« 米国 CISA 耐量子暗号標準を利用する技術向け製品カテゴリー (2026.01.23) | Main | 欧州 EDPB EDPS 欧州委員会の「AIに関するデジタルオムニバス」提案に関する共同意見書 »

2026.01.26

欧州 EDPB EU-米国データ・プライバシー枠組みに関するFAQ等 (2026.01.23)

こんにちは、丸山満彦です。

2026.01.23にEU-米国データ・プライバシー枠組みに関するFAQ等が公表されていますね。。。2024年に公開されたものの更新ですね...

 

● EDPB

Rules of Procedure for the “Informal Panel of EU DPAs” according to the EU-U.S. Data Privacy Framework - version 2.0 EU-米国データ・プライバシー枠組みに基づく「EUデータ保護当局非公式パネル」手続規則 - バージョン2.0 PDF
EU-U.S. Data Privacy Framework F.A.Q. for European businesses - version 2.0 EU-米国データ・プライバシー枠組みに関する欧州企業向けFAQ - バージョン2.0 PDF
EU-US Data Privacy Framework FAQ for European individuals - version 2.0 EU-米国データ・プライバシー枠組みに関する欧州個人向けFAQ - バージョン2.0 PDF
EU-US Data Privacy Framework Template Complaint Form for Submitting Complaints to EU DPAs related to the Data Privacy Framework Principles - version 2.0 EU-米国データ・プライバシー枠組み原則に関連するEUデータ保護当局への苦情提出用テンプレート苦情申立書 - バージョン2.0 PDF

 

そのうちにEU-米国データ・プライバシー枠組みに関する欧州企業向けFAQの内容は次のとおり...

・[PDF] EU-US Data Privacy Framework FAQ for European individuals - version 2.0

20260125-20509

 

EU-U.S. Data Privacy Framework F.A.Q. for European businesses[1]  EU-米国データ・プライバシー枠組みに関する欧州企業向けFAQ[1]
Version 2.0  バージョン2.0
Adopted on 15 January 2026  2026年1月15日採用
Version history  バージョン履歴
Version Date Adoption information  バージョン 日付 採用情報
version 1.0 16 July 2024 adoption of the FAQ  バージョン1.0 2024年7月16日 FAQ採用
version 2.0 15 January 2026 adoption of updated version  バージョン2.0 2026年1月15日 更新版採用
Table of Contents  目次
1 What is the EU-U.S. Data Privacy Framework? 1 EU-米国データ・プライバシー枠組みとは何か?
2 Which U.S. companies are eligible to the EU-U.S. Data Privacy Framework? 2 EU-米国データ・プライバシー枠組みの対象となる米国企業は?
3 What to do before transferring personal data to a company in the U.S. which is, or claims to be certified under the EU-U.S. Data Privacy Framework? 3 EU-米国データ・プライバシー枠組みの認証を取得している、または取得を主張する米国企業に個人データを移転する前にすべきことは?
 3.1 Transfers to U.S. subsidiaries of companies certified under the EU-U.S. Data Privacy Framework  3.1 EU-米国データ・プライバシー枠組み認証取得企業の米国子会社への移転
 3.2 Transfers to a company in the U.S. acting as a controller  3.2 データ管理者として機能する米国企業への移転
 3.3 Transfers to a company in the U.S. acting as a processor  3.3 データ処理者として機能する米国企業への移転
4 Where can I find guidance regarding the certification of U.S. subsidiary companies of European businesses? 4 欧州企業の米国子会社の認証に関するガイダンスはどこで入手できるか?
1 What is the EU-U.S. Data Privacy Framework?  1 EU-米国データ・プライバシー枠組みとは何か?
The EU-U.S. Data Privacy Framework (“DPF”) is a self-certification mechanism for companies in the U.S.[2] Companies that have self-certified under the DPF must comply with its principles, rules and obligations related to the processing of personal data of EEA individuals. For more information about these commitments, see the Data Privacy Framework Principles.[3]  EU-米国データ・プライバシー枠組み(以下「DPF」)は、米国企業向けの自己認証制度である[2]。DPFに基づき自己認証した企業は、EEA域内個人のパーソナルデータの処理に関連する原則、規則、義務を遵守しなければならない。これらの約束事項の詳細については、データ・プライバシー枠組み原則を参照のこと。[3] 
The European Commission considered that transfers of personal data from the EEA to companies certified under the DPF enjoy an adequate level of protection.[4] As a result, personal data can be transferred freely to U.S. certified companies, without the need to put in place further safeguards or obtain an authorisation. Here are some relevant links for more information:  欧州委員会は、EEAからDPF認証企業への個人データ移転が十分な保護水準を享受すると判断した[4]。その結果、追加的な保護措置や認可を取得する必要なく、個人データを米国認証企業へ自由に移転できる。詳細は以下の関連リンクを参照のこと:
- The European Commission’s Questions and Answers: Data Privacy Framework[5]  - 欧州委員会「データ・プライバシー枠組みに関するQ&A」[5]
- The Data Privacy Framework website as administrated by the U.S. Department of Commerce[6]  - 米国商務省が運営するデータ・プライバシー枠組み公式サイト[6]
- The European Commission’s decision on the adequate level of protection of personal data under the EU-U.S. Data Privacy Framework[7]  - EU-米国データ・プライバシー枠組みに基づく個人データの適切な保護水準に関する欧州委員会の決定[7]
The DPF applies to any type of personal data transferred from the EEA to the U.S., including personal data processed for commercial or health purposes, and human resources data collected in the context of an employment relationship (hereafter: “HR Data”), as long as the recipient company in the U.S. is self-certified under the DPF to process those types of data.[8]  DPFは、EEAから米国へ移転されるあらゆる種類の個人データに適用される。これには商業目的・医療目的で処理される個人データ、雇用関係において収集される人事データ(以下「HRデータ」)も含まれる。ただし、米国における受領企業が当該データの種類についてDPFに基づく自己認証を取得している場合に限る[8]。(以下「人事データ」という)。ただし、米国の取得者が当該データ処理についてDPFに基づく自己認証を取得している場合に限る[8]。
2 Which U.S. companies are eligible to the EU-U.S. Data Privacy Framework?  2 EU-米国データ・プライバシー枠組みの対象となる米国企業は?
In order to be eligible to self-certify to the DPF, a company in the U.S. must be subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (“FTC”) or of the U.S. Department of Transportation (“DoT”). Other U.S. statutory bodies may be included in the future.[9]  米国企業がDPFへの自己認証資格を得るには、米国連邦取引委員会(FTC)または米国運輸省(DoT)の調査権限および執行権限の対象となる必要がある。将来的に他の米国団体が追加される可能性がある。[9]
This means that, for example, non-profit organizations, banks, insurance companies and telecommunication service providers (with regard to common carrier activities) which do not fall under the jurisdiction of the FTC or DoT cannot self-certify under the DPF.  これは例えば、FTCやDoTの管轄下にない非営利団体、銀行、保険会社、電気通信プロバイダ(公共通信事業者としての活動に関して)は、DPFに基づく自己認証ができないことを意味する。
3 What to do before transferring personal data to a company in the U.S. which is, or claims to be certified under the EU-U.S. Data Privacy Framework?  3 EU-米国データ・プライバシー枠組みに基づき認証されている、または認証を主張する米国企業に個人データを移転する前に何をすべきか?
Before transferring personal data to a company in the U.S. under the DPF, a data exporter in the EEA must ascertain that the company in the U.S. holds an active self-certification (certifications must be renewed annually) and that this certification covers the data in question. When an EEA exporter intends to transfer HR Data to a company in the U.S. under the DPF,[10] the EEA exporter shall ensure that the company in the U.S. either: (a) holds an active certification covering that data as HR Data or (b) holds an active certification covering the data as another type of personal data and has committed in its privacy policy to cooperate and comply with the advice of the EU data protection authorities with regard to such data. The EEA exporter shall also inform the company in the U.S. that the transfer includes HR Data.[11]  DPFに基づき米国企業へ個人データを移転する前に、EEA域内のデータ輸出者は、当該米国企業が有効な自己認証(認証は年次更新が必要)を保持しており、かつ当該認証が対象データに適用されることを確認しなければならない。EEA域内の輸出者がDPFに基づき米国企業へ人事データを移転しようとする場合[10]、EEA域内の輸出者は、当該米国企業が以下のいずれかを満たしていることを確認しなければならない: (a) 当該データを人事データとしてカバーする有効な認証を保持していること、または (b) 他の種類の個人データとして当該データをカバーする有効な認証を保持し、かつプライバシーポリシーにおいて当該データに関してEUデータ保護当局の助言に協力し遵守することを約束していること。EEA輸出者はまた、米国企業に対し、当該移転が人事データを含むことを通知しなければならない[11]。
To verify whether or not a self-certification is active and applicable and the scope of the certification, data exporters in the EEA need to check the Data Privacy Framework List,[12] published on the U.S. Department of Commerce’s website. This list includes a register of companies that hold an active self-certification under the DPF and of companies that have been removed from the List (“inactive participants”), stating the reasons for their removal. An EEA data exporter cannot rely on the DPF for transfers of personal data to companies that do not hold an active self-certification under the DPF. Companies that have been removed from the Data Privacy Framework List must continue to apply the Data Privacy Framework Principles to personal data received while participating in the DPF for as long as they retain these data.  自己認証が有効かつ適用可能かどうか、および認証の範囲を確認するため、EEAのデータ輸出者は米国商務省ウェブサイトに掲載されているデータ・プライバシー枠組みリスト[12]を確認する必要がある。このリストには、DPFに基づく有効な自己認証を保持する企業と、リストから削除された企業(「非活動参加企業」)の登録が記載されており、削除理由も明記されている。EEA域内のデータ輸出者は、DPFに基づく有効な自己認証を保持していない企業への個人データ移転において、DPFに依拠することはできない。データ・プライバシー枠組みリストから削除された企業は、DPF参加中に受け取った個人データについて、当該データを保持している限り、データ・プライバシー枠組み原則を引き続き適用しなければならない。
For the transfer of personal data to companies in the U.S. that are not (or no longer) selfcertified under the DPF, other grounds for transfer in Chapter V of the GDPR may be used, such as Binding Corporate Rules or Standard Contractual Clauses.  DPFに基づく自己認証を取得していない(または取得しなくなった)米国企業への個人データ移転については、GDPR第V章に定めるその他の移転根拠(拘束的企業規則や標準契約条項など)を利用できる。
The fact that the recipient in the U.S. is self-certified under the DPF will enable data exporters in the EEA to comply with Chapter V of the GDPR, but all other requirements in the GDPR and any other national data protection law remain applicable.  米国における取得者がDPFに基づき自己認証されている事実は、EEA域内のデータ輸出者がGDPR第V章に準拠することを可能とするが、GDPRおよびその他の国内データ保護法のその他の要件は全て引き続き適用される。
3.1 Transfers to U.S. subsidiaries of companies certified under the EU-U.S. Data Privacy Framework  3.1 EU-米国データ・プライバシー枠組み認証企業の米国子会社への移転
In the case of transfers to companies in the U.S. that are subsidiaries of a DPF-certified parent company, EEA data exporters must check if the certification of the parent company also covers the subsidiary company concerned.  DPF認証を受けた親会社の子会社である米国事業体への移転の場合、EEAデータ輸出者は、親会社の認証が当該子会社もカバーしているかどうかを確認しなければならない。
You can find additional information on how to verify the scope of an organisation’s selfcertification, including whether other U.S. entities or U.S. subsidiaries are covered by it, here.[13]  組織の自己認証の範囲(他の米国事業体や米国子会社がカバーされているか否かを含む)を確認する方法に関する追加情報は、こちらを参照のこと。[13]
3.2 Transfers to a company in the U.S. acting as a controller  3.2 米国におけるデータ管理者として機能する企業への移転
Before transferring personal data to a controller in the U.S., an EEA data exporter must ensure the transfer complies with all relevant provisions of the GDPR. As a first step, the data exporter can only share personal data with a company in the U.S. if there is a legal basis for the processing (Article 6 of the GDPR). Moreover, all other requirements in the GDPR need to be met (e.g. purpose limitation, proportionality, accuracy and information obligations towards data subjects). Note that when data is to be transferred to a self-certified company in the U.S., the EEA data exporter, in accordance with Articles 13 and 14 GDPR, must inform data subjects about the identity of the recipients of their data and about the fact that the transfer is covered by the EU-U.S. Data Privacy Framework adequacy decision.  個人データを米国のデータ管理者に移転する前に、EEAデータ輸出者は移転がGDPRの関連規定全てに準拠していることを確認しなければならない。第一段階として、データ輸出者は処理の法的根拠(GDPR第6条)が存在する場合にのみ、米国企業と個人データを共有できる。さらに、GDPRのその他の要件(目的限定、比例性、正確性、データ対象者への情報提供義務など)も全て満たす必要がある。なお、米国における自己認証企業へのデータ移転の場合、EEAデータ輸出者はGDPR第13条及び第14条に基づき、データ対象者の身元及び移転がEU-米国データ・プライバシー枠組みの十分性認定の対象となる事実について、データ対象者に通知しなければならない。
3.3 Transfers to a company in the U.S. acting as a processor  3.3 米国における処理者としての企業への移転
When an EEA controller transfers data to a processor in the U.S., the controller and processor are obliged to conclude a data processing agreement under Article 28 GDPR (hereafter: Data processing agreement), regardless of whether the processor is self-certified under the DPF.  EEA域内のデータ管理者が米国の処理者にデータを移転する場合、処理者がDPFに基づく自己認証を受けているか否かにかかわらず、管理者と処理者はGDPR第28条に基づくデータ処理契約(以下「データ処理契約」)を締結する義務を負う。
You can find more information about the contract requirements for transfers to a processor in the U.S. here.[14]  米国における処理者への移転に関する契約要件の詳細はこちらを参照のこと。[14]
The conclusion of a data processing agreement is required in order to ensure that the U.S. processor commits to:  データ処理契約の締結は、米国における処理者が以下の事項を確約することを保証するために必要である:
• process the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;  • 処理者が従うべきEUまたは加盟国の法令により要求される場合を除き、第三国または国際機関への個人データ移転を含め、データ管理者の文書化された指示のみに基づいて個人データを処理すること。当該法令が公共の利益の重要な理由によりそのような情報を禁止する場合を除き、処理者は処理前にデータ管理者にその法的要件を通知しなければならない。
• ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;  • パーソナルデータの処理を許可された者が、守秘義務を自ら負うか、適切な法的守秘義務の下にあることを確保すること。
• implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in line with what is required by the data processing agreement (stemming from Article 32 of the GDPR) and sections 4 and 10 of the DPF;  • データ処理契約(GDPR第32条に基づく)およびDPF第4条・第10条で要求される内容に沿い、リスクに応じた適切なセキュリティレベルを確保するための技術的・組織的措置を実施すること。
• respect the conditions referred to in the data processing agreement (stemming from paragraphs 2 and 4 of Article 28 of the GDPR) and Section II.3.B of the DPF for engaging another processor;  • 他のデータ処理者を利用する場合、データ処理契約(GDPR第28条第2項及び第4項に基づく)及びDPF第II.3.B項に定める条件を遵守すること。
• taking into account the nature of the processing, assist the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR;  • 処理の性質を考慮し、GDPR第III章に定めるデータ対象者の権利行使請求への対応義務をデータ管理者が履行できるよう、可能な範囲で適切な技術的及び組織的措置により支援すること。
• assist the controller in ensuring compliance with its obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to the processor;  • 処理の性質及びデータ処理者が入手可能な情報を考慮し、GDPR第32条から第36条に基づくデータ管理者の義務遵守を確保するため、データ管理者を支援する。
• at the choice of the controller, delete or return all the personal data to the controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the personal data;  • 処理に関連するサービスの提供終了後、データ管理者の選択に基づき、全ての個人データを削除またはデータ管理者に返却する。ただし、EU法または加盟国法が個人データの保存を要求する場合は、既存のコピーを削除する。
• make available to the controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller. With regard to this last point, the processor shall immediately inform the controller if, in its opinion, an instruction infringes the DPF.  • GDPR第28条に定める義務の遵守を証明するために必要な全ての情報を管理者に提供し、管理者または管理者が委任した監査人による監査(検査を含む)の実施を許可し、これに協力する。この最後の点に関して、処理業者は、指示がDPFに違反すると判断した場合、直ちに管理者に通知しなければならない。
Where the U.S. processor engages another processor (“sub-processor”) to carry out specific processing activities on behalf of the EEA controller, the processor must ensure that the requirements under Section II.3.B DPF are fulfilled. This includes ensuring that the subprocessor provides the same level of protection of personal data as required in the DPF and the same data protection obligations as set out in the data processing agreement. Where a sub-processor fails to fulfil its data protection obligations, the initial U.S. processor shall remain fully liable to the controller for the performance of that sub-processor's obligations.  米国における処理者が、EEA域内の管理者(コントローラー)に代わって特定の処理活動を実施するため別の処理者(「サブ処理者」)を起用する場合、処理者はセクションII.3.B DPFの要件が満たされることを確保しなければならない。これには、サブプロセッサーがDPFで要求されるのと同等の個人データ保護水準を提供し、データ処理契約に定められたのと同等のデータ保護義務を負うことを確保することが含まれる。サブプロセッサーがデータ保護義務を履行しない場合、最初の米国プロセッサーは当該サブプロセッサーの義務履行についてデータ管理者に全責任を負い続ける。
4 Where can I find guidance regarding the certification of U.S. subsidiary companies of European businesses?  4 欧州企業の米国子会社の認証に関するガイダンスはどこで入手できるか?
U.S. subsidiaries of EEA businesses can self-certify to the DPF if they are subject to the jurisdiction of the FTC or the U.S. Department of Transportation DoT.  EEA企業の米国子会社は、FTCまたは米国運輸省(DoT)の管轄下にある場合、DPFへの自己認証が可能である。
You can find more information on the eligibility requirements here,[15] and a guide to the selfcertification process here.[16]  適格要件の詳細はこちら[15]、自己認証プロセスのガイドはこちら[16]を参照のこと。

 

[1] In this context, “European businesses” refers to businesses in the EEA, which transfer or may transfer personal data to companies in the U.S. certified under the DPF. この文脈における「欧州企業」とは、EEA域内の企業を指す。これらの企業は、DPF(データ保護枠組み)に基づき認証を受けた米国企業へ個人データを移転する、または移転する可能性がある。

[2] “Organisations” and “companies” are used indistinctively in this context.   本文脈では「組織」と「企業」は区別なく使用される

[3] https://www.dataprivacyframework.gov/program-articles/Participation-Requirements-Data-Privacy-Framework-(DPF)-Principles  

[4] The decision on the adequacy of the Data Privacy Framework was adopted by the European Commission on July 10, 2023. It was designed by the European Commission and the U.S. Department of Commerce to replace the Privacy Shield Decision (EU) 2016/1250 which was declared invalid by the European Court of Justice on 16 July 2020, in Case C-311/18, Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems (Schrems II)データ・プライバシー枠組みの十分性認定は、2023年7月10日に欧州委員会によって採択された。これは欧州委員会と米国商務省が共同で設計したもので、2020年7月16日に欧州司法裁判所が事件C-311/18(データ保護コミッショナー対フェイスブック・アイルランド社及びマクシミリアン・シュレムス事件、通称シュレムスII判決)において無効と判断したプライバシーシールド決定(EU)2016/1250に代わるものである

[5] https://ec.europa.eu/commission/presscorner/detail/en/qanda_23_3752  

[6] https://www.dataprivacyframework.gov/s/ 

[7] https://commission.europa.eu/system/files/2023-07/Adequacy%20decision%20EU-US%20Data%20Privacy%20Framework_en.pdf  

[8] Note that not all DPF self-certifications cover HR Data. It is therefore important to check whether this is the case, if relevant. See also Q3. すべてのDPF自己認証が人事データをカバーするわけではないことに注意せよ。したがって、該当する場合はこれを確認することが重要である。Q3も参照

[9] See Annex I to the adequacy decision, EU-U.S. Data Privacy Framework Principles issued by the U.S. Department of Commerce, para. I.2. 十分性認定の附属書I、米国商務省発行の「EU-米国データ・プライバシー枠組み原則」第I.2項を参照

[10] See definition of HR Data in Q1.

[11] The U.S. Department of Commerce, in collaboration with the European Commission, is preparing specific guidance regarding HR Data, on which the EDPB had the opportunity to share its views.  米国商務省は欧州委員会と連携し、人事データに関する具体的なガイダンスを準備中である。欧州データ保護委員会(EDPB)はこれについて意見を表明する機会を得た

[12]  https://www.dataprivacyframework.gov/list

[13] https://www.dataprivacyframework.gov/program-articles/How-to-Verify-an-Organization-s-Privacy-Data-Privacy-Framework(DPF)-Commitments  

[14] https://www.dataprivacyframework.gov/program-articles/Contract-Requirements-for-Data-Transfers-to-a-Processor  

[15] https://www.dataprivacyframework.gov/program-articles/U-S-Subsidiaries-of-European-Businesses-Participation-in-the-DataPrivacy-Framework-(DPF)-Program  

[16] https://www.dataprivacyframework.gov/program-articles/How-to-Join-the-Data-Privacy-Framework-(DPF)-Program(part%E2%80%931)  

 


 

まるちゃんの情報セキュリティ気まぐれ日記

・2024.11.10 欧州 EDPB 米国の十分性認定についての1年後のレビュー結果

・2024.07.20 欧州 EDPB EU-USデータプライバシー枠組みに関するFAQ(欧州企業向け、欧州個人向け)

・2023.07.11 欧州委員会 安全で信頼できるEUと米国のデータフローに関する新たな十分性認定を採択

・2023.03.02 EDPB EU-米国データ・プライバシー・フレームワークにおける改善を歓迎するが、いいたいことは54ページ分ほどある(^^)

・2023.01.20 EDPB 公共部門によるクラウドサービス利用のためのプライバシーに関する勧告を決定、クッキー バナータスクフォースの報告書を採択

・2022.12.16 欧州委員会 米国との安全なデータの流れを確保するための適切な決定の採択に向けたプロセスを開始

 

|

« 米国 CISA 耐量子暗号標準を利用する技術向け製品カテゴリー (2026.01.23) | Main | 欧州 EDPB EDPS 欧州委員会の「AIに関するデジタルオムニバス」提案に関する共同意見書 »

Comments

Post a comment



(Not displayed with comment.)


Comments are moderated, and will not appear on this weblog until the author has approved them.



« 米国 CISA 耐量子暗号標準を利用する技術向け製品カテゴリー (2026.01.23) | Main | 欧州 EDPB EDPS 欧州委員会の「AIに関するデジタルオムニバス」提案に関する共同意見書 »