Outline of the amended Personal Information Protection Act. April, 2016 Personal Information Protection Commission Japan

Similar documents
Overview of the Act on the Protection of Specially Designated Secrets (SDS)

PRIVACY BREACH MANAGEMENT POLICY

1 LAWS of MINNESOTA 2014 Ch 250, s 3. CHAPTER 250--H.F.No BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF MINNESOTA:

HIPAA PRIVACY TRAINING

NOTICE OF PRIVACY PRACTICES

Overview of. Health Professions Act Nurses (Registered) and Nurse Practitioners Regulation CRNBC Bylaws

POPULATION DATA BC. Privacy in Health Research. Caitlin Pencarrick Hertzman Population Data BC University of British Columbia CFRI, April 2012

Patient Privacy Requirements Beyond HIPAA

AGREEMENT BETWEEN: LA CLÍNICA DE LA RAZA, INC. AND MOUNT DIABLO UNIFIED SCHOOL DISTRICT

DIVISION I MANUAL. January

ELIGIBILITY INFORMATION DISCLOSURE AGREEMENT Shared Between Child Nutrition Program Sponsors. and. From to Effective Dates

OUR LEGAL DUTY PERSONS COVERED BY THIS NOTICE

NOTICE OF PRIVACY PRACTICES Occupations, Inc. 15 Fortune Road West Middletown, NY 10941

Export Control in Japan and CISTEC

NOTICE OF PRIVACY PRACTICES UNIVERSITY OF CALIFORNIA RIVERSIDE CAMPUS HEALTH CENTER

NOTICE OF PRIVACY PRACTICES

Recommended Principles and Standards for Restorative Justice Providers in Criminal Matters

PRIVACY BREACH GUIDELINES

NOTICE DEPUTY SHERIFF APPLICANTS

NOTICE OF PRIVACY PRACTICES

PATIENT NOTICE OF PRIVACY PRACTICES Effective Date: June 1, 2012 Updated: May 9, 2017

ADVANCED PLASTIC SURGERY, PLLC. NOTICE OF PRIVACY PRACTICES

ONE ID Alternative Registry Standard. Version: 1.0 Document ID: 1807 Owner: Senior Director, Integrated Solutions & Services

TITLE VI/NONDISCRIMINATION POLICY

CHAPTER 64. STANDARDS OF OPERATION FOR LOCAL COURT-APPOINTED VOLUNTEER ADVOCATE PROGRAMS

Information Sharing and HIPAA Compliance

The Code of Ethics applies to all registrants of the Personal Support Worker ( PSW ) Registry of Ontario ( Registry ).

POLICY STATEMENT PRIVACY POLICY

JOINT NOTICE OF PRIVACY PRACTICES

PRIVACY MANAGEMENT FRAMEWORK

Sign and return included forms. (Background Check Form, Authorization to Release Information Form, and Vehicle Use Agreement)

Approved by. The Board of Directors of RusnanoMedInvest, LLC. Minutes # 3 dated April 24, 2012

Introduction...2. Purpose...2. Development of the Code of Ethics...2. Core Values...2. Professional Conduct and the Code of Ethics...

FIREARMS TRAINING COURSE REQUIREMENTS TO OBTAIN A FIREARMS QUALIFICATION CARD

Guidelines of Application Form for the JICA Training and Dialogue Program

NOTICE OF PRIVACY PRACTICES

DATA PROTECTION POLICY (in force since 21 May 2018)

Bias Incident Response Protocol. I. Definitions

IOS - Recruitment and Testing Services

Note No. 15/2008 NEW YORK

The EU GDPR: Implications for U.S. Universities and Academic Medical Centers

OSH Laws and the Caribbean Courtroom

The Paramedics Act. SASKATCHEWAN COLLEGE OF PARAMEDICS REGULATORY BYLAWS [amended May 2, 2017]

HIPAA Notice of Privacy Practices

Funded in part through a grant award with the U.S. Small Business Administration

REGARDING THE DEPARTMENTAL REGISTER OF WANTED PERSONS, UNIDENTIFIED BODIES AND UNKNOWN HELPLESS PERSONS. 20 June 2006 No.

NURSING AND MIDWIFERY IN AFRICA

Welcome to Emergency Services E-911

Orthopedic Specialty Clinic, Ltd. Updated 05/2014

New Jersey Motor Vehicle Commission

AUSTRALIAN RESUSCITATION COUNCIL PRIVACY STATEMENT

Privacy and Security Orientation for Visiting Observers. DUHS Compliance Office

ERIE COUNTY MEDICAL CENTER CORPORATION NOTICE OF PRIVACY PRACTICES. Effective Date : April 14, 2003 Revised: August 22, 2016

Consumers at the heart of health care. 10 October 2014

The HIPAA Privacy Rule and Research: An Overview

New Jersey Motor Vehicle Commission

APPLICATION FORM ADVERTISED SUPPORT STAFF POSTIONS

always legally required to follow the privacy practices described in this Notice.

GENERAL ORDER DISTRICT OF COLUMBIA I. BACKGROUND

VOLUNTEER FIREFIGHTER APPLICATION

Employee Statement and Security Guard Application FEE $36

TWUMC APPLICATION FOR EMPLOYMENT PRE-EMPLOYMENT QUESTIONAIRE All questions must be answered completely with or without a resume.


CONSOLIDATED NATIONAL NUCLEAR SECURITY REPORT

ATI Annual Report. Report on the Access to Information Act AECL's Access to Information and Privacy Office UNRESTRICTED

Alberta Occupational Health and Safety Act Highlights of changes effective June 1, 2018

GEORGIA PEACE OFFICER STANDARDS AND TRAINING COUNCIL

PRIVACY BREACH MANAGEMENT GUIDELINES. Ministry of Justice Access and Privacy Branch

MSK Group, PC NOTICE O F PRIVACY PRACTICES Effective Date: December 30, 2015

IN THE COUNCIL OF THE DISTRICT OF COLUMBIA

Handout 8.4 The Principles for the Protection of Persons with Mental Illness and the Improvement of Mental Health Care, 1991

RESEARCH APPLICATION RESOURCE GUIDE

An Overview of Sterile Compounding. Marshall Moleschi, Registrar Ontario College of Pharmacists

Gilmer Independent School District 500 So. Trinity Gilmer, Texas Phone: (903) FAX: (903)

Draft Health Practitioner Regulation National Law Amendment Paramedic specific clauses

JOB DESCRIPTION. Day Unit St Rocco s Hospice Warrington. Orford Jubilee Neighbourhood Hub. Clinical Lead St Rocco s Hospice

Handling of Personal Information

NOTICE OF PRIVACY PRACTICES UNIVERSITY OF CALIFORNIA IRVINE HEALTHSYSTEM

Sign and return included forms. (Authorization to Release Information Form, Background Check Form and Vehicle Use Agreement)

Compliance Program Code of Conduct

COMMISSION OF THE EUROPEAN COMMUNITIES. Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

FREEDOM OF INFORMATION AND PROTECTION OF PRIVACY A. 38

Faculty of Health and Environmental Sciences FHES Undergraduate Addendum

BON SECOURS RICHMOND NOTICE OF PRIVACY PRACTICES

consultation A European health service? The European Commission s proposals on cross-border healthcare Key questions for NHS organisations

MANITOBA GOVERNMENT INVENTORY OF PERSONAL INFORMATION SYSTEMS WORKSHEET. Here are a few important pointers to help you fill out the Worksheet:

A Better You Counseling Services, LLC 1225 Johnson Ferry Road, Ste 170 Marietta GA

Chapter Two STATE FUNCTIONS FOR ENERGY EFFICIENCY PROMOTION Section I Governing Bodies

Practitioners may be recredentialed at any time, but in no circumstance longer than a 36 month period.

Guide to. Grant Aid Agreement Document. Section 39 Health Act, 2004 Section 10 Child Care Act, 1991 National Lottery

EQUAL OPPORTUNITY & ANTI DISCRIMINATION POLICY. Equal Opportunity & Anti Discrimination Policy Document Number: HR Ver 4

Privacy Rio Grande Valley HIE Policy: P1. Last date Revised/Updated 02/18/2016

Alberta Occupational Health and Safety Act Highlights of changes effective June 1, 2018

Medicare Supplement Plans

I. PURPOSE DEFINITIONS. Page 1 of 5

Pawling Central School District 515 Route 22 Pawling, NY (845) (845) Fax

SUMMARY OF NOTICE OF PRIVACY PRACTICES

New EU legislation on Medical Devices. Erik Hansson Deputy Head of Unit European Commission DG Health and Consumers 1

PRIVACY POLICY. 1. Privacy Statement

Accommodate reasonable requests you may have to communicate health information by alternative means or at alternative locations.

Transcription:

Outline of the amended Personal Protection Act April, 2016 Personal Protection Commission Japan

Agenda 1 Current Legal Framework of the Protection of Personal in Japan 2 Why was the Act on the Protection of Personal (PIPA) amended? 3 The Establishment of the Personal Protection Commission(PPC) 4 Outline of the amendment of the PIPA 5 What the PPC is going to do? 1

1. Current Legal Framework of the Protection of Personal Private Sector Public Sector Field-specific Guidelines Guidelines for A field Guidelines for B field Guidelines for C field Guidelines for D field Guidelines for E field National Government* 2 Incorporated Administrative Organs* 3 Local Governments Act on Protection of Personal Ch. IV to VI: Duties, Penal Provisions, etc. for Business Operators Act on Protection of Personal Ch. I to III: Fundamental Provisions, Responsibilities of National and Local governments, Measures for Protection of Personal Basic Policy on Protection of Personal *1 This framework is implemented until the amended Act on the Protection of Personal comes into force, which is within 2 years from the promulgation, September 9, 2015. *2 Act on the Protection of Personal Held by Administrative Organs *3 Act on the Protection of Personal Held by Incorporated Administrative Agencies, etc. 2

2.Why was the PIPA amended? Personal Protection Act (PIPA) came into force (2005) Circumstances have changed 1.Increased possibility of using personal data due to development of Technology Demand for clarifying the definition of personal information 2.Evolution of Big Data Demand for appropriate use of Big Data while protecting personal information 3.Globalization Demand for making rules on cross-border data transfer 3

3.Establishment of the Personal Protection Commission, Japan Personal Protection Commission Duty To take necessary measures to ensure the proper handling of personal information including MY NUMBER while taking into consideration the effective use of it. Organization An independent supervising authority of personal information protection Chairperson and 8 Commission members exercise their authorities independently 4

3.Establishment of the Personal Protection Commission, Japan (Cont.) PPC s duties Personal Protection Commission MY NUMBER Personal MY NUMBER Act is hold jurisdiction over by the Cabinet Office. Formulation & Promotion of Basic Policy Public Relations and Promotion Activities International Cooperation Report to the Diet etc. The PPC holds jurisdiction over Personal Protection Act. Administrative Organs and Local Governments guidance Assessment Report Specific Personal Protection Assessment Accreditation & Supervision* Accredited Personal Protection Organizations Businesses Supervision Supervision Supervision* Businesses Individuals Complaint Mediation Mediation Complaint* Mediation* Individuals *These duties start from when the amended Personal Protection Act fully takes effect. 3 5

3.Establishment of the Personal Protection Commission, Japan (Cont.) *Personal information protection is now under the supervision of the relevant competent Ministers according to the business field. These authorities will be aggregated to the PPC when the main amendments take effect. PPC Current Competent Ministers After the main amendments take effect PPC monitor/supervise monitor/supervise Personal relating to MY NUMBER Personal Personal relating to MY NUMBER Personal 6

4 Outline of the amendment of the PIPA1 Clearer definition of Personal Define in detail what Personal is, so as to remove any gray areas Personal name address Fingerprint data Facialrecognition data Passport number Driver s license number MY NUMBER (Individual numbers) date of birth =newly defined*= *Other information will be determined as personal information by Cabinet Order. 7

4 Outline of the amendment of the PIPA2 Newly Defined Sensitive Personal Sensitive is race, religion, medical history personal information which has potential to bring about unjustifiable discrimination or prejudice Require prior consent in obtaining Sensitive Personal consent Sensitive Personal 8

4 Outline of the amendment of the PIPA3 Set rules for utilization of De-identified De-identified information is information 1processed to be unidentifiable to said person 2prohibited from restoring said personal information *both conditions should be met Personal process De-identified restore 9

4 Outline of the amendment of the PIPA4 Globalization Set 3 permissible types of transfer of personal data to a third party in a foreign state 1Obtaining prior consent to do so 2The third party is in a state where regulation on personal information protection is considered to be equivalent to that of Japan. 3The third party maintains an internal personal information protection system consistent with standards set by the PPC. Set rules of the extraterritorial application of the Act Cooperation by the PPC in cross-border enforcement 10

4 Outline of the amendment of the PIPA5 Accredited Personal Protection Organizations The PPC discloses Personal Protection Guideline to the public. Hearing from multi stake holder when drafting the Guideline. Making a guidance and a recommendation to their member business operators for ensuring the Personal Protection Guideline is an obligation for the Organizations complaints about Member businesses operators Personal Protection Guidelines guidance, recommendation, etc. PPC supervise Accredited Personal Protection Organizations Member business operators 11

4 Outline of the amendment of the PIPA6 Other amendments Clarify the right to disclosure, correction and discontinuance of using personal data as a right of data subject claiming in a trial. Introduce criminal penalties for improper use of Personal databases, such as data theft or providing information to third parties etc., for wrongful gain. Apply to small business operators handling 5,000 or less items of Personal, which are not subject to the current act. 12

5 What the PPC is going to do? 1 Timeline January 1, 2014 September 9, 2015 January 1, 2016 Established the Specific Personal Protection Commission Promulgated the amended Act on the Protection of Personal Establish the Personal Protection Commission Supervision Competent Ministers 2017(TBD) The main amendments take effect Commission 13

5 What the PPC is going to do? 2 1. Drafting Cabinet Orders, Commission Rules and Guidelines Main topics stipulated in Cabinet Orders definition of personal identification code Main topics stipulated in Commission Rules details about provision to a third party in a foreign country details for ensuring traceability in relation to the provision to a third party with personal information standard to process personal data into de-identified data Main topics stipulated in Guidelines measurement specified to SMEs 14

5 What the PPC is going to do? 3 2. Mediation of complaints Establishment of handling complaints mechanism in cooperation with institutions which handle complaints from consumers such as; Accredited Personal Protection Organizations (42 organizations as of January 2016) National Consumer Affairs Center of Japan Consumer Affairs Centers 3. Promoting cooperation with foreign authorities Becoming an accredited member of international frameworks Having a dialogue and promoting cooperation with foreign authorities including EU DG Justice 15