欧州 EDPB 2025年次報告書 実践における明確性:ガイダンスと対話を通じたステークホルダーへの支援 (2026.04.09)
こんにちは、丸山満彦です。
EDPBの2025年の年次報告書です...
● EDPB
プレス...
・2026.04.09 EDPB annual report 2025: supporting stakeholders through guidance and dialogue
| EDPB annual report 2025: supporting stakeholders through guidance and dialogue | 欧州データ保護会議年次報告書2025:ガイダンスと対話を通じてステークホルダーを支援 |
| Brussels, 09 April - The European Data Protection Board (EDPB) has published its 2025 Annual Report. The report provides an overview of the EDPB work carried out in 2025 and reflects on important milestones, such as the adoption of the Helsinki Statement on Enhanced Clarity, Support, and Engagement. | ブリュッセル、4月9日 ― 欧州データ保護会議(EDPB)は、2025年次報告書を公表した。本報告書は、2025年にEDPBが実施した活動の概要を示し、「明確性、支援、関与の強化に関するヘルシンキ声明」の採択など、重要な節目について振り返っている。 |
| “In 2025, we saw the data protection landscape change significantly. The rapid expansion of the EU’s digital regulatory framework has added complexity to the data protection ecosystem. To help organisations navigate this complexity and support compliance, the EDPB focused on enhancing legal certainty, making compliance more achievable in practice, and strengthening cooperation, both among Data Protection Authorities and with other regulators. | 「2025年、データ保護の情勢は大きく変化した。EUのデジタル規制枠組みの急速な拡大により、データ保護のエコシステムは複雑さを増した。組織がこの複雑さを乗り越え、コンプライアンスを遵守できるよう支援するため、EDPBは法的確実性の向上、実務におけるコンプライアンス達成の容易化、そしてデータ保護当局間および他の規制当局との協力強化に注力した。 |
| We also prioritised meaningful dialogue with stakeholders to ensure our work reflected real-world needs. | また、我々の活動が現実のニーズを反映するよう、ステークホルダーとの有意義な対話を優先した。 |
| Our achievements support economic growth while continuing to protect individuals’ fundamental rights to privacy and data protection.” | 我々の成果は、個人のプライバシーおよびデータ保護に関する基本的権利を守り続けると同時に、経済成長を支えるものである。」 |
| EDPB Chair, Anu Talus | EDPB議長、アヌ・タルス |
| The Helsinki’s statement initiatives leading the way | 先導的なヘルシンキ声明の取り組み |
| In 2025, the EDPB worked actively to address the demand for regulatory simplification to support innovation and economic growth, while ensuring the protection of individuals’ personal data. | 2025年、EDPBは、個人の個人データの保護を確保しつつ、イノベーションと経済成長を支援するための規制簡素化への要請に対応すべく、積極的に取り組んだ。 |
| With this in mind, the Board adopted the Helsinki Statement on Enhanced Clarity, Support, and Engagement, which outlines new initiatives to make GDPR compliance easier, strengthen consistency, enhance the dialogue and improve transparency with stakeholders and boost cross-regulatory cooperation. | こうした観点から、理事会は「明確化、支援、および関与の強化に関するヘルシンキ声明」を採択した。これは、GDPRへの準拠を容易にし、一貫性を強化し、ステークホルダーとの対話を深め透明性を高め、規制当局間の協力を促進するための新たな取り組みを概説するものである。 |
| For example, the Board launched a public consultation to ask organisations which templates would be most useful, organised several stakeholder events to consult organisations on upcoming guidelines and systematically published reports on stakeholder input. | 例えば、理事会は、どのテンプレートが最も有用であるかを組織に尋ねるためのパブリック・コンサルテーションを開始し、今後のガイドラインについて組織と協議するためのステークホルダー向けイベントを複数回開催し、ステークホルダーからの意見に関する報告書を体系的に公表した。 |
| Easing compliance for organisations and providing legal advice | 組織のコンプライアンス負担の軽減と法的助言の提供 |
| In the context of ongoing discussions on regulatory simplification at EU level, the EDPB actively contributed to legislative initiatives aimed at reducing administrative burden and streamlining requirements. The Board adopted a joint opinion with the European Data Protection Supervisor (EDPS) on the Commission’s Proposal for a Regulation amending certain regulations, including the GDPR. | EUレベルでの規制簡素化に関する継続的な議論の文脈において、EDPBは、行政負担の軽減と要件の合理化を目的とした立法イニシアチブに積極的に貢献した。理事会は、GDPRを含む特定の規則を改正する欧州委員会の規則案について、欧州データ保護監察機関(EDPS)との共同意見書を採択した。 |
| In addition, the Board held important discussions on this matter during plenary meetings, which subsequently informed the EPDB/EDPS joint opinions on the Commission’s proposals on the Digital Omnibus and on the Digital Omnibus on AI adopted at the beginning of 2026. | さらに、理事会は本件について総会において重要な議論を行い、その結果は、2026年初頭に採択された「デジタル・オムニバス」および「AIに関するデジタル・オムニバス」に関する欧州委員会の提案に対するEDPB/EDPS共同意見の策定に反映された。 |
| The Board also delivered five adequacy-related opinions concerning United Kingdom, Brazil and the European Patent Organisation (EPO). | また、理事会は、英国、ブラジル、および欧州特許庁(EPO)に関する5件の十分性認定に関する意見書も提出した。 |
| In addition, the Board adopted Recommendations on the legal basis for requiring the creation of user accounts on e-commerce websites, and Recommendations on the 2027 WADA World Anti-Doping Code upon request from the Commission. | さらに、理事会は、電子商取引ウェブサイトにおけるユーザーアカウント作成の義務付けに関する法的根拠についての勧告、および欧州委員会の要請に基づき、2027年版WADA世界アンチ・ドーピング規程に関する勧告を採択した。 |
| Strengthening cross-regulatory cooperation | 規制当局間の協力の強化 |
| Cross-regulatory cooperation was a key focus for the EDPB last year. The EDPB worked together with the European Commission to clarify how data protection and digital laws interact and to address legal and practical challenges in cross-sectoral cases. | 規制当局間の協力は、昨年のEDPBにとって重要な焦点であった。EDPBは欧州委員会と協力し、データ保護法とデジタル関連法がどのように相互作用するかを明確化し、分野横断的な事案における法的・実務上の課題に対処した。 |
| In 2025, the EDPB adopted its first set of joint guidelines with the Commission on the interplay between the Digital Markets Act (DMA) and the GDPR. The Board also worked with the Commission on joint guidelines on the interplay between the AI act and EU data protection laws for adoption in 2026. | 2025年、EDPBは欧州委員会との間で、デジタル市場法(DMA)とGDPRの相互関係に関する初の共同ガイドラインを採択した。また、2026年の採択に向け、AI法とEUデータ保護法の相互関係に関する共同ガイドラインについても欧州委員会と協力した。 |
| In addition, the EDPB adopted guidelines on the interplay between the Digital Services Act (DSA) and the GDPR. | さらに、EDPBはデジタルサービス法(DSA)とGDPRの相互関係に関するガイドラインを採択した。 |
| Placing stakeholders at the heart of the EDPB work | EDPBの活動の中心にステークホルダーを据える |
| In 2025, a public consultation was launched on the joint guidelines with the Commission on the DMA and the GDPR. The Board has also organised public consultations on the EDPB guidelines on DSA and GDPR, blockchain technologies, pseudonymisation and on the recommendations on the legal basis for requiring the creation of user accounts on e-commerce websites. | 2025年、DMAとGDPRに関する欧州委員会との共同ガイドラインについて、パブリック・コンサルテーションが開始された。また、EDPBは、DSAとGDPR、ブロックチェーン技術、仮名化、および電子商取引ウェブサイトにおけるユーザーアカウント作成を義務付ける法的根拠に関する勧告についてのEDPBガイドラインについても、パブリック・コンサルテーションを実施した。 |
| In addition, in line with the Helsinki statement’s objectives to make GDPR compliance easier, the EDPB organised a public consultation to understand which templates organisations consider would be most useful for them (e.g. privacy notice template, record of processing activities template, etc.). | さらに、GDPRの遵守を容易にするというヘルシンキ声明の目的に沿い、EDPBは、組織にとって最も有用と考えられるテンプレート(例:プライバシー通知テンプレート、処理活動記録テンプレートなど)を把握するためのパブリック・コンサルテーションを実施した。 |
| n December 2025, a stakeholder event on anonymisation and pseudonymisation took place, which was followed by a report on the input collected during the event. | 2025年12月、匿名化および仮名化に関するステークホルダー・イベントが開催され、その後、イベント中に収集された意見に関する報告書が作成された。 |
| Promoting high standards of data protection worldwide | 世界的なデータ保護の高水準の促進 |
| In line with its Strategy 2024-2027, the EDPB continued to engage with the international community to promote a high level of data protection and to ensure effective protection of personal data beyond EU borders. To this end, the Board participated in international fora such as the G7 Data Protection Authorities Roundtable and the Global Privacy Assembly. | EDPBは「戦略2024-2027」に沿い、高い水準のデータ保護を促進し、EU域外においても個人データの効果的な保護を確保するため、国際社会との連携を継続した。この目的のため、理事会はG7データ保護当局円卓会議やグローバル・プライバシー・アセンブリなどの国際フォーラムに参加した。 |
| In December 2025, the EDPB also held online the second meeting with Commissioners and representatives of Data Protection Authorities (DPAs) from the countries and the organisation with an EU adequacy decision. | 2025年12月、EDPBはまた、EUの十分性認定を受けている国および組織の委員およびデータ保護当局(DPA)の代表者との第2回会合をオンラインで開催した。 |
| Providing guidance and ensuring consistency | ガイダンスの提供と一貫性の確保 |
| In 2025, three new set of guidelines focusing on pseudonymisation, blockchains technologies and on the DSA and the GDPR, and guidelines following public consultation on data transfers to third country authorities were adopted. | 2025年には、擬似匿名化、ブロックチェーン技術、およびDSAとGDPRに焦点を当てた3つの新たなガイドラインセット、ならびに第三国当局へのデータ移転に関するパブリック・コンサルテーションを経て策定されたガイドラインが採択された。 |
| 29 Art. 64(1) GDPR opinions were adopted, reflecting the Board’s continued commitment to promoting harmonisation. | GDPR第64条第1項に基づく29件の意見書が採択され、調和の促進に向けた委員会の継続的な取り組みが反映された。 |
| Supporting consistent and effective enforcement | 一貫性のある効果的な執行の支援 |
| Strengthening cooperation among DPAs was another key priority in 2025. This took place through multiple instruments aimed at facilitating joint actions and knowledge-sharing, including the Coordinated Enforcement Framework (CEF), the Support Pool of Experts (SPE) and dedicated taskforces. | 2025年におけるもう一つの重要な優先事項は、データ保護当局(DPA)間の協力強化であった。これは、協調的執行枠組み(CEF)、専門家支援プール(SPE)、および専門タスクフォースなど、共同行動や知識共有を促進することを目的とした複数の手段を通じて行われた。 |
| The Board contributed to improving cross-border cooperation, supporting DPAs in handling complex cases and ensuring alignment in enforcement practices. In 2025, 414 cross-border cases were created in the EDPB’s case register, and 1299 procedures related to the One-Stop-Shop (Art. 60 GDPR) were triggered, out of which 572 let to final decisions. | 理事会は、国境を越えた協力の改善、複雑な事案への対応におけるDPAへの支援、および執行実務の整合性の確保に貢献した。2025年には、EDPBの案件登録簿に414件の越境案件が登録され、ワンストップショップ(GDPR第60条)に関連する1299件の手続きが開始され、そのうち572件が最終決定に至った。 |
| Finally, at national level DPAs issued a total of €1,15 bn worth in fines. | 最後に、各国レベルでは、データ保護当局(DPA)が合計11億5000万ユーロ相当の罰金を科した。 |
・[PDF] Exective Summary
| Clarity in action: Supporting stakeholders through guidance and dialogue | 実践における明確性:ガイダンスと対話を通じたステークホルダーへの支援 |
| Executive Summary | エグゼクティブサマリー |
| Highlights 2025 | 2025年のハイライト |
| JANUARY: Guidelines on pseudonymisation | 1月:擬似匿名化に関するガイドライン |
| JANUARY: CEF 2024 report on right of access | 1月:アクセス権に関するCEF 2024報告書 |
| MARCH: Launch CEF 2025 on the right to erasure | 3月:消去権に関するCEF 2025の立ち上げ |
| APRIL: Guidelines on blockchain | 4月:ブロックチェーンに関するガイドライン |
| MAY: Opinion on the Commission’s draft adequacy decision regarding the European Patent Organisation (EPO) | 5月:欧州特許機構(EPO)に関する欧州委員会の十分性認定ドラフトに対する意見書 (EPO) |
| JULY: Joint Opinion on the draft Regulation on simplification measures for SMEs including the record-keeping obligation | 7月:記録保持義務を含む中小企業向け簡素化措置に関するドラフト規則案についての共同意見書 |
| JULY: Helsinki statement | 7月:ヘルシンキ声明 |
| SEPTEMBER: Guidelines on interplay DSA - GDPR | 9月:DSAとGDPRの相互関係に関するガイドライン |
| OCTOBER: Joint Guidelines on interplay DMA – GDPR | 10月:DMAとGDPRの相互関係に関する共同ガイドライン |
| OCTOBER: Opinion on draft UK adequacy decisions | 10月:英国の十分性認定決定案に関する意見書 |
| NOVEMBER: Opinion on draft Brazil adequacy decision | 11月:ブラジルの十分性認定決定案に関する意見書 |
| DECEMBER: Stakeholder event on anonymisation and pseudonymisation | 12月:匿名化および仮名化に関するステークホルダー向けイベント |
| DECEMBER: Recommendations on the creation of user accounts on e-commerce websites | 12月:電子商取引ウェブサイトにおけるユーザーアカウント作成に関する勧告 |
| DECEMBER: Election Deputy Chair | 12月:副議長の選出 |
| In 2025, the European Data Protection Board (EDPB) operated in a rapidly evolving digital landscape, shaped by the expansion of the EU’s digital regulatory framework and by swift technological developments, particularly in artificial intelligence. This environment reinforced the need for clear, consistent and practical guidance by the EDPB. Against this backdrop, the Board focused on enhancing legal certainty, simplifying compliance, and strengthening cooperation, both among Data Protection Authorities (DPAs) and with other regulators. | 2025年、欧州データ保護会議(EDPB)は、EUのデジタル規制枠組みの拡大および、特に人工知能(AI)分野における急速な技術的進展によって形作られる、急速に進化するデジタル環境の中で活動した。こうした環境下で、EDPBによる明確かつ一貫性のある実践的なガイダンスの必要性が一層高まった。こうした背景を受け、委員会は法的確実性の向上、コンプライアンスの簡素化、そしてデータ保護当局(DPA)間および他の規制当局との協力強化に注力した。 |
| The adoption of the Helsinki Statement marked a key milestone, setting a new direction for a more accessible, transparent and collaborative approach to data protection. As a result, the Board developed practical tools such as templates and FAQs. In addition, it improved stakeholder consultation processes by organising stakeholder events such as the December 2025 event on anonymisation and pseudonymisation, and by systematically publishing reports on stakeholder input. | 「ヘルシンキ声明」の採択は重要な節目となり、データ保護に対するよりアクセスしやすく、透明性が高く、協調的なアプローチに向けた新たな方向性を示した。その結果、委員会はテンプレートやFAQなどの実用的なツールを開発した。さらに、2025年12月の匿名化および仮名化に関するイベントなどのステークホルダー向けイベントを主催し、ステークホルダーからの意見に関する報告書を体系的に公表することで、ステークホルダーとの協議プロセスを改善した。 |
| Another central priority was on clarifying the interplay between the GDPR and other digital legislations, ensuring that innovation and the protection of fundamental rights progress hand in hand. Notably, Guidelines on the interplay with Digital Services Act (DSA) were adopted, Joint Guidelines on the interplay between the Digital Markets Act (DMA) and the GDPR were endorsed, and work also progressed on the interplay between the GDPR and the AI Act. | もう一つの中心的な優先事項は、GDPRと他のデジタル関連法規との相互関係を明確化し、イノベーションと基本権の保護が両立するよう確保することだった。特に、デジタルサービス法(DSA)との相互関係に関するガイドラインが採択され、デジタル市場法(DMA)とGDPRの相互関係に関する共同ガイドラインが承認されたほか、GDPRとAI法との相互関係に関する作業も進展した。 |
| The EDPB contributed to legislative developments, by delivering five adequacy-related opinions, alongside one joint EDPB-EDPS opinion on legislative simplification proposals. It participated to the debate on the Digital Omnibus. Furthermore, it continued to support harmonisation across Europe by issuing 29 consistency opinions under Art. 64(1) GDPR. | EDPBは、5件の十分性認定に関する意見書に加え、立法の簡素化提案に関するEDPB・EDPS共同意見書を提出することで、立法動向に貢献した。また、「デジタル・オムニバス」に関する議論にも参加した。さらに、第64条に基づき29件の一貫性意見書を発出することで、欧州全域における調和の促進を継続した (1)に基づき29件の一貫性意見書を公表することで、欧州全域における調和を支援し続けた。 |
| The Board promoted high standards of data protection worldwide by participating in international fora such as the G7 Data Protection Authorities Roundtable and the Global Privacy Assembly, and through 31 international speaking engagements by the Chair and Deputy Chairs. | 理事会は、G7データ保護当局円卓会議やグローバル・プライバシー・アセンブリなどの国際フォーラムへの参加、および議長と副議長による31件の国際講演を通じて、世界的なデータ保護の高水準を推進した。 |
| Supporting consistent and effective enforcement of the GDPR also remained a key priority. | GDPRの一貫した効果的な執行を支援することも、引き続き重要な優先事項であった。 |
| The EDPB strengthened cooperation among DPAs through multiple instruments, including the Coordinated Enforcement Framework (CEF), the Support Pool of Experts (SPE) and dedicated taskforces, facilitating joint actions and knowledge-sharing. It contributed to improving cross-border cooperation, supporting DPAs in handling complex cases and ensuring alignment in enforcement practices. In 2025, 414 crossborder cases were created in the EDPB’s case register, and 1299 procedures related to the One-Stop-Shop (Art. 60 GDPR) were triggered, out of which 572 led to Final Decisions. | EDPBは、調整された執行枠組み(CEF)、専門家支援プール(SPE)、および専門タスクフォースを含む複数の手段を通じて、データ保護当局(DPA)間の協力を強化し、共同行動や知識共有を促進した。また、国境を越えた協力の改善に寄与し、DPAが複雑な案件を処理することを支援し、執行実務の整合性を確保した。2025年には、EDPBの案件登録簿に414件の越境案件が登録され、ワンストップショップ(GDPR第60条)に関連する1299件の手続きが開始され、そのうち572件が最終決定に至った。 |
| The EDPB Secretariat | EDPB事務局 |
| The EDPB Secretariat played a central role in all of the Board’s activities by providing legal and technical expertise alongside administrative and logistical support. | EDPB事務局は、法的・技術的専門知識に加え、行政的・物流的支援を提供することで、理事会のあらゆる活動において中心的な役割を果たした。 |
| It led the drafting of 21 opinions and contributed to a further eight opinions, while also supporting the adoption of three new guidelines, as well as one guideline following public consultation. It contributed to efforts to make GDPR information more accessible to a wider, non-technical audience, by publishing summaries of key guidelines for non-expert audiences that make EDPB guidance more user-friendly and accessible. | 同事務局は21件の意見書の起草を主導し、さらに8件の意見書作成に貢献するとともに、3件の新規ガイドラインおよびパブリック・コンサルテーションを経た1件のガイドラインの採択を支援した。また、EDPBのガイダンスをより使いやすく、アクセスしやすいものにするため、専門家以外の読者向けに主要なガイドラインの要約を公表し、より幅広い非技術的な読者層がGDPR情報をより利用しやすくするための取り組みに貢献した。 |
| It played a role in enforcement-related activities, and led the litigation activities, with the EDPB involved in 15 cases before the Court of Justice of the European Union. | 執行関連活動においても役割を果たし、訴訟活動を主導した。EDPBは欧州連合司法裁判所における15件の訴訟に関与した。 |
| The Secretariat also ensured the smooth functioning of cooperation among Data Protection Authorities (DPAs), notably through the provision and management of IT systems and operational tools. | 事務局はまた、特にITシステムや運用ツールの提供・管理を通じて、データ保護当局(DPA)間の協力が円滑に行われるよう確保した。 |
| Operationally, the Secretariat organised over 500 meetings throughout the year and handled a significant rise in technical support requests. In particular, it processed over 10.000 inquiries across EDPB IT systems, including more than 800 support requests related to the Internal Market Information (IMI) system, thereby ensuring efficient communication and cooperation among DPAs. | 運営面では、事務局は年間を通じて500回以上の会議を主催し、技術支援要請の大幅な増加に対応した。特に、EDPBのITシステムを通じて1万件を超える問い合わせを処理し、そのうち内部市場情報(IMI)システムに関連するサポート要請は800件以上に上り、これによりデータ保護当局(DPA)間の効率的なコミュニケーションと協力を確保した。 |
・[PDF]
目次...
| Foreword | まえがき |
| Highlights | ハイライト |
| 1. The EDPB Secretariat | 1. EDPB事務局 |
| 1.1 Mission And Activities | 1.1 使命と活動 |
| 2. European Data Protection Board – Activities in 2025 | 2. 欧州データ保護会議 – 2025年の活動 |
| 2.1 Bridging Fundamental Rights and Digital Innovation Through GDPR Compliance | 2.1 GDPR遵守を通じた基本権とデジタルイノベーションの架け橋 |
| 2.1.1 Helsinki high-level meeting: enhanced clarity, support and engagement | 2.1.1 ヘルシンキハイレベル会合:明確性の向上、支援、および関与の強化 |
| 2.1.2 Regulation on procedural rules and Omnibus regulation on the record of processing | 2.1.2 手続規則に関する規則および処理記録に関するオムニバス規則 |
| 2.1.3 Cross regulatory cooperation | 2.1.3 規制当局間の協力 |
| 2.1.4 The EDPB in a global context | 2.1.4 グローバルな文脈におけるEDPB |
| 2.2 Ensuring Consistent Protection | 2.2 一貫した保護の確保 |
| 2.2.1 Guidance and Recommendations | 2.2.1 ガイダンスおよび勧告 |
| 2.2.2 Consistency Opinions | 2.2.2 一貫性に関する意見 |
| 2.2.3 Legislative Consultation | 2.2.3 立法協議 |
| 2.2.4 Stakeholder Consultation | 2.2.4 ステークホルダーとの協議 |
| 3. Supporting Enforcement | 3. 執行の支援 |
| 3.1 EDPB Activities To Support GDPR Enforcement And Cooperation Among DPAs | 3.1 GDPRの執行およびデータ保護当局(DPA)間の協力を支援するためのEDPBの活動 |
| 3.1.1 Coordinated Enforcement Framework | 3.1.1 調整された執行枠組み |
| 3.1.2 Support Pool of Experts | 3.1.2 専門家支援プール |
| 3.1.3 Taskforces | 3.1.3 タスクフォース |
| 3.2 Litigation | 3.2 訴訟 |
| 3.3 Cooperation Under The GDPR | 3.3 GDPRに基づく協力 |
| 3.4 Binding Decisions | 3.4 拘束力のある決定 |
| 3.5 National Cases With Exercise Of Corrective Powers | 3.5 是正権限の行使を伴う国内事例 |
| 3.6 Selection Of National Cases | 3.6 国内事例の選定 |
| 3.6.1 Austria | 3.6.1 オーストリア |
| 3.6.2. Belgium | 3.6.2 ベルギー |
| 3.6.3. Bulgaria | 3.6.3 ブルガリア |
| 3.6.4. Croatia | 3.6.4 クロアチア |
| 3.6.5. Cyprus | 3.6.5 キプロス |
| 3.6.6. Czech Republic | 3.6.6. チェコ共和国 |
| 3.6.7. Denmark | 3.6.7. デンマーク |
| 3.6.8. Estonia | 3.6.8. エストニア |
| 3.6.9. Finland | 3.6.9. フィンランド |
| 3.6.10. France | 3.6.10. フランス |
| 3.6.11. Germany (DPA Berlin) | 3.6.11. ドイツ(ベルリンデータ保護局) |
| 3.6.12. Germany (DPA Hamburg) | 3.6.12. ドイツ(ハンブルクデータ保護局) |
| 3.6.13. Germany (Federal DPA) | 3.6.13. ドイツ(連邦データ保護局) |
| 3.6.14. Greece | 3.6.14. ギリシャ |
| 3.6.15. Hungary | 3.6.15. ハンガリー |
| 3.6.16. Iceland | 3.6.16. アイスランド |
| 3.6.17. Ireland | 3.6.17. アイルランド |
| 3.6.18. Italy | 3.6.18. イタリア |
| 3.6.19. Latvia | 3.6.19. ラトビア |
| 3.6.20. Liechtenstein | 3.6.20. リヒテンシュタイン |
| 3.6.21. Lithuania | 3.6.21. リトアニア |
| 3.6.22. Luxembourg | 3.6.22. ルクセンブルク |
| 3.6.23. Malta | 3.6.23. マルタ |
| 3.6.24. Netherlands | 3.6.24. オランダ |
| 3.6.25. Norway | 3.6.25. ノルウェー |
| 3.6.26. Portugal | 3.6.26. ポルトガル |
| 3.6.27. Romania | 3.6.27. ルーマニア |
| 3.6.28. Slovakia | 3.6.28. スロバキア |
| 3.6.29. Slovenia | 3.6.29. スロベニア |
| 3.6.30. Spain | 3.6.30. スペイン |
| 3.6.31. Sweden | 3.6.31. スウェーデン |
| 4. Annexes | 4. 附属書 |
| 4.1 General guidance and recommendations | 4.1 一般的な指針および勧告 |
| 4.2 Consistency opinions | 4.2 一貫性に関する意見 |
| 4.3 Legislative consultation | 4.3 立法協議 |
| 4.4 Other documents | 4.4 その他の文書 |
2.2 一貫した保護の確保
| 2.2 Ensuring Consistent Protection | 2.2 一貫した保護の確保 |
| Jekaterina Macuka, | エカテリーナ・マツカ、 |
| Director of the Data State | ラトビア |
| Inspectorate of Latvia | データ保護監督局局長 |
| Effective data protection is not only about individual cases, but about solutions that protect many people at once. As an independent guardian of fundamental rights, the EDPB brings authorities together to find a balanced “golden middle” - ensuring that data protection is not seen as an obstacle to technology, but as a foundation for trust, responsible innovation and a shared European digital future. | 効果的なデータ保護とは、個別の事例だけでなく、多くの人々を同時に防御する解決策のことである。基本権の独立した守護者としてのEDPBは、各当局を結びつけ、バランスの取れた「黄金の中道」を見出す。これにより、データ保護が技術の障害と見なされるのではなく、信頼、責任あるイノベーション、そして共有される欧州のデジタル未来の基盤として位置づけられることを確保する。 |
| 2.2.1 Guidance and Recommendations | 2.2.1 ガイダンスと勧告 |
| One of the EDPB’s core competences is to clarify the GDPR by issuing guidance. Since 2018, the EDPB established a well-defined and comprehensive repository of guidelines and recommendations. This ensures that DPAs apply data protection laws consistently and it further strengthens stakeholder compliance. The EDPB continues to build and expand its guidance and makes a consistent effort to incorporate stakeholder input, which is collected via public consultation. | EDPBの中核的な役割の一つは、ガイダンスを発行することでGDPRを明確化することである。2018年以来、EDPBは明確かつ包括的なガイドラインおよび勧告のレポジトリを確立してきた。これにより、データ保護当局(DPA)がデータ保護法を一貫して適用することが保証され、ステークホルダーのコンプライアンスがさらに強化される。EDPBは引き続きガイダンスの構築と拡充を進めており、パブリック・コンサルテーションを通じて収集されたステークホルダーの意見を反映させるよう一貫して取り組んでいる。 |
| In 2025, the EDPB adopted three new guidelines, as well as one guideline following public consultation, and two set of recommendations. In addition, the EDPB and the Commission endorsed one set of joint guidelines (see Annexes, Section 4.1 for the complete list of guidelines and recommendations). | 2025年、EDPBは3つの新たなガイドライン、パブリック・コンサルテーションを経て採択された1つのガイドライン、および2つの勧告を採択した。さらに、EDPBと欧州委員会は1つの共同ガイドラインを承認した(ガイドラインおよび勧告の完全なリストについては、附属書第4.1節を参照)。 |
| 2.2.1.1 Guidelines 1/2025 on Pseudonymisation | 2.2.1.1 仮名化に関するガイドライン1/2025 |
| On 16 January 2025, the EDPB adopted Guidelines on Pseudonymisation. These guidelines explain the definition and the role of pseudonymisation, as a safeguard that may be appropriate and effective to meet data protection obligations. More specifically, the guidelines explain that pseudonymisation can help organisations meet their obligations relating to the implementation of data protection principles, data protection by design and default, and security. The guidelines analyse technical measures and safeguards, when using pseudonymisation, to ensure confidentiality and prevent unauthorised identification of individuals. These guidelines were submitted to a written public consultation, and they are complemented by a summary. Moreover, the EDPB organised a stakeholder event on this topic on 12 December 2025 (more information in Section 2.2.5.3). | 2025年1月16日、EDPBは仮名化に関するガイドラインを採択した。本ガイドラインは、データ保護義務を履行するために適切かつ有効な保護措置としての仮名化の定義と役割を説明している。より具体的には、本ガイドラインは、仮名化が、データ保護原則、設計およびデフォルトによるデータ保護、ならびにセキュリティの実施に関連する義務を組織が履行する上で役立つことを説明している。本ガイドラインは、機密性を確保し、個人の不正な特定を防止するために、仮名化を利用する際の技術的措置および保護措置を分析している。本ガイドラインは書面による公開協議にかけられ、要約が添付されている。さらに、EDPBは2025年12月12日にこのテーマに関するステークホルダー向けイベントを開催した(詳細はセクション2.2.5.3を参照)。 |
| 2.2.1.2 Guidelines 02/2025 on processing of personal data through blockchain technologies | 2.2.1.2 ブロックチェーン技術を用いたパーソナルデータの処理に関するガイドライン02/2025 |
| The EDPB adopted these guidelines on 8 April 2025 and submitted them for a written public consultation, on the basis of which the final version will be produced. A blockchain is a distributed digital ledger system that can confirm transactions and establish who owned a digital asset (such as cryptocurrency) at a given time. Blockchains can also support the secure handling and transfer of data, ensuring its integrity and traceability. | EDPBは2025年4月8日に本ガイドラインを採択し、書面によるパブリック・コンサルテーションに付した。これに基づき最終版が作成される予定である。ブロックチェーンとは、取引を確認し、特定の時点におけるデジタル資産(暗号資産など)の所有者を特定できる分散型デジタル台帳システムである。また、ブロックチェーンはデータの安全な取り扱いと転送を支援し、その完全性と追跡可能性を確保することができる。 |
| As the use of blockchain technologies is expanding, the EDPB guidelines are addressed to organisations who plan to make use of blockchain technologies. They outline the key elements to consider to ensure compliance with several provisions of the GDPR. They assess the different possible architectures and their implications for the processing of personal data. | ブロックチェーン技術の利用が拡大する中、EDPBのガイドラインは、ブロックチェーン技術の利用を計画している組織を対象としている。本ガイドラインは、GDPRのいくつかの規定への準拠を確保するために考慮すべき主要な要素を概説している。また、考えられる様々なアーキテクチャと、それらがパーソナルデータの処理に及ぼす影響を評価している。 |
| The guidelines highlight the importance of implementing technical and organisational measures at the earliest stages of the design of the processing. They clarify the roles and responsibilities of the different actors in a blockchain. The guidelines provide examples of different techniques for data minimisation, as well as for handling and storing personal data. As a general rule, storing personal data in a blockchain should be avoided if this conflicts with data protection principles. | 本ガイドラインは、処理の設計の初期段階において、技術的および組織的措置を実施することの重要性を強調している。また、ブロックチェーンにおける各関係者の役割と責任を明確にしている。さらに、データ最小化の手法や、個人データの取り扱い・保存に関する事例も提示している。原則として、データ保護の原則に抵触する場合は、ブロックチェーンへの個人データの保存を避けるべきである。 |
| Finally, the Board highlights key elements on guaranteeing the rights granted to individuals by the GDPR in the context of blockchain technologies, especially transparency, rectification and erasure of personal data. A summary on these guidelines is also available here. | 最後に、委員会は、ブロックチェーン技術の文脈において、GDPRによって個人に付与された権利、特に透明性、個人データの訂正および消去を保証するための重要な要素を強調している。本ガイドラインの概要もこちらから入手可能である。 |
| 2.2.1.3 Guidelines 3/2025 on the interplay between the DSA and the GDPR | 2.2.1.3 DSAとGDPRの相互関係に関するガイドライン3/2025 |
| The EDPB adopted these guidelines on 11 September 2025 and submitted them for public consultation, following which a final version will be produced. These guidelines are the first adopted by the EDPB addressing the interaction between the GDPR and the EU’s digital legislation. They aim to ensure a consistent and coherent interpretation and application of the Digital Services Act (DSA) and the GDPR where DSA obligations involve the processing of personal data by online intermediary service providers, including online platforms and search engines. | EDPBは2025年9月11日に本ガイドラインを採択し、パブリック・コンサルテーションに付した。その後、最終版が作成される予定である。本ガイドラインは、GDPRとEUのデジタル関連法規との相互関係を取り上げたEDPBによる初のガイドラインである。これらは、オンラインプラットフォームや検索エンジンを含むオンライン仲介サービスプロバイダによる個人データの処理がDSAの義務に含まれる場合において、デジタルサービス法(DSA)とGDPRの一貫性のある解釈および適用を確保することを目的としている。 |
| The guidelines analyse the interplay with the GDPR of certain provisions of the DSA concerning the processing of personal data by intermediary service providers. In particular, the guidelines clarify how GDPR principles, concepts and safeguards apply in the context of DSA provisions relating to notice-and-action mechanisms for reporting illegal content, recommender systems, transparency of advertising, deceptive design patterns and measures to ensure a high level of privacy, safety and security for minors, including the prohibition of profile-based advertising directed at them. They also address the prohibition of profiling-based advertising using special categories of personal data. In addition, the guidelines also underline the importance of cooperation and mutual consultation between Digital Services Coordinators, the European Commission and DPAs, with a view to enhancing coordinated enforcement, legal certainty for service providers, and the effective protection of individuals’ fundamental rights and freedoms. An EDPB factsheet summarising these guidelines is available here. | 本ガイドラインは、仲介プロバイダによる個人データの処理に関するDSAの特定の規定とGDPRとの相互関係を分析している。特に、違法コンテンツの通報に関する通知・対応メカニズム、レコメンデーションシステム、広告の透明性、欺瞞的なデザインパターン、および未成年者のプライバシー、 未成年者に対するプロファイルに基づく広告の禁止を含む。また、特別な種類の個人データを用いたプロファイリングに基づく広告の禁止についても言及している。さらに、本ガイドラインは、調整された執行の強化、プロバイダに対する法的確実性、および個人の基本的権利と自由の効果的な保護を図るため、デジタルサービス調整官、欧州委員会、およびデータ保護当局(DPA)間の協力と相互協議の重要性を強調している。これらのガイドラインを要約したEDPBのファクトシートは、こちらから入手できる。 |
| 2.2.1.4 Guidelines 02/2024 on Article 48 GDPR | 2.2.1.4 GDPR第48条に関するガイドライン02/2024 |
| Following public consultation, the EDPB adopted on 4 June 2025 the final version of Guidelines 02/2024 on data transfers to third country authorities. In its guidelines, the EDPB zooms in on Art. 48 GDPR and clarifies how organisations can best assess under which conditions they can lawfully respond to requests for a transfer of personal data from third country authorities (i.e. authorities from non-European countries). | パブリック・コンサルテーションを経て、EDPBは2025年6月4日、第三国当局へのデータ移転に関するガイドライン02/2024の最終版を採択した。本ガイドラインにおいて、EDPBはGDPR第48条に焦点を当て、組織がどのような条件下で第三国当局(すなわち、欧州以外の国の当局)からの個人データ移転要請に合法的に対応できるかを、いかにして最善の方法でアセスメントできるかを明確にしている 。 |
| The EDPB explained that judgements or decisions from third country authorities cannot automatically be recognised or enforced in Europe. As a general rule, an international agreement may provide for both a legal basis and a ground for transfer. In exceptional circumstances, other legal bases or other grounds for transfer could be considered on a case-by-case basis. | EDPBは、第三国当局による判決や決定が、欧州において自動的に承認または執行されるわけではないと説明した。原則として、国際協定が法的根拠および移転の根拠の両方を規定している場合がある。例外的な状況においては、その他の法的根拠や移転の根拠が、ケースバイケースで検討される可能性がある。 |
| The modifications introduced in the updated guidelines aim to provide further clarifications on elements brought up during the consultation. For example, the updated guidelines address the situation where the recipient of a request is a processor. They also address the situation where a subsidiary in Europe is asked to answer a request received by the mother company in a third country from that third country authority. | 改訂されたガイドラインに導入された変更点は、意見募集の過程で提起された要素について、さらなる明確化を図ることを目的としている。例えば、改訂されたガイドラインでは、要請の取得者が処理者である場合について扱っている。また、欧州にある子会社が、第三国の親会社が当該第三国の当局から受領した要請に応答するよう求められた場合についても扱っている。 |
| 2.2.1.5 Joint guidelines on the interplay between the Digital Markets Act (DMA) and the GDPR | 2.2.1.5 デジタル市場法(DMA)とGDPRの相互関係に関する共同ガイドライン |
| The EDPB and the European Commission endorsed these joint guidelines on 9 October 2025 and submitted them for public consultation, after which a final version will be produced. These are the first guidelines jointly prepared by the EDPB and the Commission and are intended to facilitate a coherent and consistent application of the DMA and the GDPR, in line with the EDPB’s 2024–2027 Strategy and the objectives of the Helsinki Statement. The guidelines aim to increase legal certainty for gatekeepers, business users, beneficiaries and individuals, while simplifying compliance with EU digital and data protection rules. | EDPBと欧州委員会は、2025年10月9日にこれらの共同ガイドラインを承認し、パブリック・コンサルテーションに付した。その後、最終版が作成される予定である。これはEDPBと欧州委員会が共同で作成した初のガイドラインであり、EDPBの2024~2027年戦略およびヘルシンキ声明の目標に沿って、DMAとGDPRの一貫した適用を促進することを目的としている。本ガイドラインは、ゲートキーパー、ビジネスユーザー、受益者、および個人に対する法的確実性を高めつつ、EUのデジタルおよびデータ保護規則への準拠を簡素化することを目指している。 |
| The guidelines clarify how GDPR principles, concepts and safeguards apply in the context of DMA obligations that entail the processing of personal data by gatekeepers. In particular, they explain how gatekeepers can implement DMA provisions that explicitly refer to GDPR concepts, such as the requirements for specific choice and valid consent under Art. 5(2) DMA, in order to lawfully combine or cross-use personal data across core platform services. The guidance also addresses other relevant DMA obligations, including those related to the distribution of third-party apps | 本ガイドラインは、ゲートキーパーによるパーソナルデータの処理を伴うDMAの義務の文脈において、GDPRの原則、概念、および保護措置がどのように適用されるかを明確にしている。特に、中核的なプラットフォームサービス間で個人データを合法的に結合または横断的に利用するために、DMA第5条(2)に基づく具体的な選択や有効な同意の要件など、GDPRの概念を明示的に参照するDMAの規定を、ゲートキーパーがどのように実施できるかを説明している。また、本ガイダンスでは、サードパーティ製アプリの配信 |
| and app stores, data portability, access to data, and the interoperability of messaging services. | やアプリストア、データポータビリティ、データへのアクセス、メッセージングサービスの相互運用性など、その他の関連するDMAの義務についても言及している。 |
| The guidelines also emphasise the complementary objectives of the DMA and the GDPR in the digital environment, with the GDPR focusing on the protection of individuals’ rights and personal data, and the DMA aiming to ensure fairness and contestability in digital markets. | また、本ガイダンスは、デジタル環境におけるDMAとGDPRの補完的な目的を強調している。すなわち、GDPRは個人の権利と個人データの保護に焦点を当て、DMAはデジタル市場における公正性と競争可能性の確保を目的としている。 |
| By clarifying common touchpoints between the two legal frameworks, the joint guidance supports a consistent, effective and complementary application of EU digital and data protection law. | 両法枠組みの共通点を明確化することで、この共同ガイダンスは、EUのデジタル法およびデータ保護法の一貫性があり、効果的かつ補完的な適用を支援するものである。 |
| The guidelines were subject to a joint public consultation, which closed on 4 December 2025, providing stakeholders with the opportunity to submit comments and feedback. The final text, incorporating input received during the consultation, will be prepared jointly by the EDPB and the European Commission and adopted by both institutions. | 本ガイドラインは共同のパブリック・コンサルテーションの対象となり、2025年12月4日に締め切られた。これにより、利害関係者は意見やフィードバックを提出する機会が与えられた。コンサルテーションで寄せられた意見を反映した最終案は、EDPBと欧州委員会が共同で作成し、両機構によって採択される予定である。 |
| 2.2.1.6 Interplay GDPR – AI Act | 2.2.1.6 GDPRとAI法の相互関係 |
| Further joint work is ongoing with the European Commission, including with the AI Office, on guidelines addressing the interplay between the AI Act and EU data protection laws, with the aim of maintaining coherent and consistent safeguards for the protection of personal data. | 個人データの保護に向けた首尾一貫したセーフガードを維持することを目的として、AI法とEUデータ保護法との相互関係に関するガイドラインについて、欧州委員会(AIオフィス含む)との間でさらなる共同作業が進行中である。 |
| 2.2.1.7 Recommendations 1/2025 on the 2027 WADA World Anti-Doping Code | 2.2.1.7 2027年版WADA世界アンチ・ドーピング規程に関する勧告1/2025 |
| On 11 February 2025, upon request from the European Commission, the EDPB adopted its Recommendations on the 2027 WADA World Anti-Doping Code, assessing the compatibility of the Code and its complementing International Standard for Data Protection (ISDP) with the GDPR. The EDPB underlined the need for Member States to ensure that national anti-doping measures, adopted in order to transpose the Code, are in line with the GDPR. | 2025年2月11日、欧州委員会の要請を受け、EDPBは2027年版WADA世界アンチ・ドーピング規程に関する勧告を採択し、同規程およびそれを補完する国際データ保護標準(ISDP)がGDPRと適合しているかについてアセスメントを行った。EDPBは、加盟国に対し、同コードを国内法に組み込むために採択される国内のアンチ・ドーピング措置が、GDPRに準拠していることを確保する必要性を強調した。 |
| The EDPB welcomed certain positive changes brought since its previous letter of 2019, but raised concerns about some other elements, mainly concerning consent, purpose limitation, and attribution of roles. | EDPBは、2019年の前回の書簡以降にもたらされた一定の肯定的な変更を歓迎したが、主に同意、利用目的の限定、および役割の帰属に関する他のいくつかの要素について懸念を表明した。 |
| 2.2.1.8 Recommendations 2/2025 on the legal basis for requiring user account creation on e-commerce websites | 2.2.1.8 電子商取引ウェブサイトにおけるユーザーアカウント作成の義務付けに関する法的根拠についての勧告2/2025 |
| On 4 December 2025, the EDPB adopted Recommendations on the legal basis for requiring the creation of user accounts on e-commerce websites, and submitted them to public consultation. These recommendations aim to clarify under which conditions e-commerce websites may require users to create an account. | 2025年12月4日、EDPBは電子商取引ウェブサイトにおけるユーザーアカウント作成の義務付けに関する法的根拠についての勧告を採択し、パブリック・コンサルテーションに付した。これらの勧告は、電子商取引ウェブサイトがユーザーにアカウント作成を義務付けることができる条件を明確にすることを目的としている。 |
| The EDPB underlined that, as a general rule, users should be able to make purchases on e-commerce websites without being required to create an account. In this regard, the Board recommended that e-commerce websites offer alternatives such as a “guest” mode or the voluntary creation of an account, in line with the principles of data protection by design and by default and with the objective of minimising the processing of personal data. At the same time, the EDPB acknowledged that mandatory account creation may be justified in a limited number of situations, for example in the context of subscriptionbased services or access to exclusive offers. | EDPBは、原則として、ユーザーはアカウント作成を求められずに電子商取引サイトで購入できるべきであると強調した。この点に関して、委員会は、データ保護を設計段階およびデフォルトで組み込むという原則に沿い、パーソナルデータの処理を最小限に抑えるという目的のもと、電子商取引サイトが「ゲスト」モードや任意のアカウント作成といった代替手段を提供することを推奨した。同時に、EDPBは、サブスクリプション型サービスや限定オファーへのアクセスといった、限られた状況においては、アカウント作成の義務付けが正当化され得ることを認めた。 |
| Overall, the recommendations reflect the EDPB’s commitment to promoting pragmatic, user-friendly and privacy-protective practices in the e-commerce sector. | 全体として、これらの勧告は、電子商取引分野において、実用的かつユーザーフレンドリーで、プライバシーを保護する慣行を推進するというEDPBの取り組みを反映している。 |
| 2.2.2 Consistency Opinions | 2.2.2 一貫性に関する意見 |
| Consistency opinions are a driving force of the EDPB’s mission to ensure the uniform interpretation and application of the GDPR across the EU. Established under Art. 64 GDPR, these opinions provide authoritative, non-binding recommendations that align DPAs decisions with a common EU framework. By addressing areas of potential divergence, consistency opinions contribute to harmonised enforcement and legal clarity. | 一貫性意見は、EU全域におけるGDPRの解釈と適用を統一するというEDPBの使命を推進する原動力である。GDPR第64条に基づき策定されたこれらの意見は、データ保護当局(DPA)の決定を共通のEU枠組みに整合させる、権威ある非拘束的な勧告を提供する。潜在的な相違が生じうる分野に対処することで、一貫性意見は執行の調和と法的な明確性に寄与する。 |
| DPAs may also request a consistency opinion from the EDPB when considering measures that could impact multiple jurisdictions. Once issued, these opinions serve as guiding documents, enabling DPAs to finalise their decisions while ensuring alignment with the GDPR standards. In 2025, 29 opinions were issued under Art. 64(1) GDPR. | また、複数の管轄区域に影響を及ぼす可能性のある措置を検討する際、データ保護当局(DPA)はEDPBに整合性意見を求めることができる。一度発行されると、これらの意見は指針となる文書として機能し、データ保護当局がGDPRの標準との整合性を確保しつつ決定を確定することを可能にする。2025年には、GDPR第64条(1)に基づき29件の意見が発行された。 |
| 2.2.2.1 Art. 64(1) GDPR Opinions | 2.2.2.1 GDPR第64条(1)に基づく意見 |
| Art. 64(1) GDPR mandates the issuance of consistency opinions for specific measures that DPAs intend to adopt. These opinions are pivotal in ensuring the uniform application of the GDPR provisions and fostering regulatory coherence across countries. The six categories of measures requiring consistency opinions under Art. 64(1) GDPR include: | GDPR第64条(1)は、データ保護当局が採択しようとする特定の措置について、整合性意見の発行を義務付けている。これらの意見は、GDPR規定の統一的な適用を確保し、各国間の規制の整合性を促進する上で極めて重要である。GDPR第 64(1)に基づき整合性意見が求められる措置の6つのカテゴリーには、以下が含まれる: |
| ` Lists of processing operations requiring and not requiring Data Protection Impact Assessments (DPIAs): these lists identify activities that are likely to pose significant risks to individuals’ rights and freedoms, and kinds of processing operations for which no DPIA is required; | ` データ保護影響アセスメント(DPIA)を必要とする処理業務および必要としない処理業務のリスト:これらのリストは、個人の権利と自由に重大なリスクをもたらす可能性のある活動、およびDPIAが不要な処理業務の種類を特定するものである; |
| ` Draft codes of conduct: tailored to specific sectors or processing activities, these codes facilitate compliance by providing industry-specific guidance while ensuring alignment with the GDPR principles; | ` 行動規範のドラフト:特定のセクターや処理活動に合わせて作成されたこれらの規範は、業界固有のガイダンスを提供することでコンプライアンスを促進すると同時に、GDPRの原則との整合性を確保するものである; |
| ` Accreditation of certification bodies, of criteria for certification bodies, and schemes: these criteria establish the standards for certification, promoting trust and accountability in data protection; | ` 認証団体、認証規準、およびスキームの認定:これらの規準は認証の基準を確立し、データ保護における信頼と説明責任を促進する; |
| ` Draft decisions on standard contractual clauses (SCC) for international data transfers: these clauses provide legally robust mechanisms for transferring personal data outside the EU, ensuring continuity in data protection; | ` 国際的なデータ移転のための標準契約条項(SCC)に関するドラフト決定:これらの条項は、EU域外への個人データ移転のための法的に堅固な仕組みを提供し、データ保護の継続性を確保する; |
| ` Authorisations for custom contractual clauses: bespoke clauses tailored to specific circumstances, requiring the EDPB review to ensure compliance with the GDPR requirements; | ` カスタム契約条項の承認:特定の状況に合わせて作成された特注の条項であり、GDPRの要件への準拠を確保するためにEDPBによる審査が必要である; |
| ` Approvals of Binding Corporate Rules (BCRs): these rules govern intra-group data transfers within multinational organisations, ensuring consistent application of the GDPR principles across jurisdictions. | ` 拘束的企業規則(BCR)の承認:これらの規則は多国籍組織内でのグループ内データ移転を規律し、管轄区域をまたいでGDPRの原則が一貫して適用されることを確保する。 |
| In 2025, the EDPB adopted 29 Art. 64(1) GDPR opinions, reflecting its continued commitment to promoting harmonisation. Since its establishment in 2018, the EDPB has issued a total of 217 Art. 64(1) opinions, demonstrating the sustained importance of this mechanism in supporting a harmonised application of the GDPR. (See Annexes, Section 4.2 for the complete list of opinions adopted in 2025). | 2025年、EDPBは29件の第 64(1)に基づく意見書29件を採択し、調和の促進に向けた継続的な取り組みを示した。2018年の設立以来、EDPBは合計217件の第64条(1)に基づく意見書を発出しており、これはGDPRの調和のとれた適用を支援する上で、このメカニズムが持続的に重要であることを示している。(2025年に採択された意見書の完全なリストについては、附属書第4.2節を参照のこと)。 |
| 2.2.3 Legislative Consultation | 2.2.3 立法に関する協議 |
| In the context of legislative consultations requested by the European Commission, the EDPB adopts opinions on issues pertaining to data protection in the EU. Opinions may be adopted solely by the EDPB or jointly with the EDPS. The EDPB may also advise the Commission on the assessment of the adequacy of the level of protection in a third country. | 欧州委員会から要請された立法に関する協議において、EDPBはEUにおけるデータ保護に関連する問題について意見を採用する。意見はEDPB単独で、あるいはEDPSと共同で採用されることがある。EDPBはまた、第三国における保護水準のアセスメントについて、欧州委員会に助言を行うこともある。 |
| Adequacy decisions, which are negotiated by the European Commission, are a key instrument of the GDPR for data transfers and require the EDPB’s consultation. | 欧州委員会が交渉を行う十分性認定は、データ移転に関するGDPRの重要な手段であり、EDPBへの諮問を要する。 |
| In 2025, the EDPB provided 5 opinions on the adequate level of protection of personal data in third countries and in an international organisation. | 2025年、EDPBは第三国および国際機関における個人データの適切な保護水準について5件の意見書を提出した。 |
| 2.2.3.1 Opinion 06/2025 regarding the extension of the European Commission Implementing Decisions under the GDPR and the LED on the adequate protection of personal data in the United Kingdom | 2.2.3.1 英国における個人データの適切な保護に関するGDPRおよびLEDに基づく欧州委員会の実施決定の延長に関する意見書06/2025 |
| The EDPB opinion addressed the proposed extension of the two UK adequacy decisions (under the GDPR and the LED), which were set to expire on 27 June 2025. The opinion only concerned the proposed 6-month extension of these adequacy decisions and did not address the level of protection of personal data afforded in the UK. The EDPB recognised the need for a technical and time-limited extension up to 27 December 2025, so as to provide the European Commission with sufficient time to evaluate the updated UK legal framework. The EDPB stressed that this extension was exceptional and due to the ongoing legislative developments in the UK. | EDPBの意見は、2025年6月27日に失効予定であった英国に関する2つの十分性認定(GDPRおよびLEDに基づく)の延長案について言及したものである。この意見は、これらの十分性認定の6ヶ月間の延長案のみを対象としており、英国における個人データの保護水準については言及していない。EDPBは、欧州委員会が更新された英国の法的枠組みを評価するための十分な時間を確保できるよう、2025年12月27日までの技術的かつ期限付きの延長が必要であると認めた。EDPBは、この延長が例外的な措置であり、英国における継続的な法整備の進展によるものであることを強調した。 |
| 2.2.3.2 Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation (EPO) | 2.2.3.2 欧州特許庁(EPO)による個人データの適切な保護に関する規則(EU)2016/679に基づく欧州委員会のドラフト実施決定案に関する意見07/2025 |
| The Board adopted an opinion on the Commission’s draft adequacy decision regarding EPO. The Board positively noted that the EPO data protection framework is largely aligned with the EU data protection framework, including on data protection rights and principles. This was the first draft adequacy decision concerning an international organisation (and not a country). The successful adoption of the adequacy decision shows that the GDPR and, in particular, its transfer provisions, can facilitate safe data flows from Europe to international organisations, while taking into account their status. | 委員会は、EPOに関する欧州委員会の十分性認定案について意見書を採択した。委員会は、EPOのデータ保護枠組みが、データ保護の権利や原則を含め、EUのデータ保護枠組みと概ね整合していることを肯定的に評価した。これは、国際機関 (国家ではない)に関する初のものである。この十分性認定の採択成功は、GDPR、特にその移転規定が、国際機関の地位を考慮しつつ、欧州から国際機関への安全なデータ流通を促進し得ることを示している。 |
| 2.2.3.3 Opinion 26/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the United Kingdom | 2.2.3.3 英国による個人データの十分な保護に関する規則(EU)2016/679に基づく欧州委員会の実施決定ドラフトに関する意見26/2025 |
| This EDPB opinion addressed the Commission’s draft adequacy decision on the extension of the validity of the UK adequacy decision under the GDPR until December 2031. The EDPB positively noted the continuing alignment between the UK and EU data protection frameworks. According to the Board, most of the changes introduced to the UK’s data protection framework aim to clarify and facilitate compliance with the law. Considering the most recent legislative developments in the UK framework, the EDPB also invited the Commission to make a more detailed assessment on certain points in its decision and to monitor several aspects, such as the rules on transfers from the UK to third countries, the restructuring of the Information Commissioner’s Office, the removal of the principle of primacy of EU law in the Retained EU Law Act 2023 or the use by the UK Government of technical capability notices requiring companies to circumvent encryption. | 本EDPB意見は、GDPRに基づく英国の十分性認定の有効期間を2031年12月まで延長する欧州委員会の十分性認定ドラフトについて言及したものである。EDPBは、英国とEUのデータ保護枠組み間の継続的な整合性を肯定的に評価した。委員会によれば、英国のデータ保護枠組みに導入された変更の大部分は、法の遵守を明確化し、円滑にすることを目的としている。英国の枠組みにおける最新の立法動向を考慮し、 EDPBはまた、欧州委員会に対し、決定における特定の点についてより詳細なアセスメントを行うよう求めるとともに、英国から第三国への移転に関する規則、情報コミッショナー事務局の再編、2023年EU法維持法におけるEU法の優越性の原則の削除、あるいは英国政府による、企業に暗号化の回避を義務付ける技術的能力通知の利用といった、いくつかの側面を監視するよう要請した。 |
| 2.2.3.4 Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom | 2.2. 3.4 英国による個人データの適切な保護に関する指令(EU)2016/680に基づく欧州委員会の実施決定ドラフトに関する意見27/2025 |
| This EDPB opinion addressed the European Commission’s draft adequacy decision on the extension of the validity of the UK adequacy decision under the LED until December 2031. While welcoming the continuous alignment between the UK and EU data protection frameworks, the EDPB encouraged the Commission to complement its assessment on specific aspects of the new legal framework which may affect the level of protection for data subjects, such as the extended national security exemptions, the changes to the rules governing onward transfers of personal data to third countries and the more permissive approach and conferral of new powers to the Secretary of State in relation to automated decision-making. Finally, the EDPB reiterated the need for the Commission to closely monitor the application of corrective powers and of remedies for individuals in the UK data protection framework. | このEDPBの意見は、LEDに基づく英国の十分性認定の有効期間を2031年12月まで延長する欧州委員会の十分性認定案について言及したものである。EDPBは、英国とEUのデータ保護枠組み間の継続的な整合性を歓迎しつつも、拡大された国家安全保障上の例外、第三国への個人データの再移転を規定する規則の変更、および自動化された意思決定に関するより寛容なアプローチや国務大臣への新たな権限付与など、データ対象者の保護水準に影響を及ぼし得る新法枠組みの特定の側面について、欧州委員会がアセスメントを補完するよう促した。最後に、EDPBは、英国のデータ保護枠組みにおける是正権限の行使および個人に対する救済措置の適用について、欧州委員会が綿密に監視する必要性を改めて強調した。 |
| 2.2.3.5 Opinion 28/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by Brazil | 2.2.3.5 ブラジルによる個人データの適切な保護に関する規則(EU)2016/679に基づく欧州委員会のドラフト実施決定案に関する意見28/2025 |
| The EDPB adopted its opinion on the European Commission’s draft adequacy decision on Brazil. The EDPB positively noted that the Brazilian data protection framework establishes requirements that are closely aligned with the GDPR and the case law of the Court of Justice of the European Union, in relation, for instance, to the principles, data subject rights, transfers, oversight and redress mechanisms. Moreover, the EDPB invited the Commission to further clarify certain aspects in its decision, as well as to monitor the practical implementation and concrete impact of certain features of the Brazilian framework, such as the limitations on transparency related to commercial and industrial secrecy and the rules on onward transfers. | EDPBは、ブラジルに関する欧州委員会の十分性認定ドラフトについて意見書を採択した。EDPBは、ブラジルのデータ保護枠組みが、例えば原則、データ対象者の権利、移転、監督および救済措置に関して、GDPRおよび欧州連合司法裁判所の判例と密接に整合する要件を定めている点を肯定的に評価した。さらに、EDPBは欧州委員会に対し、決定における特定の側面をさらに明確化すること、および商業・産業上の秘密に関連する透明性の制限や第三者への転送に関する規則など、ブラジルの枠組みの特定の特徴の実務上の実施状況と具体的な影響を監視するよう求めた。 |
| In relation to access and use by Brazilian public authorities of personal data transferred to controllers and processors in Brazil for criminal law enforcement and national security purposes (‘government access’), the EDPB noted that the Gereral Data Protection Law in Brazil (LGPD) does not apply to data processing conducted for the exclusive purposes of public safety, national defence, state security, or the investigation and prosecution of criminal offenses. At the same time, the EDPB positively noted that the Federal Supreme Court of Brazil, in its case-law, has interpreted the LGPD in a way that expanded its partial applicability to the processing of personal data for criminal investigations and maintenance of public order. In light of this, the Board invited the Commission to further assess and clarify, in the draft decision, the applicability of the Brazilian data protection law in case of personal data processing for criminal law enforcement purposes. | 刑事法執行および国家安全保障の目的でブラジルのデータ管理者およびデータ処理者に移転された個人データに対するブラジル公的機関によるアクセスおよび利用(「政府によるアクセス」)に関して、EDPBは、ブラジルの一般データ保護法(LGPD)が、公共の安全、国防、国家安全保障、または刑事犯罪の捜査および起訴を唯一の目的として行われるパーソナルデータの処理には適用されないことを指摘した。同時に、EDPBは、ブラジル連邦最高裁判所が判例において、刑事捜査および公の秩序維持のためのパーソナルデータの処理に対し、LGPDの適用範囲を部分的に拡大する解釈を示していることを肯定的に評価した。これを踏まえ、同委員会は、刑事法執行を目的としたパーソナルデータの処理の場合におけるブラジルデータ保護法の適用性について、ドラフト決定においてさらにアセスメントし明確化するよう欧州委員会に要請した。 |
| 2.2.3.6 EDPB-EDPS Joint Opinion 01/2025 on the Proposal for a Regulation on simplification measures for SMEs and SMCs, in particular the record-keeping obligation under Art. 30(5) GDPR | 2.2.3.6 中小企業(SME)および小規模事業者(SMC)向けの簡素化措置、特にGDPR第30条第5項に基づく記録保持義務に関する規則案に関するEDPB・EDPS共同意見01/2025 |
| On 8 July 2025, the EDPB and the EDPS adopted Joint Opinion 01/2025 on the Proposal for a Regulation as regards the extension of certain mitigating measures available for small and medium sized enterprises (‘SMEs’) to small midcap enterprises (‘SMCs’) and further simplification measures. Following the adoption of this Proposal on 21 May 2025, the Commission formally consulted the EDPB and the EDPS in accordance with Art. 42(2) of Regulation (EU) 2018/1725. | 2025年7月8日、EDPBおよびEDPSは、中小企業(SME)向けに利用可能な特定の緩和措置を中小中堅企業(SMC)に拡大すること、およびさらなる簡素化措置に関する規則案について、共同意見01/2025を採択した。2025年5月21日の本案採択を受け、 欧州委員会は、規則(EU)2018/1725第42条第2項に基づき、EDPBおよびEDPSに対し正式に協議を行った。 |
| The Proposal aimed at modifying the derogation under Art. 30(5) GDPR by providing that the record-keeping obligation would not apply to an enterprise or organisation employing fewer than 750 persons unless the processing they carry out would likely to result in a high risk to data subjects’ rights and freedoms. In addition, the Proposal introduced a definition of SMEs and SMCs in Art. 4 GDPR and extended the scope of Arts. 40(1) and 42(1) GDPR to the SMCs. | 本提案は、GDPR第30条第5項に基づく特例を改正し、エンタープライズまたは組織について、その行う処理がデータ対象者の権利および自由に対して高いリスクをもたらすおそれがある場合を除き、記録保持義務を適用しないことを規定することを目的としていた。さらに、本提案はGDPR第4条にSMEおよびSMCの定義を導入し、 共同意見書は、この目的の追求が個人データ保護という基本的権利の保護水準を低下させることにならない限り、SMEおよびSMCの行政負担を軽減するという本提案の一般的な目的を支持した。この点において、共同意見書は、 |
| The joint opinion supported the general objective of the Proposal to reduce the administrative burden for SMEs and SMCs as long as pursuing this objective does not result in lowering the protection of the fundamental right to protection of personal data. In this regard, it welcomed that the proposed modifications to the GDPR were targeted and limited in nature and did not affect the core principles and other obligations under the GDPR. | 共同意見は、個人データの保護という基本的権利の保護水準を低下させることにならなければ、中小企業および小規模事業者に対する行政負担を軽減するという本提案の一般的な目的を支持した。この点において、GDPRに対する提案された修正が的を絞った限定的なものであり、GDPRに基づく中核的な原則やその他の義務に影響を及ぼさないことを歓迎した。 |
| The EDPB and the EDPS welcomed the clarification and simplification efforts concerning the conditions in which the derogation under Art. 30(5) GDPR would apply by providing that this derogation would not apply to processing ‘likely to result in a high risk’. In this regard, they highlighted that the processing of personal data covered under Arts. 9 and 10 GDPR is important to assess whether the processing is likely to result in a high risk. They suggested some improvements to the Proposal. | EDPBおよびEDPSは、GDPR第30条(5)に基づく適用除外が「高いリスクをもたらす可能性が高い」処理には適用されないことを規定することで、当該適用除外の適用条件に関する明確化および簡素化の取り組みを歓迎した。この点に関して、両機関は、処理が高いリスクをもたらす可能性が高いかどうかを評価する上で、GDPR第9条および第10条の対象となるパーソナルデータの処理が重要であることを強調した。両機関は、提案書に対しいくつかの改善点を提示した。 |
| The EDPB and the EDPS noted that enterprises and organisations exempted from keeping a record of processing activities would have the flexibility to choose the most appropriate methods to ensure and demonstrate compliance. However, they would also need to ensure that those methods adequately support compliance with the GDPR and do not negatively impact the rights of data subjects. | EDPBおよびEDPSは、処理活動の記録保持が免除されたエンタープライズや組織は、コンプライアンスを確保し証明するために最も適切な方法を選択する柔軟性を持つと指摘した。ただし、それらの方法がGDPRへの準拠を適切に支援し、データ対象者の権利に悪影響を及ぼさないことも確保する必要がある。 |
| 2.2.4 Stakeholder Consultation | 2.2.4 ステークホルダーとの協議 |
| 2.2.4.1 Public consultation | 2.2.4.1 パブリック・コンサルテーション |
| Following the preliminary adoption of guidelines, the EDPB organises public consultations to give stakeholders and citizens the opportunity to provide additional input. The EDPB considers this input before adopting the guidelines in their final version. Feedback on the value of the guidance and general work of the EDPB is appreciated as it provides useful insights into the needs of stakeholders. To increase transparency, the stakeholders’ contributions to public consultations are published by the EDPB on its website. | ガイドラインの暫定採択後、EDPBはステークホルダーや市民が追加の意見を提出する機会を提供するため、パブリック・コンサルテーションを実施する。EDPBは、ガイドラインの最終版を採択する前に、この意見を検討する。ガイダンスの有用性やEDPBの活動全般に関するフィードバックは、ステークホルダーのニーズに関する有益な知見を提供するため、歓迎される。透明性を高めるため、パブリック・コンサルテーションへのステークホルダーからの寄稿は、EDPBのウェブサイト上で公開される。 |
| In 2025, 5 public consultations were launched on Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation, Guidelines 3/2025 on the interplay between the DSA and the GDPR, Guidelines 02/2025 on processing of personal data through blockchain technologies, Guidelines 01/2025 on Pseudonymisation and Recommendations 2/2025 on the legal basis for requiring the creation of user accounts on e-commerce websites. | 2025年には、「デジタル市場法(DMA)と一般データ保護規則(GDPR)の相互関係に関する共同ガイドライン」、DMAとGDPRの相互関係に関するガイドライン3/2025、 ブロックチェーン技術を通じたパーソナルデータの処理に関するガイドライン02/2025、仮名化に関するガイドライン01/2025、および電子商取引ウェブサイトにおけるユーザーアカウント作成の義務付けの法的根拠に関する勧告2/2025について、5件のパブリック・コンサルテーションが開始された。 |
| In addition, following the Helsinki Statement on enhanced clarity, support and engagement, the EDPB intends to develop a series of ready-to-use templates for organisations. Therefore, the EDPB organised a public consultation to understand which templates organisations consider would be most useful for them (e.g. privacy notice template, record of processing activities template, etc.). The public consultation started on 5 November 2025 and ended on 3 December 2025. | さらに、明確性、支援、および関与の強化に関するヘルシンキ声明を受け、EDPBは組織向けに一連の即利用可能なテンプレートを開発する意向である。そのため、EDPBは、組織が最も有用だと考えるテンプレート(例:プライバシー通知テンプレート、処理活動記録テンプレートなど)を把握するために、パブリック・コンサルテーションを実施した。このパブリック・コンサルテーションは2025年11月5日に開始され、2025年12月3日に終了した。 |
| 2.2.4.2 Survey on Practical Application of Adopted Guidance | 2.2.4.2 採択されたガイダンスの実践的適用に関する調査 |
| Under Art. 71(2) GDPR, the EDPB conducted its eighth annual survey to gather feedback on the effectiveness, clarity, and accessibility of the EDPB’s guidance issued in 2025. In previous years, the survey targeted key stakeholders, including academics, legal professionals, business and industry representatives, and non-governmental organisations. | GDPR第71条(2)に基づき、EDPBは2025年に発行したガイダンスの有効性、明確性、および利用しやすさに関するフィードバックを収集するため、第8回年次調査を実施した。過去数年間、この調査は、学者、法律専門家、企業・業界の代表者、および非政府組織を含む主要な利害関係者を対象としていた。 |
| For the first time, this annual survey was addressed to Data Protection Authorities (DPAs), ensuring that a comprehensive range of European perspectives was captured. A total of 18 DPAs responded. | 今回初めて、この年次調査はデータ保護当局(DPA)を対象とし、欧州の多様な視点が網羅されるようにした。計18のDPAが回答した。 |
| The survey explored how DPAs publish EDPB guidelines, whether directly for national use or through national adaptations, as well as which recently issued guidelines and opinions were translated into their national languages in 2025. The survey also examined the channels used to make these materials available and collected feedback on which aspects of the EDPB’s work and documents were found most and least helpful. | 本調査では、DPAがEDPBのガイドラインをどのように公表しているか(国内での直接利用のためか、あるいは国内向けに改訂した形か)、また2025年にどの最近発行されたガイドラインや意見書が各国の言語に翻訳されたかについて探った。さらに、これらの資料を公開するために使用されているチャネルを検証し、EDPBの活動や文書のうち、どの側面が最も有用であり、どの側面が最も有用でないと見なされているかについてのフィードバックを収集した。 |
| While most respondents indicated that their DPA publish the EDPB guidelines directly for national use without modification, several respondents reported complementing this approach by also issuing national guidelines based on the EDPB ones. Only a limited number of DPAs indicated that they rely exclusively on national guidelines derived from the EDPB guidelines. | 回答者の大半は、自国のデータ保護当局がEDPBのガイドラインを修正せずにそのまま国内向けに公表していると回答したが、数名の回答者は、EDPBのガイドラインに基づいた国内ガイドラインも併せて発行することで、このアプローチを補完していると報告した。EDPBのガイドラインから派生した国内ガイドラインのみに依存していると回答したデータ保護当局はごく少数であった。 |
| Overall, the responses reflect a broad engagement by DPAs in making the most recent EDPB guidelines accessible in their languages. | 全体として、回答からは、データ保護当局が最新のEDPBガイドラインを自国語で利用可能にするために幅広く取り組んでいることがうかがえる。 |
| Most respondents reported having translated several EDPB guidelines adopted in 2025 into their national language(s)). Others reported focusing primarily on the translation of guidance issued prior to 2025. | 回答者の大半は、2025年に採択された複数のEDPBガイドラインを自国語に翻訳したと報告した。その他は、主に2025年以前に発行されたガイダンスの翻訳に注力していると報告した。 |
| Concerning the guidance adopted in 2025, the EDPB Guidelines 02/2024 on Article 48 GDPR (final versions adopted after public consultation), the Guidelines 3/2025 on the interplay between the Digital Services Act (DSA) and the GDPR, and the Joint Guidelines by the EDPB and the European Commission on the Interplay between the Digital Markets Act (DMA) and the GDPR, were the guidelines most frequently cited as having been translated in 2025. | 2025年に採択されたガイダンスに関しては、GDPR第48条に関するEDPBガイドライン02/2024(パブリック・コンサルテーションを経て採択された最終版)、 デジタルサービス法(DSA)とGDPRの相互関係に関するガイドライン3/2025、およびデジタル市場法(DMA)とGDPRの相互関係に関するEDPBと欧州委員会の共同ガイドラインが、2025年に翻訳されたものとして最も頻繁に挙げられた。 |
| Several DPAs also reported publishing Guidelines 02/2025 on processing of personal data through blockchain technologies and Guidelines 01/2025 on Pseudonymisation into their national languages. | また、いくつかのデータ保護当局は、ブロックチェーン技術を通じたパーソナルデータの処理に関するガイドライン02/2025および仮名化に関するガイドライン01/2025を自国の言語で公開したと報告した。 |
| Half of the respondents reported using their website as the primary channel to make EDPB guidelines accessible to their audience. Among the other half, most indicated that, in addition to their website, they make use of social media platforms to provide links directing users to the EDPB website. | 回答者の半数は、EDPBのガイドラインを一般に公開するための主要な手段として自局のウェブサイトを利用していると報告した。 残りの半数については、その大半が、自機関のウェブサイトに加え、ソーシャルメディアプラットフォームを活用して、ユーザーをEDPBのウェブサイトへ誘導するリンクを提供していると回答した。 |
| Data Protection Authorities were also consulted on the publication of the most recent EDPB opinions into their national languages in 2025. Among the documents mentioned by some DPAs are Opinion 07/2025 regarding the European Commission Draft | また、2025年にEDPBの最新の意見書を各国の言語で公表することについても、データ保護当局に意見が求められた。一部のデータ保護当局が言及した文書には、欧州委員会によるドラフト |
| Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation and EDPB/EDPS Joint Opinion 01/2025 on the Proposal for a Regulation introducing simplification measures for SMEs and micro-enterprises, in particular the exemption from record keeping obligations under Article 30 (5) GDPR. | 実施決定に関する意見07/2025や、中小企業および零細企業向けの簡素化措置、特にGDPR第30条(5)に基づく記録保持義務の免除を導入する規則案に関するEDPB/EDPS共同意見01/2025などが挙げられた。 |
| DPAs that do not publish translations of the EDPB opinions still take steps to ensure these documents are visible and accessible in various ways. These measures include promoting them through their social media channels with links to the EDPB website, translating EDPB press releases that convey the main messages of the adopted opinion along with a link to the EDPB website, drafting brief summaries with direct links to the corresponding EDPB pages, and including translations of relevant sections to ensure clarity and accessibility for national stakeholders. | EDPBの意見書の翻訳を公表していないデータ保護当局(DPA)も、これらの文書が様々な方法で閲覧・利用可能となるよう措置を講じている。これらの措置には、EDPBウェブサイトへのリンクを掲載したソーシャルメディアチャンネルを通じた周知、採択された意見書の主要なメッセージを伝えるEDPBプレスリリースの翻訳とEDPBウェブサイトへのリンクの掲載、対応するEDPBページへの直接リンクを伴う簡潔な要約の作成、 国内の利害関係者のための明確性とアクセシビリティを確保するために、関連箇所の翻訳を含めることなどが挙げられる。 |
| All respondents regard the work of the EDPB and its guidance as highly valuable and useful for their activities. DPAs emphasized the usefulness of the EDPB work in ensuring harmonisation, consistency and clarity and reducing fragmented interpretations of the law, particularly by focusing on the interplay between data protection and digital laws. More specifically, several DPAs referred to the work on pseudonymisation and anonymisation, the interplay between the DSA and the GDPR, and the DMA and the GDPR, the Recommendations on the legal basis for requiring the creation of user accounts on e-commerce websites, and all the projects developed within the framework of the Support Pool of Experts (SPE) programme. | すべての回答者は、EDPBの活動とそのガイダンスを、自らの活動にとって極めて価値があり有用であると見なしている。データ保護当局は、特にデータ保護法とデジタル法の相互作用に焦点を当てることで、調和、一貫性、明確性を確保し、法の解釈の断片化を軽減する上で、EDPBの活動が有用であることを強調した。より具体的には、複数のデータ保護当局が、擬似匿名化および匿名化に関する取り組み、DSAとGDPR、ならびにDMAとGDPRの相互関係、電子商取引ウェブサイトにおけるユーザーアカウント作成を要求するための法的根拠に関する勧告、および専門家支援プール(SPE)プログラムの枠組み内で開発されたすべてのプロジェクトに言及した。 |
| The efforts based on the Helsinki statement on enhanced clarity, support and engagement, including making GDPR compliance easier, strengthening dialogue with stakeholders, providing more accessible and ready-to-use guidance (such as templates, checklists, and FAQs), and aligning national and EDPB guidance, was positively received. One respondent also highlighted the creation of summaries to explain the EDPB guidance to nonexperts in a clearer way as a positive aspect. | 明確性の向上、支援、および関与に関するヘルシンキ声明に基づく取り組み、すなわち、GDPR準拠の容易化、利害関係者との対話の強化、よりアクセスしやすくすぐに使えるガイダンス(テンプレート、チェックリスト、FAQなど)の提供、および各国とEDPBのガイダンスの整合化は、好意的に受け止められた。ある回答者はまた、EDPBのガイダンスを専門家以外の人々にもより明確に説明するための要約の作成を、肯定的な側面として強調した。 |
| Finally, some respondents shared feedback on aspects that could be further improved to enhance the usefulness of the EDPB work and documents. Suggestions included providing a clearer timeframe for the outcomes of public consultations and the finalisation of documents. The EDPB is already working on the points mentioned, in line with the actions arising from the objectives outlined in the Helsinki statement. | 最後に、一部の回答者からは、EDPBの活動や文書の有用性を高めるためにさらに改善できる点に関するフィードバックが寄せられた。提案には、パブリック・コンサルテーションの結果や文書の最終化に向けたより明確なスケジュールの提示が含まれていた。EDPBは、ヘルシンキ声明で概説された目標から派生する行動に沿って、既にこれらの点について取り組んでいる。 |
| 2.2.4.3 Stakeholder Events | 2.2.4.3 ステークホルダー向けイベント |
| Stakeholder events are pivotal in fostering dialogue and knowledge exchange on emerging issues in data protection. These events not only strengthen the EDPB’s understanding of stakeholder concerns but also provide a platform for diverse voices to shape the regulatory landscape. | ステークホルダー向けイベントは、データ保護における新たな課題に関する対話と知識の交換を促進する上で極めて重要である。これらのイベントは、EDPBがステークホルダーの懸念を理解する上で役立つだけでなく、多様な声が規制の枠組みを形成するための場を提供するものである。 |
| In December 2025 the Board organised a stakeholder event on anonymisation and pseudonymisation aimed at collecting input from stakeholders on implications of the CJEU’s ruling of 4 September 2025 in Case C-413/23 P – EDPS v. Single Resolution Board. | 2025年12月、理事会は匿名化および仮名化に関するステークホルダー・イベントを開催し、2025年9月4日の欧州司法裁判所(CJEU)判決(事件番号C-413/23 P – EDPS対単一破綻処理委員会)が及ぼす影響について、ステークホルダーからの意見を収集することを目的とした。 |
| Over 100 individuals representing European sector associations, organisations or NGOs and individual companies, law firms or academics took part in the event. In several breakout sessions, they debated a discussion paper listing key questions related to the CJEU’s ruling. | 欧州の業界団体、組織、NGO、および個々の企業、法律事務所、学界の代表者100名以上が本イベントに参加した。複数の分科会において、参加者は欧州司法裁判所の判決に関連する主要な質問を列挙した討議資料について議論を交わした。 |
| As part of its Helsinki commitments, the EDPB will systematically publish reports about the input received during its stakeholder events. | ヘルシンキ公約の一環として、EDPBはステークホルダー・イベントで得られた意見に関する報告書を体系的に公表する。 |
● まるちゃんの情報セキュリティ気まぐれ日記
2026年もありますが...
・2026.03.26 欧州 EDPB EDPS サイバーセキュリティ法2の提案およびNIS 2指令の改正案に関する共同意見書 (2026.03.18)
・2026.03.15 欧州 EDPB 政治広告に関するステークホルダーイベント開催予定 日本にも政治広告規制は必要?
・2026.03.10 欧州 EDPB データブローカー市場調査 (2026.03.04)
・2026.02.26 欧州 EDPB 2025年12月12日に開催された匿名化および仮名化に関するステークホルダーイベント報告書(2026.02.18)
・2026.02.22 欧州 EDPB 消去権に関する執行についての課題 (2026.02.18)
・2026.02.15 欧州 EDPB 2026-2027年度作業計画:進化するデジタル環境におけるコンプライアンスの円滑化と協力強化 (2026.02.12)
・2026.02.14 欧州 EDPB EDPS デジタルオムニバス規制案に関する共同意見書 (2026.02.11)
・2026.02.07 欧州 EDPB 国際データ保護執行協力に関する報告書 (2026.02.02)
・2026.02.01 欧州 EDPB データ保護デー2026:子どもの個人データをオンラインで安全に守る
・2026.01.29 欧州 EDPB GDPR第46条(3)(a)に基づく契約条項の認可、およびGDPR第46条(2)(d)に基づく標準契約条項の採択に関する協力手続きを定めたEDPB文書
・2026.01.27 欧州 EDPB EDPS 欧州委員会の「AIに関するデジタルオムニバス」提案に関する共同意見書
・2026.01.26 欧州 EDPB EU-米国データ・プライバシー枠組みに関するFAQ等 (2026.01.23)
・2025.11.07 欧州 EDPB ブラジル向け十分性認定ドラフト:EDPBが意見書を採択
・2025.10.23 欧州 EDPB デジタルユーロとトークンベースのオフラインモダリティ (2025.10.20)
・2025.10.22 欧州 EDPB 英国の同等性6年間延長 (2025.10.20)
・2025.10.14 欧州委員会 EDPB DMAとGPDRの相互作用に関する共同ガイドライン案
・2025.09.16 欧州 EDPB DSAとGDPRの相互関係に関するガイドライン (2025.09.12)
・2025.06.16 欧州 EDPB GDPR第48条(EU法によって認められない移転又は開示)についてのガイドライン バージョン2.0 (2025.06.04)
・2025.04.25 欧州 EDPB ブロックチェーン技術によるパーソナルデータの処理に関するガイドライン02/2025 (2025.04.14)
・2025.04.13 欧州 EDPB AIプライバシーのリスクと緩和 大規模言語モデル(LLM) (2025.04.10)
・2025.03.18 欧州 EDPB 航空会社が保管する旅客情報の取り扱いに関して(CJEU判決C-817/19を踏まえたPNR指令の実施に関する声明)(2025.03.14)
・2025.03.12 欧州 EDPB 忘れられる権利に関する協調行動 (2025.03.05)
・2025.02.13 欧州 EDPB 年齢保証 (Age Assurance) に関する声明を採択 (2025.02.11)
・2025.01.19 欧州 EDPB 意見募集 仮名化に関するガイドライン 01/2025 (2025.01.17)
・2024.12.21 欧州 EDPB AIモデルが匿名とみなされるのはどのような場合か?など、4つの質問に答える意見書を公表していますね... (2024.12.17)
以下略...
« 英国 デジタル規制協力フォーラム テーマ別イノベーション・ハブ第1弾「エージェンティックAI」の主なポイント (2026.04.10) | Main | ベルギー データ保護局「AIとデータ保護」シリーズ――人工知能がプライバシーに与える影響 (2026.04.13) »

Comments