Day 108 — 2026-08-02

Negotiation × Legal/Compliance

Phase 2 — Functional 🤝 Negotiation ⚖️ Legal/Compliance ★★★☆☆

シナリオ

今日のシナリオ

Day 106〜107で対応したインシデントの根本原因調査がLegal(Rachel Kim)とベンダー管理側で完了した。判明したのは、MetricPulse社が今年春から、契約上のsub-processorリストに載せないまま DataForge Analytics という分析基盤に一部の顧客データを流していたこと。今回の漏えいはこのDataForge側の設定ミスが起点だった。Rachelの方針は、①DataForge Analyticsを正式にDPA(データ処理契約)のsub-processorリストに登録させ監査権を確保すること、②侵害通知SLAを現行の「30日以内」から「72時間以内」へ短縮すること。技術的な実装詳細が絡むため、Day107の1on1で合意した新しいエスカレーション体制に基づき、Alex Riveraがこの交渉をMetricPulse側と直接担当する。Rachelはこの回には同席せず、事後にレビューする形。

あなた
Alex Rivera — Senior Software Engineer
Legal依頼のエスカレーション窓口としてRachelから交渉権限を委任されている
相手
Jordan Blake — VP of Customer Trust & Compliance, MetricPulse
ネイティブスピーカー。関係修復に前向きだが、自社の運用負荷とコストはできるだけ抑えたい

目的

DataForge Analyticsの正式sub-processor登録+監査権の確保、および侵害通知SLAの短縮について、関係を損なわずに、しかしRachelから委任された譲れない条件(監査権・通知の迅速性)を守った合意を形成する。

文化的コンテキスト

🔀
「コストがかかる」は要求撤回の理由にならない
相手の実務懸念を認めることと、要求の正当性を維持することは両立できる
🧭
要求を「実行可能な形」に再定義する
「不可能」への反論ではなく、完全な報告→一次通知のみ、と要求自体をリフレーミングする
🛡️
material breachかどうかは安易に譲らない
相手が使いたがる「operational gap」というフレーミングを無条件には受けない
📝
譲歩には必ず検証可能な条件を
「合意する意向」と「登録・監査アクセスの完了」という実行を混同しない

タスク

以下の3場面で、あなたはどう発言するか?各場面に対して2〜4文の英語で回答せよ。

場面 A — DataForge Analyticsの正式登録への抵抗への応答
Jordan Blake

"I hear the concern about DataForge, but formally listing every infrastructure partner as a named sub-processor gets expensive fast — we'd need to do that for every client individually. Can we handle this with an internal memo confirming DataForge's role instead?"

DataForgeは「単なるインフラパートナー」ではなく、今回の漏えいの起点になった実データ処理者であることを事実ベースで示しつつ、内部メモでは監査権が発生しないため不十分であることを伝えたい。相手の運用コスト懸念には、対象を「実際に個人データを扱うsub-processorのみ」に限定するという小さな柔軟性を示してよい。

⏱️ 3〜5分 📝 2〜4文
場面 B — 侵害通知SLA短縮への「非現実的」という反発への応答
Jordan Blake

"Fair point on DataForge — we can work with a narrower scope. But 72 hours for breach notification just isn't realistic on our end. Our internal review process alone takes longer than that. Can we agree on 5 business days instead?"

「不可能」という主張を頭ごなしに否定せず受け止めつつ、72時間は「完全な調査報告」ではなく「一次通知(把握している事実のみ)」で構わないという区別を明確にしたい。詳細な報告は後日でよいという段階的な提案でリフレーミングする。

⏱️ 3〜5分 📝 2〜4文
場面 C — Jordanの譲歩案(段階的通知+条件)への応答
Jordan Blake

"Okay, a two-stage notification — initial alert within 72 hours, full report within 10 business days — I think we can do that. In exchange, I'd want it noted that this incident isn't treated as a material breach of the master agreement, just an operational gap we're fixing."

この譲歩案(二段階通知)は評価しつつ、「material breachとして扱わない」という要求は無条件には受け入れず、DataForgeの正式登録と監査ログへのアクセスが実際に完了することを条件にするという形でまとめて合意を固めよ。

⏱️ 3〜5分 📝 2〜4文

Legal × Negotiation 必須語彙

カードをクリックすると英語表現と使い方のコツを表示します。

データ処理契約(GDPR等に基づく契約) クリックで詳細を表示 →
DPA (Data Processing Agreement) 💡 ベンダーとのデータ処理条件を定める契約文書を指す実務語
再委託先(データ処理を委託される第三者) クリックで詳細を表示 →
sub-processor 💡 契約上正式にリストへ登録・開示が求められる相手を指す
正式に登録する(リストに載せる) クリックで詳細を表示 →
formally list (someone) as a named sub-processor 💡 「内部メモ」など非公式な扱いと対比させる際の核となる表現
監査権 クリックで詳細を表示 →
audit rights 💡 sub-processorに対して監査を行える契約上の権利
一次通知(詳細確定前の速報) クリックで詳細を表示 →
initial notification / initial alert 💡 段階的通知の第一段階を指す。72時間SLA交渉で有効
重大な違反(契約解除等につながりうる) クリックで詳細を表示 →
material breach (of the agreement) 💡 契約上の重大性を左右する語。安易に譲らない領域
運用上の不備(重大な違反ではなく) クリックで詳細を表示 →
an operational gap 💡 material breachと対比させ、相手が使いたがるフレーミング
対象範囲を狭める(要求の一部に絞る) クリックで詳細を表示 →
narrow the scope (to actual data processors) 💡 相手のコスト懸念に応じ、対象を限定する際の柔軟性表現
〜を条件として クリックで詳細を表示 →
contingent on (completing X) 💡 譲歩を無条件にせず、条件付きにする際の鍵語
段階的な移行期間 クリックで詳細を表示 →
a phased transition period 💡 一括対応ではなく段階的に義務を満たしてもらう際の提案語

ヒント(段階的開示)

ヒント 1 — 構成・方向性
  • 場面A: 相手の懸念(コスト)を却下せず受け止める → DataForgeが「単なるインフラ」ではなく実データ処理者であり今回の漏えいの起点であるという事実を提示 → 対象を「実際に個人データを扱うsub-processorのみ」に絞る柔軟性を示す
  • 場面B: 「不可能」という主張を否定せず受け止める → 72時間は「完全な報告」ではなく「一次通知」でよいと区別してリフレーミング → 詳細報告は後日でよいという段階的提案
  • 場面C: 二段階通知の譲歩案を評価する → "material breachとして扱わない"という要求は無条件には受けず、DataForge登録+監査ログアクセス完了を条件にする
ヒント 2 — キーフレーズ・表現
  • 場面A: "I understand the cost concern, but DataForge isn't just infrastructure — it's the sub-processor whose misconfiguration triggered this incident, which is exactly why formal listing and audit rights matter here."
  • 場面B: "I hear that a full report in 72 hours isn't realistic, but we're not asking for that — we need an initial notification of what you know within 72 hours, with the full report to follow."
  • 場面C: "That two-stage structure works for us. I can agree to not framing this as a material breach, but that's contingent on DataForge actually being listed and audit access being in place — not just agreed in principle."
ヒント 3 — 骨格テンプレート

場面A — 懸念の受け止め → 事実の提示 → 対象を絞る柔軟性:

"I understand [相手の懸念], but [事実: DataForgeが実データ処理者で漏えいの起点]. What I can offer is [対象を絞る柔軟性], but [譲れない原則: 正式登録と監査権] stays as agreed."

場面B — 受け止め → リフレーミング → 段階的提案:

"I hear that [相手の主張: 不可能]. But [リフレーミング: 求めているのは一次通知であり完全な報告ではない]. [段階的提案の詳細]."

場面C — 評価 → 条件付き受諾 → セーフガード:

"[相手の譲歩案の評価]. I can agree to [条件付き受諾], as long as [セーフガード条項: 登録と監査アクセスの完了]."

モデル解答(B2〜C1相当)

Jordan Blake

"I hear the concern about DataForge, but formally listing every infrastructure partner as a named sub-processor gets expensive fast — we'd need to do that for every client individually. Can we handle this with an internal memo confirming DataForge's role instead?"

あなた(場面A モデル解答)

"I understand the cost concern about listing every infrastructure partner individually, but DataForge isn't just infrastructure — it's the sub-processor whose misconfiguration actually triggered this incident, which is exactly why formal listing and audit rights matter here. What I can offer is narrowing this to sub-processors that actually touch personal data, rather than every vendor in your stack, but for anyone in that category, an internal memo isn't going to satisfy the audit requirement."

Jordan Blake

"Fair point on DataForge — we can work with a narrower scope. But 72 hours for breach notification just isn't realistic on our end. Our internal review process alone takes longer than that. Can we agree on 5 business days instead?"

あなた(場面B モデル解答)

"I hear that a full report in 72 hours isn't realistic on your end, and honestly, we're not asking for that. What we need is an initial notification — just what you know at that point — within 72 hours, with the full investigation report to follow on a reasonable timeline after that. That two-stage structure should be a lot more workable than trying to complete everything in three days."

Jordan Blake

"Okay, a two-stage notification — initial alert within 72 hours, full report within 10 business days — I think we can do that. In exchange, I'd want it noted that this incident isn't treated as a material breach of the master agreement, just an operational gap we're fixing."

あなた(場面C モデル解答)

"That two-stage structure works well for us — initial alert within 72 hours, full report within 10 business days. On the material breach language, I can agree to framing this as an operational gap rather than a material breach, but that's contingent on DataForge actually being formally listed and audit log access being in place, not just agreed to in principle. Once both of those are confirmed, I'm comfortable putting that language in writing."

解説

構成分析

1
相手の懸念を却下せず受け止める: "I understand..." "I hear that..." から入ることで、相手の実務上の懸念を頭ごなしに否定しない姿勢を示す
2
事実ベースでリスクの所在を示す: "DataForge isn't just infrastructure — it's the sub-processor whose misconfiguration actually triggered this incident" のように、感情論ではなく検証可能な事実で要求の正当性を裏付ける
3
要求そのものを再定義してリフレーミング: 「72時間で完全な報告」という誤解を「72時間は一次通知のみ」と訂正し、実現不可能に見えた要求を現実的な形に変換する

重要表現まとめ

表現意味ポイント
formally list (someone) as a named sub-processor正式にsub-processorリストへ登録する内部メモなど非公式対応との対比で使う
audit rights監査権sub-processorに対して実効性のあるガバナンスを及ぼす契約上の権利
initial notification一次通知詳細確定前の速報であり、完全な報告義務と切り離すことで交渉の突破口になる
material breach vs an operational gap重大な違反 vs 運用上の不備契約上の重大性を左右する対立語。安易に相手のフレーミングを受け入れない
contingent on (completing X)〜を条件として譲歩を無条件にしないためのセーフガード表現

文化的ポイント

日本のビジネス感覚英語圏でのビジネス感覚
相手が「コストがかかる」「現実的でない」と抵抗すると、関係を優先して要求そのものを取り下げてしまいがち相手の実務懸念を認めることと、要求の正当性を維持することは両立できる、という前提で会話が進む
「不可能」と言われると、そのまま要求水準を下げてしまいがち「要求を諦める」のではなく「要求を相手が実行可能な形に再定義する」(完全な報告→一次通知のみ)
合意の意向が示されると、そこで交渉が完了したと捉えてしまいがち譲歩を示す際は必ず検証可能な条件とセットにし、「合意する意向」と「合意の実行」を混同しない

よくある日本人のミス

❌ "I see, then an internal memo should be fine."
相手のコスト懸念に押されて監査権という本質的な要求を取り下げてしまう
✅ "An internal memo isn't going to satisfy the audit requirement — DataForge needs to be formally listed."
❌ "Okay, 5 business days is fine then."
「不可能」という主張をそのまま受け入れ、要求を再定義する発想がない
✅ "We're not asking for a full report in 72 hours — just an initial notification of what you know."
❌ "Sure, we won't call it a material breach."
譲歩に条件をつけず、口約束のまま合意してしまう
✅ "I can agree to that, but it's contingent on DataForge actually being listed and audit access being in place."
❌ "Sorry to keep pushing on this, it's probably not that important."
謝罪から入り、リスクの重大性を自ら弱めてしまう
✅ "I want to be clear on why this matters — DataForge is what triggered the incident in the first place."
❌ "Whatever works best for MetricPulse is fine with us."
相手の運用負荷を優先し、自社が守るべき条件を曖昧にしてしまう
✅ "I can narrow the scope to actual data processors, but for those, formal listing stays non-negotiable."

ワンランク上の表現(Phase 2 以降)

Basic
"We need DataForge on the list and notification has to be faster."
↓ ビジネスでは
B2
"DataForge isn't just infrastructure — it's the sub-processor whose misconfiguration triggered this incident, which is why formal listing and audit rights matter here."
↓ さらに上のレベルでは
C1
"I'd rather anchor this agreement to what actually caused the incident than to what's administratively convenient for either side — a sub-processor that touches personal data gets listed and audited regardless of how it's categorized internally, and a notification SLA only works if the first stage is fast enough to matter, even if the full report takes longer."

次のステップ

  • 発展: 本日合意した内容(DataForge正式登録・二段階通知SLA・material breach非該当の条件)を正式に文書化し、Rachel Kimの事後レビューを受ける
  • 次回(月曜): Email × Legal/Compliance — 本日の交渉合意事項をJordan Blakeと社内(Rachel Kim)向けに正式に確認するフォローアップメール

自己評価(解いた後に記入)

理解度

自分の回答

場面A — DataForge正式登録への抵抗への応答
場面B — 72時間SLAへの反発への応答
場面C — 譲歩案の受諾とセーフガード

気づき・メモ