データ処理合意書(広告内)

Agreement between

Contracting Party (hereinafter „Controller“)

and fraud0 (hereinafter „Processor“)

for the processing of personal data acting on behalf of a third party (“Agreement”). Definitions in the General Terms and Conditions or the service description also apply to this Data Processing Agreement. Definitions in this Data Processing Agreement apply only to this Data Processing Agreement. The company referred to as ”fraud0″ is listed as fraud0 GmbH, Sendlingerstr. 7, 80331 Munich, Germany.

1. 契約の対象および期間

1.1 本契約の対象

本契約は、管理者様のディスプレイキャンペーンにおけるユーザー情報やインプレッションのトラフィック収集、管理、および品質分類の記録を目的としています。このため、処理者(弊社)はGDPR第4条第2項および第28条に基づき、管理者様に代わって個人データを処理します。なお、本導入に先立ち、まずはトライアル期間として、管理者様にて弊社(fraud0)ソフトウェアの動作検証を行っていただきます。

1.2 契約期間

The duration of this Agreement (term) shall correspond to the duration of the main agreement.

2. 合意内容の仕様

2.1 データの種類

収集、処理、または利用する個人データは、以下の通りです。

  • 顧客データ:ログインデータ

  • ユーザーデータ

    • ブラウザおよびデバイス情報:デバイスの種類・モデル、メーカー、OSの種類・バージョン(iOS、Androidなど)、ブラウザの種類・バージョン(Chrome、Safariなど)、ユーザーエージェント、タイムゾーン、ネットワーク接続タイプ、ハードウェア識別子(MACアドレスなど)、IPアドレス、リファラーURL、フォント数、フォントのハッシュ値、プラグイン数、プラグインのハッシュ値、画面の幅・高さ、色深度、プラットフォーム、解像度の改ざん有無、言語またはOS、ブラウザで利用可能なプロパティ・API、広告ブロックの有効化状況、トラッキング拒否(Do Not Track)の有効化状況など

    • 管理者サイト上でのエンドユーザーの行動:サイト内アクティビティに関する情報、セッションID、セッション開始・終了時刻、タイムゾーンオフセット、ユーザーのコンバージョン状況など

2.2 対象者のカテゴリ

本契約の範囲内における個人データの処理対象となる、データ主体のカテゴリは以下の通りです。

  • Website visitors or app users,

  • Customers / Registered users

3. 管理者の指示権限とデータ処理の場所

3.1 The data is handled exclusively within the framework of the agreements made and in accordance with documented instructions from the Controller (cf. Art. 28 Para. 3 lit. a GDPR). Within the scope of the description of the data processing mandate in this Agreement, the client reserves the right to issue comprehensive instructions on the type, scope and procedure of data processing, which he can specify in more detail by means of individual instructions. Changes to the object of processing and procedural changes are to be jointly agreed and documented. Any additional expenses incurred are to be remunerated by the Controller on a time and material basis. The Processor may only provide information to third parties or the person concerned with the prior written consent of the Controller.

3.2. 口頭での指示は、管理者によって直ちに書面またはEメールで確認されるものとします。処理者は指示された目的以外でデータを使用することはできず、特に第三者への提供は認められません。ただし、適切なデータ処理に不可欠なバックアップコピー、およびEU法やEU加盟国の法律に基づく法的義務や保存義務の遵守に必要なデータは例外とします。

3.3 処理者は、管理者の指示がデータ保護規則に違反していると判断した場合、GDPR第28条第3項第2文に従い、遅滞なく管理者に報告しなければなりません。また、処理者は、管理者側の責任者によって当該指示が確認または修正されるまで、その実行を一時停止することができます。

3.4 The processing of the Controller data by the Processor takes place within the EU / EEA. The Processor shall be obliged to inform the Controller prior to the commencement of the processing of the Controller’s data of a legal obligation of the Processor to carry out the processing of the Controller’s data at another location, unless such notification is prohibited by law. The processing and / or transfer to a third country outside the territory of the EU / EEA or to an international organization requires the prior written consent of the Controller. In this case, the Processor shall also be obliged to ensure an adequate level of data protection at the place of data processing in accordance with the applicable statutory provisions and the interpretations thereof by courts and authorities or – at the Controller’s option – to give the Controller the opportunity to ensure an adequate level of data protection, including by concluding or acceding to standard EU contractual clauses.

4. 機密保持について

The Processor shall ensure that employees involved in the processing of personal data and other persons working for the Processor are prohibited from processing the personal data outside the scope of the instruction. Furthermore, the Processor shall ensure that the persons authorized to process the personal data have committed themselves to confidentiality or are subject to an appropriate legal obligation of secrecy. The confidentiality / secrecy obligation shall continue to exist after the termination of the Agreement.

5. 技術的・組織的安全管理措置

5.1 Within his area of responsibility, the Processor shall design the internal organisation in such a way that it meets the special requirements of data protection. He will take appropriate technical and organisational measures to protect the personal data of the Controller which meet the requirements of Art. 32 GDPR. In particular, the technical and organisational measures are to be taken in such a way that the confidentiality, integrity, availability and resilience of the systems and services in connection with data processing are permanently guaranteed. These technical and organisational measures are described in Annex 1 of this agreement. The Controller is aware of these technical and organisational measures and is responsible for ensuring that they provide an adequate level of protection for the risks of the data to be processed.

5.2 The technical and organisational measures are subject to technical progress and further development. In this respect the Processor is permitted to implement alternative adequate measures. In doing so, the safety level of the specified measures may not be undercut. Significant changes must be documented.

6. 再委託先

6.1 処理者による副処理者の起用および変更には、管理者の同意が必要です。管理者は、以下の通り副処理者の起用に同意するものとします。

6.1.1 管理者は、本合意書の別紙2に記載されている復処理者の起用に同意するものとします。

6.1.2 The Controller agrees to the use or modification of further Subprocessors if the Processor notifies the Controller of the use or change in writing (email sufficient) thirty (30) days before the start of the data processing. The Controller may object to the use of a new Subprocessor or the change. If no objection is made within the aforementioned period, the approval of the use or change shall be assumed to have been given. The Controller acknowledges that in certain cases the service can no longer be provided without the use of a specific Subprocessor. In these cases, each party is entitled to terminate the contract without notice. If there is an important data protection reason for the objection and if an acceptable solution between the parties is not possible, the Controller is granted a special right of termination. The Controller shall declare its intention to terminate the contract in writing to the Processor within one week after the failure to reach an agreeable solution. The Processor may remedy the objection within two weeks of receipt of the declaration of intent. If the objection is not remedied, the Controller can declare the special termination, which becomes effective upon receipt.

6.2 処理者は、再処理者との契約について、本契約と同等のデータ保護義務を課すものとします。これは、再委託の範囲内におけるデータ処理の性質や規模を考慮した内容でなければなりません。また、再処理者の義務は、書面または電子的手段により合意されるものとします。

6.3 本条項が定める再委託関係には、プロセッサーが契約履行の補助として第三者から提供を受ける付随サービス(電気通信サービス、保守・ユーザーサポート、清掃、監査、データ媒体の廃棄など)は含まれません。ただし、これらの付随サービスを外部委託する場合であっても、プロセッサーは適切な契約締結や監査を行い、コントローラーのデータ保護およびセキュリティを確保する義務を負います。

7. データ主体の権利

7.1 The Processor shall support the Controller within the scope of its possibilities in meeting the requests and claims of affected persons in accordance with Chapter III of the GDPR.

7.2 プロセッサー(処理者)は、コントローラー(管理者)からの指示がある場合にのみ、本委託契約において処理されるデータに関する情報の提供、データの訂正もしくは削除、またはデータ処理の制限を行うものとします。データ主体が、自身のデータの開示、訂正、削除、またはデータ処理の制限を求めて直接プロセッサーに連絡してきた場合、プロセッサーは遅滞なくこの要求をコントローラーに転送するものとします。

8. 処理者の協力義務

8.1 プロセッサー(処理者)は、GDPR第32条から第36条に定められている個人データのセキュリティ、データ侵害時の報告義務、データ保護影響評価、および事前相談に関する義務の遵守において、コントローラー(管理者)を支援するものとします。

8.2 GDPR第33条および第34条に基づく管理者の通知・報告義務については、以下が適用されます。処理者は、(i) 個人データの保護違反が発生した場合は直ちに管理者に通知する義務、および (ii) 違反が発生した場合、必要に応じてGDPR第33条および第34条に基づく管理者の義務の履行を適切に支援する義務を負います(GDPR第28条第3項第2文f項)。なお、管理者に関するGDPR第33条または第34条に基づく通知(個人データ保護違反の通知・報告)について、処理者がこれを行う場合は、本契約第3条に基づく事前の指示がある場合に限られます。

8.3 管理者がセキュリティインシデントに関する通知や報告を行う義務がある場合、処理者は管理者側の費用負担において、そのサポートを行うものとします。

9. プロセッサーのその他の義務

9.1 プロセッサーは、法令に基づきデータ保護役員を任命するものとします。当該役員はGDPR第38条および第39条、ならびにBDSG第38条および第6条に従って業務を行うことができます。コントローラーから要請があった場合、直接連絡ができるよう当該役員の連絡先を提供します。

9.2 処理者は、監督機関がGDPR第58条に基づき実施した監査および処分について、速やかに管理者へ報告するものとします。これは、監督機関がGDPR第83条に基づき処理者を調査する場合にも適用されます。

9.3 処理者は、定期的な自主点検を通じて、本契約の適切な履行状況を管理するものとします。特に、本契約の履行に必要な規則や措置の遵守、および必要に応じた適切な調整を徹底するものとします。

10. 管理者の情報開示および監査権限

10.1 管理者は、処理者が合意された義務を遵守していることを証明するために、GDPR第28条第3項h)に基づき必要な情報の提供を求める権利を有します。また、処理者との合意のもとで監査を実施、または個別に指定された監査人に監査を委託することができます。

10.2 両当事者は、プロセッサーがその義務の遵守および技術的・組織的措置の実施を証明するため、管理者に対して説得力のある実証資料を提出する権利を有することに合意します。このような資料には、最新の監査証明書、独立機関(監査人、監査法人、データ保護役員など)による報告書またはその要約、ITセキュリティもしくはデータ保護監査(ISO 27001など)による適切な認証、または所管の監督官庁が承認した認証などが該当します。

10.3 This shall not affect the right of the Controller to conduct on-site visits. However, the Controller shall consider whether an on-site inspection is still necessary after submission of meaningful documentation, in particular taking into account the maintenance of the Processor’s regular business operations.

10.4 管理者は、原則として事前に通知した上で、処理者の業務運営における本契約の遵守状況を抜き打ち検査により確認する権利を有します。処理者は、管理者の要請に基づき、監査義務の履行に必要な情報を提供し、関連文書を開示するものとします。

11. データの消去およびデータ媒体の返却

At the discretion and request of the Controller – at the latest upon termination of the contract – the Processor shall hand over to the Controller all documents, processing and operating outputs as well as data resources that have come into his possession in the context of the contractual relationship, or destroy them in accordance with data protection laws after prior approval. The same applies to test and scrap material. The protocol of the deletion must be presented on request.

契約終了後も、適切なデータ処理が行われたことを証明する文書は、定められた保存期間に従って処理者(Processor)が保管するものとします。また、契約終了時にこれらの文書を顧客に引き渡すことで、処理者の保管義務を免除することができます。

12. 免責事項

The parties’ liability under this Agreement shall be governed internally by the liability provisions in the Processor’s General Terms and Conditions, unless otherwise stated in the service description in the offer or in a separate agreement between the parties. For the external legal liability, the regulations according to Art. 82 GDPR apply.

別紙 1

Technical-Organizational Measures/ Safety Concept of fraud0

Table of contents

  1. Measures regarding the pseudonymisation of personal data

  2. Measures to ensure confidentiality

  3. Measures to ensure integrity

  4. Measures to ensure availability 

  5. Ensuring the resilience of systems

  6. Measures to restore availability

  7. Procedures for periodic review, assessment and evaluation

The following technical and organisational measures have been implemented by the Processor and have been agreed with the Controller.

1. Measures regarding the pseudonymisation of personal data

Pseudonymisation means the processing of personal data in such a way that the personal data can no longer be attributed to a specified data subject without additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.

Measures related to the pseudonymisation of personal data are:

  • Establish a strict privacy-by-design approach

  • Reduction of data collection to the extent necessary to achieve the purpose (data minimization). Regular review of the necessity of the data collection for the achievement of the purpose. Adaptation to  state of the art.

2. Measures to ensure confidentiality

Measures to implement the requirement of confidentiality include measures for access or admission control. The technical and organisational measures taken in this context shall ensure adequate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.

 

Measures implemented by fraud0 to prevent unauthorized access to data processing systems:

  • Personal and individual user login when logging into the system (Google Cloud)

  • Password procedure (specification of password parameters with regard to complexity and update interval)

  • Additional system login for certain applications

  • Automatic blocking of the clients after a certain period of time without user activity (also password-protected screen saver or automatic pause switch)

  • Electronic documentation of all passwords and encryption of this documentation to protect against unauthorized access

  • two-factor authentication

  • Regular software updates / patching

  • Regular vulnerability scans

The servers are hosted by Google Cloud in Frankfurt, Germany. This provider guarantees reliability and protection against unauthorized access to the physical infrastructure.

 

Measures implemented by the subprocessor Google Cloud can be found here: https://cloud.google.com/terms/data-processing-terms#appendix-2-security-measures

3. Measures to ensure integrity

Measures to implement the principle of integrity are, on the one hand, those which also belong to input control, but on the other hand, those which generally protect against unauthorised access or unlawful processing, destruction or accidental damage.

3.1 Transmission control

Measures to implement the principle of integrity are, on the one hand, those which also belong to input control, but on the other hand, those which generally protect against unauthorised access or unlawful processing, destruction or accidental damage:

  • E-mail encryption

  • Encryption of CD/DVD-ROM, external hard disks and/or laptops

  • SSL-/TLS encryption

  • Data protection-compliant destruction of data, data carriers and printouts

3.2 Input control

Measures to ensure subsequent verification and determination of whether, when and by whom personal data have been submitted, modified or removed in data processing systems:

  • Contracts governing the processing of personal data with Subprocessors in compliance with the law, containing appropriate control mechanisms.

  • Obtaining self-disclosure from service providers with regard to their measures for implementing data protection requirements

  • Written confirmation of verbal instructions

  • Recording and demand-oriented provision of corresponding actions performed on systems (e.g. log files)

  • Use of logging and protocolling evaluation systems

4. Measures to ensure availability

Measures to ensure that personal information is protected against accidental destruction or loss:

  • Use of centrally tested and approved standard software from secure sources

  • Regular data backups and mirroring processes

  • Hardware (in particular servers) is deactivated after an inspection of the data carriers used therein and, if necessary, after the relevant data records have been backed up.

  • Uninterruptible power supply (UPS) in the server room

  • Separate storage of data files collected for different purposes

  • Multilayered antivirus and firewall architecture

  • Emergency planning (emergency plan for security and data protection violations with specific instructions)

  • Fire/water and temperature detection system in the server rooms

  • Fire doors

5. Ensuring the resilience of systems

This includes measures that must be implemented prior to data processing by the processor. In addition, continuous monitoring of the systems is necessary and planned. 

The subprocessor Google Cloud has ensured the resilience of its systems through the following measures:

  • Load-Balancing

  • Dynamic processes and memory activation

  • Regular load tests of the data processing systems

  • Set the load limit for the respective data processing system in advance above the necessary minimum.

More information on the procedures can be found here: https://cloud.google.com/security/overview/

6. Measures to restore availability

To ensure recoverability, sufficient backups are required on the one hand, but also action plans that can restore ongoing operations in the sense of disaster scenarios on the other. The subprocessor Google Cloud has set up a multi-level backup system, including measures such as:

  • Daily backup of the entire server

  • Service Level Agreements (SLAs) with Subprocessors

  • Backup Process

  • Redundancy (e.g. Mirroring hard drives)

  • Firewall, IDS/IPS

  • Fire protection and hydration water protection

  • Monitoring von alarms

  • Failure/emergency/restoration plans

More information on the procedures can be found here: https://cloud.google.com/security/overview/

7. Procedures for periodic review, assessment and evaluation

Regular review, assessment and evaluation of the effectiveness of the technical and organisational measures taken to ensure the security of the processing shall be carried out within the framework of the implementation of:

  • Regular revisions of the safety concept

  • Information on emerging vulnerabilities and other risk factors, revision of risk analysis and assessment as appropriate.

  • Process controls through quality management

Contact details of the data protection officer: Thomas Schmid, Am Weizenfeld 9, 86316 Friedberg, Germany, info@tom-schmid.de Tel: 0821 – 60 80 316.

別紙2

fraud0の技術的・組織的安全対策

*In addition, the standard contractual clauses between fraud0 and Google Cloud EMEA Ltd. apply here for any data transfer to the US as a result of the decision of the European Court of Justice of 16.07.2020 (ECJ, 16.7.2020 – C-311/18 “Schrems II”, available under https://cloud.google.com/terms/sccs/eu-p2p) and Auth0, Inc. (available under this link), as well as additional measures, as far as this is necessary, to ensure an adequate level of data protection (see 3.4. of the Agreement).