It appears that children’s and other personal data—up to 20.7 million records—was leaked[1] from Benesse.

This is a thought-provoking incident in many respects. Let us consider a few of them.

  • The data concerns children.
  • It is data that, for various reasons, list brokers had become unable to obtain.
  • Actual harm to individuals has been confirmed.
  • The data has been confirmed to have circulated from party to party, and awareness of that problem has begun to grow.
  • This has occurred in the midst of revising the Act on the Protection of Personal Information.

Many of these points are raised in Mr. Kusunoki’s blog post, “The Missing Piece in the List-Broker Market That Benesse Filled[2], which I recommend reading. (As for circulation from party to party, I discussed the issue in this article 5 years ago[3], and it is gratifying to see that public awareness finally appears to be growing. In this incident, several businesses are selling the data, but at least 2 of them have servers at the same IP address and appear to be effectively the same entity. This is the kind of practice I pointed out 5 years ago, and could also be viewed as 1 piece of evidence that personal data laundering is taking place.)

Below are some brief thoughts on several of these points.

This has occurred in the midst of revising the Act on the Protection of Personal Information

The timing could hardly be more exquisite. The outline issued on June 24[4] listed the problem of “so-called list brokers” as an issue for continued consideration, and I suspect its priority will now rise. This problem also stems from the “gap” left open by Article 23, paragraph 2 of the Act (that is, the laundering problem I pointed out 5 years ago). Resistance from industry had been expected here, but now that an actual incident has occurred, I think the inevitable outcome may be to follow the textbook approach and close the gap.

Handling children’s data

This incident has also made the challenges surrounding children’s data impossible to ignore. Some experts have long made this point, but children’s data requires different treatment from adults’ data. There are several aspects to this.

The first is the direct risk arising from use of the data. Children are vulnerable in many respects. They have not yet developed the judgment needed to decide whether someone can be trusted. If information about such children is allowed to circulate freely, it could readily be used to deceive them. In view of this, children’s data should be handled more carefully than adults’ data. (Even if it does not require quite the same protection as the address of a victim of domestic violence.)

In that sense, I believe the acquisition of children’s data for purposes other than directly providing a service could be prohibited, treating it in a manner comparable to sensitive information.

Another point concerns the validity of consent.

In principle, both the collection and use of data should be based on the consent of the data subject. Children, however, do not have the capacity to give this “consent.” For convenience, a parent or another person gives consent on their behalf, but it is entirely possible that, once the child reaches adulthood, that consent will be contrary to their wishes. We must therefore remember that “parental consent” is “temporary consent” lasting only until the child acquires the capacity to consent. Seen in that light, consent given by a representative should always have an expiry date; once it expires, it would be natural either to obtain consent again or to delete the data. It may also be necessary to delete the data when use of the service ends.

We will need a thorough discussion of these matters and must build a consensus going forward.

Actual harm to individuals and circulation from party to party have been confirmed

In this case, it appears that people whose data was actually leaked have received sales calls and other communications from people who acquired it. Benesse apparently wants to recover the data to limit this harm, but once digital data has left one’s control, recovering it is virtually impossible. How, then, can harm to individuals be limited?

One idea would be to regulate the following “acts,” which in this case are:

(1) acquiring data from a third party without obtaining consent from the data subject or their representative

(2) using data without obtaining consent from the data subject or their representative

Regulating these 2 acts is one possible approach. If (1) can be achieved, circulation from party to party can be stopped to some extent at that stage. Furthermore, even if the list has already been acquired, (2) would prevent its holder from contacting those individuals and would improve the state of their privacy.

Data leaks are only a matter of time. The challenge is to ensure that harm is minimized even when they occur.

Many data breaches arise from inadequate access management. Since this incident is also described as “removal by an insider who was not an employee of the group,” I suspect there may have been such a problem. Of course, access management must be properly secured. It goes without saying that identity management provides the foundation for doing so. Yet identity and access management is currently treated with extreme neglect at many companies. Businesses would do well to learn from this incident and take the opportunity to review their practices—for example, asking, “We don’t have any shared accounts, do we?” or “We’ve disabled the default system accounts, haven’t we?” Security cannot be bolted on later. It must be incorporated from the design stage. Secure by Design (SBD) is essential.[5] (At the same time, Privacy by Design (PbD) is equally important, I might add in a small act of promotion as Japan’s 2 PbD Ambassador.)

However much we do, though, we are merely reducing the probability; we are not bringing it to zero. In other words, the question is not “whether data will leak,” but “when and how much data will leak.”

Therefore, when designing a regulatory system, we must assume that data will leak and design the system so that harm is minimized even when it does. Ultimately, that can only be accomplished by regulating “how data is used.”

As it happens, work to revise the Act on the Protection of Personal Information is now underway. To express my personal hope, I would like the system to be reorganized around regulation of “acts,” focusing on the data lifecycle—such as “how data is acquired” and “how data is stored”—with regulation of “how data is used” at its center.

 


[1] NHK, “Possible Leak of Up to 20.7 million Benesse Personal Data Records” (2014/7/9), http://www3.nhk.or.jp/news/html/20140709/k10015871611000.html

[2] Kusunoki, “The Missing Piece in the List-Broker Market That Benesse Filled” (2014/7/9), Going the Mixed-Breed Route, http://d.hatena.ne.jp/mkusunok/20140709/leak#seemore

[3] Sakimura, “Is the Act on the Protection of Personal Information Really That Full of Loopholes?” (2009/11/29), .Nat Zone, http://www.sakimura.org/2009/11/656/

[4] Prime Minister’s Office, “Outline of the Institutional Reform for the Utilization of Personal Data” (2014/6/24), http://www.kantei.go.jp/jp/singi/it2/kettei/pdf/20140624/siryou5.pdf

(The following was added on 2014/7/17.)


[5] In this particular case, it appears that proper access control and individual authentication were in place. Because each user had an individual account, the culprit was quickly identified (and arrested on 7/17). Access was limited to a particular room (= location authentication) and a particular PC (= device authentication), the data could not be extracted over the network, and according to the WSJ report[6], USB access had also been disabled. The security shortcomings appear to have been limited to excessively broad data access privileges and a lack of log monitoring. In other words, this appears to have been a failure of IAM policy configuration, followed by failures in operational policy configuration and in the operations themselves. Conversely, these failures may have resulted from overconfidence in the fairly robust physical safeguards. This could be described as the limit of traditional perimeter security, and it is also why security is said to need to be reorganized around Identity. (The text in blue was added on 7/23.)

[6] Jiji Press, “Involved in Developing Customer Database—Knowledge Misused to Bypass Safeguards; Warrant Sought for Temporary Systems Engineer by Tokyo Metropolitan Police” (2014/7/17 05:30JST), Wall Street Journal Web Edition http://jp.wsj.com/news/articles/JJ10231533482860533506220261489651978215431?tesla=y&tesla=y

Related posts