®ä»ã®æ å ±ã
é¢é£ã¬ã€ãã©ã€ã³:ãããŒã¿ä¿è·åœ±é¿è©äŸ¡ïŒDPIAïŒåã³åæ±ãã2016/679èŠåã®é©çšäžããé«ããªã¹ã¯ãããããããšãäºæ³ãããããåŠãã®å€æã«é¢ããã¬ã€ãã©ã€ã³
GDPR第35æ¡ã«åºã¥ããé«ãªã¹ã¯åŠçã®å€æåºæºãšDPIAïŒããŒã¿ä¿è·åœ±é¿è©äŸ¡ïŒã®é©çšåºæºãæäŸãDPIAãå¿ èŠãªã±ãŒã¹ïŒå€§èŠæš¡ãªç£èŠããããã¡ã€ãªã³ã°ãæ©å¯ããŒã¿ã®åŠççïŒããå®æœæé ã解説ã
⪠åå€ç§»è»¢èŠå¶ãtransfers
該åœæ¡æ:
ã»ç¬¬44æ¡ ç§»è»¢ã«é¢ããäžè¬ååãArticle 44 General principle for transfers
ã»ç¬¬45æ¡ ååæ§èªå®ã«åºã¥ã移転ãArticle 45 Transfers on the basis of an adequacy decision
ã»ç¬¬46æ¡ é©åãªä¿è·æªçœ®ã«åŸã£ã移転ãArticle 46 Transfers subject to appropriate safeguards
ã»ç¬¬47æ¡ ææçäŒæ¥æºåïŒBCRïŒãArticle 47 Binding corporate rules
ã»ç¬¬48æ¡ EUæ³ã«ãã£ãŠèªããããªã移転åã¯é瀺ãArticle 48 Transfers or disclosures not authorised by Union law
ã»ç¬¬49æ¡ ç¹å®ã®ç¶æ³ã«ãããäŸå€ãArticle 49 Derogations for specific situationsæŠèŠ:
EUåå€ãžã®ããŒã¿ç§»è»¢ã¯ãååæ§èªå®ãæšæºå¥çŽæ¡é ïŒSCCsïŒãææçäŒæ¥èŠåïŒBCRsïŒãªã©ãéµå®ã
第44æ¡ ç§»è»¢ã«é¢ããäžè¬åå
çŸã«åæ±ãããŠããåã¯ç¬¬äžåœåã¯åœéæ©é¢ãžã®ç§»è»¢ã®åŸã«åæ±ããæå³ããå人ããŒã¿ç§»è»¢ã¯ããã®ç¬¬äžåœåã¯åœéæ©é¢ããå¥ã®ç¬¬äžåœåã¯åœéæ©é¢ãžã®å人ããŒã¿ã®è»¢éã«é¢ãããã®ãå«ããæ¬èŠåã®ä»ã®æ¡é ã«åŸããæ¬ç« ã«å®ããèŠä»¶ã管çè åã³åŠçè ã«ãã£ãŠéµå®ãããå Žåã«ãããŠã®ã¿ãè¡ããããæ¬ç« ã®å šãŠã®æ¡é ã¯ãæ¬èŠåã«ãã£ãŠä¿èšŒãããèªç¶äººä¿è·ã®ã¬ãã«ãäœäžããªãããšã確ä¿ããããã«é©çšãããã
第45æ¡ ååæ§èªå®ã«åºã¥ã移転
1. 第äžåœã第äžåœå ã®å°ååã¯äžè¥ããã¯è€æ°ã®ç¹å®ã®éšéãåã¯ãåœéæ©é¢ãååãªããŒã¿ä¿è·ã®æ°Žæºã確ä¿ããŠãããšæ¬§å·å§å¡äŒã決å®ããå Žåãåœè©²ç¬¬äžåœåã¯åœéæ©é¢ãžã®å人ããŒã¿ã®ç§»è»¢ãè¡ãããšãã§ããããã®ç§»è»¢ã¯ããããªãåå¥ã®èš±å¯ãèŠããªãã
ïŒä»¥äžç¥ïŒ
第46æ¡ é©åãªä¿è·æªçœ®ã«åŸã£ã移転
1. 第45æ¡ç¬¬3é ã«ãã決å®ããªãå Žåã管çè åã¯åŠçè ã¯ããã®ç®¡çè åã¯åŠçè ãé©åãªä¿è·æªçœ®ãæäŸããŠããããã€ãããŒã¿äž»äœã®å·è¡å¯èœãªæš©å©åã³ããŒã¿äž»äœã®ããã®å¹æçãªåžæ³ææžãå©çšå¯èœãªããšãæ¡ä»¶ãšããŠã®ã¿ã第äžåœåã¯åœéæ©é¢ãžã®å人ããŒã¿ã移転ããããšãã§ããã
2. 第1é ã§å®ããé©åãªä¿è·æªçœ®ã¯ãç£ç£æ©é¢ããåå¥ã®æ¿èªãå¿ èŠãšããã以äžã®ããããã«ãã£ãŠè¬ããããšãã§ããïŒ
(a) å ¬çæ©é¢åã¯å ¬ççµç¹ã®éã®æ³çææååã³å·è¡åã®ããææžïŒ
(b) 第47æ¡ã«åŸãææçäŒæ¥æºåïŒ
(c) 第93 æ¡ç¬¬2é ã§å®ãã審è°æç¶ã«åŸã£ãŠæ¬§å·å§å¡äŒã«ãã£ãŠæ¡æãããæšæºããŒã¿ä¿è·æ¡é ïŒ
(d) ç£ç£æ©é¢ã«ãã£ãŠæ¡æããããã€ã第93æ¡ç¬¬2é ã§å®ãã審è°æç¶ã«åŸã£ãŠæ¬§å·å§å¡äŒã«ãã£ãŠæ¿èªãããæšæºããŒã¿ä¿è·æ¡é ïŒ
(e) ããŒã¿äž»äœã®æš©å©ã«é¢ãããã®ãå«ããé©åãªä¿è·æªçœ®ãé©çšããããã®ææåãããå·è¡å¯èœãªç¬¬äžåœã®ç®¡çè åã¯åŠçè ã®çŽå®ã䌎ã£ãã第40æ¡ã«ããæ¿èªãããè¡åèŠç¯ïŒåã¯ã
(f) ããŒã¿äž»äœã®æš©å©ã«é¢ãããã®ãå«ããé©åãªä¿è·æªçœ®ãé©çšããããã®ææåãããå·è¡å¯èœãªç¬¬äžåœã®ç®¡çè åã¯åŠçè ã®çŽå®ã䌎ã£ãã第42æ¡ã«ããæ¿èªãããèªèšŒæ¹æ³ã
ïŒä»¥äžç¥ïŒ
第47æ¡ ææçäŒæ¥æºåïŒBCRïŒ
1. æèœç£ç£æ©é¢ã¯ã次ã«æ²ããå Žåã第63æ¡ã«å®ããäžè²«æ§ã¡ã«ããºã ã«åŸããææçäŒæ¥æºåãæ¿èªããªããã°ãªããªãïŒ
(a) ãã®åŸæ¥è ãå«ããäŒæ¥ã°ã«ãŒãåã¯å ±åçµæžæŽ»åã«åŸäºããäŒæ¥ã°ã«ãŒãã®é¢ä¿ããå šãŠã®ã¡ã³ããŒãæ³çã«ææãããããã®è ã«é©çšããããã€ããããã®è ã«ãã£ãŠå·è¡ããïŒ
(b) ãã®å人ããŒã¿ã®åæ±ããšé¢é£ããããŒã¿äž»äœã®å·è¡å¯èœãªæš©å©ãæ瀺ã§äžããŠããïŒãã€ã
(c) 第2é ã«å®ããèŠä»¶ãæºãããŠããå Žåã
ïŒä»¥äžç¥ïŒ
第48æ¡ EUæ³ã«ãã£ãŠèªããããªã移転åã¯é瀺
管çè åã¯åŠçè ã«å¯ŸããŠå人ããŒã¿ã®ç§»è»¢åã¯é瀺ãåœãã第äžåœã®è£å€æè¥ããã¯æ³å»·ã®å€æ±ºåã³å ¬çæ©é¢ã®æ±ºå®ã¯ãæ¬ç« ã«ãã移転ã®ããã®å¥ã®æ³çæ ¹æ ã劚ããããšãªãããããªãæ æ§ã«ããã«ãããåžæ³å ±å©æ¡çŽã®ãããªèŠè«å ã§ãã第äžåœãš EU åã¯å çåœãšã®éã§æå¹ãªåœéåæã«åºã¥ãå Žåã«ãããŠã®ã¿ãèªãããããåã¯å·è¡åãæããããšãã§ããã
第49æ¡ ç¹å®ã®ç¶æ³ã«ãããäŸå€
1. 第45 æ¡ç¬¬ 3é ã«ããååæ§èªå®ããªãå Žåãåã¯ææçäŒæ¥æºåãå«ãã第46æ¡ã«ããé©åãªä¿è·æªçœ®ããªãå Žåã以äžã®æ¡ä»¶äžã®ãããããæºãããŠããå Žåã«ãããŠã®ã¿ã第äžåœåã¯åœéæ©é¢ãžã®å人ããŒã¿ã®ç§»è»¢åã¯å人ããŒã¿ç§»è»¢ã®éåãè¡ãããšãã§ããïŒ
(a) ååæ§èªå®åã³é©åãªä¿è·æªçœ®ãååšããªãããã«ããã®ãããªç§»è»¢ããã®ããŒã¿äž»äœã«å¯ŸããŠçºçãããå¯èœæ§ã®ãããªã¹ã¯ã®æ å ±æäŸãåããåŸã«ããã®ããŒã¿äž»äœããææ¡ããã移転ã«æ瀺çã«åæããå ŽåïŒ
(b) ããŒã¿äž»äœãšç®¡çè ãšã®éã®å¥çŽã®å±¥è¡ã®ããã«ãã®ç§»è»¢ãå¿ èŠãšãªãå Žåãåã¯ãããŒã¿äž»äœã®èŠæ±ã«ãããå¥çŽç· çµåã®æªçœ®ãå®æœããããã«ãã®ç§»è»¢ãå¿ èŠãšãªãå ŽåïŒ
(c) 管çè åã³ãã以å€ã®èªç¶äººè¥ããã¯æ³äººãšã®éã§ããŒã¿äž»äœã®å©çã®ããã«åž°ããå¥çŽã®ç· çµãåã¯ããã®å¥çŽã®å±¥è¡ã®ããã«ç§»è»¢ãå¿ èŠãšãªãå ŽåïŒ
(d) å ¬å ±ã®å©çã®é倧ãªäºç±ã®ç§»è»¢ãå¿ èŠãšãªãå ŽåïŒ
(e) æ³ç䞻匵æã®ç«èšŒãè¡äœ¿åã¯æåŒã«ç§»è»¢ãå¿ èŠãšãªãå ŽåïŒ
(f) ããŒã¿äž»äœãç©ççåã¯æ³çã«åæãäžããããšãã§ããªãå Žåã«ãããŠãããŒã¿äž»äœåã¯ãã以å€ã®è ã®çåœã«é¢ããå©çãä¿è·ããããã«ç§»è»¢ãå¿ èŠãšãªãå ŽåïŒ
(g) EU æ³åã¯å çåœã®åœå æ³ã«åŸããå ¬è¡ã«å¯ŸããŠæ å ±ãæäŸããããšãäºå®ããŠããããã€ãå ¬è¡äžè¬åã³æ£åœãªå©çããã€ããšã説æããããšã®ã§ããè ã®äž¡è ã«å¯ŸããŠéãããŠããããåã ã®æ¡ä»¶ã«ãããŠãç §äŒã«é¢ããŠEUæ³åã¯å çåœã®åœå æ³ã«ããå®ããããæ¡ä»¶ãå 足ããé床å ã®ã¿ã«å¶éãããŠããç»é²æ©é¢ã«éããç»é²æ©é¢ããã®ç§»è»¢ãå¿ èŠãšãªãå Žåã
ïŒä»¥äžç¥ïŒ
é¢é£ã¬ã€ãã©ã€ã³:
èŠå第49æ¡ïŒç¹å®ã®ç¶æ³ã«ãããïŒäŸå€ã«é¢ããã¬ã€ãã©ã€ã³
GDPR第49æ¡ã«åºã¥ããEUåå€ãžã®ããŒã¿ç§»è»¢ã蚱容ãããäŸå€æ¡ä»¶ãå ·äœåãååæ§èªå®ããªãå Žåã§ãããŒã¿ç§»è»¢ãå¯èœãªã±ãŒã¹ïŒæ瀺çåæãå¥çŽå±¥è¡ãé倧ãªå ¬å ±å©ççïŒã解説ã
ïŒçœ°åèŠå®ãPenaltiesïŒ
該åœæ¡æ:
第84æ¡ïŒå¶è£ïŒArticle 84 Penalties
æŠèŠ:
éåã«å¯Ÿãã眰åïŒæ倧2,000äžãŠãŒããŸãã¯äŒæ¥å£²äžé«ã®4%ïŒã
第84æ¡ å¶è£
1. å çåœã¯ãæ¬èŠåã®éåè¡çºããšãããã第83æ¡ã«ããå¶è£éã«æããªãéåè¡çºã«é©çšå¯èœãªå¥ã®å¶è£ã«é¢ããæ³ä»€ãå®ãããã€ããã®æ³ä»€ãå®è£ ãããããšã確ä¿ããããã«å¿ èŠãšãªãå šãŠã®æªçœ®ãè¬ããããã®å¶è£ã¯ãå¹æçã§ãããæ¯äŸçã§ããããã€ãææ¢åã®ãããã®ãšããã
2. åå çåœã¯ã欧å·å§å¡äŒã«å¯Ÿãã2018幎5æ25æ¥ãŸã§ã«ã第1é ã«ããæ¡æããå çåœã®åœå æ³ã®æ¡é ãéç¥ãããã€ãé æ»ãªãããããã®æ¡é ã«åœ±é¿ãäžãããã®åŸã®æ¹æ£ãéç¥ããã
è©Šéšç¯å²ã®æ¡æïŒäžéšé çç¥ïŒãåæãGLã¯ä»¥äžã§ãã
ãã®ä»åèã«ãªããããªæ å ±
ãã®ä»åèã«ãªããããªæç§æžã®æå³ç¿Œã¯ãGDPRã«ã€ããŠã¯ããã©ã€ãã·ãŒãã¯ã€ãå ¬åŒæç§æžã®ç¬¬â €ç« EUã®å人æ å ±ä¿è·æ³ã®åºç€ãã§ã¯ãªãããšæããŸãã
ãã©ã€ãã·ãŒãã¯ã€ãïŒæ°éåéïŒã®å ¬åŒæç§æžãã®â €ç« GDPRéšå
![](https://assets.st-note.com/img/1738041271-KvBx62SGVHWIDufqjatUbMXh.png?width=1200)
æŠèª¬GDPR
GDPRã®è§£èª¬æ¬ã¯è€æ°åºãŠããŸãããæ¥æ¬DPOåäŒä»£è¡šçäºãå éšå çãæšèŠãå éšå çã®æãåã®å çæ¹å·çã®æ¬æžã¯ãå 容ã«ä¿¡é ŒããããŠããã€ç°¡æœã§èªã¿ãããã§ãã
å人æ å ±ä¿è·æ³ã³ã³ã¡ã³ã¿ãŒã«
è©Šéšå¯ŸçïŒÎ±ã§ãæ¥æ¬ã®å人æ å ±ä¿è·æ³ã®æ¡æã®åŸã«ãGDPRã®é¡äŒŒæ¡æã®è§£èª¬ãããããã®èãæ¹ã®å ±éé ãšéããç解ããããã®æ¬ãäžçŽè 以äžåãã
ããšãã
æãåºããçµãããããããŠè©Šéšç¯å²ããæ¡æãæ¯ãè¿ã£ãŠæ¹ããŠèªãã§ã¿ããšã
ããããããªããšãæžããŠãã£ãã®ããŒã
ãšæ°ã¥ãããšããããã®ã ãªãããšããã®ãææ³ã§ãã
æ¥æ¬ã«æ¯ã¹ãGDPRã¯åæããããæ¡æãGLãè±å¯ã«ãããŸãã
å匷ã®ä»æ¹ãšããŠãèªåã¯ã
â ãã©ã€ãã·ãŒãã¯ã€ãã®ããã¹ãã®GDPR éšåãæ軜ãªæ¬ã§æŠèŠ³
â¡è©Šéšç¯å²ã®æ¡æã«çŽ çŽãªæ°æã¡ã§ããã
â¢GLããã£ãšæãèªã¿ãã
ãããã«ãããããªïŒãšåŠæ³äžã§ãã
åè·ã§GDPRã®å®åã¯å€ããªãã£ãã®ã§äžå®ããããŸãâŠ
ã§ããŸããåããŠã®è©Šéšå®æœãªã®ã§ãããã°ããã¯åããŠã¿ãªããšããããŸãããïŒç¬ïŒ
ã§ã¯ãŸãïŒ
é¢é£Note
ä»æ¥ã®AIçµµ
![](https://assets.st-note.com/img/1738320033-g0ElvM1DuyVWiqKtPr6GQXLe.png?width=1200)