ãã£ã¦ã¿ããï¼PIAï¼ãã©ã¤ãã·ã¼å½±é¿è©ä¾¡ï¼ï¼ï¼æ¦è¦ç·¨ï¼
ã¯ããã«
å人æ
å ±ä¿è·æ³ãæ¹æ£ããããã©ã¤ãã·ã¼ã«é¢é£ããæèã社ä¼çã«é«ã¾ãä¸ã§ããé£æ¥ã®ããã«å人æ
å ±æ¼æ´©ãªã©ã®ãã¥ã¼ã¹ãå¾ã絶ã¡ã¾ãããããã¯ãªããªã®ã§ããããï¼
çç±ã¯æ§ã
ã«ããã¾ãããåå ã®ä¸ã¤ã¨ãã¦æããããã®ãå人æ
å ±çãåãæ±ãæ¥åã«ããããªã¹ã¯ã³ã³ããã¼ã«ãé©åã«å®æ½åºæ¥ã¦ããªãç¹ã«ãããã¨æãã¾ãã
PIAï¼ãã©ã¤ãã·ã¼å½±é¿è©ä¾¡ï¼ã¯å人æ
å ±åã³ãã©ã¤ãã·ã¼ã«ä¿ããªã¹ã¯åæãè©ä¾¡ã対å¿æ¤è¨ãè¡ãææ³ã§ãããå人æ
å ±çãåãæ±ãçµç¹ã«ã¨ã£ã¦æå¹ãªãªã¹ã¯ã³ã³ããã¼ã«ã«ãªãã¾ãã
ä»åã¯PIAï¼ãã©ã¤ãã·ã¼å½±é¿è©ä¾¡ï¼ã®æ¦è¦ã説æãããã¨æãã¾ãã
å 米海è»ãã¼ã¿ã¢ããªã¹ãï¼èªç§°ï¼ãå£çã¯ã¸ã£ã¹ãã£ã¹ãã³ã¹ãã¬ã大好ãã
å ãããã¯ãµã¼ãç¾å½¹æ代ã¯ããã³ãã¼ã»ã¿ã³ãã®ç°åã§æããããããé ã大好ãã
ã¤ãã¤ãã¨ãããããã¾ã¾ä¸å¹´ã«ãªã£ã¦ãã¾ã£ãè¬ã®ã¤ã«ãã²ã¼ã ã大好ãã
ãã³ã·ã¼ããç·æ¥é£çµ¡ï¼ã¶ãªã¬ãäºæ¥é¨ã¯ç´ã¡ã«åãæ±ãå人æ å ±ãæ´ãåºããPIAï¼ãã©ã¤ãã·ã¼å½±é¿è©ä¾¡ï¼ãå®æ½ããï¼
ç¸å¤ããããã³ã·ã¼ã¯ãããã§â¦â¦ãã®ã¯ã½å¿ããã¨ãã«ã¯ã·ãã®é½åãªããã¡ã¼ã¨ãèããã¨ããâ¦â¦
PIAï¼ãã©ã¤ãã·ã¼å½±é¿è©ä¾¡ï¼ã£ã¦ä½ï¼
ã¾ãã¡ããã©ããããã¤ã«åã«èª¬æããããã
PIAï¼ãã©ã¤ãã·ã¼å½±é¿è©ä¾¡ï¼ã£ã¦ãªãã ï¼
PIA: privacy impact assessmentï¼ãã©ã¤ãã·ã¼å½±é¿è©ä¾¡ï¼ï¼ä»¥ä¸ãPIAã¨ããããï¼ãç°¡åã«èª¬æããã¨ããå人æ
å ±çï¼å人ãèå¥å¯è½ãªæ
å ±ï¼ãåãæ±ãæ¥åã«ããã¦ãäºåã«ãªã¹ã¯è©ä¾¡ãè¡ããæ´ãåºããããªã¹ã¯ãé©åã«ã³ã³ããã¼ã«ï¼ä½æ¸ã»åé¿ï¼ããããã¨ãããªã¹ã¯ç®¡ççã®èãæ¹ã«ãªãã¾ãã
å人æ
å ±åãæ±ãã®åæ段éã§PIAãå®æ½ãããã¨ã«ãããã©ã®ãããªãªã¹ã¯ããããã©ã®ç¨åº¦ã®å¯¾çãå®æ½ããªããã°ãªããªãã®ããè¦ããåãããã¨ãã§ããæ¥åå
¨ä½ã®ãã©ã¤ãã·ã¼ãªã¹ã¯ããã¸ã¡ã³ããå¯è½ã«ãªãã¾ãã
ã»ãã¼ããªãã»ã©ãå人æ å ±ãåãæ±ããªãäºåã«ããã³ã¨è©ä¾¡ããä¸ã§ãããªããã£ã¦ãã¨ããªã
ããã§ãè¦åãæ³ä»¤ã§PIAã義ååãã¦ããå½ããã£ã¦ãå人æ å ±ã®åãæ±ãã¯ç¹ã«æ°ã¤ããªãããã®ããã¡ãªã¿ã«å人æ å ±ããã¦ãå½ã«ãã£ã¦ããããªå®ç¾©ãããã®ã§è¡¨ç¾ãé£ãããããã©ãæ¦ããå人ãèå¥ãããã¨ãå¯è½ãªæ å ±ãã¨ããç解ã§ããã¨æãã§ã
ãå人ãèå¥ãããã¨ãå¯è½ãªæ
å ±ãï¼
ä½ããï¼å
·ä½çã«ã¯ï¼
ãããçµæ§ããããã§ã
å人ãèå¥ãããã¨ãå¯è½ãªæ å ±ã¨ã¯ï¼
身åã証æããããå人ãèå¥ãããããã«ã¯ãåºæ¬ï¼æ å ±ï¼æ°åãæ§å¥ãçå¹´ææ¥ãä½æï¼ãä¸å¿ã«ç¢ºèªããææ³ãå¾æ¥ã¯åããã¦ãã¾ãããæ¨ä»ã§ã¯ç¤¾ä¼ã®ITåãé²ãã«ã¤ãã¦ãåºæ¬ï¼æ å ±ãä¸è¶³ãã¦ããã¨ãã¦ãæ§ã ãªæ å ±ãçµã¿åããããã¨ã§å人ã®ç¹å®ã容æã«ãªãã¾ããã人ã«ã¯ç¥ãããããªããã©ã¤ãã·ã¼æ å ±ã¾ã§ãã大éã«èç©ããããã¸ãã¹ã«æ´»ç¨ãããäºæ ã¨ãªã£ã¦ãããã¨ããããã®ãããªæ å ±ãå人æ å ±ã¨ãã¦é©åã«ç®¡çããã¹ãã¨ããèãæ¹ã«ãªãã¤ã¤ããã¾ãã
éè¡å£åº§åã¯ã¯ã¬ã¸ããã«ã¼ãæ å ± |
ãã¤ãªã¡ããªãã¯èå¥å |
ã¯ã¬ã¸ããã«ã¼ãæç´°æ¸ |
åäºä¸ã®æ罪å¤æ±ºåã¯éå |
ç¯ç½ªææ»å ±åæ¸ |
顧客çªå· |
å¹´é½¢åã¯å¼±è ã®ç¹å¥ãªãã¼ãº |
ç¯ç½ªè¡çºãè¡ã£ãã¨ãã容ç |
å¥åº·è¨ºææ å ± |
身ä½é害 |
å»çè²»æç´°æ¸ |
å¾æ¥å¡ã®çµ¦ä¸åã³äººäºãã¡ã¤ã« |
GPSä½ç½®æ å ±ãè»è·¡ |
IPã¢ãã¬ã¹ |
éä¿¡ã·ã¹ãã ããå°ãåºãããä½ç½® |
ç æ´ |
å ¬çèå¥åï¼ãã¹ãã¼ãçªå·çï¼ |
å人ã®é»åã¡ã¼ã«ã¢ãã¬ã¹ |
æ証çªå·ï¼PINï¼åã¯ãã¹ã¯ã¼ã |
WEBãµã¤ãã®å©ç¨è¿½è·¡ããå°ãåºãããå人çãªèå³ |
å人åã¯è¡åã®ãããã¡ã¤ã« |
å人ãèå¥å¯è½ãªåçåã¯æ å |
製ååã¯ãµã¼ãã¹ã®é¸è |
å ¬å ±å»çãµã¼ãã¹ã§åéãããæ å ± |
人種åã¯æ°æ |
å®æåã¯å²å¦çãªä¿¡æ¡ |
æ§çæå |
å´åçµåã¸ã®å å ¥ç¶æ³ |
èªçæ¥ |
èªå® ä½æ |
åå |
ãªããã¤ãã¤ãåºã¦æ¥ããã©ãããã£ã¦å人æ å ±ä¿è·æ³ã®å¯¾è±¡å¤ã£ã½ãã®ãå«ã¾ãã¦ãªãï¼
ã¤ã«åããã©ããªãâ¦â¦
å人æ
å ±ä¿è·æ³ã¨ãã©ã¤ãã·ã¼ä¿è·ã¯ã«ããªããããããã©ããã©ã¤ãã·ã¼ä¿è·ã®æ¹ãããç¯å²ãåºãã¦ãPIAã¯ãã©ã¤ãã·ã¼ä¿è·ãèæ
®ãã¦å®æ½ããªãããã®ãã
ãã©ã¤ãã·ã¼ä¿è·ã®è¦³ç¹ã§èæ ®ãã¹ãç¯å²
ãã©ã¤ãã·ã¼ä¿è·ã®è¦³ç¹ã§èæ ®ãã¹ãç¯å²ã¯ãå人æ å ±ä¿è·æ³ä¸ã§å®ãããã¹ãç¯å²ã«éå®ããããåãæ±ãæ å ±ãæè¡ãç°å¢ã«ãã£ã¦çµ¶ããå¤åãããã©ã¤ãã·ã¼ãå«ã¾ãã¾ãããã©ã¤ãã·ã¼ã¨ã¯ãä»äººã«ç¥ãããããªãæ å ±ï¼ç§äºãç§çæ´»æ å ±çï¼ãå人ã®ç§å¯ã¨ãã¦ç®¡çã§ãã権å©ã§ãããããã®ãããªæ å ±ãåãæ±ãã®ãªãã°ãå人æ å ±ä¿è·æ³ã«ããæ¬äººåæçã®ã«ã¼ã«éµå®ã¯å¿ è¦æä½éã®ãã¨ã§ããããã©ã¤ãã·ã¼ã¬ããã³ã¹ã¾ã§è¸ã¿è¾¼ãã 対å¿ãå¿ è¦ã«ãªã£ã¦ãã¾ãã
å³1ï¼ãã©ã¤ãã·ã¼ä¿è·ã®è¦³ç¹ã§èæ
®ãã¹ãç¯å²[2]
ã»ãã¼ãå人æ å ±ä¿è·æ³å¯¾å¿ã ãã§ãçµæ§ãããã£ãã®ã«ããã©ã¤ãã·ã¼ä¿è·ã¾ã§èããã¨å¤§å¤ã ãªãâ¦â¦
è£ãè¿ãã¨èªåã®ç¥ããªãã¨ããã§èªåã®ãã©ã¤ãã·ã¼ã侵害ãããããªæ å ±ãããã¼ããæµéãã¦ããã£ã¦ãã¨ããç¾å®ç¥ã£ããã³ã£ããããã§ã
ã§ãå人æ
å ±ä¿è·æ³ã¨éã£ã¦ç¾©åãããªããã§ããï¼
PIAã¯ï¼
ç¾æç¹ï¼2022å¹´ï¼ã§ã®æ¥æ¬ã§ã¯ç¢ºãã«ç¾©åã§ã¯ãªããæ¨å¥¨ãã¦ãã段éãã[3]ã
ãã 欧米ä¸å¿ã«ä»å½ã§ã¯PIA義ååã®æ¹åã«é²ãã§ãããããããæ¥æ¬ã§ãå人æ
å ±ä¿è·æ³ã¯3å¹´ãã¨ã«è¦ç´ããããããããå°æ¥çã«ã¯ç¾©ååããããããããªãããã§ãç¥ãããã©ã
ã¾ãããªãã¨ãªãPIAãã£ã¦ãããæ¹ããããã¨ã¯åãã£ãæ°ããããã©ãå®éã©ãããã®ï¼
ã¾ãã¯ã©ããªåºæºãææ³ãããã®ã調ã¹ã¦ã¿ãããã§ã
PIAå®æ½ã®åºæº
PIAãå®æ½ããã«ã¯ã¾ãã©ã®ãããªåºæºãããã®ã§ããããï¼
æ³ä»¤ãè¦åãå½éæ¨æºè¦æ ¼ãªã©åèã«ãªãåºæºã¯ããã¤ããããåãæ±ãå人èå¥å¯è½æ
å ±ï¼ä»¥ä¸ãPIIãã¨ãããï¼ã®è³ªã¨éãå½ï¼è¶å¢ï¼ãé©ç¨åéï¼å
¬çãå
Œ
±çãæ°éï¼ãè¦å¶ãæ¥ç¨®æ¥æ
ãé¢é£ã·ã¹ãã ããµãã©ã¤ãã§ã¼ã³çãèæ
®ãã¦æ¤è¨ããã¨è¯ãã§ããã
NO. | è¦æ ¼ã»æ³ä»¤ | æ¦è¦ |
---|---|---|
1 | ISO/IEC 29134 :2017 æ å ±æè¡ãã»ãã¥ãªãã£æè¡ ãã©ã¤ãã·ã¼å½±é¿è©ä¾¡ã®ããã®ã¬ã¤ãã©ã¤ã³ |
PIAã®æºåãããã»ã¹ãå ±åæ¸æ§æãªã©ã®åºæ¬çãªèãæ¹ãå®æ½ã®ã¬ã¤ãã³ã¹ãè¨è¼ããã¦ããå½éæ¨æºè¦æ ¼ã |
2 | ISO 22307:2008 éèãµã¼ãã¹ ãã©ã¤ãã·ã¼å½±é¿è©ä¾¡ |
éèåéã«ããããã©ã¤ãã·ã¼ãä¿è·ããå½±é¿è©ä¾¡ã®è¦æ±äºé ã¨ãã¦ãåãã¦å½éæ¨æºè¦æ ¼ã¨ãã¦çºè¡ããããã®ã |
3 | ISO/IEC 29100 :2011 æ å ±æè¡ãã»ãã¥ãªãã£æè¡ ãã©ã¤ãã·ã¼ãã¬ã¼ã ã¯ã¼ã¯ |
ãã©ã¤ãã·ã¼ãã¬ã¼ã ã¯ã¼ã¯ï¼ãã©ã¤ãã·ã¼ä¿è·ã®æ çµã¿åã³ååï¼ãè¨è¼ããã¦ããå½éæ¨æºè¦æ ¼ã |
4 | JIS Q 15001:2017 å人æ å ±ä¿è·ããã¸ã¡ã³ãã·ã¹ãã |
ãã©ã¤ãã·ã¼ãã¼ã¯ï¼Pãã¼ã¯ï¼ã§æ±ããããå人æ å ±ä¿è·ããã¸ã¡ã³ãã·ã¹ãã è¦æ±äºé ãè¨è¼ããã¦ãããæ¥æ¬å·¥æ¥è¦æ ¼ã |
5 | æ¬§å· GDPRï¼EUä¸è¬ãã¼ã¿ä¿è·è¦åï¼ DPIA |
GDPR第35æ¡çã§ã¯ãPIAã«ç¸å½ããDPIAï¼Data Protection Impact Assessmentï¼ã義åä»ãããã¦ããã |
6 | ç±³å½ ã»é»åæ¿åºæ³ç ã»CPRA |
é»åæ¿åºæ³ç¬¬208æ¡ãå½åå®å
¨ä¿éæ³222æ¡çã«ã¦è¡æ¿æ©é¢ã¯PIAå®æ½ã義åä»ãããã¦ããã ã«ãªãã©ã«ãã¢å·ã§æ½è¡äºå®ã®CPRA ï¼California Privacy Rights Actï¼ã§PIAã義åä»ããããäºå®ã |
ãªããã¤ãã¤ããã£ã¦ã©ãã«ãããããã®ãããããªããã§ããã©â¦â¦
ã¾ãã¯PIAã«ç¹åãã¦ãã1ããã¼ã¹ã«ãã¦èãã¦ãå
·ä½çãªãã§ãã¯ãªã¹ãä½æãªããã¯4ã¨ãæ¥ç¨®æ¥æ
ãã¨ã®ã¬ã¤ãã©ã¤ã³ã¨ãåèã«ããã¨ããã¨æãã§ã
ããå½ã¾ããã§PIIãåãæ±ãå ´åã¯ã5ã¨ã6ã®ããã«ãã®å½ã®æ³ä»¤ãè¦åã確èªããªãããã®ãã§ã
åãã£ããã¨ããããåºæºé¢ä¿ãèªã¿è¾¼ãã§ã¿ãããªã
ãããã¨ãã
次åã¯PIAã®æºåã«ã¤ãã¦èª¬æããäºå®ã§ãã
åèæç®
- [1]ISOï¼ISO/IEC 29100:2011 âInformation technology-Security techniques-Privacy frameworkâ
- [2]ç·åçãçµæ¸ç£æ¥çï¼2022ï¼ï¼ãDX æ代ã«ãããä¼æ¥ã®ãã©ã¤ãã·ã¼ã¬ããã³ã¹ã¬ã¤ãããã¯ver1.2ã
- [3]å人æ å ±ä¿è·å§å¡ä¼ï¼2021ï¼ï¼ãPIA ã®åçµã®ä¿é²ã«ã¤ãã¦âPIA ã®æ義ã¨å®æ½â¼¿é ã«æ²¿ã£ãçæç¹âã
- [4]ç¬æ¸æ´ä¸ãé·è°·å·ä¹ ç¾ï¼2020ï¼ï¼ãISO/IECã29134対å¿ããã©ã¤ãã·ã¼å½±é¿è©ä¾¡å®æ½ããã¥ã¢ã«ã
- â»æä¸ã®åååãä¼ç¤¾åãå£ä½åã¯ãä¸è¬ã«å社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã