I believe that the fundamental reason why personal data sharing and use can never gain speed is that the underlying setup is flawed.

Much of the time, it seems that, based on the premise that obtaining consent from individuals is impossible, organizations either try to use the data without permission and trigger an uproar, or abandon its use altogether. It is as though the only choices are to put an engine on a brakeless tricycle, accelerate, crash into a corner, burst into flames, and be wrecked, or to keep slowly pedaling it.

The assumption that “obtaining consent is impossible” could also be restated as the assumption that accessing the individual is effectively impossible due to cost. That would indeed be true if the received data were detached from any means of reaching the person. Yet while this may have been understandable in the age of paper, it is decidedly outdated in the age of the Internet of Things.

Various proposals have been made since around 2007 to break through this situation. One was the classic Consumer IdP model proposed in OpenID 2.0. In this model, attribute data is centralized at an Identity Provider, the person’s consent is obtained when data is provided from it, and that consent can be revoked at any time when necessary. The familiar Facebook Connect and Google OAuth are based on this model.

However, this model had 2 major challenges.

The first is that an IdP model “supported by advertising revenue” creates a conflict of interest between the user and the IdP. This can be said to have led to the criticism that “to Facebook, you are the product, not the customer.”

The other is that the conditions for using personal data are presented by the company using it in a difficult-to-understand manner without offering choices, so individuals cannot provide substantively valid consent.

One proposed answer to these challenges, advanced since around 2010, is the Personal Data Store/System (PDS). It emerged from the concept of VRM (Vendor Relationship Management), advocated by Doc Searls of Harvard’s Berkman Center. Put very roughly, this is a model in which, through an IdP that stands purely on the user’s side, the individual presents a personal-data-use license to a company and the company agrees to it. It was also discussed by the Ministry of Economy, Trade and Industry’s Personal Data Working Group. The issue of consent received particular attention there, and because it became the lead story in the Nikkei on May 10, 2013, many readers may remember it.

Meanwhile, several independent initiatives had also emerged in Japan. One was PS-Agent, which JIPDEC began advocating around 2011. Another, which was covered in the media and at TEDx in 2013, was the “Information Bank”.

Therefore, as 2014 begins, we would like to use the Japan Identity & Cloud Summit 2014 (#JICS2014) as an opportunity to explore this subject in a panel discussion. We will welcome Professor Hideki Sunahara of the Graduate School of Media Design at Keio University, who is deeply involved in the Information Bank concept, and Yoshihiro Sato, Business-IT Alignment Evangelist at Hewlett-Packard Japan, Ltd., who served as a member of the Ministry of Economy, Trade and Industry’s Personal Data Working Group.

We warmly encourage everyone who is available to join us.

Details

  • Date and time: January 15, 2014 (Wednesday), 15:40-16:40
  • Venue: Hitotsubashi Hall, National Center of Sciences (map)
  • Speakers:
    • Professor Hideki Sunahara, Graduate School of Media Design, Keio University
    • Yoshihiro Sato, Business-IT Alignment Evangelist, Hewlett-Packard Japan, Ltd.
    • Moderator: Natsuhiko Sakimura, Chairman, OpenID Foundation
  • Organizers: National Institute of Informatics and OpenID Foundation Japan
  • Sponsors: Ping Identity and NoSurrender
  • Supported by: Ministry of Education, Culture, Sports, Science and Technology; Ministry of Internal Affairs and Communications; Ministry of Economy, Trade and Industry; Information Processing Society of Japan
  • Registration: https://jics.nii.ac.jp/entry/ Select “Personal Data” for January 15 (Wednesday), 14:40-16:40.


View National Center of Sciences, Hitotsubashi Memorial Hall on a larger map

Related posts

Thoughts on the Benesse Personal Data Breach

It appears that children's and other personal data—up to 20.7 million records—was leaked[1] from Benesse. This is a thought-provoking incident in many respects. Let us consider…

Identity · 2014-07-11