Yesterday, the “Ultra-Secure Systems Study Group” was held at the University of Tokyo.
Ultra-Secure Systems Study Group
(Representative: Shuichi Sakai, Dean of the Graduate School of Information Science and Technology, the University of Tokyo)
Information Law Subcommittee
(Chair: Masatomo Suzuki, Professor, Faculty of Law, Niigata University)Date and time: 2016/03/24, 17:00–20:00
Location: Engineering Building 2, 12th floor, Electrical Engineering Conference Room 4, the University of TokyoPresentation 1: Consistency Between “Anonymously Processed Information” and the Concept of Easy Collation in Personal Information (30 minutes)
Akiko Fujimura and Fumihiko Magata, NTT Secure Platform Laboratories
(Discussion: 30 minutes)Presentation 2: Definition of “Personal Information” (30 minutes)
Hiromitsu Takagi, National Institute of Advanced Industrial Science and Technology
(Discussion: 30 minutes)
I arrived late after deliberations from 1 p.m. to half past 5 p.m. at the Kikai Shinko Kaikan on the JIS X 29100 Privacy Framework, so I heard almost none of Ms. Fujimura’s presentation and listened to Mr. Takagi’s presentation.

The discussion continued quite passionately on topics including “collatability at the file level” and “linkability and identifiability.” To be honest, I could not keep up. I wondered whether this was because I was tired after 4 and a half hours of JIS deliberations. But as I listened, it also seemed that the speakers did not share the same background knowledge, their definitions of terms were at cross purposes, and the discussion was not connecting, making it even harder to follow. I therefore said that they should first define the terms properly, but time ran out almost immediately and we were effectively ushered out of the room.
Afterward, following the customary social gathering, I returned home and Mr. Takagi taught me various things from around 11 p.m. I learned about the evolution of Japan’s Act on the Protection of Personal Information and its original meaning as explained article by article—in Japan, it applies to databases in which items with a certain record structure accumulate—and that in the EU as well, under the Data Protection Directive and the proposed Data Protection Regulation, the scope consists of structured information contained in, or intended to be placed in, a filing system subject to automated processing. This finally connected with Mr. Takagi’s presentation at the study group.1
On the other hand, if that were so, I could not understand why the right to be forgotten against Google in the EU had been recognized under data-protection law. We discussed whether it might have been regarded as a structure consisting of (url, keyword).
In the end, we said good night at half past 5 in the morning, meaning that we had talked for a full 6 and a half hours.
Still, the EU judgment did not sit right with me, so after saying good night I studied it further on my own. What I found was that the scope of the EU GDPR and related rules seems somewhat different from what we had assumed in the conversation above. I would like an expert to check this again and explain it to me…
Let us look at the ICO documents “What is personal data? – A quick reference guide Data Protection Act 1998”2 and “Determining what information is ‘data’ for the purposes of the DPA”3. They state that the information covered is:
(i) information processed, or intended to be processed, wholly or partly by automatic means (that is, information in electronic form usually on computer);
(ii) information processed in a non-automated manner which forms part of, or is intended to form part of, a
‘filing system’ (that is usually paper records in a filing system)(Source) ICO, “What is personal data? – A quick reference guide Data Protection Act 1998”
Directive recital (27), and the more readable wording inherited by the GDPR, state:
The protection of individuals should apply to processing of personal data by automated means as well as to manual processing, if the data are contained or are intended to be contained in a filing system.
Files or sets of files as well as their cover pages, which are not structured according to specific criteria, should not fall within the scope of this Regulation.
This should be read as:
(The protection of individuals should apply to processing of personal data) by
(automated means)
as well as
(to manual processing, if the data are contained or are intended to be contained in a filing system.)
In other words, it covers “personal data (when processed automatically) and (when processed manually, if the data are contained or intended to be contained in a filing system).” The if-clause after the comma modifies “manual processing.” Furthermore, “filing system” here does not mean an information system. It ordinarily means paper files4. In the following sentence:
Files or sets of files as well as their cover pages, which are not structured according to specific criteria, should not fall within the scope of this Regulation.
“structured according to specific criteria” means having searchability, such as being arranged according to certain criteria; it does not mean forms of the same type or records in the same format.5
If so, contrary to the study-group discussion and our subsequent conversation, the legal structures in the EU and Japan differ, and there is no longer any mystery as to why the right to be forgotten against Google in the EU was recognized under data-protection law.
Still, it is difficult because so much background knowledge is required.
The EU judgment on the right to be forgotten against Google was based on data-protection law. By contrast, the Tokyo District Court’s ruling was not based on the Act on the Protection of Personal Information (because of its framework for dispersed information, it falls outside the Act’s regulatory scope), but instead on the application of tort law and related doctrines. The two outcomes look nearly identical externally, yet their legal structures are entirely different. I think it is unreasonable to expect anyone other than legal specialists to possess that background knowledge. On that morning after staying up all night, I became even more convinced that constructive discussion in an interdisciplinary setting such as the Ultra-Secure Systems Study Group requires carefully building a common foundation—including points like these—before beginning the debate; otherwise, it will be very difficult for the discussion to converge.
- We also discussed ISO/IEC 20889 and 29191; ISO/IEC 29100’s treatment of the relationship among PII, PII 2.0, and Personal Data; and the structure and thinking of the FTC Staff Report, but I will leave those topics for another occasion.
- https://ico.org.uk/media/for-organisations/documents/1549/determining_what_is_personal_data_quick_reference_guide.pdf
- https://ico.org.uk/media/for-organisations/documents/1609/what_is_data_for_the_purposes_of_the_dpa.pdf
- including manila files, of course, but also documents placed more loosely in a cabinet so that they can be searched for and retrieved according to certain criteria
- However, this concerns only manual processing, so whether information is “structured” is irrelevant when considering processing within an information system where it is processed automatically.
Related posts

Symposium on the International Standardization of Privacy and Personal Information Protection and Management Systems in Japan
Organizer: Information Network Law Association, Personal Information Protection Law Study Group Co-organizer: Masao Horibe Information Law Study Group Supported by: Institute of Information Security Purpose Japan…

The Provider Liability Limitation Act Has Become the Information Distribution Platform Act (May 10)
Following deliberations by the Ministry of Internal Affairs and Communications’ Study Group on Platforms, of which I was also a member, the amended “Provider Liability Limitation…

Appearing on NHK: MIC Study Group on Platform Services
The Ministry of Internal Affairs and Communications' “Study Group on Platform Services” began on October 19, 2018. In light of platform operators' recent provision of services…

You must be logged in to post a comment.