Kojiro Murakami1“A Study Toward a Typology of the Right to Information Privacy” is a peer-reviewed paper that broadly surveys previous theories of the right to information privacy, including the theory of the right to control one’s own information, and proposes a new typology that integrates them.

Overview

The overview is roughly as follows.

The Importance and Evolution of the Right to Information Privacy

  • The traditional “consent principle” and “notice-and-choice approach” were emphasized, but the spread of IoT and AI has made effective consent difficult.
  • Legal theories concerning the right to privacy have been affected. Although the theory of the right to control one’s own information had been dominant, changes in the recent information environment have prompted new views.

Typology of the Right to Privacy

  • The right to privacy can be divided into “information privacy,” “decisional privacy,” and “territorial privacy.”
  • The right to information privacy is classified into the following 3 rights:
    • The right to control one’s own information
    • The right to the proper handling of one’s own information
    • The right to keep private life undisclosed

Recent Theories and Critiques of Them

  • Koji Sato’s theory: The view of Koji Sato, who advocated the theory of the right to control one’s own information. It defines the right to privacy as “the right of an individual to decide the extent to which their information may be disclosed and used.” Based on the right to pursue happiness under Article 13 of the Constitution, information is classified into “inherent information”2 and “extended information”3 Inherent information requires particularly strong protection and, in principle, intervention by public authorities is prohibited; this theory emphasizes the distinction between inherent and extended information.
    • Critique: The concepts of “one’s own information” and “control” are vague, and the handling of extended information is especially unclear. It is unclear at what specific point the “misuse” or “aggregated use” of extended information constitutes an infringement of the right to privacy.
  • Tatsuhiko Yamamoto‘s theory: While viewing the right to privacy as the “right to control one’s own information,” he advocates the “structural review theory (system-control-right theory),” which focuses on the structure of information systems and databases. He argues that reviewing database structures and architecture can address their broad social impact. His view is also distinctive in understanding the substance of the right to privacy pluralistically and, given that inherent information can be derived from extended information, making extended information subject to control as well. Yamamoto’s view takes an approach based on whether a system has defects and is consistent with the Supreme Court judgment in the Basic Resident Registration Network case.
    • Critique: First, the theory is overly committed to defining the right to privacy in a unitary manner and lacks the flexibility to consider pluralistic views. Furthermore, the concepts of “one’s own information” and “control” are vague, and it is criticized as being too powerful because it subjects extended information to control without distinguishing it from inherent information.
  • Shinichi Doi’s theory: It understands the basis of the right to control one’s own information pluralistically, takes the 2-part classification of inherent and extended information as its foundation, and also suggests an intermediate category of information in some respects. It divides control into “control as a right to decide” and “control as a check,” with the former applying in principle only to inherent information. Another distinctive feature is its recognition of an interest in having personal information handled properly. This clarifies the right to control one’s own information and makes it more effective.
    • Critique: The status of the “right to have one’s own information handled properly” is unclear. The need to recognize this right broadly without distinguishing between “inherent information” and “extended information” is also questioned. Furthermore, the theory is said to lack a theoretical framework for privacy issues between private parties.
  • Tomonobu Otonashi’s theory: It criticizes the right to control one’s own information and reconstructs the right to privacy as the “right to have one’s own information handled properly.” It takes account of information environments involving IoT, big data, and the like. It models this right on Article 31 of the Constitution. In response, Murakami argues that it should be made concrete by reference to the OECD’s FIPs principles rather than modeled on Article 31 of the Constitution.
    • Critique: Although it grounds the “right to have one’s own information handled properly” in Article 13 of the Constitution, referring to the model of Article 31 of the Constitution is contradictory. Another problem is that it does not specify the circumstances in which the person’s consent is required. Finally, the theory is also criticized for being limited to relations between private parties and public authorities, making it difficult to apply between private parties.
  • Takayuki Kato’s theory: Seeking to reevaluate the right to privacy, it recommends the traditional right to privacy, the “right to keep private life undisclosed.” He analyzes case law under British, Irish, and Japanese law in detail, particularly praising the definition of and test for the right to privacy in the After the Banquet case. Where the right to privacy and freedom of expression conflict between private parties, recognizing a powerful right such as the right to control one’s own information would go too far, and it is appropriate to limit protection to the traditional right to privacy. He also recognizes a “right to receive personal information protection.”
    • Critique: First, the reevaluation of the “traditional right to privacy” is said to be inadequate for the new information environment. The scope of the traditional right to privacy is also vague, and specific standards for its application are unclear. Furthermore, the inadequate explanation of the substance of the “right to receive personal information protection” is also viewed as a problem.
  • Hiromitsu Takagi’s theory: It criticizes rights to privacy such as the right to control one’s own information and argues that data-protection legislation should be based on a “decision-oriented interest model.” He supports the views of Jon Bing and Frits Hondius and maintains that the core of the legal interest to be protected lies in the “principle of relevance.”
    • Critique: Traditional Japanese theories of the right to control one’s own information, such as Koji Sato’s theory, have tended to emphasize control over the “flow” of one’s own information, but perhaps they should be reconsidered so as to include control over the “content” of one’s own information (relevance, accuracy, completeness, and currency). With respect to Otonashi’s theory of the right to the proper handling of one’s own information, “relevance” may already be considered to some extent, but it seems appropriate to consider the propriety of the content as a whole, including accuracy, completeness, and currency.

Moving Beyond Either-Or Thinking

Having considered the above, Murakami advocates moving beyond either-or thinking.

Moving beyond either-or thinking means criticizing both Japan’s previous tendency to define the right to privacy in a unitary way and the either-or debate between the traditional right to privacy (the right to keep private life undisclosed) and the modern right to privacy (the right to control one’s own information), and recognizing that both should coexist. In particular, rather than classifying rights as old or new, it is reasonable to allow three rights—the right to control one’s own information, the right to the proper handling of one’s own information, and the right to keep private life undisclosed—to coexist according to their respective strength.

Pluralistic Theory of Foundations and a Typology of the Right to Information Privacy

The pluralistic theory of foundations is a position that understands the values supporting the right to privacy pluralistically and offers multiple foundations to address the diverse circumstances in which privacy may be infringed. For example, Tatsuhiko Yamamoto identifies “personal values,” “values related to building relationships,” and “community-constituting values.” Recognizing multiple values in this way strengthens the foundation of the right to privacy.

The typological theory is an approach that divides the right to privacy into several types corresponding to these pluralistic values. Kojiro Murakami classifies the right to privacy into 3 types—the “right to control one’s own information,” the “right to the proper handling of one’s own information,” and the “right to keep private life undisclosed”—and clarifies the relative strength of each right. This systematically organizes various privacy problems and is proposed as a framework capable of responding to advances in the information society.

A Tentative New Typology of the Right to Information Privacy

Basic Policy for Developing the Typology

First, the analysis is organized on the basis of the pluralistic theory of foundations. Specifically, it divides the foundations of the right to privacy into 3 categories: “① individual foundations (personal values and property values), ② relational foundations (protection of reasonable trust and expectations and protection of vulnerable people), and ③ social foundations (democratic values, values that restrain government authority, and anti-totalitarian values),” thereby seeking a rational typology.

Next, it classifies the right to information privacy into 3 rights—the “right to control one’s own information,” the “right to the proper handling of one’s own information,” and the “right to keep private life undisclosed”—and adopts a framework based on their relative strength. In descending order of strength, these are the right to control one’s own information, the right to the proper handling of one’s own information as an intermediate right, and the right to keep private life undisclosed as a weaker right.

Cases Between Private Parties and Public Authorities

Cases Involving Inherent Information

Inherent information is “information concerning the foundations of moral autonomy” and principally refers to sensitive information about an individual’s mind and body. When public authorities handle this information, the powerful “right to control one’s own information” should be recognized. In principle, the person’s consent is required to acquire or use inherent information, and rights to request disclosure, correction, and erasure of the information are also recognized. Structural review of information systems and databases is also important, and control extends to the “content” of information.

The “compelling-interest test” is applied as the standard of constitutional review, requiring the purpose to be indispensable and the means to be limited to the minimum necessary. In its Supreme Court judgment in the criminal-record inquiry case (April 14, 1981), the Court held that “criminal records and similar matters directly concern a person’s honor and reputation, and even a person with such a record is protected against its indiscriminate disclosure,” thereby recognizing strict protection for inherent information.

Cases Involving Extended Information

Extended information is “individual pieces of information about matters of external life that are not directly and deeply connected to the foundations of moral autonomy,” and the “right to the proper handling of one’s own information” should be recognized for the handling of such information. With reference to the OECD’s 8 principles, collection limitation, data quality, purpose specification, use limitation, security safeguards, openness, individual participation, and accountability should be ensured. The person’s consent is required only in cases of exceptional handling, and its scope is limited. Rights to request disclosure, correction, and erasure of extended information are also recognized, and structural review of information systems is necessary.

The “strict rationality test” or “rationality test” is used as the standard of constitutional review, with judgments based on the confidentiality and importance of the information in question and the nature of the regulatory action. In its Supreme Court judgment in the Basic Resident Registration Network case (March 6, 2008), the Court held that extended information such as name, date of birth, sex, and address has a low degree of confidentiality and was therefore constitutional under the rationality test; it also confirmed that there were no systemic defects.

Cases Between Private Parties

Between private parties, infringement of the right to privacy principally becomes an issue as a claim for damages under Article 709 of the Civil Code. In theoretical terms, because the doctrine of the Constitution’s effect between private parties is involved, the interests in conflict differ from those in cases involving public authorities. Accordingly, the paper proceeds on the basis of the 3 foundations advanced by the new pluralistic theory of effect (① individual foundations, ② relational foundations, and ③ social foundations).

Cases Involving Inherent Information

For inherent information, the individual foundations of “personal values” and “property values” are strongly recognized, while “social values” are also recognized to some extent. Although it depends on the case, it is appropriate to apply the strongest right, the “right to control one’s own information.” In principle, acquiring and collecting, retaining and managing, using, and disclosing and providing information without the person’s consent are unlawful. As a positive aspect of the right, requests for disclosure, correction, and erasure of one’s own information are also recognized, while structural review is required where information systems or databases are involved. In the HIV-testing case, for example, a company’s acquisition of information without the person’s consent was held unlawful.

Cases Involving Extended Information

Extended information has the individual foundations of “personal values” and “property values,” but they are not particularly strong. As in cases involving public authorities, the right to the proper handling of one’s own information applies. The substance of this right is modeled on the OECD’s 8 principles. Although the consent principle is not strictly adopted, rights to request disclosure, correction, and erasure of one’s own information are recognized to a certain extent. Structural review to safeguard information systems and databases is required as a condition of the right to proper handling of external information. In the Waseda University lecture attendee-list submission case, privacy rights were infringed because the information was disclosed beyond the purpose of use.

Cases Requiring Reconciliation with Freedom of Expression

Where reconciliation with freedom of expression is necessary, the right to information privacy often conflicts with freedom of expression. Particularly in cases involving media exposure of private life, it is appropriate to apply the “right not to have one’s private life indiscriminately disclosed” rather than the powerful right to control one’s own information. The judgment in the After the Banquet case identified the following 3 requirements as the test for infringement of the right to privacy: (i) the matter must be a fact of private life; (ii) judged by the sensibilities of an ordinary person, it must be a matter that the person would not want disclosed; and (iii) it must not yet be known to the general public. This balances the right to information privacy with freedom of expression.

Conclusion

It concludes that the right to privacy should be considered by dividing it into “information privacy,” “decisional privacy,” and “territorial privacy,” and that the right to information privacy in particular should be understood pluralistically and classified into 3 rights: the “right to control one’s own information,” the “right to the proper handling of one’s own information,” and the “right to keep private life undisclosed.” Taking the relative strength of each right into account, it positions the right to control one’s own information as the strongest and the right to keep private life undisclosed as the weakest. This view, which revises and develops the traditional theory of the right to control one’s own information, systematizes existing influential views rather than advancing an entirely novel theory.

Nevertheless, many issues remain, including defining the specific scope of inherent and extended information, further specifying the substance of the right to privacy, and clarifying the relationship between the right to information privacy and personal information protection legislation.

Footnotes

  1. Professor at the Institute of Information Security
  2. “information concerning the foundations of moral autonomy,” meaning “information concerning the fundamentals of an individual’s mind and body (so-called sensitive information), namely basic information about their thoughts, beliefs, mental state, and body, and information that could cause serious social discrimination”
  3. “individual pieces of information about matters of external life that are not directly and deeply connected to the foundations of moral autonomy.” Specifically, this is personally identifying information other than inherent or sensitive information.

Related posts