ã«ãªãã©ã«ãã¢å· æ¶è²»è ãã©ã¤ãã·ã¼æ³ï¼CCPAï¼ã®æ¦è¦
ã¯ããã«
GDPRï¼EU ä¸è¬ãã¼ã¿ä¿è·è¦åï¼ã2018å¹´5æã«æ½è¡ããã欧å·å°åããå½å¢ãè¶
ããå人ãã¼ã¿ã®åãæ±ãã«ã¤ãã¦ãä¸çåå½ã対å¿ããªããã°ãªããªãæ代ã¨ãªãã¾ããã
ç¾å¨ã§ãææ¢ãã®é¨åã¯ãããã¨æãã¾ããããã©ã¤ãã·ã¼ä¿è·ã®èªèãä¸çä¸ã§é«ã¾ããèªåã®å人ãã¼ã¿ã¯èªåã§ç®¡çããã¨ããåºæ¬ååãå°ããã¤åºã¾ã£ã¦ããããã«æãã¾ãã
ä¸æ¹ã§å人ãã¼ã¿ã®å¦çã転éãè¡ãä¼æ¥ï¼çµç¹ï¼ã¯ãæ¬äººããã®æ±ãã«å¿ãã対å¿æ段ãæ´åããããã³ã¨ããå®å ¨å¯¾çãè¡ããªããã°å·¨é¡ã®å¶è£éã課ãããããããæå³ããã·ã¤æ代ã«ãªã£ãã¨ãè¨ãã¾ãã
ãããªä¸ã2020å¹´1æããCCPAï¼ã«ãªãã©ã«ãã¢å·æ¶è²»è ãã©ã¤ãã·ã¼æ³ï¼ãç±³å½ã«ãªãã©ã«ãã¢å·ã§é©ç¨éå§ã¨ãªã£ã¦ããããã¡ãã«ã¤ãã¦ãä»å½ã¸ã®å½±é¿ãé¿ããããªãå 容ã¨ãªã£ã¦ãã¾ããä¸çä¸ã§ãã©ã¤ãã·ã¼é¢é£æ³ã®æ´åãé²ãä¸ã§ããç¹ã«æ³¨ç®ãããCCPAã®æ¦è¦ã説æãããã¨æãã¾ãã
- ï¼ãªããæ¬å 容ã¯2020/1/15ç¾å¨ã®å ¬éæ å ±ãåèã«ãã¦ä½æãã¦ãããæ¡ææ¹æ£ãªã©ã«ããä¿®æ£å¤æ´ã®å¯è½æ§ããããã¨ããèæ ®ãã ããã
CCPAã¨ã¯ä½ãï¼
CCPAã¨ã¯ãã«ãªãã©ã«ãã¢å·æ¶è²»è ãã©ã¤ãã·ã¼æ³ï¼CCPAï¼California Consumer Privacy Actï¼ãã®ç¥ç§°ã§ãããç±³å½ã«ãªãã©ã«ãã¢å·ã§2020å¹´1æããé©ç¨éå§ã¨ãªããã©ã¤ãã·ã¼æ³ã®ãã¨ãè¨ãã¾ããã«ãªãã©ã«ãã¢å·ã®ä½æ°ï¼ä»¥ä¸ããä½æ°ãã¨å¼ã¶ï¼ï¼ï¼ã«å¯¾ãããã©ã¤ãã·ã¼ä¿è·ãå®ããå·æ³ã§ãããä½æ°ã«ãã©ã¤ãã·ã¼ã«é¢é£ãã権å©ãä¸ããä½æ°ã®å人æ å ±ãå©ç¨ããäºæ¥è ã«ã¯é©æ£ç®¡çã®ç¾©åãå®ãããã®ã«ãªãã¾ãã
- ï¼1 æ¡æã§ã¯ãä½æ°ãã§ã¯ãªããConsumerï¼æ¶è²»è ï¼ãã¨è¡¨ç¾ããã¦ãã¾ãã
CCPAã注ç®ãããçç±
ã«ãªãã©ã«ãã¢å·ã¯ã¢ã¡ãªã«è¥¿æµ·å²¸å°åã®ä¸ã¤ã§ãããç±³å½ã®æ°ããå·ã®ä¸ã§ãæã人å£ãå¤ãï¼2018年度ã§ç´4000ä¸äººï¼ãçµæ¸æ´»åãæ´»çºãªå·ã§ããã¾ãã
å·ã®GDPã¯2017å¹´ã§2å
7470åãã«ã§ãããåç¬ã®å·ã§ãããªããå
é²å½TOP5ã«å
¥ãçµæ¸è¦æ¨¡ãèªãå·ã¨ãªã£ã¦ãã¾ããä¸ççã«æåãªITæ¥çãéç´ããã·ãªã³ã³ãã¬ã¼ãæ ç»ç£æ¥ã®ããªã¦ããããã£ãºãã¼ã©ã³ãã§ã馴æã¿ã®ãã£ãºãã¼ã»ã«ã³ããã¼ãªã©ãåªè¯ä¼æ¥ãéã¾ãå¼·åæç·ã«ãªã£ã¦ãã¾ãã
ç±³å½ã®ä¸ã§ãå½±é¿åããã£ãå·ã§ãããCCPAãæ½è¡ããããã¨ã«ãã£ã¦ãä»ã®å·ããã¯ã¤ããã¡ããã¨ãããªããããªãããã¨ãã£ãããã«è¿½éããå¯è½æ§ãé«ããªãããã§ãããã®ãããªåãã«å¯¾ãã¦ãé£é¦æ³ã¨ãã¦ãã©ã¤ãã·ã¼é¢é£æ³ãæ´åãããã¨ããåããããã¾ãããå®ç¾ãããã©ããã¯ä»ã®ã¨ãããããã¾ããã
ãã ãGDPRã欧å·å°åã®çµ±æ¬çãªãã©ã¤ãã·ã¼æ³ã«ãªã£ãã¨åæ§ã«ãCCPAãç±³å½ã§ã®ãã©ã¤ãã·ã¼æ³ã®ç¤ã¨ãªãå¯è½æ§ããããã¨ãããæ¥æ¬ãå«ãä»å½ã§ã対岸ã®ç«äºã¨ã¯è¨ãããGDPRæ½è¡æã®ããã«ãããããã£ã¡ãã§ããã©ãªããããããã¨ããããã«æ³¨ç®ãéãã¦ããçç±ã«ãªã£ã¦ãã¾ãã
å人æ å ±ã®å®ç¾©
å人æ å ±ã®å®ç¾©ã¯ç¬¬1798.140æ¡ï¼oï¼(1)ã«è¨è¼ããã¦ãã¾ããå¹ åºãæ å ±ãå人æ å ±ã¨å®ç¾©ãã¦ãããå ·ä½çäºé ãå«ãã¦ç´°ããè¨è¼ããã¦ãã¾ããããéå®ãããããã§ã¯ãªããããããã«éãããªãããªã©ã®è¡¨ç¾ããããããè¨è¼ããã¦ãã以å¤ã®æ å ±ãå ´åã«ãã£ã¦ã¯å人æ å ±ã¨ãã¦åãæ±ããã¨ãæå³ãã¦ããããã§ãã
CCPAã®é©ç¨å¯¾è±¡
CCPAã®é©ç¨å¯¾è±¡ã«ã¤ãã¦ã¯ç¬¬1798.140æ¡ã®ãããã«è¨è¼ããã¦ãã¾ããæ¡æãèªãã¨å¤§ãã3ã¤ã»ã©ã®ã«ãã´ãªã¼ãããã¨æããã¾ãããä½æ°ã®å人æ å ±æä¾é¢ä¿ãå¥ç´ã«ãã£ã¦ããã®ä»ã«ãé©ç¨å¯¾è±¡ã«å«ã¾ããã¨ã³ãã£ãã£ï¼entitiesï¼ãããããã§ãã
CCPAã®é©ç¨å¯¾è±¡ï¼äºæ¥è ï¼ãã®1
äºæ¥è
ï¼Businessï¼ã®èª¬æã¨ãã¦ã¯ã第1798.140æ¡ï¼cï¼ã«è¨è¼ãããã¾ãã
CCPA対å¿ã®ãã¢ã«ãªãç®æãªã®ã§åæã®æ¥æ¬èªè¨³ãã¾ãè¨è¼ãã¾ãã
CCPAã®é©ç¨å¯¾è±¡ï¼äºæ¥è ï¼ãã®2
äºæ¥è
ï¼Businessï¼ã®èª¬æãããå°ãåãããããããã¨ä»¥ä¸ã®ããã«ãªãã¾ãã
ä¸è¦ããã¨æ¡ä»¶ãå³ãããå½±é¿ããã¾ãç¡ãããã«æãã¾ãããããã¤ã注æç¹ãããã¾ãã
CCPAã®é©ç¨å¯¾è±¡ï¼ãµã¼ãã¹æä¾è ï¼
ãµã¼ãã¹æä¾è
ï¼Service Providerï¼ãã®èª¬æã¨ãã¦ã¯ã第1798.140æ¡ï¼vï¼ä»¥å¤ã«ããå·è¡è¦åæ¡ï¼§999.314. Service Providersï¼ã«ãè¨è¿°ãããã¾ãã
GDPRã®ãProcessorãã®å½¹å²ã«è¿ããäºæ¥è
ã¨ã®å¥ç´ã«åºã¥ãä½æ°ã®å人æ
å ±ã®ãå¦çï¼Processingï¼ããå®æ½ããå¶å©ç®çã®ã¨ã³ãã£ãã£ã¨ãã¦ç解ããã°ããã¨æãã¾ãã
CCPAã®é©ç¨å¯¾è±¡ï¼ç¬¬ä¸è ï¼
第ä¸è
ï¼Third partyï¼ã®èª¬æã¨ãã¦ã¯ã第1798.140æ¡ï¼wï¼ä»¥å¤ã«ããå人æ
å ±ãä½æ°ããç´æ¥åéããªãã¨ã³ãã£ãã£ã¨ãã¦å·è¡è¦åæ¡ï¼§999.301(e)ï¼ã«ãè¨è¿°ãããã¾ãã
å
·ä½çãªã¨ã³ãã£ãã£ã®è¨è¼ä¾ãããã¾ããããããã«éããªãã¨ããç¹ã«æ³¨æãå¿
è¦ã§ãã
ã¾ããä½æ°ã®å人æ å ±ãä¿æãã¦ãããå¶å©ç®çã§ãªãå ´åï¼éå¶å©å£ä½çï¼ã§ããCCPAãç¡è¦ããä½æ°ã®å人æ å ±è²©å£²ãç®çå¤ä½¿ç¨çã¯ç¦æ¢ããã¦ãããããéåãã¦ããªããã¨ãã«ã¯ã¸ãã«ããããã®ç¢ºèªä½æ¥ãå¿ è¦ã«ãªãã¨èãããã¾ãã
CCPAã®ä¸»ãªå 容ï¼ãã©ã¤ãã·ã¼ã®æ¨©å©ï¼
CCPAã®ç®çã®ä¸ã¤ä½æ°ã®ãã©ã¤ãã·ã¼ã®æ¨©å©ã®æ¦è¦ã¯ä¸»ã«ä»¥ä¸ã®ããã«ãªãã¾ãã
èªèº«ã®å人æ
å ±ã«é¢ããé示è«æ±ãåé¤ã販売åæ¢ãªã©ã®æ¨©å©ããããã¨ãå®ãããã¦ãã¾ãã
CCPAã®ä¸»ãªå 容ï¼äºæ¥è ã®ç¾©åï¼
CCPAã®ç®çã®ä¸ã¤äºæ¥è
ã®ç¾©åã®æ¦è¦ã¯ä¸»ã«ä»¥ä¸ã®ããã«ãªãã¾ãã
äºæ¥è
ã®ç¾©åã¯æ¡æã®ä»ã«ãå·è¡è¦åæ¡ã®éµå®ãå¿
è¦ã«ãªããããé©ç¨å¯¾è±¡ã¨ãªãããããªå ´åã¯ãã¡ããç解ãã¦ããå¿
è¦ãããã¾ããï¼24ã«æéã®è¨é²ã®ä¿ç®¡ãªã©æ¡æã§è¨è¼ã®ç¡ãäºé
ãããã¾ããï¼
ããªã¥ã¼ã ãå¤ããããä»åã¯æ¡æã®ä¸»è¦ãªç®æãç®æ¬¡ã¬ãã«ã§ç´¹ä»ãã¾ãã
æ°äºå¶è£éã¨æ°äºè¨´è¨
CCPAã®ç¾©åéåãè¡ã£ãå ´åãã«ãªãã©ã«ãã¢å·å¸æ³é·å®æ訴ã«ããæ°äºå¶è£éã¨ä½æ°ã«ããæ°äºè¨´è¨ã«ããè³ åéè«æ±ã®å¯è½æ§ãããã¾ãã ãªããä½æ°ã«ããæ°äºè¨´è¨ã§å¯¾è±¡ã¨ãªãå人æ å ±ã®å®ç¾©ã¯å¥éå®ãããã¦ãããããã»ã³ã·ãã£ããªå人æ å ±ã対象ã¨ãã¦ãã¾ãã
åççãªã»ãã¥ãªãã£å¯¾çã¨ã¯ï¼
第1798.150æ¡ã§ã¯ã»ãã¥ãªãã£å¯¾çã«ã¤ãã¦ãå°ãè¨è¼ããããä½æ°ã®å人æ å ±ã¸ã®ã¢ã¯ã»ã¹ã³ã³ããã¼ã«ãæå·å対å¿ãªã©ãæ±ãããã¦ããããã§ãã
ã¾ããå·è¡è¦åæ¡ã§ããåççãªã»ãã¥ãªãã£å¯¾çãå®æ½ããããªã©ã®è¨è¼ãããã¤ããããã»ãã¥ãªãã£å¯¾çãå¿
è¦ãªãã¨ã¯è¨è¼ãã¦ãã¾ãããå
·ä½çã«ãã©ãã¾ã§ä½ããããã¨ãããã¨ã¯è¨è¼ããã¦ãã¾ããã
NISTãISO/IECãCISããªã©ãã¾ãã¾ãªæ©é¢ãå£ä½ããã»ãã¥ãªãã£åºæºãçºè¡ããã¦ãã¾ãããã«ãªãã©ã«ãã¢å·å¸æ³é·å®ãéå»ï¼2016å¹´ï¼ã«å
¬è¡¨ãããã¼ã¿ããªã¼ãã¬ãã¼ãã§ã¯ãCISï¼Center For Internet Securityï¼ã®ãCIS Controlsããæ¨ãã¦ããããã§ãã
ããå ·ä½çãªå 容ã¯ã¬ã¤ãã©ã¤ã³å¾ ã¡ãã¨ãæãã¾ãããé©ç¨å¯¾è±¡ã«ãªãå¯è½æ§ãããå ´åã¯ãæä½éã®ã»ãã¥ãªãã£å¯¾çã¨ãã¦ãCIS Controlsããç®å®ã¨ããã»ãã¥ãªãã£ã³ã³ããã¼ã«ã®ãã§ãã¯ããå§ãã¦ã¿ãã¨ããã®ã§ã¯ãªãã§ããããã
ãåèãCIS Controlsãver7 ï¼Control 1 ï½ Control 20ï¼
主ãªåèæç®
- å人æ
å ±ä¿è·å§å¡ä¼
ãã«ãªãã©ã«ãã¢å·æ¶è²»è ãã©ã¤ãã·ã¼æ³ 2018å¹´ æ¡æãï¼2019å¹´8æ29æ¥æç¹ï¼ ã - JETRO
ãæ½è¡ãè¿«ããã«ãªãã©ã«ãã¢å·æ¶è²»è ãã©ã¤ãã·ã¼æ³ãï¼ç±³å½ï¼ã
ãã«ãªãã©ã«ãã¢å·æ¶è²»è ãã©ã¤ãã·ã¼æ³(CCPA)å®åãã³ãããã¯ã - California Legislative Information
ãTITLE 1.81.5. California Consumer Privacy Act of 2018[1798.100-1798.199] ã - California Attorney General
ãCalifornia Consumer Privacy Act (CCPA) FACTãSHEETã
ãText of Proposed Regulations - California Consumer Privacy Act(CCPA)ã
ãCalifornia Data Breach ReportãFebruary 2016ã - CIS
ãCIS Controls version 7ã
- ï¼æ¬ææ¸ä¸ã®ç¿»è¨³ææ¸ã¯ãNTTãã¼ã¿å
端æè¡æ ªå¼ä¼ç¤¾ã«ããæ
å ±æä¾ããã¦ãã¾ãã
ããã¯ãæ¬é ã主ãªåèæç®ãã«ã¦å ¬éãããæç« ã®ãéå ¬å¼ã®ç¿»è¨³ãå«ã¿ã¾ãã
è±æãå ¬å¼çã§ããã¨ã¿ãªããã翻訳æã¨è±æã«ããã¦ã®ææ§ããä¸æçãã«ã¤ãã¦ã¯ãè±æãåªå ããã¾ãã
NTTãã¼ã¿å 端æè¡æ ªå¼ä¼ç¤¾ã¯ãæ¬ç¿»è¨³ææ¸ã«å«ã¾ããé失ã«å¯¾ãã責任ãè² ãã¾ããã
Writer Profile
ã»ãã¥ãªãã£äºæ¥æ¬é¨
ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°æ
å½ ãã¼ãã³ã³ãµã«ã¿ã³ã
å¹³äº åæ²»
Tweet