I have talked about this in various places, so I imagine many of you may be thinking, “I’ve heard this before…”
Currently, a Study Group on Personal Data[1] is being held by the Cabinet Secretariat. Its basic mission is to consider “how personal information can be made more widely usable,” and it forms part of the Abe administration’s third arrow. Because the meetings are open to the public, anyone can attend as an observer, but they reach capacity almost immediately, making admission something of a platinum ticket.
Among the matters under consideration are “(tentatively named) quasi-personal information” and “(tentatively named) data with reduced personal identifiability.” For the definitions, please refer to the technical working group’s interim report[2] (← an extraordinary piece of work and essential reading), produced under this study group. Roughly speaking, “quasi-personal information” means “information that, even if an individual has not been identified, carries a risk that the individual could be identified,” while “data with reduced personal identifiability” means “quasi-personal information that has been processed so as to have a low likelihood of identifying an individual, making it difficult to identify the individual.” The idea is then to allow such data to circulate without consent.
But, as I have continued to say, I wonder why there is so much fixation on “identification,” or on the type of data[3]. Put differently, the question is, “What was the objective again?”
Wasn’t the objective to
(1) “make it possible to use personal information without the person’s consent,”
(2) “provided that there is no adverse effect on the person (privacy impact)”?
This 1. could be stated a little more strongly as
(1a) provided that the benefits to the person outweigh the disadvantages,
or, incorporating the perspective of Article 13 of the Constitution, as
(1b) when the disadvantages to the person are within tolerable limits and the use promotes the public welfare,
either would be fine.
Seen in that light, regulating according to the type of data is not a particularly sound approach. That is because even with the same data, the benefits and disadvantages to the person, and the effects on public welfare, vary depending on how it is handled (the act involved).
Therefore, the essential starting point for thinking about this is to ask:
- Compared with not using it, does its use have an adverse effect on the person? If so, is that effect within tolerable limits, or can it be compensated for?
- Compared with not using it, does its use have a positive effect on the person and the public that outweighs the adverse effect on the person?
This is what is called a Privacy Impact Assessment (PIA).
Do this first.
And if the conclusion is that it is better to use the information, isn’t the important thing to ensure that you can always “explain” why that conclusion was reached? If so, there is no longer any particular need to distinguish quasi-personal information from personal information. To begin with, it is not necessarily the case that using quasi-personal information has a smaller privacy impact than using personal information[4], so there is little point in ranking them. Rather than classifying information, we should focus on the intent with which the information will be processed and on what kind of processing will be performed, evaluate it (conduct a PIA), and then decide whether or not to proceed. That seems better for the person concerned and easier for businesses as well…
[1] Study Group on Personal Data
[2] Study Group on Personal Data, Technical Study Working Group, “Consideration from a Technical Perspective of ‘(Tentatively Named) Quasi-Personal Information’ and ‘(Tentatively Named) Data with Reduced Personal Identifiability’ (Interim Report),” 2014/5
[3] In fact, I suspect the technical working group probably feels the same way.
In the
report cited above[2], the technical working group divides privacy infringements into
① cases in which a specific individual is identified from “(tentatively named) quasi-personal information” under some circumstances, resulting in an infringement of rights and interests
② cases in which rights and interests are infringed while no specific individual is identified from “(tentatively named) quasi-personal information”
these 2 types. It mainly discusses ①, stating that only ① can be discussed within the confines of technology. At the same time, however, it urges the parent study group to consider the issue, stating that “It is not the case that no infringement of rights and interests occurs if an individual is not identified.” and “Because questions such as what kind of information is ‘closely related to an individual’s personality’ fall outside the scope of the WG’s expertise, consideration of this issue isleft to the parent study group.” I believe the parent study group should listen sincerely to this message.
[4] If we compare a case where someone’s address and name alone are leaked with a case where their address and name are unknown and they cannot be identified, but they are recognized by a cookie, profiled as having a genetically high probability of developing heart disease, and offered only higher-priced insurance products, the latter clearly has the greater privacy impact.
Related posts

Outline of the Proposed Amendments to the Act on the Protection of Personal Information—From the Masao Horibe Information Law Research Society Symposium
Although this may still change, Councillor Sawaki of the Personal Information Protection Commission explained the current state of deliberations on the outline of proposed amendments to…

【Update】Italian Privacy Authority Orders Immediate Restriction on ChatGPT’s Processing of Italian Users’ Data
(Updated on April 2 at hour 16) At March 30 local time in Rome, the GPDP, Italy's supervisory authority for personal data protection(commonly known as the…

President Signs the U.S. Consumer Privacy Bill of Rights
On February 23, 2012 U.S. time, President Barack Obama signed the administration white paper “Consumer Data Privacy in a Networked World”. The paper sets out a…


You must be logged in to post a comment.