In connection with the “Number”/My Number system (it remains regrettable that so many media outlets still call it the “Common Number”), calls such as “Let the private sector use the ‘Number’!” and “Let us obtain the 4 pieces of information (name, date of birth, sex, and address)!” can be heard from one organization after another.
I have always believed that data only has value when it is moved and used, so I understand the sentiment. But I also think nothing will happen if people merely make demands. Put another way, what I want to ask is:
Has the groundwork for “private-sector use” been completed?
This was also mentioned on May 24, 2011 (Tuesday), on the 6F of the East Research Building at Keio University’s Mita Campus, at the GIE symposium “Considering the Common Number System and National ID System”: how do we ensure that companies receiving such information handle it properly?
Large corporations belonging to a certain business federation may be fine, but they are not the only companies in Japan. For example, if only large companies listed in TSE Section 1 could obtain the information, it would have to be called unfair. There are many small companies that handle information just as carefully as, or more carefully than, large corporations. (Conversely, there are also plenty of large corporations that do not….) A mechanism is needed to assess and ensure that each company handles information properly.
Such a mechanism, or framework, for ensuring trust is called a Trust Framework.
Typical conditions that a trust framework should satisfy include the following:
- Documented and published assessment criteria (organizational stability, information-handling standards, etc.) exist.
- An institution exists to accredit the people and organizations that perform assessments.
- People and organizations exist to perform assessments.
- People and organizations exist to be assessed.
- Assessment results are published.
If people are going to call for private-sector use of the “Number,” they must begin by establishing a trust framework like this.
Nothing will begin if all they do is demand to be given the data.
Should the private sector not first take action to establish such a trust framework and demonstrate that information can be handled safely [*1] within it?
[*1] When people say “safe,” there is a tendency to emphasize security alone, but it goes without saying that something cannot be called safe unless privacy is also handled properly. Whenever a system or business process is designed in the first place, both “Security Considerations” and “Privacy Considerations” should always be examined.
Related posts

Overview and Future Outlook of the Student ID Trust Framework
On May 17, 2012, the OpenID Foundation Japan Student Identity Trust Framework WG held “Trust Framework Seminar vol. 2: Use Student IDs to Provide Online Student-Discount…

Storage and Linking Operations for the Common Number/My Number
First, please look at the following Cabinet Secretariat diagram concerning My Number. The item labeled “number” is the My Number. In this diagram, the My Number…
E-Woman Roundtable: “Do You Support Introducing a National Numbering System?”
E-Woman's roundtable has begun. → Here This leading question is not good. For something like this to be meaningful, a vote must be taken after fairly…

You must be logged in to post a comment.