The 90th Computer Security and 38th Security Psychology and Trust Joint Research Meeting (Security Summit) gave me the opportunity to deliver an invited lecture on Day 2 entitled “Privacy Policies That Inform the Data Subject—Based on ISO/IEC 29184.”

I believe that Japanese companies generally publish what they call “privacy policies.” Unfortunately, however, many of these are designed to protect the companies that publish them and are utterly incomprehensible to ordinary people who are not accustomed to reading legal documents. A true “privacy policy,” by contrast, must tell the data subject and other stakeholders how the data will be handled.

In this lecture, I will explain what such a proper “privacy policy”—called a Privacy Notice in English—should be, drawing on the standard published in month 6: ISO/IEC 29184.

Please register to attend at https://service.kktcs.co.jp/smms2/m2event/ipsj1/201800408.

■Session: Organized Session (2) 14:30 – 15:30
(27) 2020-07-21 14:30-15:30
Invited Lecture: “Privacy Policies That Inform the Data Subject—Based on ISO/IEC 29184”
Nat Sakimura (Convenor, ISO/IEC JTC 1/SC 27/WG 5)

0721-Notice-and-Consent-ja-