The proposed amendment to the Act on the Protection of Personal Information was approved by the Cabinet on Tuesday and has been published[1].

Several problems with it have been pointed out. Today, I will discuss two of them:

1. The scope subject to regulation for anonymously processed information has not been set appropriately
2. The scope subject to the record-keeping obligation for provision to third parties has not been set appropriately

These are the 2 points I will address.

1. The scope of regulation for anonymously processed information has not been set appropriately

Professor Takagi has pointed out the problems concerning anonymously processed information in his diary entry “The Provisions on Anonymously Processed Information Are Half-Baked and Could Cause Serious Problems (The Future of Personal Data Protection Legislation, Part 15)”[2]. In short:

(1) Anonymization is an extremely broad concept that includes deleting some information and pseudonymization (Article 2, paragraph 9).

(2) An entity that creates a database from this information and uses it for business is called an anonymously processed information handling business operator (Article 2, paragraph 10). Note that this would include almost anyone.

(3) When creating a database of anonymously processed information:

(a) The personal information must be processed in accordance with standards prescribed by the rules of the Personal Information Protection Commission. (Article 36, paragraph 1)

(b) When anonymously processed information has been created, the categories of information concerning individuals contained in the anonymously processed information must be made public in accordance with the rules of the Personal Information Protection Commission. (Article 36, paragraph 3)

As written, this would require companies to follow a “method prescribed by the rules of the Personal Information Protection Commission” for an extremely broad range of uses, including analyzing personal information internally[3]. I think this is simply a bug, so naturally it will be fixed. Right? The process that causes bugs like this is also fairly clear, so I would like that to be properly fixed as well.

[1] http://www.cas.go.jp/jp/houan/189.html

[2] http://takagi-hiromitsu.jp/diary/20150310.html#p01

[3] I first noticed this only after Professor Takagi pointed it out to me somewhere. I clearly do not have a discerning eye, so I suppose I am unqualified to work at the Personal Information Protection Commission or anywhere like that.

Related posts