Day 106 — 2026-07-31

分析ベンダーへの個人データ漏えいをGDPRコンプライアンスレポートとして報告する

Phase 2 — Functional 📄 Report/Doc ⚖️ Legal/Compliance ★★★☆☆

シナリオ

あなたはSaaS企業 Novalite(EU顧客を多数抱えるB2B分析プラットフォーム)の Senior Software Engineer です。昨日(7/30)実施した四半期セキュリティ監査で、サードパーティ分析ベンダー MetricPulse が過去3ヶ月間、EUユーザー約48,000名分のプレーンテキストのメールアドレスとIPアドレスを受け取り続けていたことが判明しました。原因は、4月にMetricPulse SDKを統合した際、デフォルトで有効な「autocapture user traits」設定を無効化し忘れたことです。

さらに深刻なのは、MetricPulseがEU顧客とのData Processing Agreement(DPA)上、承認済みsub-processorとして登録されていない点です。これはGDPR Article 28違反の可能性に加え、Article 33(72時間以内の監督機関への通知義務)が発生する「個人データ侵害」に該当するかどうかの法的判断が急務です。あなたはすでに設定ミスの修正とEU向け分析トラフィックの一時停止を実施済みで、法務担当 Rachel Kim(Legal Counsel / Acting DPO)と CPO David Chen に状況をまとめた社内コンプライアンスレポートの提出を求められています。

48K
影響を受けたEUユーザー数
14M
3ヶ月間の送信イベント数
72hrs
Article 33通知期限(発見時起算)
Day 0
設定修正の完了までの日数
あなた
Alex Rivera — Senior Software Engineer
Novalite(EU顧客向けB2B分析プラットフォーム)
読み手
Rachel Kim(Legal Counsel / Acting DPO)・David Chen(CPO)
Article 33通知の要否と是正策への承認を判断する意思決定者

文化的コンテキスト

⚖️
事実は断定、法的評価は条件文で
discovered / spanning のような事実は断定的に書き、may constitute のような法的評価だけを条件的に書くメリハリが求められる
⏱️
72時間ルールは発見時点から起算
「対応完了時点」ではなく「発見時点」からカウントが始まる法的現実を冒頭で明示する
🙅
法的判断を自分で下さない
「違反です」と断定せず、"we need Legal's determination" と最終判断をLegal/DPOに明確に委ねる
「すでに動いている」対応とセットで
設定修正やトラフィック停止など、すでに取った行動を先に示すことで後手感を消す

タスク

以下のデータをもとに、社内向けコンプライアンスインシデントレポート(MEMO形式・BLUF構成)を英語で作成してください。

Internal Memo · MetricPulse GDPR Review · Confidential
To:Rachel Kim (Legal Counsel / Acting DPO), David Chen (CPO)
From:Alex Rivera, Senior Software Engineer
Date:July 31, 2026
Re:Potential GDPR Personal Data Breach — MetricPulse Analytics Integration [Time-Sensitive: Article 33 Review Needed]
事実概要 + 該当しうるリスク + 依頼事項の方向性を3文以内で...
根本原因・影響範囲・発見経緯をそれぞれ事実ベースで(箇条書き3点)...
Article 28 / 32 / 33 それぞれの論点を箇条書き3点で...
施策3点(各施策にOwner・Due・KPIを明記)...
Legal/DPOへの判断依頼で締める(期限を明示)...
⏱️ 20分 📝 220〜300語程度

使える表現・フレーズ

カードをクリックすると英語フレーズを表示します。

データ処理契約 クリックで英語を表示 →
Data Processing Agreement (DPA) 💡 GDPR文脈で必須の契約用語。sub-processorとセットで使う
下請け処理者(第三者ベンダー) クリックで英語を表示 →
sub-processor 💡 データ管理者から処理を委託された第三者。DPAへの明記が必須
個人データ侵害 クリックで英語を表示 →
personal data breach 💡 Article 33の適用要否を議論する際の正式な用語
72時間以内の通知義務 クリックで英語を表示 →
the 72-hour notification requirement 💡 Article 33の核心。発見時刻から起算されることを明記する
監督機関(データ保護当局) クリックで英語を表示 →
supervisory authority 💡 EU各国のデータ保護局を指す正式名称
データ最小化原則 クリックで英語を表示 →
data minimization 💡 必要最小限のデータのみ収集する原則。Article 32の文脈で使う
自動収集設定(意図しないPII取得) クリックで英語を表示 →
autocapture (misconfiguration) 💡 SDKのデフォルト挙動が原因だと技術的に説明する語
根本原因 クリックで英語を表示 →
root cause 💡 インシデント報告の定番語。技術的要因を1文で示す
是正措置 クリックで英語を表示 →
remediation 💡 対応策セクションの見出し語としても頻出
〜についてLegalの判断を仰ぐ クリックで英語を表示 →
we need Legal's determination on... 💡 法的判断を自分で下さず、明確に依頼する締めの定型表現

ヒント(段階的開示)

ヒント 1 — 構成・方向性

GDPRインシデントの社内コンプライアンスレポートは「事実概要(期限つき)→事実詳細→条文ごとのリスク整理→すでに取った対応→判断依頼」の5段構成。エンジニアは「これはArticle 33違反です」と断定せず、"this may constitute..." のように可能性として提示し、最終判断はLegal/DPOに委ねる。ただし通知期限(8/2)が迫っていることは冒頭で明確に伝え、後回しにできない案件だと示す。

  • Executive Summary: 事実概要と、該当しうるリスクを同じ文の中で提示
  • Incident Details: 「根本原因・影響範囲・発見経緯」を必ず数値と事実で
  • GDPR Risk Assessment: Article 28 / 32 / 33 を条文ごとに分解し、断定を避けた表現で
  • Immediate Remediation: 施策名・Owner・Due・KPIの4点セット。すでに完了した施策も含める
  • Recommended Decision: 判断期限を明示し、Legal/DPOへの依頼で締める
ヒント 2 — キーフレーズ(表現)
  • Executive Summary: "During yesterday's routine security audit, we discovered that our analytics vendor, MetricPulse, has been receiving plaintext email addresses and IP addresses for roughly 48,000 EU-based users over the past three months."
  • Risk(断定を避ける言い方): "This may constitute both an Article 28 compliance gap and a reportable personal data breach under Article 33."
  • 期限の明示: "The 72-hour clock to notify the supervisory authority started at discovery (July 30, 14:00 CET) — the deadline is August 2, 14:00 CET."
  • Remediation: "Autocapture Config Disabled | Owner: Alex (Eng) | Due: Completed July 30 | KPI: payload sampling confirms zero PII fields transmitted"
  • 締め: "We need Legal/DPO's determination by August 1 on whether this meets the Article 33 threshold, so we can act before the August 2 deadline if required."
ヒント 3 — 骨格テンプレート

MEMO ヘッダー:

To: Rachel Kim (Legal Counsel / Acting DPO), David Chen (CPO) From: Alex Rivera, Senior Software Engineer Date: July 31, 2026 Re: Potential GDPR Personal Data Breach — MetricPulse Analytics Integration [Time-Sensitive: Article 33 Review Needed]

Executive Summary(3文以内):

[事実概要 + 該当しうるリスク + 依頼事項の方向性を3文以内]

Incident Details(箇条書き3点):

• Root cause: [技術的原因] • Scope: [影響範囲を数値で] • Discovery: [発見経緯]

GDPR Risk Assessment(箇条書き3点):

• Article 28 (sub-processors): [論点] • Article 32 (security of processing): [論点] • Article 33 (breach notification): [期限を含めた論点]

Immediate Remediation(3点)+ Recommended Decision:

1. [施策名] | Owner: [誰] | Due: [いつ] | KPI: [何で測る] 2. [施策名] | Owner: [誰] | Due: [いつ] | KPI: [何で測る] 3. [施策名] | Owner: [誰] | Due: [いつ] | KPI: [何で測る] [Legal/DPOへの判断依頼 + 期限]

モデル解答(B2〜C1相当)

Internal Memo · Confidential
Model Answer

Header

To: Rachel Kim (Legal Counsel / Acting DPO), David Chen (CPO)
From: Alex Rivera, Senior Software Engineer
Date: July 31, 2026
Re: Potential GDPR Personal Data Breach — MetricPulse Analytics Integration [Time-Sensitive: Article 33 Review Needed]

Executive Summary

During yesterday's routine security audit, we discovered that our analytics vendor, MetricPulse, has been receiving plaintext email addresses and IP addresses for roughly 48,000 EU-based users over the past three months, due to a misconfigured SDK setting. MetricPulse is not currently listed as an approved sub-processor under our EU customer DPAs, which may constitute both an Article 28 compliance gap and a reportable personal data breach under Article 33. We've already patched the misconfiguration and paused EU analytics traffic, but we need Legal's determination on the 72-hour notification clock, which started at discovery.

Incident Details

  • Root cause: MetricPulse's default "autocapture user traits" setting was left enabled during the April 28 SDK integration; the approved data mapping covers only anonymized user_id and event_name.
  • Scope: approximately 48,000 EU-based users and 14 million events, spanning April 28 to July 30.
  • Discovery: identified during our quarterly security audit on July 30; not flagged by any external report or user complaint.

GDPR Risk Assessment

  • Article 28 (sub-processors): MetricPulse was never added to our sub-processor list or covered by a signed DPA — a disclosure gap with EU customers.
  • Article 32 (security of processing): transmitting plaintext PII outside our approved data flow is a data minimization failure.
  • Article 33 (breach notification): if this meets the personal data breach threshold, the 72-hour clock started at discovery (July 30, 14:00 CET) — the notification deadline is August 2, 14:00 CET.

Immediate Remediation

  1. Autocapture Config Disabled | Owner: Alex (Eng) | Due: Completed July 30 | KPI: payload sampling confirms zero PII fields transmitted
  2. Vendor Deletion Request Sent | Owner: Alex + Rachel | Due: August 3 | KPI: written deletion confirmation from MetricPulse
  3. DPA / Sub-processor Review | Owner: Rachel (Legal) | Due: August 7 | KPI: MetricPulse formally approved or fully removed as a sub-processor

Recommended Decision

We need Legal/DPO's determination by August 1 on whether this meets the Article 33 threshold, so we can act before the August 2 deadline if required.

解説

構成分析

1
件名に [Time-Sensitive] を明記: 通知期限が迫るコンプライアンス案件だと件名だけで伝わる。優先度の高い法務エスカレーションの慣例。
2
Executive Summaryで「事実」と「可能性」を切り分ける: "we discovered that..." は断定、"may constitute..." は可能性の言葉を使い分けることで、エンジニアが法的判断を勝手に下していない印象を保つ。
3
Incident Detailsは根本原因・範囲・発見経緯の3点固定: 特に発見経緯(外部通報ではなく自主監査)を明記することは、規制当局対応の観点でも重要な事実。
4
GDPR Risk Assessmentは条文ごとに分解: Article 28 / 32 / 33 を並べることで、法務が個別に判断しやすい構造になる。曖昧に「GDPR違反かもしれません」とまとめない。
5
締めで期限と依頼を1文にまとめる: "We need Legal/DPO's determination by August 1... before the August 2 deadline" と、依頼内容と背景の期限を同じ文で結びつけることで緊急性が伝わる。

重要表現

"may constitute" 〜に該当する可能性がある
エンジニアが法的結論を断定しない際の必須表現。事実の断定文と組み合わせて使う 💡 "this is a violation" と言い切らず、判断の余地をLegal側に残す
"the 72-hour clock started at discovery" 発見時点から72時間のカウントが始まる
GDPR Article 33の実務上の核心。修正完了時点ではなく発見時点が起算点だと明示する 💡 期限(deadline)と必ずセットで書く
"disclosure gap" 契約上の開示不備
sub-processor未登録のようなガバナンス上の穴を指す語。責任の所在を明確にする 💡 "a mistake" より制度上の欠陥だと伝わる表現
"data minimization failure" データ最小化原則違反
Article 32文脈での標準表現。承認範囲外のデータ送信を技術的に指摘する 💡 GDPR Risk Assessmentの見出し語としてそのまま使える

文化的ポイント

⚖️
事実は断定、法的評価は条件文で
日本語では「〜かもしれません」とぼかしがちだが、英語圏では discovered / spanning のような事実は断定的に書き、may constitute のような法的評価だけを条件的に書くメリハリが求められる
🙅
法的判断の自己完結を避ける
エンジニアが通知要否を自己判断して報告を遅らせることは重大なリスク。"we need Legal's determination" と明確に権限委譲することが専門性の高さの証として評価される
期限を冒頭近くで明示
72時間ルールの起算点と締切を早い段階で示すことで、読み手が優先順位を即座に判断できる
すでに取った行動を淡々と記述
設定修正やトラフィック停止は対立的な行為ではなく「即座に取った是正措置」として事実ベースで記述するのが標準的なトーン

よくある日本人のミス

ミス原因正しい表現
"We think this might be a problem." 曖昧で深刻度・条文根拠が伝わらない "This may constitute both an Article 28 compliance gap and a reportable personal data breach under Article 33."
"We already fixed it, so it should be fine." エンジニアが法的判断まで自己完結させている "We've patched the issue, but we need Legal's determination on whether this meets the Article 33 threshold."
"About 48,000 users were affected, we're not totally sure." 数字を濁すと報告の信頼性を損なう "Approximately 48,000 EU-based users, based on our event log analysis for April 28–July 30."
"We will ask the vendor to delete the data soon." 期限・担当者がなく実行が担保されない "Vendor Deletion Request Sent | Owner: Alex + Rachel | Due: August 3 | KPI: written deletion confirmation from MetricPulse"
"Please let us know if we need to report this to anyone." 締切への切迫感が伝わらず受け身な依頼になる "We need Legal/DPO's determination by August 1, so we can act before the August 2 deadline if required."

ワンランク上の表現

"The clock started the moment we found it, not the moment we finish fixing it."
発見時点から72時間のカウントが始まるという法的現実を端的に伝え、対応の緊急性を的確に示すフレーミング。
"This isn't a call we're equipped to make alone — it's a joint decision between Engineering and Legal."
技術者が法的判断を独断で下さない姿勢を示す、成熟したエスカレーションの言い回し。
"Being wrong about under-reporting costs us more than being wrong about over-reporting."
過小報告のリスクの方が過大報告より高くつくという判断基準を示す、上級者らしいリスクフレーミング。

次のステップ

  • 発展: MetricPulseとのDPA修正・sub-processor登録交渉をロールプレイで練習する(Negotiation × Legal、日曜日 Day 108)
  • 次回予告(土曜: Day 107): 1on1/会話 × Legal — MetricPulseインシデント対応で高まった負荷と責任範囲の不安をマネージャーに率直に相談する

自己評価(解いた後に記入)

理解度

自分の回答

コンプライアンスインシデントレポート(英語)

気づき・メモ