Tomorrow, 3/2, at OpenID BizDay #8, we will hold a roundtable discussion on “Practical Privacy Protection Considerations for Companies,” with Professor Masatomo Suzuki of Niigata University and Hiromitsu Takagi of AIST as our guests. As moderator, I hope that by asking them various questions, I can bring into focus how companies should engage with privacy in their business activities. Incidentally, the reason the OpenID Foundation Japan is doing this is that OpenID is a framework for obtaining consent plus a framework for providing attributes.
Plans are provisional and often change, but for now I plan to ask the following questions. Just reading these is exciting, isn’t it?!
Oh, and incidentally, this is a paid event. Register for the event here.
Q.1 There seem to be many relevant laws, including the Act on the Protection of Personal Information (scheduled for amendment this year), the Penal Code, the Consumer Contract Act, the law of obligations (scheduled for amendment this year), and tort law. Could you explain how they relate to one another? Even if something is acceptable under the Act on the Protection of Personal Information, it seems that other laws may often prohibit it, so complying with that Act alone does not appear to provide immunity. Please explain that aspect as well.
For example, although this appears to have been omitted from the current amendment, even if changing the purpose of use were permitted, detrimental changes are prohibited under the Consumer Contract Act, and the same applies under the law of obligations. It seems that if a company presses ahead merely because something is acceptable under the Act on the Protection of Personal Information, it may quite often become entangled in other laws. For example:
- Matters related to purposes of use: crimes involving electronic or magnetic records containing unauthorized commands, the Telecommunications Business Act, the Radio Act, the Civil Code (obligations), the Civil Code (torts), the Consumer Contract Act, and METI Q45
- Matters related to security management: the Unfair Competition Prevention Act
All of these must be taken into account when considering legal compliance. Our guests will explain how these laws relate to one another as well.
Q.2 I think a company’s business objective is not so much about the law itself as it is about enhancing brand value and earning greater appreciation for its products and services. Yet that seems quite disconnected from the current discussion surrounding the Act on the Protection of Personal Information. Why is that, and what are your views?
Companies operating internationally must consider not only domestic law but also the laws of other countries. That is quite a challenge. Moreover, in conducting business, simply obeying the law is not enough. What matters is earning consumers’ trust—in other words, establishing a brand. Obeying the law is a given; this is about going beyond that. International standards actually describe how to reach that level, but when I listen to public debate, this perspective seems to be entirely missing. What is the situation here?
Q.3 What is a “specific individual”? I have heard from various quarters that this was a major point of contention in the current amendment and that the intention is to narrow the scope of “personal information” as much as possible. Could you explain this concept in some detail?
At this point, we may move on to an explanation of the concept of linkability under ISO/IEC 29100.
Q.4 Does narrowing the scope of “personal information” actually benefit companies? When preservation of brand value is also considered, narrowing the range of information under consideration seems instead to increase risk.
I can understand the desire to “limit it as much as possible” if the only concern is compliance with the Act on the Protection of Personal Information. But as noted above, that is not sufficient, and personally I find this argument deeply troubling. Corporate and government representatives from nearly 80 countries created the ISO/IEC 29100 Privacy Framework, and this argument heads in exactly the opposite direction. That framework defines personally identifiable information (PII) very broadly as “any information that (a) can be used to identify the PII principal to whom such information relates, or (b) is or might be directly or indirectly linked to a PII principal”[1]. It even devotes an entire 1 section to identifying personal information that may be hidden. It then calls for assessing the privacy impact arising from how that “personal information” is used and taking measures appropriate to the level of risk. For example, sharing business-card information within a department for contact purposes is low risk, so proportionate measures are enough; by contrast, health-consultation information entrusted to a company requires very strong safeguards. When potential damage to brand value is also considered, I think this approach is far more practical.
Q.5 What form should publication, notification, and consent take before terms and conditions are changed?
Google, for example, kept publishing and sending notifications for months on end, while some businesses make changes almost unnoticed. Yet it is generally the former that gets criticized, which feels rather unbalanced. How far in advance of a change should a company begin making the details widely known?
Q.5 It appears that a new category called “anonymously processed information” will be introduced this time…. But “anonymous processing” that does not even require an opt-out would seem to be an even more limited form of aggregation, and that already appears permissible under the current law…. Could you explain this in detail?
I feel somewhat uneasy about the background from which this idea emerged and the way it was debated. It appears to start from the FTC’s 3 requirements, but I think they have been seriously misunderstood. Those requirements were never about allowing information to be provided to any party at will. They rest on Section 5 of the FTC Act, and the point is to have entities accept these 3 requirements so that the provision can be invoked against both data providers and recipients. As for the first condition, “de-identification,” it is preceded by extensive discussion explaining that there is no safe form of de-identification that makes re-identification impossible. The technical implementation therefore need not be especially strong; what matters is requiring an entity to declare that it has de-identified the data and, under the 2nd and 3rd requirements, to declare that it will not re-identify the data itself and will assume responsibility for ensuring that recipients do not do so either. This makes it possible to invoke Section 5 of the FTC Act. Discussing this in Japan, where there is no equivalent of Section 5 of the FTC Act, is another matter. If this is the approach Japan wants to take, it would need to amend the Antimonopoly Act so that the Japan Fair Trade Commission could intervene, or take some similar step.
Q.6 This concerns cross-border data transfers. I have heard that a globally operating company could run into trouble if it brings data on employees residing in the EU to Japan and conducts their performance evaluations in Japan. Is that so? How can this be done safely?
Well, the company could move the data to the EU and conduct the performance evaluations there. It has an EU subsidiary anyway, and could simply make that the headquarters instead, so one could argue that it makes little difference to the company.
Q.7 I understand that one of the proposed amendments to the Act on the Protection of Personal Information is to “add record-keeping obligations for both the provider & recipient when information is provided to a third party.” How far must companies go?
Consider the practicalities. Suppose attributes are shared through OpenID Connect / OAuth. The IdP should have a record of the recipient to which the attributes were provided. In principle, the RP should also have a record. After that, however, the data will often be placed into a database regardless of the route by which it arrived, and along the way the RP may also receive new information directly from the individual. At that point, it is no longer possible to tell where the information came from or for what purpose, so systems like these may require considerable modification. This is a classic example of how failing to practice privacy by design leads to severe costs later. ISO/IEC 29101, the Privacy Architecture Framework, likewise says that this must be properly designed from the outset….
[1] SOURCE: ISO/IEC 29100. 2.9 PII = any information that (a) can be used to identify the PII principal to whom such information relates, or (b) is or might be directly or indirectly linked to a PII principal
Related posts

Data Sustains Lives—MyDataConference 2026 Opening Address
The following is the opening address for the MyData Japan Conference 2026, delivered by Nat Sakimura in his capacity as Chair of the General Incorporated Association…

The MyData Conference 2026 Is This Wednesday. See You at Hitotsubashi Hall!
I have been posting announcements on X every few days, and the MyDataJapan Conference 2026 is this Wednesday. There are many highlights: Naohiro Fujie, Representative Director…

Unsubmitted Public Comment on the Call for Comments on the Draft First Report of the Youth Protection Working Group on Information Distribution in the Digital Space
July 823:59 was the deadline for the call for comments on the draft first report. I ended the FAPI WG early and23:40 began the submission process…
