GDPR対象æ¥è ã®å¤æåºæºã¨ãã©ã¤ãã·ã¼ããªã·ã¼ãæ¸ãéã®ãã¤ã³ãã¾ã¨ã
Markdownãã¼ãã¢ããªInkdropãä¸äººã§éçºãã¦ããTAKUYAã§ããInkdropã¯EUã«ãã¦ã¼ã¶ãçµæ§ããã®ã§ãGDPR (EU General Data Protection Regulation)ã¸ã®å¯¾å¿æºåãé²ãã¦ãã¾ãããGDPRã¯EUã®å人æ å ±ä¿è·ã«é¢ããæ°ããæ³å¾ã§ãããã®åº¦ãæ½è¡äºå®æ¥ã®2018å¹´5æ25æ¥ã«ç¡äºéã«åããããã¨ãã§ãã¾ããã
ãã©ã¤ãã·ã¼ããªã·ã¼ãã¤ãããæ¸ãç´ããææ§ãªè¡¨ç¾ãé¿ãã¦ãGDPRã§è¦æ±ããã¦ããå人æ å ±åãæ±ãã«é¢ããæ å ±ãå ¨ã¦é示ãã¾ãããæ¸ãã®å¤§å¤ã ã£ãã»ã»ã
å æ¥ãGDPRã«é¢ããèªåç¨ã®ã¡ã¢ã¨ãã¦ä»¥ä¸ã®è¨äºãæ¸ããããäºæ³ä»¥ä¸ã«åé¿ã大ããã¦ã³ã£ãããã¾ãããæ¥æ¬èªã§éçºè åãã®åãããããã¾ã¨ã¾ã£ãæ å ±ãç¡ãã®ãã¾ãåé¡ã§ããã
æ¬ç¨¿ã§ã¯å®éã«å¯¾å¿ãã¦ã¿ã¦åãã£ããã¨ãããã©ã¤ãã·ã¼ããªã·ã¼æºåã®æ³¨æç¹ãªã©ãã·ã§ã¢ãããã¨æãã¾ãããããã対å¿ãããæ¹ã®åèã«ãªãã°å¹¸ãã§ãã
ããããGDPR対象æ¥è ã§ã¯ãªãã£ã
Inkdropã¯ä»åGDPR対å¿ãããã®ã®ãGDPR対象æ¥è ã¨ã¯ãè¦ãªãããªããã¨ãã夿ãåºæ¥ã¾ãããªã®ã§ã対å¿ããªãã¨ãã鏿è¢ãããã¾ãããçç±ã¯ä»¥ä¸ã®ã¨ããã§ãã
GDPRã¯ãµã¼ãã¹ãä¼ç¤¾ã®è¦æ¨¡ã«é¢ä¿ãªãé©ç¨ãããã«ã¼ã«ãªã®ã§ããã¨ãå人éçºã®é¶ç´°ã¢ããªã§ãããã¨ãåå対象ã¨ãªãã¾ããããããªããããããè±èªã§ãµã¼ãã¹ãå ¬éããã ãã§å¯¾è±¡ã«ãªãã®ãã¨ããã¨å¿ ãããããã§ã¯ããã¾ãããããã§ã¯åã®ããã«æ¥æ¬ã§æ´»åãã¦ãã¦EUã«æ ç¹ããªãæ¥è ã«ã¤ãã¦æ¤è¨ãã¾ãã
EUã«æ ç¹ããªãæ¥è 㯠âArticle 3 Territorial scopeâã®åå¤é©ç¨ã®é ç®ã«è©²å½ãã¾ããããã«é¢ããæ¥æ¬èªã®è§£èª¬ã¯ä»¥ä¸ã®è¨äºãå½¹ã«ç«ã¤ã§ãããã
以ä¸ã®ããããã«è©²å½ããã°GDPR対象æ¥è ã¨ã¿ãªããã¾ãï¼
(a)EU å¨ä½ã®ãã¼ã¿ä¸»ä½ã«å¯¾ããååã»ãµã¼ãã¹ã®æä¾ã«é¢ããå¦çã
(b) EU åå ã§è¡ããããã¼ã¿ä¸»ä½ã®è¡åã®ç£è¦ã«é¢ããå¦çã
(a)ã¯EUã«ã¦ã¼ã¶ãããã°å¯¾è±¡ã¨ãªãããã«åãåãã¾ãããå ¨ã¦ã§ã¯ããã¾ããããªããªãã¤ã³ã¿ã¼ãããã®ãµã¼ãã¹ã¯åºæ¬çã«ã©ãããã§ãå©ç¨å¯è½ã ããã§ããããªããæ¥æ¬äººåãã«ä½ã£ã¦ããã¨ãã¦ããã¤ã³ã¿ã¼ãããã«å ¬éãã¦ããã°EUã®äººã使ããã¨ã¯åççã«å¯è½ã§ãããã®ãããGDPRã¯Recital 23ã«ã¦ä»¥ä¸ã®ããã«è£è¶³ãã¦ãã¾ãï¼
Recital 23: âWhereas the mere accessibility of the controllerâs, processorâs or an intermediaryâs website in the union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention.â â What does territorial scope mean under the GDPR?
ããªãã¡ãåã«ã¢ã¯ã»ã¹å¯è½ã§ãããã¨ã¯EUå¨ä½ã«å¯¾ãããµã¼ãã¹æä¾ã¨ã¯ã¿ãªãããªãã¨ããäºã§ããã§ã¯ã©ãããæã«ã¿ãªãããã®ãã¨ããã¨ï¼
Recital 24: âFactors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.â â What does territorial scope mean under the GDPR?
ããã¯çµæ¸ç£æ¥çã®ã¬ã¤ãã©ã¤ã³ã«ãåãå 容ã®è£è¶³ãããã¾ãï¼
â»4 ã©ã®ãããªè¨èªãé貨ã使ç¨ããã¦ããããEUåå ã®å人ã«é¢ããè¨åãããããååããµã¼ãã¹ã®æä¾ç¯å²çãèæ ®ãã¦å¤æ ãããåã«è±èªã®ã¦ã§ããµã¤ããè¼ãã¦ããã ãã§ã¯é©ç¨ããã¾ããã
ã¤ã¾ããã¦ã¼ãããã³ã建ã¦ã®æ±ºæ¸ã«å¯¾å¿ãã¦ãããããã©ã³ã¹èªã§ãµã¼ãã¹ãæä¾ãã¦ãããããã¨å¯¾è±¡ã«ãªãã¾ããEUåãã«åºåãåºãã¦ãã¦ã対象ã«ãªãã¾ããInkdropã®å ´åã¯è±èªã§ãUSDã«ããæ±ºæ¸ã®ã¿å¯¾å¿ãã¦ãã¾ããåºåã¯åºãã¦ãã¾ããããªã®ã§ã(a)ã«ã¯è©²å½ããªãã¨å¤æã§ãã¾ãã
ãã®äºãããããããªããç¹ã«EUåãã«ãµã¼ãã¹ãæä¾ãã¦ããªããªããGDPRãé¿ããããã«ããããEUããã®ã¢ã¯ã»ã¹ãã·ã£ããã¢ã¦ãããå¿ è¦ã¯ããã¾ããã
(b)ã«é¢ãã¦ã¯ãã¦ã¼ã¶ã®è¡åå±¥æ´ãåéãã¦ããã該å½ãã¾ããããããå ¨ã¦ã§ã¯ããã¾ãããRacital 24ã«ããã°ã主ã«ç¨éã§å·¦å³ããã¾ãï¼
Recital 24: âNatural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning her or him or for analyzing or predicting her or his personal preferences, behaviors and attitudes.â â What does territorial scope mean under the GDPR?
è¦ããã«ãå人ã®å好ãåæãã¦ãã¼ã½ãã©ã¤ãºããæ©è½ãä»ããããåºåã®ãªã¿ã¼ã²ãã£ã³ã°ãè¡ã£ããããç®çã§æ å ±ãåéããã¨å¯¾è±¡ã¨ãªãã¾ããã¾ããä½ç½®æ å ±ããã©ããã³ã°ããã®ãããã«è©²å½ãã¾ããå°å³ç³»ãã©ã¤ããã°ç³»ã¯æ³¨æã§ãããInkdropã§ã¯ãããã®ç®çã§å人æ å ±ãåãæ±ã£ã¦ããªãã®ã§è©²å½ããªãã¨å¤æã§ãã¾ãã
以ä¸ã®çç±ãããInkdropã¯GDPRã«å¯¾å¿ããªãã¨ãã鏿ãåºæ¥ã¾ãããããããªãããInkdropã¯å人ç¨ã¡ã¢ãµã¼ãã¹ã¨ãã¦ã»ã³ã·ãã£ããªãã¼ããã¼ã¿ãæ±ãã¾ãããµã¼ãã¹ãGDPRã«æºæ ãã¦ããã¨è¨ããã¨ã¯ä¸å®ã®ãã©ã¤ãã·ã¼ä¿è·åºæºãæºããã¦ããã¨è¨ããã¨ã§ããããã¯EUã®ã¿ãªããæ¥æ¬ãå«ããã¦ã¼ã¶ã®çããã«ã¨ã£ã¦ãå®å¿ã§ããã¡ãªãããããã¾ããã ããInkdropã対å¿ããæç¾©ã¯ã¨ã¦ã大ããã¨èãã¾ããã
Data Protection Officer (DPO)ãéã義åã¯ç¡ãã£ã
GDPRã¯ã対象æ¥è ã«DPO(ãã¼ã¿ä¿è·æ å½è )ãä»»å½ããããã«ç¾©åä»ãã¦ãã¾ããè¦ã¯ãã©ã¤ãã·ã¼ã¨æ³å¾ã®å°éå®¶ãéã£ã¦æ¥è ã®å¥å ¨æ§ãä¿ã¤ã®ãç®çã§ããå人éçºè ã«ã¨ã£ã¦ããã®è²»ç¨ã¯ç大ãªãã®ã§ãã
å½åInkdropã¯DPOãéãå¿ è¦ãããã¨åéããã¦ãã¦ãå æ¥ãéããªãããGDPRã®å¯¾å¿ã諦ããããã¨ã¦ã¼ã¶ã«ã¢ãã¦ã³ã¹ãã¾ãããã§ãä¸é¨ã®è¦ªåãªã¦ã¼ã¶ããã以ä¸ã®æ å ±ãæãã¦ä¸ãã£ããããã§ãDPOãéããªãã¦ããããã¨ãåããã¾ãããæ¬å½ã«æè¬ã
DPOã®ä»»å½ã¯å ¨ã¦ã®æ¥è ã«ç¾©åä»ãããããã®ã§ã¯ãªãã以ä¸ã®ãããªæ¡ä»¶ãããã¾ãï¼
You should consider whether you are required to formally designate a Data Protection Officer (DPO). You must designate a DPO if you are:
* a public authority (except for courts acting in their judicial capacity);
* an organisation that carries out the regular and systematic monitoring of individuals on a large scale; or
* an organisation that carries out the large scale processing of special categories of data, such as health records, or information about criminal convictions. The Article 29 Working Party has produced guidance for organisations on the designation, position and tasks of DPOs.
From Point 11 on https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf
ã¤ã¾ããããªããå ¬çæ©é¢ã ã£ãããå¤§è¦æ¨¡ã«å人æ å ±ãåéãã¦å¦çããããå»çãã¼ã¿ãæ¿æ²»ãã¼ã¿ãåãæ±ã£ã¦ããå ´åã¯ç¾©åãããã¾ããInkdropã¯ãããã該å½ããªãã®ã§ãä»»å½ç¾©åã¯ããã¾ããã
GDPRå¯¾å¿æ¸ã¿ã®ãµã¼ãã¹ã®ãã©ã¤ãã·ã¼ããªã·ã¼ãåèã«ãã
GDPRã®åã ã®ä¿è·è¦åã«ã¯ææ§ãªç¹ãå¤ããå°éå®¶ã®éã§ã夿ã®åãããã¨ãããå¤ãã§ãããããä¸è¨ã®ããã«æ¥è ãå°éå®¶ãéã義åããªããã¨ãããå¼è·å£«ãªã©ã«ç¸è«ããã«å¯¾å¿ãããã¨ã¯å®è³ªå¯è½ã§ããã¨ã¯ããé©å½ã«å¯¾å¿ãã¦æå³ããã«ã¼ã«ãç ´ãããã«ã¯ããã¾ãããããã§Inkdropã¯å¯¾å¿æ¸ã¿ã®ãµã¼ãã¹ã«å£ããã¨ã«ãã¾ããã
ãã¯ãåèã«ãããªãæ¥çããªã¼ããããããªæåãµã¼ãã¹ã§ããDigital OceanãEvernoteãKickstarterãªã©ãªã©ãä¸è¨ã®ãããªãµã¼ãã¹ã使ã£ã¦GDPRå¯¾å¿æ¸ã¿ã®ãµã¼ãã¹ãæ¢ãã¦åèã«ããã®ãããã§ãããã
åã¯npm, inc.ã®ãã©ã¤ãã·ã¼ããªã·ã¼ãåèã«ãã¾ããããªããªãæãã·ã³ãã«ã§åãããããã£ãããã§ããããããè¦ç´ç³»ææ¸ã¯æ³çç¨èªãªã©ãå¤ç¨ããé£è§£ãªè¨ãåããå¤ãã®ã宿 ã§ãããããnpmã®ãã®ã¯å¸¸ç¨èªã®ã¿ã§è¡¨ç¾ããã¦ãã¦æå¿«ã§ããããããçä¼¼ãã¦Inkdropã®ãã©ã¤ãã·ã¼ããªã·ã¼ã使ãã¾ããã
以éãããã©ã¤ãã·ã¼ããªã·ã¼ã«æè¨ãã¹ããã¤ã³ãã説æãã¾ããnpmã®ãã©ã¤ãã·ã¼ããªã·ã¼ã¨ç §ããåãããªããèªãã§ã¿ã¦ãã ããã
ãã¤ã©ããã£ã¦åéããã®ã
ã¾ãã¯æ¹æ³ããæç¢ºã«ãã¾ãããµã¼ãã¹ã«ç»é²ããæãªã®ãããµã¤ãã«ã¢ã¯ã»ã¹ããæãªã®ããã¢ããªãå©ç¨ããæãªã®ãããªã©ãªã©ã
ä½ãä½ã®ããã«åéããã®ã
次ã«ãå ·ä½çã«åéãããã¼ã¿ã®å 容ã説æãããã®ç®çã説æãã¾ããã¦ã¼ã¶ã®æç¨¿ãã¼ã¿ãèç©ãããªããã®æ¨ã¨ç®çãããµã¼ããã°ãèç©ãããªããIPã¢ãã¬ã¹ãURLãªã©ã
ãã¼ã¿ãä¸è¦ã«ãªã次第åé¤ãããã¨
IPã¢ãã¬ã¹ãªã©ãè¨ããããµã¼ããã°ãªã©ã¯æ°é±é以å ã«åé¤ããæ¨ãæè¨ãã¾ãããã ãããµã¼ãé害対å¿ãªã©å¿ è¦ã«å¿ãã¦é·ãä¿æãããã¨ããããã¨ãè¨ãã¾ãã
æ¯ææ å ±ã¯ã©ã®ããã«åãæ±ãããã®ã
ã«ã¼ãæ å ±ã¯ç¹ã«è²´éãªã®ã§è©³ãã説æãã¾ããã©ã®å¤é¨ã·ã¹ãã ã¨é£æºãã¦è«æ±ãè¡ãã®ããã«ã¼ãæ å ±ã¯èª°ãåãåã£ã¦ä¿ç®¡ããã®ããªã©ãæè¨ãã¾ããä¸è¦ã«ãªã次第æ¶å»ããããã¨ãè¨è¼ãã¾ãã
ãã¼ã¿ãã©ãã«ä¿åãããã®ã
ãã¼ã¿ãä¿åããããµã¼ãã¯ã©ã®å½ã«ããã®ããæè¨ãã¾ããéçºã®ããã«ãã¼ã¿ã䏿çã«åå¾ããå ´åããåå¾è ã¯ã©ã®å½ã«ãã¦ä½æ¥ããã®ãè¨ãã¾ãã
ã©ããã£ã¦ã¦ã¼ã¶ã®ãã¼ã¿ã«ã¢ã¯ã»ã¹ããã®ã
ã¦ã¼ã¶ã¯èªåã®ãã¼ã¿ã«ã©ãããã°ã¢ã¯ã»ã¹ã§ããã®ããæè¨ãã¾ããã¨ã¯ã¹ãã¼ãã®æ¹æ³ãè¨è¼ãã¾ãã
ãã¼ã¿ã®å餿¹æ³
ãå¿ããããæ¨©å©ããæºããããã®æ©è½ã説æãã¾ããã¦ã¼ã¶ã¯ãã¤ã§ããã¼ã¿ãåé¤ã§ãããã¨ãè¨è¼ãã¾ããã¢ã«ã¦ã³ããåé¤ããã¨ä½ãèµ·ããã®ããæè¨ãã¾ãããã¼ã¿ãåé¤ããã代ããã«å¿ååãããå ´åã¯ãããæè¨ãã¾ããå¿ è¦ãããã°ãããåé¤ã§ãããã¨ã説æãã¾ãã
ã©ã®ãµã¼ããã¼ãã£ãµã¼ãã¹ã使ã£ã¦ããã
Google Analyticsã«ä»£è¡¨ããããããªãµã¼ããã¼ãã£ã¼ãã¼ã«ã使ã£ã¦å人æ å ±ãåãæ±ãå ´åã¯ãå ¨ã¦ã®ä½¿ç¨ãµã¼ãã¹ãåæãã¾ããã¤ã¾ãAWSãHerokuãªã©ãå«ãããã¼ã¿ã®ä¿åãå¦çããããã«ä½¿ã£ã¦ãããµã¼ãã¹ããã¹ã¦æ¸ãåºãã¾ãã
å人æ å ±ãæ©æ¢°çãªå¤æã«ç¨ãã¦ãããã©ãã
ä¾ãã°ãã¼ã½ãã©ã¤ã¼ã¼ã·ã§ã³ããªã¿ã¼ã²ãã£ã³ã°ã®ããã«å人æ å ±ã使ã£ã¦ããå ´åã¯ããã®æ¨ã詳ãã説æãã¾ãããã£ã¦ããªããã°ããã¦ããªããã¨ãæè¨ãã¾ãã
èª å®ã«ãã¼ã¿ãåãæ±ãã ãã§ãã
以ä¸ãInkdropã®GDPR対å¿ãéãã¦å¦ãã äºãã¾ã¨ãã¾ãããå¤å°ã®è¦å´ã¯å¼·ãããã®ã®ãGDPRã¯åºæ¬çã«å人æ å ±ã®åæ±ãã«ãã¾ããæããªããã°ãããªã対å¿ã§ãã¾ããé©å½ã«ã³ããã§ã¯æ¸ã¾ãªãã®ã§ãè±èªãè¦æã ã£ããæ»ã«ã¾ãããé°ã§æ³å¾é¢ä¿ã®è±æè³æã«å°ãã ãå¼·ããªãã¾ããã
ç¹ã«SNSã¯ãããããã¼ã¿å©ç¨ã«é¢ãã¦é¢¨å½ãããå¼·ããªãããã§ããæ°ãããµã¼ãã¹ãä½ãéã¯ãã¨ã¯ã¹ãã¼ãæ©è½ã¨æ¶å»æ©è½ã«æ°ãã¤ããã°åé¡ãªãããã§ããè¤éãªãã¼ã¿ã¢ãã«ã ã¨ããã®å®è£ ãé¢åãªãã§ããã©ããä»å¾ãDBMSãSaaSã«ãã®è¾ºã®è¦å´ãç·©åãã¦ãããæ©è½ãä»ããã¨ãæå¾ ãã¾ãã