Zero Right to Refuse! From Medical History to Social Media—Shared with Companies Without Consent… The “Worst Legislative Amendment” That Steals Your Personal Information | FRIDAY DIGITAL

Zero Right to Refuse! From Medical History to Social Media—Shared with Companies Without Consent… The “Worst Legislative Amendment” That Steals Your Personal Information

  • Share on Twitter
  • Share on LINE
Before you know it, your medical history and social media activity are being shared with companies… At the government’s Digital Administrative Reform Conference held late last year, Prime Minister Takaichi, aiming to make Japan “the country where AI is easiest to utilize in the world,” instructed relevant cabinet ministers to amend laws and establish new systems to allow the private sector to use personal data held by the government.

Medical records and social media— …The Horror of No Consent Required

Medical records, prescription histories, online shopping histories, social media posts… This information—which pertains to personal privacy—will be provided to companies without the individual’s knowledge.

The “Amended Personal Information Protection Act” was passed and enacted at the House of Councillors plenary session on July 10 and promulgated on the 17th.This amendment includes “Special Provisions for Statistical Purposes (Statistical Provisions),” which allow personal information to be provided to third parties without the individual’s consent, limited to use for statistical compilation and AI development. Information security experts, medical professionals, and consumer groups have criticized the content of these provisions, arguing that they “threaten individual rights and interests.”

Professor Ichiro Sato of the National Institute of Informatics, who has been involved in the development of the Personal Information Protection Act as a member of an expert panel since 2015, states, “The statistical exception is designed to promote the expanded use of personal information,” and points out the following:

“Under the Act on the Protection of Personal Information, consent from the individual was generally required for the provision of personal data to third parties or for use for purposes other than those originally specified. However, under the Statistics Exception, consent is no longer required as long as the company receiving the personal information—the ‘recipient’—uses it for the purpose of compiling statistics or training AI models.Furthermore, the company acting as the ‘provider’ of the data is not required to process the data—such as through anonymization or pseudonymization. 

‘Sensitive personal information’—such as medical history, criminal history, political opinions, and religious beliefs—can lead to discrimination or disadvantage, so the individual’s consent is mandatory for its provision to third parties. However, since the provision of unprocessed raw data—including names and addresses—now no longer requires consent, the likelihood that sensitive personal information will not be adequately protected has increased.”

Furthermore, the barriers for companies from which personal information is obtained are extremely low. There are no government licenses, permits, or prior reviews, nor are there any restrictions based on the size or nationality of the business. Sole proprietors, overseas companies, and even law enforcement agencies can all be sources of personal information.

“Normally, for a change of this magnitude, the details of the amendment should have been made public—whether through thorough discussion in an expert panel or by soliciting public comments.However, this statistical exception seemed to emerge out of nowhere and was enacted without the public being shown the full picture. That is the impression I have.” (Professor Sato, as quoted below)

Is the Goal “Data Matching”? Individuals Left Completely Exposed…

The government’s stated aim in establishing this special provision through the recent amendment is to relax regulations on the use of personal information and promote the development of domestically produced AI. But is that really the objective? If the data is to be used for AI training or purely for statistical purposes, personally identifiable information such as names should not be necessary.

“While the government’s stated goal is to relax regulations on personal information, isn’t the real aim of companies seeking to utilize the data actually ‘data linking’? 

Companies that collect personal information will be able to perform ‘name matching,’ which links multiple data sets using names and other identifiers as keys. For example, they might collect ‘medical records’ from hospitals, ‘grades’ from schools, ‘purchase histories’ from e-commerce sites, and ‘posting histories with names’ from social media providers.By matching these data sets, a vast amount of profiling data—that is, a detailed portrait of an individual—can be created for a single person.”

It is said that data matching also makes it possible to identify specific individuals.

Generally speaking, name matching can be performed with just three pieces of information: ‘date of birth,’ ‘gender,’ and ‘zip code.’ This is because there are extremely few people within the same zip code area who match both the date of birth and gender. 

Let’s say a local store whose primary customer base is within a specific ZIP code area conducts an anonymous survey that asks only for date of birth and gender. If the store possesses data on local residents that includes their names and dates of birth, it can easily identify individuals simply by matching the data.”

Why was the obligation to delete names or anonymize data omitted, even though this is a law intended to “protect personal information”?

“It’s because so many companies wanted to be exempt from the obligation to anonymize data. This was a deregulation measure aimed at addressing that demand, and business organizations likely lobbied politicians strongly for it. As a result, the amendment ended up swallowing the business community’s demands whole. I have to say that.”

What kind of harm could occur if, in the worst-case scenario, a company that collected the data were to aggregate a person’s detailed private information through data matching?

“For example, a company might purchase the social media posting history of college juniors and seniors, analyze the content, and exclude them from the hiring process. Or, based on a purchase history of books related to illness, a company might infer the possibility of a disease with a high risk of recurrence or progression and refuse to issue insurance coverage. Depending on how companies utilize personal information, some people will suffer adverse consequences. 

There is also a risk that the data could be misused—such as through data leaks to unscrupulous businesses or criminal groups.”  

Sensitive personal information includes not only past criminal records but also information regarding victimization by crime. If individuals who are susceptible to fraud are identified through data matching and their information falls into the hands of specialized fraud groups like Tokuryu, we might see an increase in “Ore-Ore” scams.”

Through “data linking”—the process of connecting multiple data points—even casual, everyday shopping histories can become subject to surveillance. With just three pieces of information, companies can piece together a detailed profile of an individual, including their hobbies, preferences, and daily routines, creating a terrifying prospect that individuals could be completely exposed.

With extremely lenient penalties, citizens are left with no recourse

The provisions of the amended law state that exceptions apply to cases where “there is little risk of harming an individual’s rights and interests.” However, as Professor Sato points out, there are significant concerns regarding these exceptions.

“The Personal Information Protection Commission, which oversees the Personal Information Protection Act, is responsible for monitoring and supervising whether the data usage by the acquiring company infringes on an individual’s rights and interests. While the commission’s members include academics and former corporate executives, and its secretariat consists mainly of officials from various government ministries, it is doubtful whether this organization possesses the capacity for effective monitoring and supervision. 

In most cases where the Personal Information Protection Commission has issued administrative guidance, it only took action after the matter was reported in the media or following a whistleblower report. Can an organization that is unable to identify problems on its own truly fulfill its monitoring role?

Going forward, the Personal Information Protection Commission will be tasked with formulating specific regulations and guidelines.

“These rules and guidelines cannot exceed the framework of the law enacted by the Diet. For example, given the structure of the amended law, it would be impossible to include provisions in the guidelines such as ‘requiring a licensing system for data-providing businesses’ or ‘allowing opt-out.’ 

Furthermore, during the Diet deliberations on the amended law, the government stated in its response that ‘under the special provisions for statistics, it is permissible to transfer data from the source provider as-is.’ This has made it difficult to create regulations or guidelines based on the premise of prior data processing. In effect, the government’s response in the Diet has made it harder to implement safeguards.”

Penalties for both data providers and recipients are also lenient. Although a “surcharge system” was introduced as a financial penalty, in response to fierce opposition from the business community (Professor Sato), its application was limited to cases involving particularly egregious conduct, concrete violations, and at least 1,000 victims.

The amount of the surcharges was also capped at a level equivalent to the profits gained from the malicious acts. The economic deterrent effect is likely to be minimal.”

The introduction of a class-action lawsuit system—in which government-certified consumer groups would file for injunctions on behalf of individuals—was also shelved.

“Class-action lawsuits are a necessary system for redressing individual harm, but the business community opposed this as well. As a result, a situation has been cemented in which individuals who have suffered harm are forced to accept their losses without recourse. 

Going forward, there is a possibility that more businesses will engage in data usage that infringes on individuals’ rights and interests, assuming that affected individuals will simply accept their losses without recourse.”

Zero Right to Refuse! The Looming Darkness of a Surveillance Society

There are no legal safeguards, and individuals are not even granted the most basic right of refusal—the “opt-out” mechanism (a system allowing individuals to stop or refuse the provision of their personal information to third parties). It is fair to say that the public has been effectively cut off from any means of protecting their own personal information.

“Not only are individuals unable to refuse to provide information, but we can also anticipate a situation where companies asked to provide information will find it difficult to refuse. 

For example, if a social media operator is asked by law enforcement agencies to provide the posting histories, names, and email addresses of all members for ‘statistical purposes,’ the operator has no legal basis to refuse. Therefore, it’s best to assume that social media posts, as well as footage from street surveillance cameras and smart glasses, have the potential to be provided to law enforcement agencies.”

Professor Sato is further concerned about the advent of a society where citizens monitor one another, a consequence of the widespread adoption of smart glasses.

“Since smart glasses can record surrounding video and audio simply by facing a certain direction, I believe people will emerge who post such content online out of curiosity or grudges. As a result, people will become suspicious—wondering, ‘Am I being filmed?’—and some will become so intimidated that they restrict their own behavior. I believe the impact of the ‘statistical exception’ on society is by no means insignificant.”

Data from social media posts that people use on a daily basis could also be provided to third parties, such as companies, without the individual’s consent. It is foreseeable that the relaxation of domestic regulations could backfire, ironically leading to a situation where users migrate to major overseas IT companies that have stricter policies regarding the handling of information.

Will overseas IT companies end up winning it all?

The amended law strongly reflects the wishes of the ruling party and the business community. However, if they prioritize the immediate utilization of data to the point of failing to examine the risks on the opposite end of the spectrum… Professor Sato sounds the alarm, warning that “this could ultimately undermine the very foundations of the companies themselves.”

When users utilize a service, the deciding factor in whether they consent or not is ‘trust in the company.’ 

However, by uniformly loosening the regulations through this amendment, we may actually foster distrust among users and even erode the trust in reputable companies. For companies that have carefully built that trust over time, this must be a major setback.”

This is a grave situation for the business community. However, the miscalculation does not stop at the loss of trust in domestic companies. It is also foreseeable that, driven by distrust of domestic operators, the public will “shift toward overseas companies” as a form of self-defense—an ironic outcome.

“Overseas companies, which are exempt from the statistical exceptions, can actually be considered safer because they require proper consent when sharing data with third parties. In the end, the biggest beneficiaries may well be the major overseas IT companies that can easily access Japanese data. 

“Although this special provision was pushed through based on the interests of political and business circles, it’s simply too ill-conceived.”

▼ Ichiro Sato, Professor, Information Society Correlation Research Division, National Institute of Informatics; Doctor of Engineering. Completed his doctoral program at Keio University Graduate School in 1996. Served as a research assistant and associate professor at Ochanomizu University Graduate School, and as an associate professor in the Software Research Division at the National Institute of Informatics, before assuming his current position in 2006.He has served as chair of the Digital Agency’s “Expert Panel on Policy Evaluation,” among other roles.

  • Reporting and Text Sayuri Saito PHOTO Afro

Photo Gallery3 total

Related Articles