I am sometimes asked whether email addresses and telephone numbers are personal information. My answer to this question is:

Are you still wearing yourself out debating whether something qualifies as personal information?

That is my answer. From the perspective of actual management, spending time debating whether such things qualify as personal information is an utter waste of effort.

Naturally, an email address or telephone number is personal information if it is connected to an individual, such as when it is used by that person; otherwise, it is not personal information. Asking whether email addresses or telephone numbers in general are personal information is therefore the wrong question to begin with. The urge to ask such a question arises because Japan’s Act on the Protection of Personal Information uses ease of cross-referencing in its definition of personal information. But neither the EU’s GDPR, ISO/IEC 29100 (JIS X 9250), nor GAFA considers anything like ease of cross-referencing. What concerns them instead is “the potential for future cross-referencing.” The idea is that if information could potentially be linked to an individual, it should be treated as personal information. The reason is that if information is excluded from management because it cannot currently be cross-referenced, then when cross-referencing becomes possible in the future, no one will even know where that information is, leaving it impossible to manage and putting the organization in an untenable position.

Thus, from a management perspective, closely scrutinizing whether something qualifies as personal information is a poor approach. The proper course is to recognize personal information broadly, classify it by high or low risk, and apply measures appropriate to that risk. Whether a particular email address presents high or low risk depends on the purpose for which it is handled and the other data linked to it, so discussing its risk in isolation is meaningless.

For example, consider a case where an email address is linked to a login account. In that case, the email address must be treated as retained personal data. Whether it presents high or low risk, however, depends on the nature of the company’s service, so a risk analysis must be performed and countermeasures devised. The risk would be very high for an information site serving patients with a disease that could expose them to discrimination, while it would be low for a general newspaper subscription service.

It is important to meet the standard set by law. But that standard is merely the minimum required, and falling below it immediately makes the conduct unlawful. For normal operations, working right at the edge of noncompliance is far too dangerous. Organizations should operate with a sufficient safety margin. We have also entered an era in which doing so leads to customer trust.

One of the greatest problems facing Japanese organizations in personal information protection is that they become trapped and immobilized by the anachronism of debating whether information qualifies as personal information. Put differently, the real problem is a mindset that does not classify information by risk and can think only in the binary terms of maximum risk or zero risk. Let us break free of that as soon as possible and take the next step.

Related posts