Professor Natsui’s blog[1] carried commentary on Japan’s personal information protection legislation, framed as a review of the so-called “privacy freak book”[2]. I strongly agree.

The professor writes:

 We need to make the obvious, commonsense point that “the Act on the Protection of Personal Information is an administrative regulation” much more widely and thoroughly known.

Leaving legal professionals aside, I suspect this is not understood at all by the general public. That is why I gave this point considerable emphasis at the recent OpenID BizDay[3].

In many cases, returning to basics and considering the matter through the legal interpretation of tort law leads to a more reasonable conclusion.
(…[中略]…)
In doing so, the most helpful framework is still Prosser’s taxonomy; this kind of classical theoretical structure is in fact more useful.

Another good point is that it is actually highly compatible with technology. A taxonomy like this can be converted directly into “Objectives” and “Threat,” which also makes “Control” easier to design.

However, applying the Act on the Protection of Personal Information does not provide direct redress for harm suffered by the person to whom the personal information relates. That is not what this law is for. In my view, it has many defects and should be completely revised.

This may be something many people have felt but have been unable to say.
Lately, I too have been saying in various places, “Why not try writing it from a clean slate?” though.

What Japanese legal scholars should properly be doing, I believe, is exhausting every possible effort to determine whether the matter can somehow be addressed through the interpretation and application of the tort law prescribed in Japan’s Civil Code, particularly Article 723.

I truly agree with this as well. When talking with people in the United States, that is where the discussion begins. You also hear fairly often that effective privacy protection may work better in the United States than in the EU. Unlike the United States, however, Japan does not seem to have the various mechanisms needed in this area, so putting those mechanisms in place appears to be another task.

At the same time, there is also the need to address the WTO-loophole issue created by the EU’s use of data-protection administration. So, separate from substantive privacy protection, personal information protection law is of course useful as a diplomatic instrument for dealing with trade friction. If that is the case, though, we need to steer decisively in that direction. As things stand now, it all feels frustratingly half-hearted.


[1] Takato Natsui: “Masatomo Suzuki, Hiromitsu Takagi, and Ichiro Yamamoto, ‘Japan’s Personal Information: For Everyone Who Believes That Information That Identifies an Individual Is Personal Information’,” Cyberlaw Blog, (2015/3/23), http://cyberlaw.cocolog-nifty.com/blog/2015/03/post-bafd.html


[2] Masatomo Suzuki, Hiromitsu Takagi, and Ichiro Yamamoto, ‘Japan’s Personal Information: For Everyone Who Believes That Information That Identifies an Individual Is Personal Information’,  Shoeisha (2015/2/20)


[3] Natsuhiko Sakimura: ‘Seminar: Practical Privacy Protection for Companies—The Act on the Protection of Personal Information Does Not Provide Immunity,’ @_Nat Zone, (2015-03-01) http://www.sakimura.org/2015/03/2911/

 

Related posts