シナリオ
あなたはSaaS企業 Novalite(EU顧客を多数抱えるB2B分析プラットフォーム)の Senior Software Engineer です。昨日(7/30)実施した四半期セキュリティ監査で、サードパーティ分析ベンダー MetricPulse が過去3ヶ月間、EUユーザー約48,000名分のプレーンテキストのメールアドレスとIPアドレスを受け取り続けていたことが判明しました。原因は、4月にMetricPulse SDKを統合した際、デフォルトで有効な「autocapture user traits」設定を無効化し忘れたことです。
さらに深刻なのは、MetricPulseがEU顧客とのData Processing Agreement(DPA)上、承認済みsub-processorとして登録されていない点です。これはGDPR Article 28違反の可能性に加え、Article 33(72時間以内の監督機関への通知義務)が発生する「個人データ侵害」に該当するかどうかの法的判断が急務です。あなたはすでに設定ミスの修正とEU向け分析トラフィックの一時停止を実施済みで、法務担当 Rachel Kim(Legal Counsel / Acting DPO)と CPO David Chen に状況をまとめた社内コンプライアンスレポートの提出を求められています。
文化的コンテキスト
discovered / spanning のような事実は断定的に書き、may constitute のような法的評価だけを条件的に書くメリハリが求められる
「対応完了時点」ではなく「発見時点」からカウントが始まる法的現実を冒頭で明示する
「違反です」と断定せず、"we need Legal's determination" と最終判断をLegal/DPOに明確に委ねる
設定修正やトラフィック停止など、すでに取った行動を先に示すことで後手感を消す
タスク
以下のデータをもとに、社内向けコンプライアンスインシデントレポート(MEMO形式・BLUF構成)を英語で作成してください。
使える表現・フレーズ
カードをクリックすると英語フレーズを表示します。
ヒント(段階的開示)
ヒント 1 — 構成・方向性
GDPRインシデントの社内コンプライアンスレポートは「事実概要(期限つき)→事実詳細→条文ごとのリスク整理→すでに取った対応→判断依頼」の5段構成。エンジニアは「これはArticle 33違反です」と断定せず、"this may constitute..." のように可能性として提示し、最終判断はLegal/DPOに委ねる。ただし通知期限(8/2)が迫っていることは冒頭で明確に伝え、後回しにできない案件だと示す。
- Executive Summary: 事実概要と、該当しうるリスクを同じ文の中で提示
- Incident Details: 「根本原因・影響範囲・発見経緯」を必ず数値と事実で
- GDPR Risk Assessment: Article 28 / 32 / 33 を条文ごとに分解し、断定を避けた表現で
- Immediate Remediation: 施策名・Owner・Due・KPIの4点セット。すでに完了した施策も含める
- Recommended Decision: 判断期限を明示し、Legal/DPOへの依頼で締める
ヒント 2 — キーフレーズ(表現)
- Executive Summary:
"During yesterday's routine security audit, we discovered that our analytics vendor, MetricPulse, has been receiving plaintext email addresses and IP addresses for roughly 48,000 EU-based users over the past three months." - Risk(断定を避ける言い方):
"This may constitute both an Article 28 compliance gap and a reportable personal data breach under Article 33." - 期限の明示:
"The 72-hour clock to notify the supervisory authority started at discovery (July 30, 14:00 CET) — the deadline is August 2, 14:00 CET." - Remediation:
"Autocapture Config Disabled | Owner: Alex (Eng) | Due: Completed July 30 | KPI: payload sampling confirms zero PII fields transmitted" - 締め:
"We need Legal/DPO's determination by August 1 on whether this meets the Article 33 threshold, so we can act before the August 2 deadline if required."
ヒント 3 — 骨格テンプレート
MEMO ヘッダー:
Executive Summary(3文以内):
Incident Details(箇条書き3点):
GDPR Risk Assessment(箇条書き3点):
Immediate Remediation(3点)+ Recommended Decision:
モデル解答(B2〜C1相当)
Header
To: Rachel Kim (Legal Counsel / Acting DPO), David Chen (CPO)
From: Alex Rivera, Senior Software Engineer
Date: July 31, 2026
Re: Potential GDPR Personal Data Breach — MetricPulse Analytics Integration [Time-Sensitive: Article 33 Review Needed]
Executive Summary
During yesterday's routine security audit, we discovered that our analytics vendor, MetricPulse, has been receiving plaintext email addresses and IP addresses for roughly 48,000 EU-based users over the past three months, due to a misconfigured SDK setting. MetricPulse is not currently listed as an approved sub-processor under our EU customer DPAs, which may constitute both an Article 28 compliance gap and a reportable personal data breach under Article 33. We've already patched the misconfiguration and paused EU analytics traffic, but we need Legal's determination on the 72-hour notification clock, which started at discovery.
Incident Details
- Root cause: MetricPulse's default "autocapture user traits" setting was left enabled during the April 28 SDK integration; the approved data mapping covers only anonymized user_id and event_name.
- Scope: approximately 48,000 EU-based users and 14 million events, spanning April 28 to July 30.
- Discovery: identified during our quarterly security audit on July 30; not flagged by any external report or user complaint.
GDPR Risk Assessment
- Article 28 (sub-processors): MetricPulse was never added to our sub-processor list or covered by a signed DPA — a disclosure gap with EU customers.
- Article 32 (security of processing): transmitting plaintext PII outside our approved data flow is a data minimization failure.
- Article 33 (breach notification): if this meets the personal data breach threshold, the 72-hour clock started at discovery (July 30, 14:00 CET) — the notification deadline is August 2, 14:00 CET.
Immediate Remediation
- Autocapture Config Disabled | Owner: Alex (Eng) | Due: Completed July 30 | KPI: payload sampling confirms zero PII fields transmitted
- Vendor Deletion Request Sent | Owner: Alex + Rachel | Due: August 3 | KPI: written deletion confirmation from MetricPulse
- DPA / Sub-processor Review | Owner: Rachel (Legal) | Due: August 7 | KPI: MetricPulse formally approved or fully removed as a sub-processor
Recommended Decision
We need Legal/DPO's determination by August 1 on whether this meets the Article 33 threshold, so we can act before the August 2 deadline if required.
解説
構成分析
重要表現
文化的ポイント
日本語では「〜かもしれません」とぼかしがちだが、英語圏では discovered / spanning のような事実は断定的に書き、may constitute のような法的評価だけを条件的に書くメリハリが求められる
エンジニアが通知要否を自己判断して報告を遅らせることは重大なリスク。"we need Legal's determination" と明確に権限委譲することが専門性の高さの証として評価される
72時間ルールの起算点と締切を早い段階で示すことで、読み手が優先順位を即座に判断できる
設定修正やトラフィック停止は対立的な行為ではなく「即座に取った是正措置」として事実ベースで記述するのが標準的なトーン
よくある日本人のミス
| ミス | 原因 | 正しい表現 |
|---|---|---|
| "We think this might be a problem." | 曖昧で深刻度・条文根拠が伝わらない | "This may constitute both an Article 28 compliance gap and a reportable personal data breach under Article 33." |
| "We already fixed it, so it should be fine." | エンジニアが法的判断まで自己完結させている | "We've patched the issue, but we need Legal's determination on whether this meets the Article 33 threshold." |
| "About 48,000 users were affected, we're not totally sure." | 数字を濁すと報告の信頼性を損なう | "Approximately 48,000 EU-based users, based on our event log analysis for April 28–July 30." |
| "We will ask the vendor to delete the data soon." | 期限・担当者がなく実行が担保されない | "Vendor Deletion Request Sent | Owner: Alex + Rachel | Due: August 3 | KPI: written deletion confirmation from MetricPulse" |
| "Please let us know if we need to report this to anyone." | 締切への切迫感が伝わらず受け身な依頼になる | "We need Legal/DPO's determination by August 1, so we can act before the August 2 deadline if required." |
ワンランク上の表現
次のステップ
- 発展: MetricPulseとのDPA修正・sub-processor登録交渉をロールプレイで練習する(Negotiation × Legal、日曜日 Day 108)
- 次回予告(土曜: Day 107): 1on1/会話 × Legal — MetricPulseインシデント対応で高まった負荷と責任範囲の不安をマネージャーに率直に相談する