欧州連合
GDPR
General Data Protection Regulation
要点
The EU's baseline privacy law. It requires a lawful basis for processing personal data, and for cookies and trackers that means freely given, specific, informed and unambiguous prior consent.
地域
欧州連合
施行状況
In force since 2018
分類
ヨーロッパ・イギリス
遵守が必要な事業者
Any organization that offers goods or services to people in the EU or monitors their behavior, wherever the organization is based.
制裁
Up to €20 million or 4% of global annual turnover, whichever is higher.
主な義務
- Obtain prior, opt-in consent before non-essential cookies
- Make refusing as easy as accepting
- Keep records that prove consent
- Honor withdrawal at any time
- Respect data subject rights (access, erasure, portability)
ConsentX で GDPR に対応する方法
- 1
サイトをスキャンする
無料スキャンでサイト上のすべての Cookie とトラッカーを検出し、GDPR の下で何に同意が必要かを正確に把握します。
- 2
地域を判定する同意バナーを表示する
ConsentX のバナーを設置します。訪問者の地域を検出し、GDPR が求める同意の体験を自動的に表示します。
- 3
同意まではトラッカーをブロックする
訪問者が同意するまで、必須でない Cookie とトラッカーをブロックしたままにし、同意前には何も発火しないようにします。
- 4
改ざん検知可能な証跡を記録する
すべての選択は改ざん検知可能な同意レシートとして保存され、GDPR の監査で提示できます。
- 5
データ主体の請求に期限内に対応する
SLA タイマー付きの DSAR ワークフローを使い、開示、削除、オプトアウトの請求に法定期限内に回答します。