“Optimal Solution” discussed the “joint use” of personal information under the Act on the Protection of Personal Information in his email newsletter. This is a surprisingly important point in practice, so I will address it here.

Take the case of an airline, for example (this was one of the first issues to arise with the EU Directive). Without this concept of “joint use,” things could become extremely cumbersome. That said, since I have not actively investigated the matter, I do not know how such joint use has been made “readily knowable to the person.” If even I cannot figure it out, it does not seem to be readily knowable, but…

I also serve on the Membership Information Committee of Josuikai, my university’s alumni association. The first issue we faced there was providing information to the various class representatives (for example, representatives for each graduating year). Needless to say, although these representatives are Josuikai members, whether data provided to Josuikai may in turn be given to them is a gray area. Ultimately, we decided to resolve the issue by invoking this concept of “joint use.” There is still some debate, however, over what form the “readily knowable” condition should take. If everyone were online, posting the information on the website would probably suffice. Since that is not the case, I expect we will notify members in the Josuikai bulletin. (What do you think about this, Mr. Tsurumaki?)
By the same token, this will likely affect the future flow of information between Josuikai and Hitotsubashi University, which has now become an independent administrative institution. It would probably be advisable to announce in advance that the university is also a “joint user.”

Returning to the law and the guidelines themselves, the notion of being readily knowable is rather tricky.

Example 1) Information is continuously posted in a location that can be reached in approximately 1 operation from the website’s home page.
Example 2) Information is continuously displayed or made available at an office reception desk or similar location.
Example 3) Information is published regularly in a widely distributed periodical.
Example 4) In electronic commerce, a link is continuously displayed on the webpage introducing the product.
(Source) Guidelines for the Economic and Industrial Sectors Pertaining to the Act on the Protection of Personal Information

In a case like Josuikai’s, examples 1) through 3) above would probably present no problem at all. With a dubious business, however, even if it did something like the above, the person concerned would not find out “readily.” It would obviously be easier if Digital Identity were more firmly established, but that is still several years away. I wish there were a better idea for handling this… Does anyone have one?

Related posts