ãã®ããŒãžã¯æ©æ¢°ç¿»èš³ãããã客æ§ã®äŸ¿å®ã®ããã«ã®ã¿æäŸããããã®ã§ãããå ã®è±èªçãšå³å¯ã«å¯Ÿå¿ããŠããªãå¯èœæ§ããããŸããèšèŒãããçšèªãæ¡ä»¶ãè¡šçŸã®æå³ã¯ãè±èªã«ãããå®çŸ©ããã³è§£éã«åŸããã®ãšããŸããè±èªçãšç¿»èš³çã®éã«çžéãççŸãããå Žåã¯ãè±èªçãåªå ãããŸãã
ããŒãžã§ã³5ã2022幎12æ30æ¥æœè¡
Cloudflare, Inc. ("Cloudflare") ãšæ¬èŠçŽã«åæããååŒçžæïŒ"ã客æ§") ã¯ãCloudflareãæäŸãããµãŒãã¹ã«é¢ããEnterprise Subscription Agreement, Self-Serve Subscription AgreementãŸãã¯ãã®ä»ã®æžé¢ãããã¯é»åå¥çŽïŒ"æ¬å¥çŽ") ãç· çµããŠããŸãã æ¬ããŒã¿åŠçè£éºãä»é²ãå«ã ïŒãDPAãïŒãæ¬å¥çŽã®äžéšãæ§æããŠããŸãã
æ¬DPAã¯ãã客æ§ãæ¬DPAã«çœ²åããæ¥ãŸãã¯åœäºè ãæ¬DPAã«å¥éåæããæ¥ïŒä»¥äžãDPAçºå¹æ¥ãïŒããæå¹ãšãªãããã®äž»é¡ã«é¢é£ãã以åã«é©çšãããæ¡ä»¶ïŒæ¬ãµãŒãã¹ã«é¢ããããŒã¿åŠçã®ä¿®æ£ãåæãè£éºãå«ãïŒã«åã£ãŠä»£ãããåªå ããããã®ãšããŸãã
ã客æ§ãã客æ§ã代衚ããŠæ¬DPAãåè«Ÿããå Žåãã客æ§ã¯ä»¥äžã®ããšãä¿èšŒãããã®ãšããŸãïŒ(a) ã客æ§ãæ¬DPAã«ææããæ³çæš©éãå®å šã«æããŠããããšã(b) æ¬DPAãèªã¿ãç解ããããšã(c) ã客æ§ã代衚ããŠãæ¬DPAã«åæããããšã ã客æ§ãææããæ³çæš©éããªãå Žåã¯ãæ¬DPAãåè«Ÿããªãã§ãã ããã
ããŒã¿åŠçæ¡ä»¶
æ¬DPAã¯ãæ¬ãµãŒãã¹ãæäŸããããã«ãCloudflareãã客æ§ã«ä»£ãã£ãŠããã»ããµãŒïŒãŸãã¯è©²åœããå Žåã¯ãµãããã»ããµãŒïŒãšããŠå人ããŒã¿ãåŠçããåœè©²å人ããŒã¿ãé©çšããŒã¿ä¿è·æ³ïŒä»¥äžã«å®çŸ©ããŸãïŒã®å¯Ÿè±¡ãšãªãå Žåã«é©çšãããŸãã
äž¡åœäºè ã¯ãé©çšãããããŒã¿ä¿è·æ³ã«åŸã£ãŠåœè©²å人ããŒã¿ãä¿è·ããããã«é©åãªä¿è·æªçœ®ãè¬ããããŠããããšã確èªããããã«ãæ¬DPAãç· çµ ããããšã«åæããŸããã åŸã£ãŠãCloudflareã¯ãã客æ§ã®ããã«ããã»ããµãŒïŒãŸãã¯è©²åœããå Žåã¯ãµãããã»ããµãŒïŒãšããŠåŠçããå人ããŒã¿ã«é¢ããŠã以äžã®èŠå®ãéµå®ããããšã«åæãããã®ãšããŸãã
1. å®çŸ©
1.1 ãã®DPAã§ã¯ã以äžã®å®çŸ©ã䜿çšããŸãïŒ
a) "é©åãªåœ" ãšã¯ã欧å·ããŒã¿ä¿è·æ³ã«åºã¥ããå人ããŒã¿ã®é©åãªä¿è·ãæäŸãããšèªããããŠããåœãŸãã¯å°åãæå³ããŸãã
b) "é¢é£äŒç€Ÿ" ãšã¯ãåœäºè ã«é¢ããŠãçŽæ¥çãŸãã¯éæ¥çã«ãåœè©²åœäºè ãæ¯é ããåœè©²åœäºè ã«æ¯é ããããŸãã¯åœè©²åœäºè ãšå ±éæ¯é äžã«ããäŒæ¥äœãæå³ããŸãïŒãã ããåœè©²æ¯é ãååšããéãã«ãããŠã®ã¿ïŒã
c) ãé©çšãããããŒã¿ä¿è·æ³ããšã¯ã欧å·ããŒã¿ä¿è·æ³ããã³ç±³åœããŒã¿ä¿è·æ³ãå«ããæ¬å¥çŽã«åºã¥ãå人ããŒã¿ã®åŠçã«é©çšããããã¹ãŠã®æ³ä»€ããããŸãã
d) ãCloudflare Groupããšã¯ãCloudflareããã³ãã®é¢é£äŒç€Ÿã®ãããããæå³ããŸãã
e) "ã³ã³ãããŒã©" å人ããŒã¿ã®åŠçã®ç®çããã³æ段ã決å®ããäºæ¥è ãæå³ããé©çšãããããŒã¿ä¿è·æ³ã«åºã¥ããŠå®çŸ©ããããã³ã³ãããŒã©ãããããžãã¹ãããŸãã¯é¡äŒŒã®çš èªãå«ã¿ãŸãã
f) ãã客æ§ã°ã«ãŒãããšã¯ãã客æ§ããã³ãã®é¢é£äŒç€Ÿãæå³ããŸãã
g) ã欧å·ããŒã¿ä¿è·æ³ããšã¯ãæ¬å¥çŽã«åºã¥ãå人ããŒã¿ã®åŠçã«é©çšããã欧å·é£åã欧å·çµæžé åããããã®å çåœãã¹ã€ã¹ããã³è±åœã®ãã¹ãŠã®æ³ä»€ïŒè©²åœããå ŽåãïŒiïŒå人ããŒã¿ã®åŠçã«é¢ããèªç¶äººã®ä¿è·ããã³åœè©²ããŒã¿ã®èªç±ç§»åã«é¢ãã欧å·è°äŒããã³çäºäŒã®èŠå2016/679ïŒäžè¬ããŒã¿ä¿è·èŠåïŒïŒthe"EU GDPR" )ãå«ãïŒ(ii) ã€ã®ãªã¹ã®æ¬§å·é£åïŒé¢è±ïŒæ³2018åã³ã€ã®ãªã¹ããŒã¿ä¿è·æ³2018ã®ç¬¬3æ¡ã«ããã€ã®ãªã¹æ³ã«ä¿åãããEU GDPRïŒã"UK GDPR" ãïŒïŒ (iii) 1992幎6æ19æ¥ã®ã¹ã€ã¹é£éŠããŒã¿ä¿è·æ³åã³ãã®å¯Ÿå¿æ¡äŸïŒãSwiss DPAãïŒïŒ(iv) EU e-ãã©ã€ãã·ãŒæ什ïŒæ什2002/58/ECïŒãããã³ (v) (i)ã(ii)ã(iii)ã(iv)ã®ããããã«åºã¥ããããã«åŸãããŸãã¯ãããšé¢é£ããŠé©çšãããããããåœå ããŒã¿ä¿è·æ³ã
h) "å人ããŒã¿" ãšã¯ãé©çšãããããŒã¿ä¿è·æ³ã«ãããŠã'å人ããŒã¿', 'å人æ å ±', ãŸã㯠'å人èå¥æ å ±' ïŒãŸãã¯é¡äŒŒã®çšèªïŒãšå®çŸ©ãããŠãããã¹ãŠã®ããŒã¿ãæå³ããŸãã
i) "åŠç", "ããŒã¿äž»äœ", åã³ "ç£ç£æ©é¢" ã¯ã欧å·ããŒã¿ä¿è·æ³ã«ãããŠä»äžãããæå³ãæãããã®ãšããŸãã
j) "Processor" ãšã¯ãã³ã³ãããŒã©ã«ä»£ãã£ãŠå人ããŒã¿ãåŠçããäºæ¥è ãæå³ããæ å ±ãåãåãäºæ¥è ããµãŒãã¹ãæäŸããç®çã§ã®ã¿å人ããŒã¿æ å ±ãä¿æã䜿çšããŸãã¯é瀺ããããšãèŠæ±ããæžé¢ã«ããå¥çŽã«åºã¥ããä»ã®äºæ¥è ãäºæ¥ç®çã®ããã«èªç¶äººã®å人æ å ±ãé瀺ããäºæ¥è ãå«ã¿ããããã»ããµããããµãŒãã¹ãããã€ããŒããŸãã¯é©çšããŒã¿ä¿è·æ³ã«åºã¥ããŠå®çŸ©ãããé¡äŒŒçšèªãå«ã¿ãŸãã
k) "ãµãŒãã¹" ã¯ãã€ã³ã¿ãŒãããããããã£ãã¢ããªã±ãŒã·ã§ã³ããã³ãããã¯ãŒã¯ã®ããã©ãŒãã³ã¹ãã»ãã¥ãªãã£ããã³å¯çšæ§ãé«ããããã«èšèšããããCloudflareãŸãã¯ãã®èªå®ããŒãããŒãæäŸãããŒã±ãã£ã³ã°ãŸãã¯è²©å£²ãããã¹ãŠã®ã¯ã©ãŠãããŒã¹ãœãªã¥ãŒã·ã§ã³ãšãäžèšã«é¢é£ããŠå©çšå¯èœãšãªããœãããŠã§ã¢ããœãããŠã§ã¢éçºãããããã³ã¢ããªã±ãŒã·ã§ã³ããã°ã©ãã³ã°ã€ã³ã¿ãŒãã§ãŒã¹ïŒ"API" ïŒãæããã®ãšããŸãã
l) "EUSCCs" ãšã¯ã欧å·è°äŒããã³çäºäŒã®èŠåïŒEUïŒ2016/679ã«åºã¥ãå人ããŒã¿ã®ç¬¬äžåœãžã®ç§»è»¢ã«é¢ããæšæºå¥çŽæ¡é ã«é¢ãã2021幎6æ4æ¥ã®æ¬§å·å§å¡äŒã®å®æœæ±ºå®2021/914ã«ä»å±ããå¥çŽ æ¡é ã®ããšããããŸãã
m) "Restricted Transfer" ãšã¯ã以äžãæå³ããïŒ(i) EU GDPRãŸãã¯ããŒã¿ä¿è·ã«é¢ããã¹ã€ã¹é£éŠæ³ãé©çšãããå Žåã欧å·å§å¡äŒãŸãã¯ã¹ã€ã¹é£éŠããŒã¿ä¿è·ã»æ å ±ã³ããã·ã§ããŒïŒè©²åœããå ŽåïŒã«ããé©åæ§å€æã®å¯Ÿè±¡ãšãªããªãã欧å·çµæžé åãŸãã¯ã¹ã€ã¹ïŒè©²åœããå ŽåïŒãã欧å·çµæžé åãŸãã¯ã¹ã€ã¹ä»¥å€ã®åœãžã®å人ããŒã¿ã®ç§»è»¢ãããã³ (ii) è±åœGDPRãé©çšãããå Žåãè±åœããŒã¿ä¿è·æ³2018ã®17Aæ¡ã«ããååæ§èŠå¶ã«åºã¥ããªãè±åœãããã®ä»ã®åœãžã®å人ããŒã¿ã®ç§»è»¢ã該åœããŸãã
n) "UK Addendum" ãšã¯ãè±åœããŒã¿ä¿è·æ³2018ã®s.119(A)ã«åºã¥ãæ å ±ã³ããã·ã§ããŒäºåæãçºè¡ããåœéããŒã¿ç§»è»¢è£éºïŒããŒãžã§ã³B1.0ïŒïŒéææŽæ°ãŸãã¯ä¿®æ£ãããïŒããããŸãã
o) ãç±³åœããŒã¿ä¿è·æ³ããšã¯ãæ¬å¥çŽã«åºã¥ãå人ããŒã¿ã®åŠçã«é©çšãããç±³åœã®ãã¹ãŠã®æ³ä»€ãæå³ããïŒaïŒ2018幎ã«ãªãã©ã«ãã¢æ¶è²»è
ãã©ã€ãã·ãŒæ³ã2020幎ã«ãªãã©ã«ãã¢ãã©ã€ãã·ãŒæš©æ³ã«ããæ¹æ£ããããã®ïŒCalïŒ Civ. Code § 1798.100 - 1798.199, 2022ïŒããã³ãã®æœè¡èŠåïŒä»¥äžãç·ç§°ããŠãCCPAãïŒãïŒbïŒããŒãžãã¢å·æ¶è²»è
ããŒã¿ä¿è·æ³ïŒçºå¹æïŒãïŒcïŒã³ãã©ãå·ãã©ã€ãã·ãŒæ³ããã³ãã®æœè¡èŠåïŒçºå¹æïŒãïŒdïŒãŠã¿å·æ¶è²»è
ãã©ã€ãã·ãŒæ³ïŒçºå¹æïŒãïŒeïŒã³ããã«ããå· SB6ãå人ããŒã¿ãã©ã€ãã·ãŒãšãªã³ã©ã€ã³ã¢ãã¿ãªã³ã°ã«é¢ããæ³åŸïŒçºå¹æïŒã
1.2 ãšã³ã㣠ã㣠"ã³ã³ãããŒã«ãº" ã¯ã以äžã®å Žåãä»ã®ãšã³ãã£ãã£ãå¶åŸ¡ããïŒ(a) ãã®äŒæ¥ã®è°æ±ºæš©ã®éåæ°ãä¿æããã(b) ãã®äŒæ¥ã®äŒå¡ãŸãã¯æ ªäž»ã§ããããã®äŒæ¥ã®åç· åœ¹äŒãŸãã¯åçã®çµå¶æ©é¢ã®éåæ°ã解任ããæš©å©ãæããã(c) ãã®äŒæ¥ã®äŒå¡ãŸãã¯æ ªäž»ã§ãããåç¬ãŸãã¯ä»ã®æ ªäž»ãŸãã¯äŒå¡ãšã®åæã«åºã¥ããŠããã®äŒæ¥ã®è°æ±ºæš©ã®éåæ°ãæ¯é
ããŠããïŒãŸãã2ã€ã®äºæ¥äœã¯ãã©ã¡ãããä»æ¹ãïŒçŽæ¥ãŸãã¯éæ¥çã«ïŒæ¯é
ããŠããå Žåããããã¯äž¡è
ãåãäºæ¥äœã«ïŒçŽæ¥ãŸãã¯éæ¥çã«ïŒæ¯é
ãããŠããå Žåããå
±éæ¯é
ãã«ãããã®ãšããŠæ±ãããŸãã
1.3 æ¬ DPA ã«ãããŠãæ¬ãµãŒãã¹ããæäŸããããŸãã¯ãæäŸããããšã¯ãæ¬å¥çŽã«å®çŸ©ãããæ¬ãµãŒãã¹ãæäŸããããšãæå³ããŸãïŒ
2. åœäºè ã®ç¶æ³
2.1 æ¬DPAã«åŸã£ãŠåŠçãããå人ããŒã¿ã®çš®é¡ãããã³åŠçã®äž»é¡ãæéãæ§è³ªãç®çãããŒã¿äž»äœã®ã«ããŽãªãŒã¯ãä»å±æž1ã«èšèŒãããŠãããšããã§ãã
2.2 ååœäºè ã¯ãå人ããŒã¿ã«é¢é£ããŠãé©çšãããããŒã¿ä¿è·æ³ãèŠæ±ããã®ãšåã¬ãã«ã®ãã©ã€ãã·ãŒä¿è·ãéµå®ãæäŸããããšãä¿èšŒããŸãã åœäºè éã«ãããŠãå人ããŒã¿ã®æ£ç¢ºæ§ãå質ãé©æ³æ§ãããã³ã客æ§ãå人ããŒã¿ãååŸããæ段ã«ã€ããŠã¯ãã客æ§ãå¯äžã®è²¬ä»»ãè² ããã®ãšããŸãã
2.3 å人ããŒã¿ã«é¢ããæ¬DPAã«åºã¥ãåœäºè ã®æš©å©ããã³çŸ©åã«é¢ããŠãåœäºè ã¯ãã客æ§ãã³ã³ãããŒã©ãŒïŒãŸãã¯ç¬¬äžè ã®ã³ã³ãããŒã©ãŒã«ä»£ãã£ãŠå人ããŒã¿ãåŠçããããã»ããµãŒïŒã§ãããCloudflareãããã»ããµãŒïŒãŸãã¯å Žåã«ãããµãããã»ããµãŒïŒã§ããããšãèªããåæãããã®ãšããŸãã
2.4 ã客æ§ãåŠçè ã§ããå Žåãã客æ§ã¯ãã¯ã©ãŠããã¬ã¢ãå¥ã®åŠçè ãšããŠä»»åœããããšãããã³è©²åœããå Žåã¯EU SCCïŒäžèšç¬¬6.2æ¡ïŒbïŒããã³ïŒcïŒã§ä¿®æ£ãããå Žåãå«ãïŒã®ç· çµãå«ãå人ããŒã¿ã«é¢ããã客æ§ã®æ瀺ããã³è¡åããé¢é£ãã第äžè ã®ç®¡çè ã«ãã£ãŠæ¿èªãããŠããïŒããã³æ¬DPAã®æéäžã¯ãåŒãç¶ãæ¿èªããïŒããšãã¯ã©ãŠããã¬ã¢ã«ä¿èšŒãããã®ãšããŸãã
3. Cloudflareã®çŸ©å
3.1 Cloudflareã¯ãããã»ããµãŒãŸãã¯ãµãããã»ããµãŒãšããŠã®åœ¹å²ã«ãããŠåŠçãããã¹ãŠã®å人ããŒã¿ã«é¢ããŠã以äžã®ããšãä¿èšŒããŸãïŒ
(a) æ¬ãµãŒãã¹ãæäŸãããšããéå®çãã€ç¹å®ãããäºæ¥ç®çã®ããã«ã®ã¿ããã€ã以äžã«åŸã£ãŠå人ããŒã¿ãåŠçããããšïŒ(i) æ¬å¥çŽããã³æ¬DPAã«èŠå®ãããã客æ§ã®æžé¢ã«ããæ瀺ããã ããã¯ã©ãŠããã¬ã¢ãé©çšãããEUãŸãã¯å çåœã®æ³åŸã«ããèŠæ±ãããå Žåã¯ãã®éãã§ã¯ãªãã(ii) é©çšããŒã¿ä¿è·æ³ã®èŠä»¶ã«åŸãã ã¯ã©ãŠããã¬ã¢ãé©çšããŒã¿ä¿è·æ³ã«åºã¥ããŠå人ããŒã¿ãåŠçããå¿ èŠãããå Žåãã¯ã©ãŠããã¬ã¢ã¯ããã®æ³åŸãå ¬å ±ã®å©çã®éèŠãªçç±ã§ãã®ãããªæ å ±ãçŠæ¢ããŠããªãéããåŠçåã«ã ã®æ³çèŠä»¶ãã客æ§ã«éç¥ãããã®ãšããŸãïŒ
(b) ããŒã±ãã£ã³ã°ãŸãã¯åºåã®ç®çã§å人ããŒã¿ã䜿çšããªãããšïŒ
(c) å人ããŒã¿ã®åŠçã«ãã£ãŠãããããããªã¹ã¯ã«é©ããã»ãã¥ãªãã£ã¬ãã«ãç¹ã«å人ããŒã¿ã®å¶çºçãŸãã¯éæ³ãªç Žå£ãæ倱ãæ¹ãããäžæ£ãªé瀺ããŸãã¯ã¢ã¯ã»ã¹ã«å¯Ÿããä¿è·ã確ä¿ããããã®é©åãªæè¡çããã³çµç¹çæ段ãå®æœããããšã ãããæªçœ®ã«ã¯ãä»å±æž2ã«å®ããã»ãã¥ãªãã£å¯ŸçïŒãã»ãã¥ãªãã£å¯ŸçãïŒãå«ãŸããããããã«éå®ãããªãã ã客æ§ã¯ãã»ãã¥ãªãã£å¯Ÿçãæè¡çãªé²æ©ããã³éçºã®å¯Ÿè±¡ãšãªãããšããªãã³ã«ããããæŽæ°ããã³ä¿®æ£ãæ¬ãµãŒãã¹ã®å šäœçãªã»ãã¥ãªãã£ãäœäžãŸãã¯æžå°ãããªãããšãæ¡ä»¶ã«ãCloudflareãã»ãã¥ãªãã£å¯ŸçãéææŽæ°ãŸãã¯ä¿®æ£ããããšãããããšãèªããŸãïŒ
(d) æš©éãæããè ã®ã¿ãåœè©²å人ããŒã¿ã«ã¢ã¯ã»ã¹ã§ããããã«ããå人ããŒã¿ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããè ãå¥çŽäžãŸãã¯æ³ä»€äžã®å®ç§çŸ©åãè² ã£ãŠããããšã確èªããããšïŒ
(e) Cloudflareããã®ãµãããã»ããµãŒããŸãã¯ãã®ä»ã®ç¹å®ãããã¯æªç¹å®ã®ç¬¬äžè ããã客æ§ãžã®ãµãŒãã¹æäŸãç®çãšããŠéä¿¡ãä¿åããŸãã¯ãã®ä»ã®åŠçãè¡ã£ãå人ããŒã¿ã®å¶çºçãŸãã¯éæ³ãªç Žå£ãæ倱ãå€æŽãäžæ£ãªé瀺ããŸãã¯ã¢ã¯ã»ã¹ã«ã€ãªããã»ãã¥ãªãã£éåã«æ°ã¥ããå Žåãé床ãªé 延ãªãã客æ§ã«éç¥ããããŸãã¯ãã®ä»ã®ç¹å®ãããã¯æªç¹å®ã®ç¬¬äžè ïŒãå人ããŒã¿äŸµå®³ãïŒã«å¯ŸããŠãå人ããŒã¿ã«åœ±é¿ãåãŒãéãã«ãããŠãåœè©²å人ããŒã¿äŸµå®³ã«é¢ããŠã¯ã©ãŠããã¬ã¢ãä¿æãããã¹ãŠã®åççãªæ å ±ãå«ããåççãªååããã³æ¯æŽãã客æ§ã«æäŸããŸãïŒ
(f) é©çšãããæ³åŸã«ããèŠæ±ãããå Žåãé€ããã客æ§ã®äºåã®æžé¢ã«ããåæãªãã«ãå人ããŒã¿ã®äŸµå®³ã«é¢ããå ¬è¡šïŒãBreach NoticeãïŒãè¡ããªãããšïŒ
(g) ããŒã¿å¯Ÿè±¡è ãã客æ§ãšé¢é£ããŠããããšãCloudflareã確èªã§ããç¯å²ã«ãããŠãããŒã¿å¯Ÿè±¡è ãããã®ããŒã¿å¯Ÿè±¡è ã®å人ããŒã¿ã«é¢ããããŒã¿ä¿è·æš©ïŒã¢ã¯ã»ã¹æš©ãä¿®æ£æš©ãæ¶å»æš©ãå«ãïŒã®è¡äœ¿ãæ±ããèŠè«ïŒãããŒã¿å¯Ÿè±¡è ã®èŠè«ãïŒãåããå Žåãéããã«ã客æ§ã«éç¥ããŸãã Cloudflareã¯ãã客æ§ã®äºåã®æžé¢ã«ããåæãªãã«ãããŒã¿å¯Ÿè±¡è ã®ãªã¯ãšã¹ãã«å¿ããªããã®ãšããŸãããã ããåœè©²ãªã¯ãšã¹ããã客æ§ã«é¢ãããã®ã§ããããšã確èªããå Žåã¯ããã®éãã§ã¯ãããŸããïŒã客æ§ã¯ããã«åæãããã®ãšããŸãïŒïŒ
(h) Cloudflareãå¯èœãªç¯å²ã§ãé©çšæ³ã«æ²¿ã£ãŠã顧客ãCloudflareã®æ¯æŽãªãã«ããŒã¿å¯Ÿè±¡è ãªã¯ãšã¹ãã«å¯ŸåŠããèœåãæããªãå ŽåãããŒã¿å¯Ÿè±¡è ã®å人ããŒã¿ã«é¢ããŠé©çšããŒã¿ä¿è·æ³ã«åºã¥ãããŒã¿ä¿è·æš©ïŒã¢ã¯ã»ã¹ãä¿®æ£ãŸãã¯æ¶å»ã®æš©å©ãå«ãïŒãè¡äœ¿ããããã®ããŒã¿å¯Ÿè±¡è ãªã¯ãšã¹ãã«å¯Ÿå¿ããããã«ã顧客ã«å¯ŸããŠåççæ¯æŽãæäŸããŸãã ã客æ§ã¯ãèŠæ±è ããèŠæ±ããªãããå人ããŒã¿ã«é¢ããããŒã¿äž»äœã§ããããšã確èªãã責任ãè² ããŸãã Cloudflareã¯ãæ¬æ¬Ÿã«äŸæ ããŠã客æ§ã«åæã§æäŸãããæ å ±ã«å¯ŸããŠãäžåã®è²¬ä»»ãè² ããŸããã ã客æ§ã¯ãåœè©²æ¯æŽã®æäŸã«é¢é£ããŠCloudflareãè² æ ãããã¹ãŠã®è²»çšãè² æ ãããã®ãšããŸãïŒ
(i) é©çšæ³ä»€ãéµå®ããããã«å¿ èŠãªç¯å²ãé€ããæ¬å¥çŽã®çµäºãããã¯æºäºãŸãã¯æ¬ãµãŒãã¹ã®å®äºåŸãã客æ§ã®éžæã«ãããæ¬DPAã«åŸã£ãŠåŠçããããã¹ãŠã®å人ããŒã¿ïŒãã®åããå«ãïŒãåé€ãŸãã¯è¿åŽããããšïŒ
(j) åŠçã®æ§è³ªããã³ã¯ã©ãŠããã¬ã¢ãå©çšå¯èœãªæ å ±ãèæ ®ããé©çšãããããŒã¿ä¿è·æ³ã«åºã¥ãã¯ã©ãŠããã¬ã¢ã®çŸ©åã«é¢ããŠã顧客ãåççã«èŠæ±ããæ¯æŽã顧客ã«æäŸããããšïŒ
(i) ããŒã¿ä¿è·åœ±é¿è©äŸ¡ããã³äºååè°ïŒãããã®çšèªã¯é©çšãããããŒã¿ä¿è·æ³ã§å®çŸ©ãããŸãïŒïŒ
(ii) å人ããŒã¿ã®äŸµå®³ã«å¯Ÿå¿ãããé©çšããŒã¿ä¿è·æ³ã«åºã¥ãç£ç£åœå±ãžã®éç¥åã³/åã¯ã客æ§ã«ããããŒã¿äž»äœãžã®é£çµ¡ã
(iii) ã客æ§ããåŠçã®å®å šæ§ã«é¢ããŠé©çšããŒã¿ä¿è·æ³ã«åºã¥ã矩åãéµå®ããŠããããšïŒ
ãã ããã客æ§ã¯ãåœè©²æ¯æŽã®æäŸã«é¢é£ããŠã¯ã©ãŠããã¬ã¢ãè² æ ãããã¹ãŠã®è²»çšãè² æ ãããã®ãšããŸãã
(k) 第3.1æ¡(a)ã«åºã¥ãã客æ§ããæäŸãããæ瀺ãé©çšããŒã¿ä¿è·æ³ã䟵害ãããšã¯ã©ãŠããã¬ã¢ãå€æããå ŽåããŸãã¯é©çšããŒã¿ä¿è·æ³ã«åºã¥ã矩åããã¯ãæããããšãã§ããªããšã¯ã©ãŠããã¬ã¢ãå€æããå Žåãã客æ§ã«éç¥ããããš ii.
3.2 ã¯ã©ãŠããã¬ã¢ãCCPAã®ç¯å²å ã§ã客æ§ã«ä»£ãã£ãŠå人ããŒã¿ãåŠçããç¯å²ã«ãããŠãã¯ã©ãŠããã¬ã¢ã¯ã客æ§ã«å¯ŸããŠä»¥äžã®è¿œå çŽæãããŸãïŒã¯ã©ãŠããã¬ã¢ã¯ãæ¬å¥çŽããã³æ¬DPAã«èŠå®ãããç®ç以å€ã®ç®çãããã³ã販売ãå 責äºé ãå«ãCCPAã®äžã§èš±å¯ãããç®ç以å€ã§ãåœè©²å人ããŒã¿ãä¿æã䜿çšããŸãã¯é瀺ããªããã®ãšããŸãã Cloudflareã¯ãCCPAã§å®çŸ©ãããŠããããã«ãåœè©²å人ããŒã¿ãã販売ããŸãã¯ãå ±æãããããšã¯ãããŸããã æ¬ç¬¬3.2æ¡ã¯ãæ¬å¥çŽãŸãã¯æ¬DPAã«ãããŠã¯ã©ãŠããã¬ã¢ãã客æ§ã«å¯ŸããŠè¡ãããŒã¿ä¿è·ã®çŽæãå¶éãŸãã¯åæžãããã®ã§ã¯ãããŸããã
3.3 Cloudflareã¯ã第2é
ããã³ç¬¬3é
ã®çŸ©åããã³å¶éããªãã³ã«é©çšãããããŒã¿ä¿è·æ³ãç解ãããããéµå®ããããšã蚌æãããã®ãšããŸãã
4. ãµãããã»ã·ã³ã°
4.1 ã¯ã©ãŠããã¬ã¢ã¯ãæ¬ãµãŒãã¹ãæäŸããç¹å®ã®ç®çã®ããã«ã®ã¿ãå人ããŒã¿ããµãããã»ããµãŒã«é瀺ãããã®ãšããŸãã
4.2 ã¯ã©ãŠããã¬ã¢ã¯ãæ¬DPAã«é¢é£ããŠãã¯ã©ãŠããã¬ã¢ã«ä»£ãã£ãŠãµãŒãã¹ã®äžåŽé¢ãæäŸããããã«é¢äžãããµãããã»ããµãŒããåœè©²ãµãããã»ããµãŒã«å¯ŸããŠãæ¬DPAã«ãããŠã¯ã©ãŠããã¬ã¢ã«èª²ããããæ¡ä»¶ïŒããªãã¡ãããŒã¿ä¿è·çŸ©åïŒã«å£ããªãå人ããŒã¿ã®ä¿è·æ¡ä»¶ã課ãæžé¢ã«ããå¥çŽïŒãé¢é£æ¡ä»¶ãïŒã«åºã¥ããŠã®ã¿ãããªãããã«ãããã®ãšããŸãã ã¯ã©ãŠããã¬ã¢ã¯ãåœè©²ãµãããã»ããµãŒã«ããé¢é£æ¡é ã®å±¥è¡ã確ä¿ããåœè©²ãµãããã»ããµãŒã«ããé¢é£æ¡é ã®éåã«ã€ããŠãã客æ§ã«å¯ŸããŠè²¬ä»»ãè² ããã®ãšããŸãã
4.3 ã客æ§ã¯ã(a)CloudflareãCloudflare Groupã®ä»ã®ã¡ã³ããŒããµãããã»ããµãŒãšããŠä»»åœããããšã(b)Cloudflareããã³Cloudflare Groupã®ä»ã®ã¡ã³ããŒãããµãŒãã¹ã®å±¥è¡ããµããŒãããããã«ç¬¬äžè ã®ããŒã¿ã»ã³ã¿ãŒéå¶è ãããžãã¹ããšã³ãžãã¢ãªã³ã°ããã³ã«ã¹ã¿ããŒãµããŒããããã€ããŒããµãããã»ããµãŒãšããŠä»»åœããããšããæžé¢ã«ããäžè¬æ¿èªãšããŠä»äžãããã®ãšããŸãã
4.4 Cloudflareã¯ããµãããã»ããµã®ãªã¹ãã https://www.cloudflare.com/gdpr/subprocessors/ ã§ç®¡çããŸãã ãŸããå人ããŒã¿ã®åŠçãéå§ããæ¥ã®å°ãªããšã30æ¥åãŸã§ã«ãæ°èŠããã³ä»£æ¿ã®ãµãããã»ããµãŒåããªã¹ãã«è¿œå ããŸãã ã客æ§ãããŒã¿ä¿è·ã«é¢é£ããåççãªçç±ã§æ°èŠãŸãã¯äº€æã®ãµãããã»ããµãŒã«ç°è°ãå±ããå Žåãã客æ§ã¯ãéç¥ãã10æ¥ä»¥å ã«æžé¢ã«ãŠåœè©²ç°è°ãã¯ã©ãŠããã¬ã¢ã«éç¥ããåœäºè ã¯èª å®ã«åé¡ã®è§£æ±ºã«åªãããã®ãšããŸãã ã¯ã©ãŠããã¬ã¢ããµãããã»ããµãŒã䜿çšããã«æ¬å¥çŽã«åŸã£ãŠã客æ§ã«æ¬ãµãŒãã¹ãæäŸããããšãåççã«å¯èœã§ããããã®è£éã§ããããããšã決å®ããå Žåãã客æ§ã¯ææ¡ããããµãããã»ããµãŒäœ¿çšã«é¢ããŠæ¬ç¬¬4æ¡4é ã«åºã¥ããã以äžã®æš©å©ãæããªããã®ãšããŸãã Cloudflareããã®è£éã§ãµãããã»ããµãŒã®äœ¿çšãèŠæ±ããææ¡ãããæ°èŠãŸãã¯ä»£æ¿ãµãããã»ããµãŒã®äœ¿çšã«é¢ããã客æ§ã®ç°è°ãæºããããšãã§ããªãå Žåãã客æ§ã¯ãå人ããŒã¿ã®åŠçã«ææ¡ãããæ°èŠãµãããã»ããµãŒã䜿çšãããµãŒãã¹ã«é¢ããŠã®ã¿ãCloudflareãåœè©²æ°èŠãŸãã¯ä»£æ¿ãµãããã»ããµãŒã®äœ¿çšãéå§ããæ¥ããã£ãŠè©²åœãã泚ææžãçµäºããããšãã§ãããã®ãšããŸãã ã客æ§ããæ¬ç¬¬4.4æ¡ã«åŸã£ãŠãæ°èŠãŸãã¯äº€æã®ãµãããã»ããµãŒã«å¯ŸããŠé©æã«ç°è°ãè¿°ã¹ãªãå Žåãã客æ§ã¯ãåœè©²ãµãããã»ããµãŒã«åæããç°è°ãç³ãç«ãŠãæš©å©ãæŸæ£ãããã®ãšã¿ãªãããŸãã
5. ç£æ»ãšèšé²
5.1 ã¯ã©ãŠããã¬ã¢ã¯ãé©çšããŒã¿ä¿è·æ³ã«åŸããã¯ã©ãŠããã¬ã¢ãå人ããŒã¿ã®åŠçã«é¢ããŠé©çšããŒã¿ä¿è·æ³äžã®åŠçè ã®çŸ©åãéµå®ããŠããããšã瀺ãç®çã§ã顧客ãåççã«èŠæ±ããããšãã§ããã¯ã©ãŠããã¬ã¢ã®ä¿æãŸãã¯ç®¡çããæ å ±ã顧客ã«æäŸãããã®ãšããŸãã
5.2 ã¯ã©ãŠããã¬ã¢ã¯ãå人ããŒã¿ã«é¢é£ããé©çšä¿è·æ³ã«åºã¥ãã客æ§ã®ç£æ»æš©ããæäŸããããšã«ããå±¥è¡ããããšãã§ãããã®ãšããŸãïŒ
(a) ç¬ç«ããå€éšç£æ»äººãäœæãããCloudflareã®æè¡çããã³çµç¹çãªå¯Ÿçãååã§ãããèªããããæ¥çã®ç£æ»åºæºã«åŸã£ãŠããããšã蚌æãã13ã¶æ以å ã®ç£æ»å ±åæžïŒ
(b) æ¬DPAã«åºã¥ãã¯ã©ãŠããã¬ã¢ãå®æœããå人ããŒã¿ã®åŠçã«é¢é£ããŠããŒã¿ä¿è·ç£ç£åœå±ãè¿œå æ å ±ãèŠæ± ãŸãã¯èŠæ±ããå Žåãã¯ã©ãŠããã¬ã¢ãä¿æãŸãã¯ç®¡çããŠããè¿œå æ å ±ã
(c) ã客æ§ã®å人ããŒã¿ãEU SCCsã®å¯Ÿè±¡ãšãªããæ¬5.2é ã«åŸã£ãŠæäŸãããæ å ±ããã客æ§ã®åççãªå€æã«ãããã¯ã©ãŠããã¬ã¢ãæ¬DPAãŸãã¯é©çšããŒã¿ä¿è·æ³ã«åºã¥ã矩åãéµå®ããŠããããšã確èªããã«ã¯äžååã§ããéããã¯ã©ãŠããã¬ã¢ã¯ãã客æ§ããæ¬å¥çŽæéïŒæ¬å¥çŽã§å®çŸ©ïŒäžã®å¹Žéæéã«ã€ã1åã®ãªã³ãµã€ãç£æ»ãèŠæ±ããã¯ã©ãŠããã¬ã¢ã5.3é ã«åŸããæ¬DPAã®çŸ©åéµå®ããŠããããšã確èªã§ãããã®ãšããŸãã
5.3 ã客æ§ãåžæããç£æ»ã«ã¯ã以äžã®è¿œå æ¡ä»¶ãé©çšããããã®ãšããŸãïŒ
(a) ã客æ§ã¯ãCloudflareã®ç£æ»å ±åæžã®ã¬ãã¥ãŒã«é¢ããèŠæããcustomer-compliance@cloudflare.com ã«éä»ããå¿ èŠããããŸãã
(b) Cloudflareã第5.2æ¡(c)ã«åºã¥ãç£æ»ã®äŸé Œãåé ããåŸãCloudflareããã³ã客æ§ã¯ãåççãªéå§æ¥ãç¯å²ãæéãããã³ç¬¬5.2æ¡(c)ã«åºã¥ãç£æ»ã«é©çšããã»ãã¥ãªãã£ããã³æ©å¯ç®¡çã«ã€ããŠäºåã«åè°ãåæãããã®ãšããŸãã å¯èœãªéãããã®ãããªç£æ»ã®ããã®èšŒæ ã¯ãCloudflareã®çŽè¿ã®ç¬¬äžè ç£æ»ã§åéããã蚌æ ã«éå®ãããŸãã
(c) Cloudflareã¯ã第5.2æ¡(c)ã«åºã¥ãç£æ»ã«å¯ŸããŠãææ°æïŒCloudflareã®åççãªè²»çšã«åºã¥ãïŒãè«æ±ã§ãããã®ãšããŸãã Cloudflareã¯ããããç£æ»ã«å ç«ã¡ãé©çšãããæéã®è©³çŽ°ããã³ãã®èšç®æ ¹æ ãã客æ§ã«æäŸããŸãã ã客æ§ã¯ããããç£æ»ã®å®è¡ã®ããã«ã客æ§ãæåããç£æ»äººãè«æ±ããææ°æãè² æ ãããã®ãšããŸãã
(d) ã¯ã©ãŠããã¬ã¢ã¯ã5.2(c)é ã«åºã¥ãç£æ»ãè¡ãããã«é¡§å®¢ãæåããç£æ»äººããã¯ã©ãŠããã¬ã¢ã®åççãªèŠè§£ã«ãããŠãé©åãªè³æ ŒãŸãã¯ç¬ç«æ§ãæããŠããªããã¯ã©ãŠããã¬ã¢ã®ç«¶åä»ç€ŸããŸãã¯ãã®ä»ã®æããã«äžé©åœïŒããªãã¡ãäžèšã®åŽé¢ãšåçã®ã¯ã©ãŠããã¬ã¢ã®äºæ¥ã«æ害ãªåœ±é¿ãäžããå¯èœæ§ãããç£æ»äººïŒã§ããã°ãæžé¢ã«ãŠç°è°ãç³ãç«ãŠããããã®ãšããŸãã Cloudflareã«ãããã®ãããªç°è°ç³ãç«ãŠããã£ãå Žåãã客æ§ã¯å¥ã®ç£æ»äººãä»»åœããããèªãç£æ»ãå®æœããå¿ èŠããããŸãã EU SCCïŒä»¥äžã®ç¬¬6.2æ¡(a)é ããã³(b)é ã«ãããŠä¿®æ£ãããå Žåãå«ãïŒãé©çšãããå Žåãæ¬ç¬¬5.3é ã®ãããªãèŠå®ããEU SCCãå€æŽãŸãã¯ä¿®æ£ãããã®ã§ã¯ãªããEU SCCã«åºã¥ãç£ç£åœå±ãŸãã¯ããŒã¿äž»äœã®æš©å©ã«åœ±é¿ãäžãããã®ã§ã¯ãªãã
6. EEAãã¹ã€ã¹ãè±åœããã®ããŒã¿ç§»è»¢
6.1 æ¬ãµãŒãã¹ã«é¢é£ããŠãåœäºè ã¯ãCloudflareïŒããã³ãã®ãµãããã»ããµãŒïŒãã欧å·çµæžé åïŒãEEAãïŒãã¹ã€ã¹ãããã³è±åœå€ã§ãã客æ§ãŸãã¯ã客æ§ã°ã«ãŒãã®ã¡ã³ããŒãã³ã³ãããŒã©ãŒïŒãŸãã¯å Žåã«ãã第äžè ã®ã³ã³ãããŒã©ãŒã«ä»£ããããã»ããµãŒïŒãšãªãå¯èœæ§ã®ããã欧å·ããŒã¿ä¿è·æ³ã«ãã£ãŠä¿è·ãããç¹å®ã®å人ããŒã¿ãåŠçããããšããããšæ³å®ããŠããŸãã
6.2 åœäºè ã¯ã欧å·ããŒã¿ä¿è·æ³ã«ããä¿è·ãããå人ããŒã¿ã®ã客æ§ãŸãã¯ã客æ§ã°ã«ãŒ ãã®ã¡ã³ããŒããCloudflareãžã®ç§»è»¢ãå¶éä»ã移転ã§ããå Žåã以äžã®ããã«é©åãªEU SCCã®å¯Ÿè±¡ãšãªãããšã«åæãããã®ãšããŸãïŒ
(a) EU Transfers: EU GDPRã«ãã£ãŠä¿è·ãããå人ããŒã¿ã«é¢é£ããŠãEU SCCsã¯ä»¥äžã®ããã«å®æããŠé©çšãããŸãïŒ
(i) ã客æ§ïŒãŸãã¯ã客æ§ã°ã«ãŒãã®é¢é£ã¡ã³ããŒïŒãã³ã³ãããŒã©ãŒã§ããå Žåãã¢ãžã¥ãŒã« 2 ãé©çšãããã客æ§ïŒãŸãã¯ã客æ§ã°ã«ãŒãã®é¢é£ã¡ã³ããŒïŒãããã»ããµãŒã§ããå Žåãã¢ãžã¥ãŒã« 3 ãé©çšãããŸãïŒ
(ii) 第 7 æ¡ã«ãããŠããªãã·ã§ã³ã®ãããã³ã°æ¡é ãé©çšãããŸãïŒ
(iii) 第9æ¡ã«ãããŠããªãã·ã§ã³2ãé©çšããããµãããã»ããµã®å€æŽã®äºåéç¥ã®æéã¯ãæ¬DPAã®ç¬¬4.3æ¡ã«å®ãããšãããšããŸãïŒ
(iv) 第 11 æ¡ã«ãããŠããªãã·ã§ã³æèšã¯é©çšãããªãïŒ
(v) 第17æ¡ã«ãããŠããªãã·ã§ã³2ãé©çšãããããŒã¿èŒžåºè ã®å çåœã第äžè ã®åçæš©ãèªããªãå Žåããã€ãã®æ³åŸãé©çšããããã®ãšããŸãïŒ
(vi) 第18æ¡(b)ã«ãããŠãçŽäºã¯ãåœäºè éã®æ¬å¥çŽã管èœããè£å€ç®¡èœã®è£å€æããŸãã¯åœè©²è£å€ç®¡èœãEUå çåœã§ãªãå Žåã«ã¯ããã€ãã»ãã¥ã³ãã³ã®è£å€æã«ãããŠè§£æ±ºãããã®ãšããŸãã ãããã®å Žåã«ãããŠãã第17æ¡ããã³ç¬¬18æ¡ïŒbïŒã¯ãè£å€å°ã®éžæããã³è£å€ç®¡èœãæºæ æ³ã®åœã«å±ãããšããç¹ã§äžèŽãããã®ãšããŸãïŒ
(vii) EU SCCã®Annex Iã¯ãæ¬DPAã®Annex 1ã«èšèŒãããæ å ±ã«ããå®æãããã®ãšã¿ãªãããã
(viii) EU SCCs ã® Annex II ã¯ãæ¬ DPA ã® Annex 2 ã«èšèŒãããæ å ±ã§å®äºãããã®ãšã¿ãªããã®ãšããã
(b) UK Transfers: UK GDPRã§ä¿è·ãããŠããå人ããŒã¿ã«é¢ããŠã¯ãæ¬DPAã®ç¬¬6.2é (a)ã«èšèŒãããŠããããã«ãEU SCCãé©çšãããåœè©²å人ããŒã¿ã®ç§»è»¢ã«ã¯ã以äžãé€ããŠé©çšããããã®ãšããŸãïŒ
(i) EU SCCã¯ãè²æž¡ãã顧客ïŒãŸãã¯é¡§å®¢ã°ã«ãŒãã®é¢é£ã¡ã³ããŒïŒãšCloudflareãšã®éã§ç· çµããããã®ãšã¿ãªãããUK Addendumã«ãã£ãŠèŠå®ãããããã«ä¿®æ£ããããã®ãšããŸãïŒ
(ii) EU SCC ã®æ¡ä»¶ãšè±åœè£éºã®æ¡ä»¶ãšã®éã«ççŸãããå Žåã¯ãè±åœè£éºã®ç¬¬ 10 æ¡ããã³ç¬¬ 11 æ¡ã«åŸã£ãŠè§£æ±ºããããã®ãšããŸãïŒ
(iii) è±åœè£éºã®ç®çäžãè±åœè£éºç¬¬1éšã®è¡š1ïœè¡š3ã¯ãæ¬DPAã®ä»å±æžã«å«ãŸããæ å ±ãçšããŠå®æãããã®ãšã¿ãªãããããšã
(iv) è±åœè£éºç¬¬1éšã®è¡š4ã¯ã"neither party "ãéžæããããšã«ãããèšå
¥ããããã®ãšã¿ãªãããã
(c) ã¹ã€ã¹ç§»è»¢ïŒ ããŒã¿ä¿è·ã«é¢ããã¹ã€ã¹é£éŠæ³ïŒæ¹æ£ãŸãã¯çœ®æããããã®ïŒã«ãã£ãŠä¿è·ãããå人ããŒã¿ã«é¢ããŠã¯ãæ¬DPAã®ç¬¬6.2æ¡ïŒaïŒã«èŠå®ãããEU SCCsããåœè©²å人ããŒã¿ã®ç§»è»¢ã«é©çšããããã®ãšããŸããã以äžã®å Žåã¯é€ããŸãïŒ
(i) åœè©²å人ããŒã¿ã«é¢ãã管èœç£ç£å®åºã¯ãã¹ã€ã¹é£éŠããŒã¿ä¿è·ã»æ å ±å§å¡äŒãšããŸãïŒ
(ii) 第 17 æ¡ã«ãããŠãæºæ æ³ã¯ã¹ã€ã¹æ³ãšããŸãïŒ
(iii) EU SCC ã«ããããå çåœããšããè¡šçŸã¯ãã¹ã€ã¹ãæããã®ãšè§£éãããã¹ã€ã¹ã«æåšããããŒã¿äž»äœã¯ãã¹ã€ã¹ã«ãã㊠EU SCC ã«åºã¥ãæš©å©ãè¡äœ¿ããå®æœããæš©å©ãæãããã®ãšããã
(iv) EU SCCã«ããããäžè¬ããŒã¿ä¿è·èŠåãããèŠå2016/679ããŸãã¯ãGDPRããžã®èšåã¯ãããŒã¿ä¿è·ã«é¢ããã¹ã€ã¹é£éŠæ³ïŒæ¹æ£ãŸãã¯çœ®ãæãããããã®ïŒãžã®èšåãšç解ãããã®ãšããŸãã
(d) 以äžã®æ¡é ã¯ãEU SCCïŒäžèš6.2(b)é ããã³(c)é ã«åºã¥ãä¿®æ£ãããå Žåãå«ãïŒïŒ
(i) ã客æ§ã¯ãæ¬ DPA ã®ç¬¬ 5 æ¡ã«èŠå®ããããã®èŠä»¶ã«åŸã£ãŠãEU SCC ã«åºã¥ãç£æ»ã®æš©å©ãè¡äœ¿ããããšãã§ããŸãã
(ii) ã¯ã©ãŠããã¬ã¢ã¯ãæ¬DPA第4æ¡ããã³ç¬¬6.3æ¡ã«èŠå®ããããã®èŠä»¶ã«åŸã£ãŠãµãããã»ããµãŒãä»»åœããããšãã§ããã客æ§ã¯ãEU SCCã«åºã¥ããµãããã»ããµãŒã«å¯Ÿããç°è°ç³ãç«ãŠã®æš©å©ããæ¬DPA第4.3æ¡ã«èŠå®ãããæ¹æ³ã§è¡äœ¿ããããšãã§ããŸãã
(e) æ¬DPAã®ããããã®æ¡é ããçŽæ¥çãŸãã¯éæ¥çã«EU SCCïŒããã³å¿ èŠã«å¿ããŠUK AddendumïŒãšççŸããå ŽåãåŸè ãåªå ããããã®ãšããŸãã
6.3 第6.2æ¡ã«åºã¥ããŠCloudflareã«è¡ãããå¶éä»ã移転ã«é¢ããŠãCloudflareã¯ãïŒå人ããŒã¿ã®ã茞åºè ãã§ããããèŒžå ¥è ãã§ããããåããïŒæ¬§å·ããŒã¿ä¿è·æ³ãå®å šã«éµå®ããŠãå人ããŒã¿ã®èŒžåºè ãšèŒžå ¥è ã®éã§å®æœãããEU SCCã«åŸã£ãŠããŸãã¯èŒžå ¥è ãæ¡çšãã代æ¿ç§»è»¢ã¡ã«ããºã ïŒç¬¬6.5æ¡ã«å®çŸ©ïŒãé©çšãããŠããªãéããå人ããŒã¿ã®ãããªãå¶éä»ã移転ã«åå ããªãïŒãŸããµãããã»ããµãåå ããã®ãèš±å¯ããªãïŒãšãããã®ãšããŸãã
6.4 ã客æ§ãç¹å®ã®åœãŸãã¯å°åãžã®è»¢éã«é¢ããEU SCCã®åŠ¥åœæ§ã®è©äŸ¡ãè¡ãããšããå ŽåãCloudflareã¯ãå¯èœãªç¯å²ã§ãåœè©²è©äŸ¡ã®ç®çã®ããã«ã客æ§ã«åççãªæ¯æŽãæäŸãããã®ãšããã客æ§ã¯åœè©²æ¯æŽã®æäŸã«é¢é£ããŠCloudflareãè² æ ãããã¹ãŠã®è²»çšãè² æ ãããã®ãšããŸãã
6.5 Cloudflareãæ¬DPAã«èšèŒãããŠããªãå人ããŒã¿ã®ç§»è»¢ã«ã€ããŠä»£æ¿ããŒã¿èŒžåºã¡ã«ããºã ïŒé©çšããã欧å·ããŒã¿ä¿è·æ³ã«åŸã£ãŠæ¡çšããããã©ã€ãã·ãŒã·ãŒã«ãã®æ°ããŒãžã§ã³ãŸãã¯åŸç¶ãå«ãïŒãæ¡çšããç¯å²ïŒ"代æ¿ç§»è»¢ã¡ã«ããºã " )ãã客æ§ã¯ãæ¬DPAã«èšèŒãããé©çšå¯èœãªç§»è»¢ã¡ã«ããºã ã®ä»£ããã«ä»£æ¿ç§»è»¢ã¡ã«ããºã ãé©çšããïŒãã ããåœè©²ä»£æ¿ç§»è»¢ã¡ã«ããºã ã欧å·ããŒã¿ä¿è·æ³ã«æºæ ããå人ããŒã¿ã移転ãããå°åã«åã¶ç¯å²ã«éãïŒãåœè©²ä»£æ¿ç§»è»¢ã¡ã«ããºã ã«æ³çå¹åãäžããããã«åççã«å¿ èŠãšãªããã®ä»ã®ææžã®ç· çµããã³ãã®ä»ã®è¡çºãè¡ãããšã«åæãããã®ãšããŸãã
7. 第äžè ã«ããããŒã¿ã¢ã¯ã»ã¹èŠæ±
7.1 ã¯ã©ãŠããã¬ã¢ãããã»ããµãŒãŸãã¯ãµãããã»ããµãŒïŒè©²åœããå ŽåïŒãšããŠé¡§å®¢ã®ããã«åŠçããå人ããŒã¿ãèŠæ±ãã第äžè ã®æ³çæç¶ãã«æ°ã¥ããå Žåãã¯ã©ãŠããã¬ã¢ã¯ä»¥äžãè¡ããŸãïŒ
(a) ãã®ãããªéç¥ãæ³çã«çŠæ¢ãããŠããå Žåãé€ããçŽã¡ã«ãã®æšãã客æ§ã«éç¥ããããšïŒ
(b) 第äžè ãå人ããŒã¿ã®åŠçè ãŸãã¯ãµãåŠçè ïŒè©²åœããå ŽåïŒã§ãããã客æ§ã®åæãªãã«å人ããŒã¿ãé瀺ããæš©éããªãããšãéç¥ããããšïŒ
(c) 第äžè ãã客æ§ã«é£çµ¡ããããŒã¿èŠæ±ãã客æ§ã«åããããæ瀺ã§ãããããå¿ èŠæäœéã®ã客æ§ã®é£çµ¡å ã第äžè ã«é瀺ããããšã
(d) Cloudflareããã客æ§ã®æ¿èªãåŸãŠããŸãã¯åŒ·å¶çãªæ³ç匷å¶åã«ããã第äžè ã®æ³çæç¶ãã«å¿ããŠå人ããŒã¿ãžã®ã¢ã¯ã»ã¹ãæäŸãŸãã¯é瀺ããç¯å²ã«ãããŠãCloudflareã¯ãæ³çã«èŠæ±ãããç¯å²å ã§ãé©çšãããæ³çæç¶ãã«åŸã£ãŠãæå°éã®å人ããŒã¿ãé瀺ãããã®ãšããŸãã
7.2 ã¯ã©ãŠããã¬ã¢ã®ããã»ããµãŒãŸãã¯ãµãããã»ããµãŒãšããŠã®åœ¹å²ïŒè©²åœããå ŽåïŒã«ãããŠãæ¿åºåœå±ïŒåžæ³åœå±ãå«ãïŒãçºè¡ããå人ããŒã¿ãžã®ã¢ã¯ã»ã¹ãŸãã¯é瀺ãèŠæ±ãã第äžè ã®æ³çæç¶ãã®å¯Ÿè±¡ãšãªãå ŽåããããŸãã ã¯ã©ãŠããã¬ã¢ãããã»ããµãŒãŸãã¯ãµãããã»ããµãŒïŒè©²åœããå ŽåïŒãšããŠã客æ§ã®ããã«åŠçããå人ããŒã¿ãèŠæ±ããæ¿åºåœå±ïŒåžæ³åœå±ãå«ãïŒãçºè¡ãã第äžè ã®æ³çæç¶ãã«æ°ä»ããå Žåã㯠ã©ãŠããã¬ã¢ãåççãªåªåã§ãã®èŠæ±ãæ€èšãããã®çµæãå人ããŒã¿ãèŠæ±ããåœè©²ç¬¬äžè ã®æ³çæç¶ããæ³åŸã®ççŸãçããããããšãç¹å®ã§ããç¯å²ã§ãã¯ã©ãŠããã¬ã¢ã¯ä»¥äžãè¡ããŸãïŒ
(a) äžèš7.1é ã«ãããŠç¹å®ããããã¹ãŠã®æªçœ®ãè¬ããïŒ
(b) å人ããŒã¿ãäœæããåã«ãæ§èšŽè£å€æã¬ãã«ãŸã§æ³çææžãè¿œæ±ããããšã
(c) é©çšãããæç¶ãäžã®èŠåã«ããèŠæ±ããããŸã§ïŒãããŠãã®ç¯å²å ã§ïŒãå人ããŒã¿ãé瀺ããªãããšã
7.3 第7.1æ¡ããã³ç¬¬7.2æ¡ã¯ãå人ã«å¯Ÿããæ»äº¡ãŸãã¯é倧ãªèº«äœçå·å®³ã®å±éºã䌎ãç·æ¥äºæ ã«ãããæ¿åºã®èŠè«ãå¿ èŠã§ãããšã¯ã©ãŠããã¬ã¢ãèª å®ã«ä¿¡ããå Žåã«ã¯é©çšãããªããã®ãšããŸãã ãã®å ŽåãCloudflareã¯ãããŒã¿é瀺ãæ³çã«çŠæ¢ãããŠããå Žåãé€ããé瀺åŸã§ããã ãæ©ãã客æ§ã«éç¥ãããã®è©³çŽ°ãã客æ§ã«æäŸãããã®ãšããŸãã
7.4 ã¯ã©ãŠããã¬ã¢ã¯ãå人ããŒã¿ãèŠæ±ãã第äžè ã®æ³çæç¶ãã«ã€ããŠãã¯ã©ãŠããã¬ã¢ã®åæéææ§ã¬ããŒãïŒhttps://www.cloudflare.com/transparency/ïŒã®åœ¢ã§ãã客æ§ã«å®æçã«ææ°æ å ±ãæäŸããŸãã
7.5 ã客æ§ãCloudflareãšæ¬DPAãç· çµããæç¹ã§ãCloudflareã¯ä»¥äžã«åæããã³ãããã¡ã³ããè¡ããŸãã Cloudflareã¯ã https://www.cloudflare.com/transparency/ã«ãããŠãå¿ èŠã«å¿ããŠãããã®ã³ãããã¡ã³ããæŽæ°ããŸãïŒ
(a) Cloudflareã¯ãåœç€Ÿã®æå·åããŒãèªèšŒããŒããããã¯é¡§å®¢ã®æå·åããŒãèªèšŒããŒã誰ãã«æž¡ããããšã¯ãããŸããã
(b) Cloudflareã¯ãåœç€Ÿã®ãããã¯ãŒã¯ã®ã©ãã«ããæ³å·è¡æ©é¢ã®ãœãããŠã§ã¢ãæ©åšãã€ã³ã¹ããŒã«ããããšã¯ãããŸããã
(c) Cloudflareã¯ããããªãæ³å·è¡æ©é¢ã«å¯ŸããŠããåœç€Ÿã®ãããã¯ãŒã¯ãééããã客æ§ã®ã³ã³ãã³ãã®ãã£ãŒããæäŸããããšã¯ãããŸããã
(d) Cloudflareã¯ãæ³å·è¡æ©é¢ãŸãã¯ãã®ä»ã®ç¬¬äžè ã®èŠè«ã«ããããã®æå·åã匱ãããã劥åããããç Žå£ãããããããšã¯ãããŸããã
8. äžè¬
8.1 æ¬DPAã¯ãåŒãç¶ãå®å šãªå¹åãæããæ¬å¥çŽã«åºã¥ãåœäºè ã®æš©å©åã³çŸ©åã害ãããã®ã§ã¯ãããŸããã æ¬DPAã®æ¡é ãšæ¬å¥çŽã®æ¡é ãççŸããå Žåãäž»é¡ãå人ããŒã¿ã®åŠçã«é¢ä¿ããéããæ¬DPAã®æ¡é ãåªå ãããã®ãšããŸãã
8.2 EU SCCã®ããšãå«ãæ¬DPAã«åºã¥ãããŸãã¯ããã«é¢é£ããCloudflareã®è²¬ä»»ã¯ãæ¬å¥çŽã«å«ãŸãã責任ã®é€å€ããã³å¶éã«åŸããã®ãšããŸãã ãããªãå ŽåããCloudflareã¯ãããŒã¿äž»äœãŸãã¯ç®¡èœã®ããŒã¿ä¿è·åœå±ã«å¯Ÿãã責任ãå¶éãŸãã¯æé€ããŸããã
8.3 EU SCC ã«æ瀺çã«èŠå®ãããŠããå ŽåãŸãã¯é©çšããŒã¿ä¿è·æ³ã®åé¡ãšããŠèŠæ±ãããå Žåãé€ããæ¬ DPA ã¯ã第äžè åçæš©ãä»äžãããã®ã§ã¯ãªããæ¬å¥çŽã®åœäºè ããã³ããããã®èš±å¯ã ããåŸç¶è ããã³è²å人ã®ã¿ã®å©çãæå³ããŠããããã®ä»ã®è ã®å©çã®ããã§ã¯ãªããæ¬å¥çŽã®ãããªãæ¡é ãå·è¡ããããšã¯ã§ããªãã
8.4 æ¬DPAããã³ããã«é¢é£ããè¡çºã¯ãæ³ã®æµè§Šã«é¢ããååã«åœ±é¿ãããããšãªããæ¬å¥çŽã«èŠå®ãããæ³åŸã«æºæ ããããã«åŸã£ãŠè§£éããããã®ãšããŸãã åœäºè ã¯ãæ¬å¥çŽã«å®ããè£å€æã®äººç管èœæš©ããã³è£å€å°ã«åæãããã®ãšããŸãã
8.5 æ¬DPAã®ããããã®æ¡é ãäœããã®çç±ã§ç¡å¹ãŸãã¯å·è¡äžèœãšå€æãããå Žåã§ããæ¬DPAã®ä»ã®æ¡é ã¯åŒãç¶ãå·è¡å¯èœã§ãã äžèšã®äžè¬æ§ãå¶éããããšãªããã客æ§ã¯ã第8.2æ¡ïŒè²¬ä»»ã®å¶éïŒããæ¬DPAã®ããããã®æ¡é ã®å·è¡äžèœã«ããããããæå¹ã«åç¶ããããšã«åæãããã®ãšããŸãã
8.6 æ¬DPAã¯ãæ¬å¥çŽã®äž»é¡ã«é¢ããåœäºè ã®æçµçãå®å šãã€æä»çãªåæã§ãããåœè©²äž»é¡ã«é¢ããåœäºè éã®ãã¹ãŠã®äºåã®åè°ããã³åæã«åªå ããçµ±åããããã®ãšããŸãã
ããŒã¿åŠçã®èª¬æ
æ¬ä»å±æž1ã¯ãDPAã®äžéšãæ§æããCloudflareãã客æ§ã®ããã«è¡ãåŠçãèšè¿°ããŠããŸãã
A.åœäºè ãªã¹ã
æè¡çã»çµç¹çãªã»ãã¥ãªãã£å¯Ÿç
Cloudflareã¯ãISO/IEC 27000èŠæ Œã«æºæ ããæ å ±ã»ãã¥ãªãã£ããã°ã©ã ãå®æœããç¶æãããã®ãšããŸãã Cloudflareã®ã»ãã¥ãªãã£ããã°ã©ã ã«ã¯ã以äžã®ãã®ãå«ãŸãããã®ãšããŸãïŒ
å人ããŒã¿ã®æå·åã®æªçœ®
Cloudflareã¯ãå人ããŒã¿ãé©åã«ä¿è·ããããã«ãæå·åãå®æœããŠããŸãïŒ
å ¬çæ©é¢ãå©çšã§ããããšãåãã£ãŠãããªãœãŒã¹ã§ãèœåçããã³ååçãªæ»æã«å¯Ÿããå¹æçãªä¿è·ãæäŸããããã«èšèšãããæå 端ã®æå·åãããã³ã«ã䜿çšããïŒ
ä¿¡é Œã§ããå ¬ééµèªèšŒå±ããã³ã€ã³ãã©ã¹ãã©ã¯ãã£ïŒ
察称åæå·åã§ã¯æäœ128ãããã®éµé·ãé察称åã¢ã«ãŽãªãºã ã§ã¯æäœ2048ãããRSAãŸãã¯256ãããECCéµé·ãªã©ãå¹æçãªæå·åã¢ã«ãŽãªãºã ãšãã©ã¡ãŒã¿åã
åŠçã·ã¹ãã ããã³ãµãŒãã¹ã®ç¶ç¶çãªæ©å¯æ§ãå®å šæ§ãå¯çšæ§ããã³å埩åã確ä¿ããããã®æªçœ®
Cloudflareã¯ãæ¬çªç°å¢ã«ãããåŠçã·ã¹ãã ããµãŒãã¹ã®ã»ãã¥ãªãã£ã以äžã®ããã«åŒ·åããŸãïŒ
æ¬ãµãŒãã¹ãæäŸããããã«äœ¿çšãããã³ãŒãã®ã»ãã¥ãªãã£ãé«ããããã«ã³ãŒãã¬ãã¥ãŒããã»ã¹ãæ¡çšãã䜿çšåããã³äœ¿çšäžã«ã³ãŒãããã³ã·ã¹ãã ã®è匱æ§ããã¹ãããŠããŸãïŒ
å€éšããã®ãã°ããŠã³ãã£ãŒããã°ã©ã ãç¶æããïŒ
æå·åãããããŒã¿ã®æŽåæ§ãæ€èšŒããããã®ãã§ãã¯ã䜿çšããããšãš
äºé²çãåå¿çãªäŸµå ¥æ€ç¥ãæ¡çšã
Cloudflareã¯ãå°ççã«åæ£ãããããŒã¿ã»ã³ã¿ãŒã«é«å¯çšæ§ã·ã¹ãã ãå°å ¥ããŠããŸãã
Cloudflareã¯ãå人ããŒã¿ãä¿è·ããæ©å¯æ§ãç¶æããããã«ã以äžã®ãããªå ¥å管ççãå®æœããŠããŸãïŒ
ããŒã¿ã®å ¥åãé²èŠ§ãå€æŽãåé€ã®ããã®æš©éèŠå®ïŒ
èªèšŒæ å ±ïŒãã¹ã¯ãŒãïŒããã³ããŒãããŒã¯ã³ã䜿çšããŠãèªèšŒããã人å¡ãèªèšŒããããšïŒ
ãŠãŒã¶ãŒIDãäžå®æé䜿çšãããªããšãèªåçã«ãµã€ã³ã¢ãŠãããæ©èœïŒ
ããŒã¿ã®å ¥åãä¿åãããããŒã¿ã®èªã¿åããå€æŽãåé€ãä¿è·ããããšã
ããŒã¿åŠçæœèšïŒã³ã³ãã¥ãŒã¿ã®ããŒããŠã§ã¢ããã³é¢é£æ©åšãå容ããéšå±ïŒãæœé ããŠå®å šã«ä¿ç®¡ããããšã矩åã¥ããã
ç©ççãŸãã¯æè¡çãªäºæ ãçºçããå Žåã«ãå人ããŒã¿ãžã®å¯çšæ§ããã³ã¢ã¯ã»ã¹ãé©æã«å埩ããèœåã確ä¿ããããã®æªçœ®
Cloudflareã¯ãå人ããŒã¿ãå¶çºçãªç Žå£ãŸãã¯æ倱ããä¿è·ããããã«ãç¶æããããšãå«ãæªçœ®ãå®æœããŸãïŒ
çœå®³åŸ©æ§ããã³äºæ¥ç¶ç¶ã®èšç»ããã³æé ïŒ
å°ççã«åæ£ãããããŒã¿ã»ã³ã¿ãŒã§
é»æºãã€ã³ã¿ãŒãããæ¥ç¶ãªã©ã®ã€ã³ãã©ãåé·åããŠããŸãïŒ
ããã¯ã¢ããã¯ä»£æ¿ãµã€ãã«ä¿åããããã©ã€ããªã·ã¹ãã ã®é害æã«åŸ©å å¯èœã§ããã
å®æçã«ãã¹ããããã€ã³ã·ãã³ã管çæé ã
åŠçã®å®å šæ§ã確ä¿ããããã«ãæè¡çã»çµç¹çæªçœ®ã®æå¹æ§ãå®æçã«ãã¹ãããè©äŸ¡ããè©äŸ¡ããããã»ã¹
Cloudflareã®æè¡çããã³çµç¹çãªå¯Ÿçã¯ãCloudflareã®ã»ãã¥ãªãã£& ãã©ã€ãã·ãŒã³ã³ãã©ã€ã¢ã³ã¹ããã°ã©ã ã®äžç°ãšããŠãå€éšã®ç¬¬äžè ç£æ»äººã«ããå®æçã«ãã¹ãããã³è©äŸ¡ãããŠããŸãã ããã«ã¯ãISO/IEC 27001ã®å¹Žæ¬¡ç£æ»ãAICPA SOC 2 Type IIãPCI DSS Level 1ãããã³ãã®ä»ã®å€éšç£æ»ãå«ãŸããå ŽåããããŸãã ãŸãã察çã¯å éšç£æ»ã«ãã£ãŠå®æçã«æ€èšŒãããããã«å¹Žæ¬¡ããã³ç®æšã«å¿ãããªã¹ã¯ã¢ã»ã¹ã¡ã³ããå®æœãããŠããŸãã
ãŠãŒã¶ãŒã®èå¥ãšèªèšŒã®ããã®æªçœ®
Cloudflareã¯ããŠãŒã¶ãŒèªèšŒãšæš©é管çã«ã€ããŠã以äžã®ãããªå¹æçãªå¯Ÿçãå®æœããŠããŸãïŒ
匷å¶çãªã¢ã¯ã»ã¹å¶åŸ¡ãšèªèšŒã®ããªã·ãŒãé©çšããããšïŒ
èå¥ãšèªå¯ã®ãŒããã©ã¹ãã¢ãã«ãé©çšããïŒ
ç©ççãªããŒãããŒã¯ã³ã®äœ¿çšã矩åä»ãããªã©ãåºæã®èªèšŒæ å ±ããã³åŒ·åãªå€èŠçŽ èªèšŒã䜿çšããŠãèš±å¯ããã人å¡ãèªèšŒããããšïŒ
圹å²ã«å¿ããé©åãªæš©éã®å²ãåœãŠãšç®¡çãæ¿èªãäŸå€ç®¡çã
æå°æš©éã¢ã¯ã»ã¹ã®ååãé©çšããã
éä¿¡äžã®ããŒã¿ä¿è·ã®ããã®æªçœ®
Cloudflareã¯ãéä¿¡äžã«æš©éã®ãªãè ã«ãã£ãŠå人ããŒã¿ãèªã¿åãããã³ããŒãããå€æŽããããŸãã¯åé€ãããããšãé²ãããã«ãå¹æçãªå¯Ÿçãå®æœããŸãïŒä»¥äžããéä¿¡äžããšãããŸãïŒ
å ¬çæ©é¢ãå©çšå¯èœã§ããããšãåãã£ãŠãããªãœãŒã¹ã§ãèœåçããã³ååçãªæ»æã«å¯Ÿããå¹æçãªä¿è·ãæäŸããããã«èšèšãããæå 端ã®ãã©ã³ã¹ããŒãæå·åãããã³ã«ã䜿çšããïŒ
ä¿¡é Œã§ããå ¬ééµèªèšŒå±ãã€ã³ãã©ãå©çšããïŒ
é©åãªãã¡ã€ã¢ãŠã©ãŒã«ãçžäºã®TLSæå·åãAPIèªèšŒãããŒã¿ãééããã²ãŒããŠã§ã€ããã€ãã©ã€ã³ãä¿è·ããããã®æå·åããœãããŠã§ã¢ã®è匱æ§ãããã¯ãã¢ã®å¯èœæ§ããã¹ããããªã©ããã©ã³ã¹ããŒãæå·åãæäŸããéåä¿¡ã·ã¹ãã ã«å¯Ÿããã¢ã¯ãã£ãããã³ããã·ãæ»æã«å¯Ÿããä¿è·çãå®æœããïŒ
察称åæå·åã§ã¯æäœ128ãããã®éµé·ãé察称åã¢ã«ãŽãªãºã ã§ã¯æäœ2048ãããã®RSAãŸãã¯256ãããã®ECCéµé·ãªã©ãå¹æçãªæå·åã¢ã«ãŽãªãºã ãšãã©ã¡ãŒã¿åãæ¡çšããïŒ
æ£ããå®è£ ãããæ£ããä¿å®ããããœãããŠã§ã¢ã䜿çšããè匱æ§ç®¡çããã°ã©ã ã®å¯Ÿè±¡ãšããç£æ»ã«ããé©åæ§ããã¹ãããïŒ
æå·éµã確å®ã«çæã管çãä¿ç®¡ãä¿è·ããããã®å®å šãªæ段ãå®æœããããšã
ç£æ»ãã°ãç£èŠãããŒã¿éä¿¡ã®è¿œè·¡ã
ä¿ç®¡äžã®ããŒã¿ä¿è·ã®ããã®æªçœ®
Cloudflareã¯ãä¿ç®¡äžã®å人ããŒã¿ãä¿è·ããããã«ãããŒã¿åŠçã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããã³å¶éããå¹æçãªå¯Ÿçãå®æœããŸãïŒ
å ¬çæ©é¢ãå©çšå¯èœã§ããããšãåãã£ãŠãããªãœãŒã¹ã§ãèœåçããã³ååçãªæ»æã«å¯Ÿããå¹æçãªä¿è·ãæäŸããããã«èšèšãããæå 端ã®æå·åãããã³ã«ã䜿çšããïŒ
ä¿¡é Œã§ããå ¬ééµèªèšŒå±ãã€ã³ãã©ãå©çšããïŒ
ããŒã¿ãä¿åããŠããã·ã¹ãã ã®ãœãããŠã§ã¢ã®è匱æ§ãããã¯ãã¢ã®å¯èœæ§ãæ€èšŒããïŒ
å人æ å ±ãä¿åãããã¹ãŠã®ãã£ã¹ã¯ã128ããã以äžã®éµé·ãæã€AES-XTSã§æå·åããããšã矩åä»ãããªã©ãå¹æçãªæå·åã¢ã«ãŽãªãºã ãšãã©ã¡ãŒã¿åãè¡ãã
æ£ããå®è£ ãããæ£ããä¿å®ããããœãããŠã§ã¢ã䜿çšããè匱æ§ç®¡çããã°ã©ã ã®å¯Ÿè±¡ãšããç£æ»ã«ããé©åæ§ããã¹ãããïŒ
æå·éµã確å®ã«çæã管çãä¿ç®¡ãä¿è·ããããã®å®å šãªæ段ãå®æœããããšïŒ
ããŒã¿åŠçã·ã¹ãã ã«ã¢ã¯ã»ã¹ããã·ã¹ãã ããã³ãŠãŒã¶ãèå¥ããæš©éãä»äžããããšïŒ
äžå®æéæäœãè¡ãããªããšãèªåçã«ãŠãŒã¶ãŒããµã€ã³ã¢ãŠããããããšã
ããŒã¿åŠçã·ã¹ãã ããã³ã¹ãã¬ãŒãžã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ã®ç£æ»èšé²ãç£èŠãããã³è¿œè·¡ã
Cloudflareã¯ãããŒã¿åŠçã·ã¹ãã ã®ç¹å®ã®é åã«å¯ŸããŠã¢ã¯ã»ã¹å¶åŸ¡ãå®æœããèš±å¯ããããŠãŒã¶ãŒã®ã¿ããããããã®ã¢ã¯ã»ã¹èš±å¯ïŒèªå¯ïŒã«ãã£ãŠã«ããŒãããç¯å²ããã³çšåºŠã§å人ããŒã¿ã«ã¢ã¯ã»ã¹ã§ããããšãããã³å人ããŒã¿ãèš±å¯ãªãèªã¿åããã³ããŒãä¿®æ£ãŸãã¯åé€ãããªãããšãä¿èšŒããŸãã ãå«ãæ§ã ãªæœçã«ããå®çŸãããã®ãšããïŒ
å人ããŒã¿ã«å¯ŸããååŸæ¥å¡ã®ã¢ã¯ã»ã¹æš©ã«é¢ããåŸæ¥å¡ããªã·ãŒããã³ãã¬ãŒãã³ã°ïŒ
ãŠãŒã¶ãŒèå¥ãšèªå¯ã®ãŒããã©ã¹ãã¢ãã«ãé©çšããïŒ
ç©ççãªããŒãããŒã¯ã³ã®äœ¿çšã矩åä»ãããªã©ãåºæã®èªèšŒæ å ±ããã³åŒ·åãªå€èŠçŽ èªèšŒã䜿çšããŠãèš±å¯ããã人å¡ãèªèšŒããããšïŒ
å人ããŒã¿ã®åé€ãè¿œå ãä¿®æ£ã®æš©éãæã€è ã®è¡åãç£èŠããããšïŒ
å·®å¥åãããã¢ã¯ã»ã¹æš©ã圹å²ã®å²ãåœãŠãå«ããèš±å¯ããã人ç©ã«ã®ã¿ããŒã¿ãå ¬éããããšã
ããŒã¿ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããããŒã¿ã®ç Žæ£ãå¶åŸ¡ããææžåããã
å人ããŒã¿ãåŠçãããå Žæã®ç©ççã»ãã¥ãªãã£ã確ä¿ããããã®æªçœ®
ã¯ã©ãŠããã¬ã¢ã¯ãå人ããŒã¿ãåŠçãŸãã¯äœ¿çšãããããŒã¿åŠçè£ çœ®ïŒããªãã¡ãããŒã¿ããŒã¹ããã³ã¢ããªã±ãŒã·ã§ã³ãµãŒããŒããªãã³ã«é¢é£ããŒããŠã§ã¢ïŒã«å¯ŸããŠãæš©éã®ãªãè ãã¢ã¯ã»ã¹ããããšãé²ãããã«ãå¹æçãªç©ççã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒããã³æ段ãç¶æããã³å®æœããŸãïŒä»¥äžãå«ã¿ãŸãïŒ
ã»ãã¥ã¢ãšãªã¢ã®ç¢ºç«
ã¢ã¯ã»ã¹çµè·¯ãä¿è·ã»å¶éããïŒ
åŸæ¥å¡ããã³ç¬¬äžè ã«å¯Ÿããã¢ã¯ã»ã¹æš©éã®èšå®ïŒããããã®ææžãå«ãïŒïŒ
å人ããŒã¿ããã¹ããããŠããããŒã¿ã»ã³ã¿ãŒãžã®ãã¹ãŠã®ã¢ã¯ã»ã¹ã¯ãèšé²ãç£èŠã远跡ãããŸãã
å人ããŒã¿ãä¿ç®¡ãããŠããããŒã¿ã»ã³ã¿ãŒã¯ãã»ãã¥ãªãã£ã¢ã©ãŒã ã·ã¹ãã ãããã³ãã®ä»ã®é©åãªã»ãã¥ãªãã£æ段ã«ãã£ãŠä¿è·ãããŠããŸãã
ã€ãã³ããã®ã³ã°ã確å®ã«è¡ãããã®å¯Ÿç
Cloudflareã¯ãã·ã¹ãã 管çè ãå«ãå人ããŒã¿ãžã®ã¢ã¯ã»ã¹ãèšé²ãç£èŠã远跡ããåãåã£ãæ瀺ã«åŸã£ãŠããŒã¿ãåŠçãããããã«ããããããã°èšé²ããã³ç£èŠããã°ã©ã ãå®æœããŠããŸãã ãªã©ãããŸããŸãªæœçã§å®çŸããŠããŸãïŒ
ç©ççãªããŒãããŒã¯ã³ã®äœ¿çšã矩åä»ãããªã©ãåºæã®èªèšŒæ å ±ããã³åŒ·åãªå€èŠçŽ èªèšŒã䜿çšããŠãèš±å¯ããã人å¡ãèªèšŒããããšïŒ
ãŠãŒã¶ãŒèå¥ãšèªå¯ã®ãŒããã©ã¹ãã¢ãã«ãé©çšããïŒ
ã·ã¹ãã 管çè ã®èå¥æ å ±ãæŽæ°ããŠããããšïŒ
é«ãªã¹ã¯ã®ç°åžžãæ€ç¥ã»è©äŸ¡ãã察å¿ããããã®æ段ãå°å ¥ããŠããïŒ
åŠçã€ã³ãã©ã«å¯Ÿããå®å šãã€æ£ç¢ºã§ãå€æŽãããŠããªãã¢ã¯ã»ã¹ãã°ã12ã¶æéä¿åããããšã
ãã°ã®èšå®ãç£èŠã·ã¹ãã ãã¢ã©ãŒããã€ã³ã·ãã³ã察å¿ããã»ã¹ãå°ãªããšã幎1åãã¹ãããããšã
åæèšå®ãå«ãã·ã¹ãã æ§æã確ä¿ããããã®æ¹ç
Cloudflareã¯ããµãŒãããŒãã£ãŒã®ã·ã¹ãã ãå«ããæ¬çªã®ããŒã¿åŠçç°å¢ããµããŒããããã¹ãŠã®ã·ã¹ãã ã®æ§æããŒã¹ã©ã€ã³ãç¶æããŠããŸãã èšå®ããŒã¹ã©ã€ã³ã¯ãCISïŒCenter for Internet SecurityïŒã¬ãã«1ãã³ãããŒã¯ãªã©ã®æ¥çã®ãã¹ããã©ã¯ãã£ã¹ã«åãããå¿ èŠããããŸãã èªååãããã¡ã«ããºã ã䜿çšããŠãæ¬çªã·ã¹ãã ã«ããŒã¹ã©ã€ã³æ§æã匷å¶ããäžæ£ãªå€æŽãé²æ¢ããå¿ èŠããããŸãã ããŒã¹ã©ã€ã³ã®å€æŽã¯ãå°æ°ã®æš©éãæã€Cloudflareã®æ åœè ã«éå®ãããå€æŽç®¡çããã»ã¹ã«åŸãå¿ èŠããããŸãã å€æŽã¯ç£æ»å¯èœã§ãªããã°ãªãããããŒã¹ã©ã€ã³æ§æããã®éžè±ãæ€åºããããã«å®æçã«ãã§ãã¯ããªããã°ãªããªãã
Cloudflareã¯ãæå°ç¹æš©ã®ååã䜿çšããŠæ å ±ã·ã¹ãã ã®ããŒã¹ã©ã€ã³ãæ§æããŸãã ããã©ã«ãã§ã¯ãã¢ã¯ã»ã¹èšå®ã¯ãdeny-allãã«èšå®ãããŠãããããã©ã«ãã®ãã¹ã¯ãŒãã¯ãCloudflareãããã¯ãŒã¯ãžã®ããã€ã¹ã®ã€ã³ã¹ããŒã«åããŸãã¯ãœãããŠã§ã¢ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ã€ã³ã¹ããŒã«çŽåŸã«ãCloudflareã®ããªã·ãŒã«åãããã«å€æŽããå¿ èŠããããŸãã ã·ã¹ãã ã¯ãåœéååæãŸãã¯åå®äžçæïŒUTCïŒã«åºã¥ããŠã·ã¹ãã ã®æéã¯ããã¯ãåæãããããã«æ§æãããæéããŒã¿ã®ä¿®æ£ãžã®ã¢ã¯ã»ã¹ã¯èš±å¯ããã人å¡ã«å¶éãããŸãã
ITã»ITã»ãã¥ãªãã£ã®å éšã¬ããã³ã¹ãšãããžã¡ã³ãã®ããã®æœç
Cloudflareã¯ãITã·ã¹ãã ã®èš±å®¹ããã䜿çšãšäžè¬çãªæ å ±ã»ãã¥ãªãã£ã«é¢ããå éšããªã·ãŒãç¶æããŸãã ã¯ã©ãŠããã¬ã¢ã¯ãå šåŸæ¥å¡ã«å¯Ÿããå°ãªããšãæ¯å¹Žãäžè¬çãªã»ãã¥ãªãã£ããã³ãã©ã€ãã·ãŒã«é¢ããæèåäžãã¬ãŒãã³ã°ãå®æœããããæ±ããŠããŸãã Cloudflareã¯ãå人ããŒã¿ã®åŠçãå¶éãä¿è·ããææžåãå®æœããŠããŸãïŒ
Cloudflareã®ããŒã¿ããã³æ å ±ã·ã¹ãã ã®æ©å¯æ§ãå®å šæ§ãçæ£æ§ãå¯çšæ§ãä¿è·ããæ¥åããµããŒãããããŒã¿ããã³æ å ±ã·ã¹ãã ã«å¯Ÿããã»ãã¥ãªãã£ç®¡çã®æå¹æ§ã確ä¿ããããã«ãæ£åŒãªæ å ±ã»ãã¥ãªãã£ç®¡çã·ã¹ãã ïŒISMSïŒãå°å ¥ããŸãã
Cloudflareã¯ã顧客æ å ±ã®åŠçè ããã³ç®¡çè ãšããŠãCloudflareã®ã°ããŒãã«ãããŒãžããããã¯ãŒã¯ãæ¯ããæ¹éããã³æç¶ãã®æ©å¯æ§ãå®å šæ§ãçæ£æ§ãå¯çšæ§ãä¿è·ããããã«ãæ£åŒãªãã©ã€ãã·ãŒæ å ±ç®¡çã·ã¹ãã ïŒPIMSïŒãå°å ¥ããŠããŸãã
Cloudflareã¯ãç£æ»ã«åãããŸã蚌æ ä¿å šã®ãããæè¡çã»çµç¹çæªçœ®ã®ææžãä¿ç®¡ããŸãã Cloudflareã¯ããã®éçšããè åã³åœè©²è·å Žã®ãã®ä»ã®è ããæ¬ä»å±æž2ã«å®ããæè¡çåã³çµç¹çæªçœ®ãèªèãããããéµå®ããããåççãªæªçœ®ãè¬ãããã®ãšããŸãã
ããã»ã¹ã補åã®èªèšŒã»ä¿èšŒã®ããã®æªçœ®
ã¯ã©ãŠããã¬ã¢ã®ISMSã®å®æœãšé¢é£ããã»ãã¥ãªãã£ãªã¹ã¯ç®¡çããã»ã¹ã¯ãæ¥çæšæºã§ããISO/IEC 27001ã®å€éšèªèšŒãååŸããŠããŸãã ã¯ã©ãŠããã¬ã¢ã®å æ¬çãªPIMSã®å®è£ ã¯ã顧客æ å ±ã®åŠçè ããã³ç®¡çè ã®äž¡æ¹ãšããŠãæ¥çæšæºã®ISO/IEC 27701ã®å€éšèªèšŒãååŸããŠããŸãã
Cloudflareã¯PCI DSS Level 1ã«æºæ ããŠãããCloudflareã¯ç¬¬äžè ã§ããQualified Security Assessorã«ãã£ãŠæ¯å¹Žç£æ»ãåããŠããŸãã Cloudflareã¯ãAICPA Trust Service Criteriaã«åºã¥ãAICPA SOC 2 Type IIèªèšŒãªã©ããã®ä»ã®èªèšŒãååŸããŠããããããã®èªèšŒãCloudflareãéæååŸããèªèšŒã®è©³çŽ°ã¯ãCloudflareã®ãŠã§ããµã€ãã«ãŠå ¬éãããŸãã
ãµãïŒããã»ããµãŒãžã®è»¢éã«ã€ããŠã¯ã管çè ïŒããã³ããã»ããµãŒãããµãããã»ããµãŒãžã®è»¢éã«ã€ããŠã¯ãããŒã¿ãšã¯ã¹ããŒã¿ãŒïŒã«æ¯æŽãæäŸã§ããããã«ãïŒãµãïŒããã»ããµãŒãåãã¹ãç¹å®ã®æè¡çããã³çµç¹çæªçœ®ã«ã€ããŠãèšè¿°ããããšã
å©çšéå§
ãªãœãŒã¹
ãœãªã¥ãŒã·ã§ã³
ã³ãã¥ããã£
ãµããŒã
äŒç€Ÿ