PIA system, method and program

The PIA system addresses the lack of PIA support by automating risk evaluation and countermeasure generation, enhancing the efficiency and accuracy of privacy impact assessments.

JP2025097360APending Publication Date: 2025-07-01CO CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023213508
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-19
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Current technologies lack support for implementing Privacy Impact Assessment (PIA), which is essential for evaluating the risk of personal information handling, as existing systems do not provide comprehensive tools for risk management and lack reference information, specialized knowledge, and there is a shortage of personnel with the necessary skills.

Method used

A PIA system that includes an acquisition unit for handling information and a risk information generation unit to evaluate the impact on privacy, utilizing risk templates and artificial intelligence for generating and presenting risk information, along with countermeasure suggestions.

Benefits of technology

Facilitates efficient and accurate PIA implementation by automatically generating risk information and countermeasures, reducing the burden on personnel and ensuring compliance with privacy regulations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025097360000001_ABST
    Figure 2025097360000001_ABST
Patent Text Reader

Abstract

To provide a technique that supports the implementation of PIA.SOLUTION: A PIA system (1) for performing information processing for evaluating the impact on privacy of an activity that handles privacy-related data, comprises an acquisition unit (121) for acquiring handling information that represents the content of the privacy-related data handled in the activity and a risk information generation unit (122) for generating risk information regarding the impact of the activity on privacy based on the handling information and presenting the risk information to a user.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a technology for supporting Privacy Impact Assessment (PIA).

Background Art

[0002] In conducting business, it has become essential to handle the personal information of users and clients. For example, Patent Document 1 discloses a personal information protection system for protecting the personal information of users in electronic commerce transactions via the Internet or the like.

[0003] By the way, when handling personal information, there is a risk of leakage of personal information. Therefore, in managing personal information, it is important to evaluate the risk of holding personal information. In such a situation, in recent years, the concept of "Privacy Impact Assessment (PIA)" has been attracting attention.

[0004] Privacy Impact Assessment (hereinafter referred to as PIA) is a risk management method for evaluating the impact in advance in order to reduce and avoid the risk of infringement of the rights and interests of individuals when starting or changing a business involving the collection of personal information and the like. It is important to incorporate a process of considering the perspective of protecting personal information and the like from the planning and design stages of the business into the life cycle of the business.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] However, at present, there is room for consideration because services and technologies for supporting the implementation of PIA are not provided. For example, Patent Document 1 only discloses a personal information protection system for protecting users' personal information in e-commerce transactions via the Internet or the like, and does not disclose a technology for supporting the implementation of PIA.

[0007] The non-limiting embodiments in the present disclosure are made in view of the above background and contribute to the provision of a technology for supporting the implementation of PIA.

Means for Solving the Problem

[0008] A PIA system according to an aspect of the present disclosure is a PIA system that performs information processing for evaluating the impact on privacy caused by an activity related to handling privacy-related data related to privacy, and includes an acquisition unit that acquires handling information representing the content of the privacy-related data handled in the activity, and a risk information generation unit that generates risk information related to the risk of the impact on the privacy caused by the activity based on the handling information and presents it to the user.

[0009] A method according to an aspect of the present disclosure uses a PIA system that performs information processing for evaluating the impact on privacy caused by an activity related to handling privacy-related data related to privacy, and includes a step of acquiring handling information representing the content of the privacy-related data handled in the activity, and a step of generating risk information related to the risk of the impact on the privacy caused by the activity based on the handling information and presenting it to the user.

[0010] A computer program according to an aspect of the present disclosure is a program for causing a computer to function as the above-described PIA system, and causes the computer to function as each unit.

[0011] Note that these general or specific aspects may be implemented in a system, method, integrated circuit, computer program, or recording medium, or may be implemented in any combination of a system, device, method, integrated circuit, computer program, and recording medium.

Advantages of the Invention

[0012] According to one aspect of the present disclosure, a technique for assisting the implementation of PIA can be provided.

[0013] Further advantages and effects in one aspect of the present disclosure will be clarified from the specification and drawings. Such advantages and / or effects are provided by some embodiments and the features described in the specification and drawings, respectively, but not necessarily all are provided in order to obtain one or more identical features.

Brief Description of the Drawings

[0014]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Embodiments for Carrying Out the Invention

[0015] Hereinafter, with appropriate reference to the drawings, one embodiment of the present disclosure will be described in detail. However, a more detailed description than necessary may be omitted. For example, detailed descriptions of well-known matters and redundant descriptions of substantially the same configurations may be omitted. This is to avoid making the following description unnecessarily redundant and to facilitate the understanding of those skilled in the art. Note that the accompanying drawings and the following description are provided to enable those skilled in the art to fully understand the present disclosure, and it is not intended to limit the subject matter described in the claims thereby.

[0016] 〔Embodiment〕

[0017] Hereinafter, the PIA system 1 according to this embodiment will be described in detail with reference to the drawings. The PIA system 1 is an information processing system for supporting Privacy Impact Assessment (PIA). First, an overview of Privacy Impact Assessment (hereinafter referred to as PIA) will be described.

[0018] <<Overview of PIA>>

[0019] PIA is performed, for example, when planning, constructing, renovating, etc. an information system involving the collection of personal information, to "pre-evaluate" the impact on the privacy of information providers and to promote the proper construction and operation of the information system.

[0020] In order to appropriately extract risks by PIA, for example, specialized knowledge is required regarding various privacy-related regulations including the Personal Information Protection Law, so it is not easy to implement.

[0021] Therefore, when conducting a PIA, although the implementing entities are each individually trying with their own interpretations and judgments, regarding PIA, the reading difficulty of the government-issued guidebooks and ISO standards is high, it is unclear where to start, and it is difficult to translate them into specific actions.

[0022] In addition, at present, there is a lack of reference information on best practices for PIA, and there is no PIA benchmark for the company's similar business types and similar services. Moreover, the information and data necessary for privacy risk analysis are scattered within the organization.

[0023] Furthermore, from the perspective of human resources, there is a shortage of personnel with the knowledge (laws, technologies) necessary for privacy risk analysis, personnel who understand the necessity and know-how of PIA, and personnel who can be responsible for the operation and management of PIA.

[0024] When conducting a PIA, first, the necessary information is sorted out, risks are evaluated based on the sorted information, and countermeasures are sorted out. After that, a report summarizing the evaluation results of the PIA is created, and the risk countermeasures are actually implemented.

[0025] As an example, the implementation of PIA includes the processes of "(1) data mapping", "(2) data flow sorting", "(3) risk identification", "(4) risk assessment", and "(5) risk countermeasure sorting". The outlines of each process are described below. It should be noted that each process described below is only an example, and the processes included in PIA and the content of each process are not limited to the content described below.

[0026] (1) Data mapping: In the process of data mapping, relevant documents (such as terms of use / privacy policy / contract, etc.) are checked. In addition, the basic information on the personal data to be utilized is sorted out.

[0027] (2) Data flow organization: It is organized regarding the parties handling personal data, the processing flow, communication with users, etc.

[0028] (3) Risk identification: Laws and regulations / rules related to the business field, such as the Personal Information Protection Law, guidelines, and relevant laws and regulations, are organized, and risks are extracted.

[0029] (4) Risk assessment: The identified risks are evaluated on two axes of impact degree / likelihood of occurrence and multiple levels (for example, four levels). Also, response policies (such as avoidance / reduction / retention, etc.) for each risk are organized.

[0030] (5) Risk countermeasure organization: Countermeasures for each risk (excluding retained risks) are organized.

[0031] After that, a PIA implementation result report is made. That is, a report on the PIA implementation results (for example, a PIA implementation report, related documents, etc.) is prepared and submitted. Furthermore, risk countermeasures are implemented. That is, the countermeasures for each risk organized in the PIA are implemented, and the implementation status is managed.

[0032] <<Overview of PIA System 1>>

[0033] PIA System 1 is a system that performs information processing for evaluating the impact on privacy caused by activities related to handling privacy-related data related to privacy.

[0034] Privacy-related data related to privacy refers to specific data actually handled in various activities. For example, data related to customers' purchase behavior, personal information provided in a new service enrollment campaign, or employee data submitted by employees in a company, etc., actual individual data (raw data, processed data, etc.) can be cited, but these are only examples and are not particularly limited. Also, regarding the content of the data, it is not limited to character data or numerical data, but also includes image data, etc., and the types of data are not particularly limited.

[0035] In addition, privacy-related data includes all data that should be handled with consideration for privacy. For example, privacy-related data includes not only personal information that can identify an individual, but also personal data that constitutes an aggregate of information including personal information, such as a personal information database, which is systematically configured so that specific personal information can be searched. In addition, data related to an individual that can be identified by an ID of a device or browser, or data related to an individual's actions and states, such as location information and purchase history, etc. are also included. As long as it is information that can be the subject of a PIA evaluation, there is no particular limitation.

[0036] The Ministry of Economy, Trade and Industry has published the "Corporate Privacy Governance Guidebook in the DX Era", and privacy impact assessment (PIA) is published together with cases as one of the privacy governance efforts.

[0037] In addition, the Personal Information Protection Commission has also published the "Points to Note in Accordance with the Significance and Implementation Procedures of PIA" and the "Data Mapping Toolkit" for appropriately managing personal data, which is promoting privacy governance in the private sector.

[0038] In addition, activities involving the handling of privacy-related data include, for example, business activities such as the collection of purchase history data through a purchase-related information processing system. However, it is not necessarily limited to business activities such as commercial transactions, and various activities other than business activities can also be targeted. For example, data of residents collected in various administrative procedures provided by the state, local governments, etc., data of children collected in schools, data of patients collected in hospitals, data of subscribers to long-term care insurance, etc. All activities involving the handling of various types of personal information and personally identifiable information (hereinafter sometimes referred to as business activities, etc.) can be the subject of PIA in this disclosure.

[0039] In addition, when conducting such activities, it is desirable to evaluate the impact on privacy in advance in order to reduce and avoid the risk of infringement of an individual's rights and interests. The PIA system 1 is a system for supporting such an evaluation. When developing or modifying various information processing systems (for example, a purchase history management system, etc.) that handle privacy-related data, the system design is carried out based on the specifications based on the results of the evaluation.

[0040] <<Configuration of PIA System 1>>

[0041] FIG. 1 is a block diagram showing an example of the functional configuration of the PIA system 1. The PIA system 1 is an information processing system constituted by an information processing device. The PIA system 1 may be constituted by one device or may be constituted by a plurality of devices. Also, when the information processing device is constituted by a plurality of devices, it is not necessary for each device to be provided in the same space such as the same room, and they may be provided in different rooms, different buildings, different regions, etc., and there is no particular limitation.

[0042] In FIG. 1, the PIA system 1 includes a server 10 and a user terminal 20. The server 10 is an example of an information processing apparatus in the present disclosure. The server 10 and the user terminal 20 are communicably connected via a network N1. The network N1 connecting the server 10 and the user terminal 20 is a wired LAN (Local Area Network), a wireless LAN, the Internet, a public switched telephone network, a mobile data communication network, or a combination thereof.

[0043] (Configuration of User Terminal 20)

[0044] In FIG. 1, the user terminal 20 includes a storage unit 21 and a control unit 22. The control unit 22 acquires various types of information (input information) input by the user of the PIA system 1 via an input device. In some cases, the fact that the information is input by the user via the input device may simply be described as being input by the user.

[0045] In addition, the control unit 22 presents to the user various types of information (output information) transmitted from the server 10 in response to the transmission of the information input by the user, by displaying the information on a display device. In some cases, presenting to the user by displaying on the display device may simply be described as presenting to the user. Further, the storage unit 21 stores information transmitted and received with the server 10.

[0046] (Configuration of Server 10)

[0047] The server 10 includes a storage unit 11 and a control unit 12.

[0048] (Storage Unit 11)

[0049] In addition to the information transmitted and received with the user terminal 20, the storage unit 11 stores information transmitted and received with other devices communicably connected via the network N1.

[0050] (Control Unit 12)

[0051] The control unit 12 includes an acquisition unit 121, a risk information generation unit 122, a risk template management unit 123, a risk information correction reception unit 124, a countermeasure-related information generation unit 125, a countermeasure-related information correction reception unit 126, a correction impact identification unit 127, a correction update unit 128, a countermeasure update unit 129, a correction notification unit 130, a related document information reception unit 131, a handling information correction reception unit 132, a data flow management unit 133, and a data flow correction reception unit 134.

[0052] Note that this is merely an example of the functional configuration of the PIA system 1 and does not necessarily have to include all functional blocks. For example, depending on the user's needs, if there are functions that do not need to be provided, a configuration with only a necessary combination of functional blocks may be sufficient.

[0053] <<Risk Assessment>>

[0054] The functions related to risk assessment by the PIA system 1 will be described below.

[0055] Here, as an example of activities involving handling privacy-related data, information processing by the PIA system 1 for evaluating the impact on privacy caused by business activities involving the collection of customer purchase-related data will be described. Note that the scope of PIA is not limited to activities involving the collection of purchase-related data as described above.

[0056] In the PIA system 1, as an example, activities related to handling privacy-related data may be defined as projects. FIG. 2 is a diagram showing an example of an input screen for project management information. In the example shown in FIG. 2, business activities for managing purchase data are defined as a purchase data management PIA project. As shown in the input field for the business overview in FIG. 2, this project involves multiplying the company's own purchase data by the settlement data received from the credit card company to understand what actions the company's members are taking at other companies. Note that the projects targeted by this disclosure are not limited to those that manage purchase data, but include all projects related to activities that handle privacy-related data, and are not particularly limited.

[0057] As an example in this embodiment, in the PIA system 1, the acquisition unit 121 acquires handling information representing the content of privacy-related data handled in business activities and the like, and the risk information generation unit 122 generates risk information regarding the risk to privacy due to business activities and the like based on the handling information and presents it to the user.

[0058] (Handling information)

[0059] The handling information is information representing the content of privacy-related data, which is specific data actually handled in various activities, and is information used to generate the risk information described later. In this embodiment, as an example of the handling information, information representing data set names and data items such as "purchase data", "purchase store", "purchase date and time", and "purchased goods" can be mentioned. Note that the above-described project management information (input information such as the business overview) may also be used as handling information for generating risk information.

[0060] The handling information is information that defines the content of privacy-related data, and in addition to the data type, it may also be various meta-information representing the attributes, characteristics, structure, meaning, relationships (including how it is handled, etc.) of the data. Also, the handling information is not limited to information such as the data set name and data item name. For example, as described above, project-related input information may also be used as handling information. Here, "handled" includes, for example, actions such as collecting, storing, using, providing, and discarding data, but may also include actions such as processing, and is not particularly limited.

[0061] Figure 3 is a diagram showing an example of an input screen for handling information. In the example shown in Figure 3, as an example of handling information, information "Purchase Data" is entered in the column for the data set name. Also, in the example shown in Figure 3, as an example of handling information, the specific purpose of data use is entered in the column for the purpose of use. Also, in the example shown in Figure 3, as an example of handling information, information "Purchase Store", "Purchase Date and Time", and "Purchased Product" is entered in the column for the items of the data set.

[0062] As shown in Figure 3, the data set defined as "Purchase Data" includes data items "Purchase Store", "Purchase Date and Time", and "Purchased Product", and this data set is used for the purposes of "data analysis (matching with customer information, purchase information, credit card company information, etc.)" and "utilization for product planning and marketing, analysis of purchase information at competing companies".

[0063] Note that the data set may also include other information such as the data type and project type. The project type is information representing the type of project, and for example, all project types related to activities involving privacy-related data, such as projects related to smart cities and projects related to information banks, are targeted and not particularly limited.

[0064] (Acquisition Unit 121)

[0065] For example, the input screen for handling information shown in FIG. 3 is displayed on the screen of the user terminal 20. When the user inputs handling information as shown in FIG. 3 via the user terminal 20, the acquisition unit 121 acquires the handling information input from the user terminal 20.

[0066] Note that, as a configuration mode in which the acquisition unit 121 acquires handling information, the configuration of acquiring handling information input by the user via the user terminal 20 is merely an example, and as will be described later, it can also be acquired by other configurations.

[0067] (Risk information)

[0068] The risk information includes risk items, for example, as information regarding risks related to the impact on privacy due to business activities. The risk items are used to evaluate the risk of the impact on privacy due to business activities. The risk items may be, for example, information directly representing the content of the risk of the impact on privacy due to business activities or the like, or may be content representing matters that require attention, and are not particularly limited with respect to the information used for evaluating the risk. In addition to the risk items, the risk information may also include information such as risk levels and risk maps, as will be described later.

[0069] FIG. 4 is a diagram showing an example of the risk information to be presented. In the example shown in FIG. 4, as the risk information, risk items, the scenes in which the risk items occur, the possibility, impact level, and risk level regarding the occurrence of the risk items, and links for displaying countermeasures are displayed.

[0070] In the example shown in FIG. 4, as an example, regarding the business activity of managing purchase data, there is a risk item that "when integrating and analyzing the company's personal data with other companies, it is necessary to obtain consent from the individual for third-party provision". Regarding this risk item, as shown by "collection" as the "scenario", it is shown that it occurs in the scenario of "collecting" privacy-related data corresponding to the handled information (for example, purchase data such as the purchase store, purchase date and time, and purchased goods).

[0071] Furthermore, regarding this risk item, regarding the occurrence of the risk, it is shown as "4" for "likelihood", "4" for "impact", and "8" for "risk level". These values numerically represent the evaluation of the risk in order to compare or make it easier to recognize the degree of "likelihood", "impact", and "risk level" regarding the occurrence of the risk with other risk items. These values of "likelihood", "impact", and "risk level" may have default evaluation values predetermined for each risk item.

[0072] Also, for example, the impact may be evaluated in four levels of "4: very large / 3: large / 2: medium / 1: small", the likelihood of occurrence may be evaluated in four levels of "4: occurs at any time / 3: often occurs / 2: may occur / 1: hardly ever occurs", and from the perspectives of impact and likelihood of occurrence, the risk level may be evaluated in three levels ("3: avoid / 2: reduce / 1: maintain"). Note that the evaluation of the impact and the likelihood of occurrence is not limited to four levels, and the risk level is not limited to three levels, and there is no particular limitation.

[0073] Regarding the countermeasure, the display of "+1" may indicate that one countermeasure has been added. For example, a link to the page displaying the countermeasure may be set in this text of "Countermeasure +1", and the countermeasure may be displayed when the user clicks on the text part of "Countermeasure +1". The details of the risk countermeasures will be described later.

[0074] (Risk Information Generation Unit 122)

[0075] Based on handling information (such as purchase data like the purchase store, purchase date, and purchased products, etc.), the risk information generation unit 122 generates risk information (such as the information shown in FIG. 4, etc.) regarding the risk to privacy due to various activities (such as business activities for managing purchase data, etc.) and presents it to the user.

[0076] For example, for each piece of information representing a data set included in the handling information acquired by the acquisition unit 121, information representing predetermined risk items, etc. (such as the risk content itself, information on the possibility and impact degree of the risk, etc.) by the user or artificial intelligence, etc. may be stored in the storage unit 11 in an associated manner.

[0077] Then, the risk information generation unit 122 may read out information on risk items, etc. corresponding to the data set included in the handling information acquired by the acquisition unit 121, and generate it as risk information, including information that defines or controls the display mode, etc. of the information on risk items, etc.

[0078] For example, for the data set "purchase data" included in the handling information, one or more risk items as shown in FIG. 4, and information such as the scenario, possibility, impact degree, risk level, and link information on countermeasures for each risk item may be set by the user in advance.

[0079] Then, when the risk information generation unit 122 determines that the handling information acquired by the acquisition unit 121 includes the data set of "purchase data", it reads out the risk items set for "purchase data", their scenarios, possibilities, impact degrees, risk levels, link information on countermeasures, etc. from the storage unit 11, and generates, for example, list display information as shown in FIG. 4 as risk information and presents it to the user. Note that the risk information is not limited to list display information, and may be information displayed for each individual risk item, and the display mode is not particularly limited.

[0080] Note that the configuration is not limited to the case where information on one or more risk matters as shown in FIG. 4 is set in advance by the user or the like for the dataset "purchase data", and information on one or more risk matters as shown in FIG. 4 may be set in advance by the user or the like according to the items of the dataset included in the single dataset "purchase data".

[0081] That is, when the dataset is "purchase data", for example, when the dataset includes three items, namely, "purchase store", "purchase date and time", and "purchased product", and when the dataset includes only two items, namely, "purchase store" and "purchase date and time", different configurations may be adopted in which information on risk matters and the like is set in advance by the user or the like. In that case, the risk information generation unit 122 may read out information on risk matters and the like corresponding to the content of the data items constituting the dataset included in the handling information acquired by the acquisition unit 121, and generate information representing the content to be presented to the user as risk information.

[0082] Further, for example, the risk information generation unit 122 may be configured to generate risk information using an artificial intelligence model (artificial intelligence function) such as a large language model. For example, the risk information generation unit 122 inputs prompt information including the dataset included in the handling information acquired by the acquisition unit 121 and information such as a data flow described later into a large language model (not shown), receives information on risks generated and output by the artificial intelligence function of the large language model, and presents that information to the user as risk information.

[0083] (Large language model)

[0084] Here, as an example of the artificial intelligence model, a large language model will be described. A large language model is a type of artificial intelligence used in the field of natural language processing. It statistically learns the probability distribution of words and sentences from a huge amount of text data and can generate a natural language output like a human for a given input (such as a prompt).

[0085] More specifically, a large language model is a type of deep learning model that is based on a computational model that mimics the functioning of neurons in the human brain, called a neural network. A neural network has a structure consisting of multiple layers, receives an enormous amount of input data, and learns patterns, thereby adjusting its parameters.

[0086] A large language model is composed of a huge neural network consisting of an enormous number of parameters and is a model trained using a large amount of text data. As a result, the large language model M will have language knowledge such as grammar, meaning, and context internally and will be able to generate an appropriate output for a given input. The large language model according to this embodiment is a model trained to generate appropriate risk information based on information to be handled and the like.

[0087] Note that the large language model may be included, for example, in the server 10, or may be configured to use functions provided by an external device communicably connected via the network N1 or the like, and is not particularly limited.

[0088] (Risk Template Management Unit 123)

[0089] In the PIA system 1, the risk template management unit 123 may manage a risk template including risk items used for evaluating risks regarding privacy impacts. Then, the risk information generation unit 122 may select a risk template based on the information to be handled and present, as risk information, the risk items included in the risk template or the risk template.

[0090] The risk template management unit 123 provides a function for managing risk templates. For example, the risk template management unit 123 can accept the registration of a new risk template or accept modifications to an already registered risk template. Also, when new risk information is registered, if the risk template management unit 123 receives a request from the user to read an existing risk template, it may display the received risk template as default information when registering the new risk information.

[0091] The risk template may be set according to various regulations such as the Personal Information Protection Law. Also, the risk template may be set according to various standards (for example, ISO / IEC 29314 (PIA guidelines), ISO / IEC 29184 (notification / consent for online services), JIS Q 15001 (P mark), JIS Q 27001 (ISMS), JIS Q 31010 (risk management), JIS X 9250 (privacy framework), etc.). Furthermore, the risk template may be set according to privacy protection-related guidelines. These templates related to privacy risks may be preset by the user, for example.

[0092] Also, the risk template is not necessarily set for each of the above regulations, standards, and guidelines, and may be set according to use cases, etc., and is not particularly limited. For example, as a risk template for the third-party provision of personal data, the privacy risk in the case of third-party provision of personal data may be templatized based on the Personal Information Protection Law. Also, as a risk template for the utilization of anonymized information, the privacy risk in the case of jointly using anonymized information may be templatized based on the Personal Information Protection Law. Or, as a risk template for the utilization of personal-related information, the privacy risk in the case of utilizing personal-related information may be templatized based on the Personal Information Protection Law.

[0093] Furthermore, as a risk template for the information bank service, the privacy risk when operating the information bank service may be templatized based on the Personal Information Protection Act, the guidelines for the operation of the Data Ethics Review Committee, etc. In addition, as a risk template for the medical version information bank service, the privacy risk when operating the information bank service that handles personally identifiable information may be templatized based on the Personal Information Protection Act, the guidelines for the operation of the Data Ethics Review Committee, etc. Note that these are just examples, and a configuration in which risk templates corresponding to other use cases, etc. are newly added by the user may be adopted, and there is no particular limitation.

[0094] FIG. 5 is a diagram showing an example of a screen for newly creating risk information. As shown in FIG. 5, the user can create new risk information from a risk template. For example, when the user selects any of the risk templates shown in FIG. 5 and presses the "Create from Template" button, the risk template management unit 123 reads out the information of the selected risk template and displays it as default information on the new registration screen for risk information. Note that in the example shown in FIG. 5, risk templates with template names such as "Third-party provision of personal data", "Utilization of pseudonymized information", "Utilization of personal-related information", and "Information bank service" are registered.

[0095] FIG. 6 is a diagram showing an example of the information included in a risk template. In the example shown in FIG. 6, the information included in the risk template with the template name "Utilization of pseudonymized information" is displayed. This risk template is a template that includes information on risk matters, etc. assumed when utilizing pseudonymized information.

[0096] Specifically, as shown in FIG. 6, the risk template of "utilization of anonymized information" includes, as risk items, "Is there a possibility that those without permission will access the co-use environment illegally?", "Is there no problem with the risk of identifying individuals by aggregating and integrating anonymized information?", "Is there no risk of identifying an individual from the segment information to be created?", "Will no illegal information be accumulated in the co-use environment?", "Does adding or acting on the company's personal information based on segment information not correspond to individual identification?", and other items. Also, in the example of the risk template shown in FIG. 6, information such as the risk scenario, occurrence possibility, impact degree, and risk level is included for each risk item.

[0097] For example, the risk information generation unit 122 may generate risk information by selecting a risk template registered in advance in association with the handling information acquired by the acquisition unit 121. For example, in the PIA system 1, anonymized information is registered in advance by the user as one of the information included in the handling information, and information for associating the risk template of "utilization of anonymized information" shown in FIG. 6 with the anonymized information is registered. Then, when the handling information acquired by the acquisition unit 121 is anonymized information, the risk information generation unit 122 can select the risk template associated with the anonymized information.

[0098] Note that a configuration may be adopted in which an artificial intelligence function such as a large language model autonomously determines and selects a risk template strongly related to the handling information. For example, when the risk information generation unit 122 inputs a prompt including the handling information acquired by the acquisition unit 121 into a large language model (not shown), a model that has learned about the relationship between the handling information and the risk template outputs a risk template related to the handling information, and the risk information generation unit 122 may be configured to select the risk template output from the large language model.

[0099] Then, the risk information generation unit 122 presents, as risk information, risk items included in the risk template via the user terminal 20, for example, as shown in FIG. 6. Alternatively, the risk information generation unit 122 may be configured to present, as risk information, once the information of the risk template (such as a list of related template names). In this case, when a specific risk template is selected by the user from the list of risk templates, the risk items included in the risk template may be displayed.

[0100] Note that in the PIA system 1, for the risk template shown in FIG. 6, for example, an edit button may be provided, and the configuration may be such that the content can be modified by pressing the edit button.

[0101] (Risk information modification reception unit 124)

[0102] In the PIA system 1, the risk information modification reception unit 124 accepts modifications to the risk information presented by the risk information generation unit 122 from the user. For example, in the example shown in FIG. 4, an edit button (a figure in the shape of a pen) is provided corresponding to each risk item, and when the user presses this edit button, a screen for accepting addition or change of information about the risk item is displayed. Then, the risk information modification reception unit 124 accepts the modification of the risk information from the user via this screen.

[0103] In addition, information such as scenes, possibilities, impact levels, and risk levels may be similarly modified. Furthermore, a new addition button for adding new risk items or the like may be provided, and the configuration may be such that the input of new risk items or the like is accepted when the user presses the new addition button, and there is no particular limitation. As a result, exceptional risk items or the like can be managed according to individual cases, so that not only the content of typical risk information set in templates or the like but also risk management can be more flexibly handled.

[0104] (Risk Map)

[0105] Also, in the PIA system 1, the risk information generation unit 122 may display map information regarding risks as risk information by mapping, with respect to risk items included in the risk information and used for evaluating risks regarding the impact on privacy, the degree of risk impact and the possibility of risk occurrence on a map with the axes of the degree of risk impact and the possibility of risk occurrence.

[0106] For example, as shown in FIG. 4, the risk information includes information on risk items, the possibility of risks, and the degree of risk impact. The risk information generation unit 122 can display the map information by mapping this information on a map with the axes of the degree of risk impact and the possibility of risk occurrence.

[0107] FIG. 7 is a diagram showing an example of map information regarding risks. As an example, the risk information generation unit 122 generates the risk map (map information regarding risks) shown in FIG. 7 as risk information and displays it via the user terminal 20. In the example of the risk map shown in FIG. 7, the horizontal axis corresponds to the axis of the possibility of risk occurrence, and the vertical axis corresponds to the axis of the degree of risk impact.

[0108] The possibility of risk occurrence is, for each risk item included in the risk information, the possibility that the risk of the content of the risk item occurs, and is evaluated in four levels: "1. Very high", "2. Certain possibility", "3. Somewhat high", and "4. Very high".

[0109] Also, the degree of risk impact is, for each risk item included in the risk information, the degree of the impact exerted by the risk of the content of the risk item, and is evaluated in four levels: "1. Negligible", "2. Limited", "3. Significant", and "4. Immense".

[0110] In the example of Fig. 7, the numerical values displayed within the square frames are arranged in a matrix. For example, for the bottom left square, the display of "1" indicates that there is one risk item with an evaluation of "1 (very low)" for the likelihood of occurrence and "1 (negligible)" for the impact level.

[0111] Similarly, for the upper right square, the display of "8" indicates that there are eight risk items with an evaluation of "4 (very high)" for the likelihood of occurrence and "4 (severe)" for the impact level.

[0112] In this way, by displaying it as a matrix map, the distribution of high-priority and low-priority risks for which countermeasures should be taken is presented visually and understandably, so that the user can easily recognize the existence of risks.

[0113] Also, in the example of the risk map shown in Fig. 7, a list of risks to be "avoided" is displayed. The risks to be "avoided" are the risk items among the risk items included in the risk information that should be avoided and for which some countermeasures need to be taken.

[0114] In the example shown in Fig. 7, the risk item "Is there a risk that an individual can be identified from the segment information to be created?" is cited as a risk item to be avoided. It can occur in the "provision" scenario and is at a high level both in terms of the impact level "4 (severe)" and the likelihood of occurrence "4 (very high)". And as for the status of countermeasures for the risk item, as currently being addressed and shown as "1 / 3", there are three countermeasures to be taken, and it indicates that the first one has been completed. Note that risk countermeasures will be described later.

[0115] Also, in the example shown in Fig. 7, as another risk item to be avoided, there is a risk item of "Is there a possibility that unnecessary information accumulates in the co-use environment?", which can occur in the "provision" scenario, and both the impact level "4 (severe)" and the occurrence possibility "4 (very high)" are at a high level. And as for the status of response to the risk item, it is completed, and as shown by the display of "2 / 2", there are two countermeasures to be taken, indicating that both have been completed.

[0116] In this way, as risk information, by displaying the list of risk items to be "avoided", the user can recognize at a glance the risk items with high priority to be addressed, including the scenario, impact level, and occurrence possibility, and moreover, can grasp the status of response. Therefore, for risk items with a high risk level, corresponding measures can be taken without omission or forgetting.

[0117] <<Risk Response Measures>>

[0118] Hereinafter, the functions related to the risk response measures by the PIA system 1 will be described.

[0119] (Countermeasure-related Information Generation Unit 125)

[0120] In the PIA system 1, the countermeasure-related information generation unit 125 generates countermeasure-related information related to the countermeasures to the risk for the risk items included in the risk information, which are the risk items used for evaluating the risk to privacy due to business activities, etc., and presents it to the user.

[0121] The countermeasure-related information includes, for example, information representing countermeasures for eliminating the risks listed as risk items in the risk information generated by the risk information generation unit 122 and countermeasures for reducing the risks.

[0122] FIG. 8 is a diagram showing an example of a screen on which risk countermeasure information is displayed. The countermeasure-related information generation unit 125 may generate, for example, as countermeasure-related information, a list of a plurality of risk countermeasures as shown in FIG. 8. Further, the countermeasure-related information generation unit 125 may generate, for example, as countermeasure-related information, information representing only the countermeasures for the risks included in one risk item, or may generate information representing all the countermeasures for the risks included in a plurality of risk items, and there is no particular limitation on the mode of presenting information to the user.

[0123] For example, information representing risk countermeasures or the like predetermined by a user, artificial intelligence, or the like may be stored in the storage unit 11 in association with the risk items included in the risk information generated by the risk information generation unit 122. Then, the countermeasure-related information generation unit 125 may read out information such as risk countermeasures corresponding to the risk items included in the risk information generated by the risk information generation unit 122, and generate information related to the risk countermeasures as countermeasure-related information. Note that the countermeasure-related information may be only information representing the risk countermeasures themselves, may be information including information such as the deadline of risk response, or may further be information including information defining the display mode and the like of these information. The countermeasure-related information may include, for example, action content, associated risk, person in charge, response date, response status, status (not implemented, in progress, awaiting approval, completed), and the like.

[0124] Further, for example, the countermeasure-related information generation unit 125 may be configured to generate countermeasure-related information by using the function of artificial intelligence such as a large language model. For example, the countermeasure-related information generation unit 125 inputs prompt information including information such as risk items included in the risk information generated by the risk information generation unit 122 into a large language model (not shown), receives information related to the risks generated and output by the artificial intelligence function of the large language model, and presents the information to the user as countermeasure-related information.

[0125] (Countermeasure-Related Information Modification Reception Unit 126)

[0126] In the PIA system 1, the response measure related information modification reception unit 126 receives modifications by the user to the response measure related information generated by the response measure related information generation unit 125. FIG. 9 is a diagram showing an example of a screen for receiving modifications to the response measure related information. For example, in the example shown in FIG. 9, as a response measure for the risk of "Is there a risk that unnecessary information will accumulate in the co-use environment?", a response measure of "When the analysis is completed, all data created in the co-use environment will be deleted" is input, but the user can modify the content of this input field. In addition, modifications such as the response period and the person in charge can also be received. That is, the response measure related information modification reception unit 126 receives modifications to the risk information from the user via this screen.

[0127] <<Response to Legal Amendments, etc.>>

[0128] Hereinafter, the functions related to the response of the PIA system 1 to legal amendments, etc. will be described.

[0129] (Amendment Impact Identification Unit 127)

[0130] In the PIA system 1, when a modification occurs in at least one of the privacy-related laws and regulations, standards, or guidelines, the amendment impact identification unit 127 can identify, based on a template including risk items used to evaluate the risk to privacy, a pre-amendment template set according to at least one of the privacy-related laws and regulations, standards, or guidelines before the amendment, and a post-amendment template set according to at least one of the privacy-related laws and regulations, standards, or guidelines after the amendment, among the risk items included in the risk information, the risk items affected by the amendment or the response measures to the risk of the risk items (risk response measures), and present them to the user.

[0131] That is, the amendment impact identification unit 127 can, for example, compare the risk templates before and after the amendment, identify the risk items and risk countermeasures affected by the amendment from the differences, and present them to the user.

[0132] For example, in the risk template, risk items corresponding to at least one of the laws, regulations, standards, or guidelines related to privacy are set. However, when the laws, regulations, standards, or guidelines are amended, the content of the risk items to be set in the risk template will also change. Therefore, when comparing the risk templates before and after the amendment, the content of the set risk items is different.

[0133] Therefore, in the PIA system 1, for example, when a risk item that was not included before the amendment is newly added after the amendment, the amendment impact identification unit 127 may identify the newly added risk item and present it to the user. Furthermore, the amendment impact identification unit 127 may identify the risk countermeasures set in association with the newly added risk item and present them to the user.

[0134] Alternatively, in the PIA system 1, for example, when a risk item that was included before the amendment is deleted after the amendment, the amendment impact identification unit 127 may identify the deleted risk item and present it to the user. Furthermore, in the PIA system 1, for example, even when the risk items included in the risk template are the same before and after the amendment, if the risk countermeasures set in association with the risk items are changed before and after the amendment, the changed risk countermeasures may be identified and presented to the user.

[0135] (Amendment update unit 128)

[0136] In the PIA system 1, the amendment update unit 128 can update the risk information based on the post-amendment template for the risk items affected by the amendment identified by the amendment impact identification unit 127.

[0137] For example, the correction and update unit 128 may regenerate the risk information using the corrected risk template. That is, the correction and update unit 128 may regenerate the risk information including risk items and the like included in the corrected risk template, and update the risk information by replacing the old risk information with the regenerated risk information.

[0138] (Countermeasure update unit 129)

[0139] In the PIA system 1, the countermeasure update unit 129 can update the countermeasure-related information related to the countermeasures against the risks for the risk items identified by the correction impact identification unit and present it to the user.

[0140] For example, the countermeasure update unit 129 may regenerate the countermeasure-related information using the countermeasures against the risks (risk countermeasures) set in association with the risk items included in the corrected risk template. That is, the countermeasure update unit 129 may regenerate the countermeasure-related information including the risk countermeasures set in association with the risk items included in the corrected risk template, and update the countermeasure-related information by replacing the old countermeasure-related information with the regenerated countermeasure-related information.

[0141] (Correction notification unit 130)

[0142] In the PIA system 1, when a correction occurs regarding at least any one of the privacy-related laws and regulations, standards, or guidelines, the correction notification unit 130 can notify the information regarding the correction.

[0143] For example, when a correction occurs regarding at least any one of the privacy-related laws and regulations, standards, or guidelines, for example, information regarding the correction may be transmitted from the server managed by the vendor of the PIA system 1 to the PIA system 1. Then, when the correction notification unit 130 receives the information regarding the correction, it notifies the information regarding the correction via the user terminal 20.

[0144] <<Information Extraction from Related Documents>>

[0145] Hereinafter, the function of extracting information from related documents by the PIA system 1 will be described.

[0146] (Related Document Information Reception Unit 131)

[0147] The PIA system 1 further includes a related document information reception unit 131 that receives the input of related document information regarding related documents related to business activities and the like, and the acquisition unit 121 may acquire handling information based on the related document information.

[0148] Related documents refer to various documents that contain information corresponding to handling information. For example, documents such as service use agreements, service use terms, privacy policies, and service operation policies can be cited as examples, but are not particularly limited thereto.

[0149] By the way, for one business activity, a plurality of related documents such as service use agreements, service use terms, privacy policies, and service operation policies are prepared, and in each related document, the words representing the information corresponding to the handling information are not necessarily unified.

[0150] For example, when the word "purchase data" is used as the handling information used by the PIA system 1 to generate risk information, in one related document, it may be expressed as "purchase data" just like the handling information, and in another related document, it may be expressed as, for example, "data of purchase", "purchase-related data", or "purchase history data". That is, there are variations in the notation of the words representing the same thing as the handling information used by the PIA system 1 to generate risk information, and in each related document, it may be expressed in different words.

[0151] That is, as an example, the handling information represents what is used when generating risk information in the PIA system 1 (for example, a dataset set for generating risk information, etc.), and the information corresponding to the handling information represents the same content as the handling information included in each related document (for example, information at the stage extracted from the related document, etc.).

[0152] Note that the above is merely an example. For example, when the terms "purchase data" and "purchase history data" have different meanings in each related document and need to be distinguished, each term may be mapped to different handling information.

[0153] Examples of the information corresponding to the handling information include, among the information included in the related text, information representing, for example, the responsible department, personal information name, personal information items, purpose of use, disclosure status, presence or absence of information requiring special consideration, medium, acquisition route / method, storage location, storage method, access right holders, usage period, storage period, entrustment / provision / joint use, return / disposal method, etc., but are not particularly limited thereto.

[0154] The related document information related to the related document may be, for example, the related document itself. That is, the related document information reception unit 131 may receive the input of an electronic file such as a service use agreement. The process of the acquisition unit 121 acquiring the information corresponding to the handling information from an electronic file such as a service use agreement as the handling information will be described later.

[0155] Also, the related document information may be an address that can access the related document itself (such as an Internet URL or an address indicating the file storage location on the in-house network). In this case, the related document information reception unit 131 receives the input of an address that can access the related document itself. The acquisition unit 121 may use this address to access the related document and acquire the handling information.

[0156] The acquisition unit 121 may, for example, discriminate and extract information corresponding to the handling information from among the information included in the related documents input as the related document information, and acquire it as the handling information. The acquisition unit 121 may, for example, use the functions of artificial intelligence such as the large language model described above to extract information corresponding to the handling information included in the related documents. The large language model is a model that has been learned to discriminate and extract information handled in the business activities, etc. from among the information representing the content of the business activities, etc. in the related documents.

[0157] In the case of implementing PIA for a business activity that handles customer purchase data, the large language model can determine, for example, from project-related information such as the project name and business overview registered in the PIA system 1, that it is a business activity that handles purchase data. Therefore, the acquisition unit 121 may use the large language model to discriminate and extract information related to the purchase data from among the related documents input as the related document information as information corresponding to the handling information.

[0158] The acquisition unit 121 may acquire, as it is, the information corresponding to the extracted handling information as the handling information. For example, when there is only one related document or when the same words are used in a unified manner in a plurality of related documents, the acquisition unit 121 may acquire, as it is, the information discriminated and extracted as the information corresponding to the handling information as the handling information.

[0159] For example, the acquisition unit 121 may be configured to acquire as the handling information by automatically registering the information discriminated and extracted as the information corresponding to the handling information in the columns such as the dataset name and dataset items in FIG. 3. In this case, for example, when a dataset editing screen with input items similar to those in FIG. 3 is launched, the acquired handling information is input as default information.

[0160] In addition, for example, even when there are fluctuations in the expressions of words representing the same content in a plurality of related documents, or when there are words with a usage frequency of a certain level or higher as words representing the same content, the acquisition unit 121 may extract information corresponding to the handling information and acquire it as the handling information.

[0161] (An example of data mapping)

[0162] Data mapping refers to the work of organizing the data handled by a business operator across the entire business operator and visualizing the handling status and the like. Visualization is performed by creating a data mapping table or the like, and the Personal Information Protection Commission has disclosed an example of a data mapping table. The items of the data mapping table include, for example, but are not limited to, the name of the data, the handling department, the person in charge, the number of people, the items of the data, the purpose of use, the classification of the data, the presence or absence of personal information requiring special consideration, the person to whom the data belongs, the method of obtaining the data, consent for third-party provision, etc.

[0163] Regarding the automation of data mapping, various methods are assumed, and any conceivable method is applicable to the present disclosure. As an example, the acquisition unit 121 may be configured to acquire handling information using data mapping information in which candidates for handling information that may be used when performing a PIA are widely listed. This configuration will be described below using, as an example, a business activity that handles customer purchase data.

[0164] Note that the data mapping information may be in tabular form, for example. Hereinafter, an example using a data mapping table, which is data mapping information in tabular form, will be described. However, the data mapping information does not necessarily have to be in tabular form and is not particularly limited.

[0165] For example, when conducting a PIA on business activities that handle customer purchase data, as candidates for handling information that may be used to generate risk information, the data set name "purchase data" and data items such as "purchase store", "purchase date and time", and "purchased item" may be listed in the data mapping table stored in the storage unit 11.

[0166] For the automation of data mapping, the acquisition unit 121 uses an artificial intelligence function such as a large language model to determine whether information corresponding to the listed "purchase data", "purchase store", "purchase date and time", and "purchased item" is included in the relevant document and extracts it. For example, even if terms such as "data related to purchases" or "purchase history data" are used in the relevant document, the large language model may determine that such terms correspond to the "purchase data" of the data set in the PIA system 1 based on the context, etc.

[0167] Here, it is assumed that the acquisition unit 121 uses a large language model to determine that the information corresponding to "purchase store" is not included in the relevant document, while the information corresponding to "purchase data", "purchase date and time", and "purchased item" is included in the relevant document, and extracts the information corresponding to "purchase data", "purchase date and time", and "purchased item".

[0168] In this case, the acquisition unit 121 may associate and register the "purchase data", "purchase date and time", and "purchased item" included in the data mapping table with the information corresponding to the "purchase data", "purchase date and time", and "purchased item" included in the relevant document (for example, terms such as "data of purchase", "date and time of purchase", and "item purchased") and update the data mapping table.

[0169] Then, the acquisition unit 121 may acquire, as handling information, "purchase data", "purchase date and time", and "purchased item" to which information corresponding to the handling information is mapped among the information listed as candidates for handling information in the updated data mapping table. Also in this case, for example, when a data set editing screen with input items similar to those in FIG. 3 is launched, the acquired handling information may be input as default information.

[0170] Alternatively, for example, the acquisition unit 121 may use an artificial intelligence function such as a large language model to automatically determine and extract the items of the data mapping table from related documents based on the summary information of the PIA (such as the summary information of the project) included in the prompt input by the user, thereby generating the data mapping table. There is no particular limitation.

[0171] (Example of existing system / DB linkage)

[0172] Also, the related document information may be information regarding related documents that are pre-input in an existing information processing system or database that is linked to the PIA system 1. For example, as the related document information, information corresponding to the handling information included in each related document may be pre-input in an existing information processing system or database that is linked to the PIA system 1 in association with related documents such as service use agreements.

[0173] Also, the related document information may be such that information corresponding to the handling information included in each related document is input by the user to the PIA system 1 in association with related documents such as service use agreements and stored in the storage unit 11. Alternatively, the storage unit 11 of the PIA system 1 may be configured to copy information corresponding to the handling information included in each related document in association with each related document from an existing information processing system or database that is linked to the PIA system 1.

[0174] In addition, the acquisition unit 121 identifies the related document corresponding to the related document information for which the input has been received, and acquires information corresponding to the handling information included in the related document from the storage unit 11. Note that a configuration in which a storage device or database of an information processing system that cooperates with the PIA system 1 functions as the storage unit 11 of the PIA system 1 may be adopted, and there is no particular limitation.

[0175] Then, for example, the acquisition unit 121 performs mapping of information corresponding to the handling information acquired from the storage unit 11 with respect to the above-described data mapping table, and among the information listed as candidates for the handling information in the data mapping table, information to which the information corresponding to the handling information is mapped may be acquired as the handling information.

[0176] (Handling Information Modification Reception Unit 132)

[0177] The PIA system 1 may further include a handling information modification reception unit 132 that receives modification of the handling information acquired by the acquisition unit 121 from the user. For example, on the input screen for the handling information shown in FIG. 3, “Create New Dataset” is displayed, and it is a screen for newly registering, for example, the name of a dataset, the items of the dataset, the purpose of use, etc., which are examples of the handling information. However, for example, when the user selects and requests modification of the handling information registered in the PIA system 1 (for example, pressing an edit button for specific handling information), an input screen similar to FIG. 3 may be displayed on the user terminal 20. That is, the handling information modification reception unit 132 may be configured to receive modification of the handling information from the user via the input screen.

[0178] In addition, for example, on the input screen similar to FIG. 3, the handling information acquired from the information processing system or database that cooperates with the PIA system 1 described above, or the handling information acquired by the large language model may be displayed as default values. Also in this case, the handling information modification reception unit 132 may be configured to receive modification of the handling information from the user via the input screen.

[0179] <<Data Flow Management>>

[0180] The functions of the PIA system 1 for data flow management will be described below.

[0181] The PIA system 1 may further include a data flow management unit 133 that manages data flow information capable of identifying at least one or more of the acts of collection, storage, use, provision, processing, or disposal of privacy-related data in business activities, etc., and the entities related to such acts. In this case, the risk information generation unit 122 can generate risk information based on the data flow information.

[0182] FIG. 10 is a diagram showing an example of the data flow information managed by the data flow management unit 133. In the example shown in FIG. 10, the data flow information is a matrix table with the items representing the content of the act on the vertical axis and the items representing the entity of the act on the horizontal axis, and the handling information, the content and timing of the specific act are mapped.

[0183] As an example of the data flow information managed by the data flow management unit 133, it is possible to identify at least one or more of the acts of collection, storage, use, provision, processing, or disposal of privacy-related data in business activities, etc., and the entities related to such acts by this matrix table.

[0184] More specifically, in the example shown in FIG. 10, the vertical axis of the matrix table of the data flow information shows three items: "collection", "storage / use / provision", and "disposal", and the horizontal axis shows four items: "consumer (user)", "own company (PIA implementation entity)", "payment company (credit company)", and "outsourced data analysis company".

[0185] In the example shown in FIG. 10, for example, it is possible to identify that an act of "collecting" the "purchase data" and "personal information" of "consumers (users)" occurs by the "company (PIA implementation entity)". Also, for example, it is possible to identify that the "purchase data" and "personal information" are "collected" at the time of "settlement at the cash register", "member registration", or "card company registration" of the "consumer (user)". Also, for example, it is possible to identify that each act of "storage, use, and provision" such as the "purchase data" and "personal information" being "linked and stored in the database", "pseudonymized and shared", "data (share) provided", "result share sent", "restored (integration of result share) and result utilized (product planning, etc.)" occurs by the "company (PIA implementation entity)". Also, it is possible to identify that an act of "disposal" of "disposing after result sending" occurs by the "data analysis contractor".

[0186] Note that FIG. 10 is merely an example of data flow information. As types of acts involving handling privacy-related data, apart from "storage, use, and provision", for example, the act of "processing" such as that of a vendor specializing in anonymizing data, etc., may be distinguished and added as an item on the vertical axis, and is not particularly limited to the matrix table of FIG. 10. Also, the data flow information does not necessarily have to be a matrix table, and the display form is not particularly limited.

[0187] As an example of the management of data flow information, the data flow information is stored in the storage unit 11, and the data flow management unit 133 displays the matrix table shown in FIG. 10 on the user terminal 20, for example, in response to a display request from the user.

[0188] In addition, the data flow management unit 133 may generate data flow information from the data mapping information. For example, in the above-described data mapping table, an example was described in which information corresponding to the handling information was extracted from the relevant documents for business activities and the like subject to PIA and mapped to the candidates for the handling information. However, in the data mapping table, for each candidate for the handling information, it may also be listed what kind of entity may be related and what kind of actions may occur.

[0189] Then, for example, the data flow management unit 133 may use a large language model to extract from the relevant documents what kind of entities are related and what kind of actions occur in the business activities and the like subject to PIA, and map them to the above-described data mapping table.

[0190] Alternatively, for example, as the relevant document information, information about what kind of entities are related and what kind of actions occur, together with the information corresponding to the handling information included in each relevant document, may be associated with relevant documents such as the service use agreement and pre-input into an existing information processing system or database that cooperates with the PIA system 1 and stored in the storage unit 11.

[0191] Then, the data flow management unit 133 may obtain information representing what kind of entities are related and what kind of actions occur in the business activities and the like subject to PIA from the relevant document information stored in the storage unit 11, and map it to the above-described data mapping table.

[0192] As described above, by performing the mapping to the data mapping table, it becomes possible to specify which entity performs what kind of actions for which handling information. Therefore, the data flow management unit 133 may generate data flow information (for example, the matrix table shown in FIG. 10) from this data mapping table.

[0193] The data flow information may be generated as information representing relationships such as a data processing flow (acquisition → storage → utilization → transfer → storage → utilization → deletion), players (individual users / service providers / service operators), and processing steps (data type, processing content, cooperation destination, cooperation method). According to the data flow information, it is also possible to grasp the presence or absence of third-party provision and the like.

[0194] Then, the risk information generation unit 122 generates risk information based on the data flow information. For example, the risk information generation unit 122 may generate risk information by selecting a risk template registered in advance in association with the handling information included in the data flow information.

[0195] For example, in the PIA system 1, anonymization information is registered in advance by the user as one of the information included in the handling information, and information is registered to associate the risk template of "utilization of anonymization information" shown in FIG. 6 with the anonymization information. Note that the associated risk template is not limited to one, and a plurality of risk templates may be associated.

[0196] When the handling information included in the data flow information is anonymization information, the risk information generation unit 122 selects the risk template of "utilization of anonymization information" associated with the anonymization information.

[0197] Alternatively, the risk information generation unit 122 may generate risk information by selecting a risk template registered in advance in association with the handling information included in the data flow information, the content of the action on the handling information, and each subject of the action.

[0198] For example, in the PIA system 1, anonymized information is registered in advance by the user as one of the information included in the handling information. For the combination where "storage, use, and provision" occur as actions on the anonymized information and the subject of the action is "the company itself (the PIA implementation entity)", information is registered so as to associate the risk template of "utilization of anonymized information" shown in FIG. 6. Note that the associated risk template is not limited to one, and a plurality of risk templates may be associated.

[0199] And, if the data flow information includes anonymized information as one of the information included in the handling information, and "storage, use, and provision" occur as actions on the anonymized information and the combination where the subject of the action is "the company itself (the PIA implementation entity)" is included, the risk information generation unit 122 selects the risk template of "utilization of anonymized information" associated with the combination.

[0200] (Data flow modification reception unit 134)

[0201] The PIA system 1 may further include a handling information modification reception unit that receives modifications by the user for the data flow managed by the data flow management unit. For example, on the display screen of the data flow information shown in FIG. 10, when the user performs a process for requesting a modification (for example, pressing an edit button for data flow information not shown), an edit screen for modifying the data flow information may be displayed on the user terminal 20. That is, the data flow modification reception unit 134 may be configured to receive modifications of the handling information by the user via the input screen.

[0202] <<An example of the processing flow in the PIA system 1>>

[0203] An example of the operation of the PIA system 1 configured as described above will be described with reference to FIG. 11. FIG. 11 is a flowchart for explaining an example of the operation of the PIA system 1. Note that the flowchart shown in FIG. 11 is merely an example of the processing flow. For example, depending on the user's request, other steps may be included, the same step may be repeatedly executed, or the order of the steps may be changed or some steps may not be executed, and it is not particularly limited.

[0204] In step S101, as an example, the control unit 22 of the user terminal 20 transmits the handling information input by the user to the server 10. As described in the above-described embodiment, as another example, a related document including information corresponding to the handling information may be specified by the user via the user terminal 20 and uploaded to the server 10.

[0205] In step S102, as an example, the acquisition unit 121 of the server 10 acquires the handling information by receiving it from the user terminal 20. As described in the above-described embodiment, as another example, for example, the acquisition unit 121 may discriminate and extract information corresponding to the handling information from the uploaded related documents and set it as the handling information.

[0206] In step S103, as an example, the risk information generation unit 122 of the server 10 generates risk information including risk items and the like based on the handling information acquired by the acquisition unit 121. The risk information generation unit 122 transmits the generated risk information to the user terminal 20.

[0207] In step S104, as an example, the control unit 22 of the user terminal 20 presents the risk information including the risk items and the like included in the received risk information to the user. The user checks the risk information of the presented risk items and the like. The user may check the default value of the risk level included in the risk information and consider the validity of the risk level in accordance with the actual situation of the activity content.

[0208] In step S105, as an example, the control unit 22 of the user terminal 20 receives the user's modification to the risk items (such as addition or deletion of risk items by the user) and the risk level modified by the user for each risk item, etc., and the results of the user's modification and risk assessment regarding the risk items, and transmits the information representing the content to the server 10.

[0209] In step S106, as an example, in the server 10, the user's modification to the risk information and the content of the risk assessment (such as addition or deletion of risk items by the user and the risk level reset by the user for each risk item) are stored in the storage unit 11. Then, the risk information generation unit 122 of the server 10 generates map information regarding the risk based on the user's modification to the risk information and the content of the risk assessment. For example, the generation of this risk map may be performed according to the user's request, and it is not necessarily the case that a risk map must be generated.

[0210] In step S107, as an example, the control unit 22 of the user terminal 20 presents the received map information regarding the risk to the user. The user checks the presented map information regarding the risk.

[0211] In step S108, as an example, the control unit 22 of the user terminal 20 transmits information instructing the presentation of countermeasure-related information input by the user to the server 10. Note that the instruction for the presentation of countermeasure-related information may be performed, for example, in the step immediately after receiving the presentation of risk information in S104.

[0212] In step S109, as an example, the countermeasure-related information generation unit 125 of the server 10 generates countermeasure-related information. As the countermeasure-related information, risk countermeasures predetermined according to the content of the risk may be displayed in various display modes, or the optimal risk countermeasures may be generated each time by an artificial intelligence function.

[0213] In step S110, as an example, the control unit 22 of the user terminal 20 presents the received countermeasure-related information to the user. The user checks the presented countermeasure-related information. The user may check the risk countermeasures and the like included in the countermeasure-related information and examine the validity of the risk countermeasures in accordance with the actual situation of the activity content.

[0214] In step S111, as an example, the user inputs information for modifying the risk countermeasures as needed, and the control unit 22 of the user terminal 20 transmits the countermeasure-related information reflecting the modification content input by the user to the server 10. At the server 10, the modified countermeasure-related information is stored in the storage unit 11.

[0215] With the above, the PIA system 1 ends its operation. As described above, the flowchart shown in FIG. 11 only explains an example of the operation of the PIA system 1, and the operation of the PIA system 1 is not limited thereto.

[0216] 〔Example of Realization by Software〕

[0217] The control block of the server 10 may be realized by a logic circuit (hardware) formed in an integrated circuit (IC chip) or the like, or may be realized by software. In the latter case, each of the server 10 and the user terminal 20 is configured using, for example, a computer (electronic computer).

[0218] (Physical Configuration of Server 10)

[0219] FIG. 12 is a block diagram illustrating the physical configuration of a computer used as the server 10 and the user terminal 20.

[0220] As shown in FIG. 12, the server 10 can be configured by a computer including a bus 110, a processor 101, a main memory 102, an auxiliary memory 103, and a communication interface 104. The processor 101, the main memory 102, the auxiliary memory 103, and the communication interface 104 are connected to each other via the bus 110.

[0221] As the processor 101, for example, a CPU (Central Processing Unit), a microprocessor, a digital signal processor, a microcontroller, or a combination thereof, etc. are used.

[0222] As the main memory 102, for example, a semiconductor RAM (random access memory), etc. are used.

[0223] As the auxiliary memory 103, for example, a flash memory, an HDD (Hard Disk Drive), an SSD (Solid State Drive), or a combination thereof, etc. are used. A program for causing the processor 101 to execute the operations of the server 10 described above is stored in the auxiliary memory 103. The processor 101 expands the program stored in the auxiliary memory 103 onto the main memory 102 and executes each instruction included in the expanded program.

[0224] The communication interface 104 is an interface for connecting to the network N1.

[0225] In this example, the processor 101 and the communication interface 104 are an example of hardware elements that implement the control unit 12. Also, the main memory 102 and the auxiliary memory 103 are an example of hardware elements that implement the storage unit 11.

[0226] (Physical Configuration of the User Terminal 20)

[0227] As shown in FIG. 12, the user terminal 20 can be configured by a computer including a bus 210, a processor 201, a main memory 202, an auxiliary memory 203, a communication interface 204, and an input / output interface 205. The processor 201, the main memory 202, the auxiliary memory 203, the communication interface 204, and the input / output interface 205 are connected to each other via the bus 210. An input device 206 and an output device 207 are connected to the input / output interface 205.

[0228] As the processor 201, for example, a CPU, a microprocessor, a digital signal processor, a microcontroller, or a combination thereof is used.

[0229] As the main memory 202, for example, a semiconductor RAM or the like is used.

[0230] As the auxiliary memory 203, for example, a flash memory, an HDD, an SSD, or a combination thereof is used. A program for operating the computer as the user terminal 20 is stored in the auxiliary memory 203. The processor 201 expands the program stored in the auxiliary memory 203 onto the main memory 202 and executes each instruction included in the expanded program. Also, various data that the processor 201 refers to for operating the computer as the user terminal 20 are stored in the auxiliary memory 203.

[0231] The communication interface 204 is an interface for connecting to a network.

[0232] As the input / output interface 205, for example, a USB interface, a short-range communication interface such as infrared or Bluetooth (registered trademark), or a combination thereof is used.

[0233] As the input device 206, for example, a keyboard, a mouse, a touch pad, a microphone, or a combination thereof, etc. is used. As the output device 207, for example, a display, a printer, a speaker, or a combination thereof is used.

[0234] In this example, the processor 201 and the communication interface 204 are an example of the hardware elements that implement the control unit 22. Also, the main memory 202 and the auxiliary memory 203 are an example of the hardware elements that implement the storage unit 21.

[0235] Note that instead of being stored in the auxiliary memories 103 and 203 respectively, the above-described programs may be recorded on an external recording medium and supplied to the corresponding computer by being read from the external recording medium. As the external recording medium, a "non-transitory tangible medium" readable by a computer, for example, a tape, a disk, a card, a semiconductor memory, a programmable logic circuit, etc. can be used. Also, the above-described programs may be supplied to a computer via any transmission medium (such as a communication network or a broadcast wave) that can be transmitted. Further, one aspect of the present invention can also be realized in the form of a data signal embedded in a carrier wave in which each program is embodied by electronic transmission.

[0236] The present invention is not limited to the above-described embodiments, and various modifications are possible within the scope shown in the claims. Embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of the present invention.

[0237] <<Summary of the Present Disclosure>>

[0238] Hereinafter, the operation and effects of the PIA system according to one aspect of the present disclosure will be mainly described. All the configurations described below can also be used as the configurations of the present embodiment.

[0239] A PIA system according to one aspect of the present disclosure is a PIA system that performs information processing for evaluating the impact on privacy caused by an activity related to handling privacy-related data related to privacy, and includes an acquisition unit that acquires handling information representing the content of the privacy-related data handled in the activity, and a risk information generation unit that generates risk information regarding the risk of the impact on the privacy caused by the activity based on the handling information and presents it to a user.

[0240] According to the above configuration, when implementing PIA (evaluation of the impact on privacy caused by an activity related to handling privacy-related data), since appropriate risk information is automatically generated by the PIA system based on the handling information, the entity implementing PIA can easily implement appropriate PIA even when lacking experience in PIA.

[0241] In the PIA system according to one aspect of the present disclosure, it is preferable that the risk information generation unit presents to the user, as the risk information, risk items used for evaluating the risk of the impact on the privacy caused by the activity.

[0242] According to the above configuration, since risk items are automatically presented when implementing PIA, the user can efficiently evaluate the risk.

[0243] The PIA system according to one aspect of the present disclosure further includes a risk template management unit that manages a risk template including risk items used for evaluating the risk of the impact on the privacy, and it is preferable that the risk information generation unit selects the risk template based on the handling information and presents, as the risk information, the risk items included in the risk template or the risk template.

[0244] According to the above configuration, risk items and risk templates included in the risk template selected based on the handling information are presented. That is, a list of risk items included in the selected one or more templates may be presented, or alternatively, a list of the selected one or more risk templates may be presented once. Thereby, since PIA can be implemented using a pre-prepared template, the prior setting in the PIA system becomes easy, and the work for implementing PIA can be simplified.

[0245] In the PIA system according to one aspect of the present disclosure, it is preferable that the risk template management unit manages the risk template set according to at least any one of privacy-related laws and regulations, standards, guidelines, or the content of the activity.

[0246] According to the above configuration, risk templates are set according to privacy-related laws and regulations, standards, guidelines, and use cases of activities (not limited to business activities) that handle privacy-related data. Note that the risk templates do not necessarily need to be set for each law and regulation or use case, and they may be set for each combination thereof, and the unit of setting is not particularly limited. Thereby, appropriate risk templates assuming various laws and regulations and scenarios can be set.

[0247] In the PIA system according to one aspect of the present disclosure, it is preferable that the risk information generation unit presents to the user a risk level based on an evaluation of at least either the degree of risk impact or the likelihood of risk occurrence, in association with risk items used for evaluating the risk of the impact on the privacy by the activity as the risk information.

[0248] According to the above configuration, the risk information includes information on the risk level representing an evaluation based on the degree of risk impact, occurrence probability, etc. for each risk item. The risk level may be numerically represented, for example, to relatively evaluate the degree of risk, and the form of expression is not limited to numerical values and may be represented by a graph or the like and is not particularly limited. Thereby, the user can appropriately determine, for example, which risk items should be prioritized.

[0249] In the PIA system according to one aspect of the present disclosure, it is preferable that the risk information generation unit presents a preset evaluation value for each of the risk items as the risk level.

[0250] According to the above configuration, for example, a default value set in advance for the standard degree of risk for each risk item is presented, so that it is not necessary for the user to set it individually each time PIA is implemented, the work is simplified, and the implementation of PIA can be made more efficient.

[0251] The PIA system according to one aspect of the present disclosure preferably further includes a risk information correction reception unit that receives correction by the user for the risk information presented by the risk information generation unit.

[0252] According to the above configuration, since the user can correct the risk information presented by the PIA system, even when the content of the risk information presented by the PIA system is not necessarily appropriate due to individual circumstances of PIA, etc., the user can reset appropriate risk information, and thus PIA can be appropriately implemented.

[0253] In the PIA system according to one aspect of the present disclosure, the risk information generation unit maps, for risk items included in the risk information and used for evaluating risks regarding impacts on privacy, to a map with the degree of risk impact and the likelihood of risk occurrence as axes, and displays map information regarding risks as the risk information. This is preferable.

[0254] According to the above configuration, the user can check the risk map as one of the presentation modes of risk information. As a result, since the user can visually grasp the situation of risks potentially present in business activities and the like subject to PIA, it becomes possible to improve awareness for risk countermeasures.

[0255] The PIA system according to one aspect of the present disclosure further includes a countermeasure-related information generation unit that generates countermeasure-related information related to countermeasures against risks for risk items included in the risk information and used for evaluating risks regarding impacts on privacy due to the activities, and presents it to the user. This is preferable.

[0256] According to the above configuration, countermeasure-related information for each risk item is generated and presented to the user. When presenting countermeasure-related information that is, for example, set in advance in association with risk items, information according to the presentation mode (display item information included in individual display, list display information, or voice information, etc.) may be generated. Also, the countermeasure-related information may be generated using, for example, a large language model or the like based on risk information such as risk items and risk levels. As a result, appropriate risk countermeasures to be executed for each risk item are automatically presented, so that PIA including risk countermeasures can be easily implemented.

[0257] In the PIA system according to one aspect of the present disclosure, it is preferable to further include a countermeasure-related information modification reception unit that receives modification by the user for the countermeasure-related information generated by the countermeasure-related information generation unit.

[0258] According to the above configuration, since the user can modify the countermeasure-related information presented by the PIA system, even if the content of the countermeasure-related information presented by the PIA system is not necessarily appropriate due to individual circumstances of the PIA, etc., the user can reset appropriate information such as countermeasures, so that the PIA can be appropriately implemented.

[0259] A PIA system according to an aspect of the present disclosure is a template including risk items used to evaluate the risk regarding the impact on privacy when a correction occurs regarding at least any one of privacy-related laws, regulations, standards, or guidelines, and is based on a pre-correction template set according to at least any one of privacy-related laws, regulations, standards, or guidelines before the correction, and a post-correction template set according to at least any one of privacy-related laws, regulations, standards, or guidelines after the correction. Further provided is a correction impact identification unit that identifies, among the risk items included in the risk information, the risk items affected by the correction or the countermeasures against the risk regarding the risk items and presents them to the user.

[0260] According to the above configuration, for example, based on the differences between the pre-correction and post-correction templates, the risk items and risk countermeasures that have changed due to legal amendments, etc. are identified and presented to the user. Therefore, the user can easily grasp the impact of legal amendments, etc. on the implemented PIA and take appropriate actions as needed.

[0261] A PIA system according to an aspect of the present disclosure preferably further includes a correction update unit that updates the risk information including the risk items affected by the correction identified by the correction impact identification unit based on the post-correction template.

[0262] According to the above configuration, when the risk matters in the already implemented PIA are changed due to the impact of law amendment or the like, the user can check the risk information including the risk matters reflecting the content of the law amendment or the like, so that the user can easily grasp the minimum necessary scope for coping with the law amendment or the like, and can efficiently perform the risk assessment again after the law amendment.

[0263] Preferably, the PIA system according to one aspect of the present disclosure further includes a countermeasure update unit that updates countermeasure-related information related to countermeasures against risks for the risk matters specified by the amendment impact specifying unit.

[0264] According to the above configuration, when the risk countermeasures in the already implemented PIA are changed due to the impact of law amendment or the like, the user can check the risk countermeasures reflecting the content of the law amendment or the like, so that the user can easily grasp the minimum necessary scope for coping with the law amendment or the like, and can efficiently perform the risk countermeasures again after the law amendment.

[0265] Preferably, the PIA system according to one aspect of the present disclosure further includes a correction notification unit that notifies information regarding the correction when a correction occurs in at least any one of privacy-related regulations, standards, or guidelines.

[0266] According to the above configuration, when a law amendment or the like occurs, the user can receive the notification, so that the user can appropriately perform the risk assessment and risk countermeasures required by the law amendment or the like.

[0267] Preferably, the PIA system according to one aspect of the present disclosure further includes a related document information reception unit that receives an input of related document information regarding related documents related to the activity, and the acquisition unit acquires the handling information based on the related document information.

[0268] According to the above configuration, for example, by uploading the relevant documents themselves such as service usage agreements, or by inputting the addresses of relevant documents on the network, the names of relevant documents, file names, etc., the handling information is input into the PIA system. Therefore, even users with little experience in PIA can easily implement PIA.

[0269] In the PIA system according to one aspect of the present disclosure, it is preferable that the acquisition unit uses an artificial intelligence model to extract information corresponding to the handling information included in the relevant document and acquire it as the handling information.

[0270] According to the above configuration, by the function of artificial intelligence such as a large language model, for example, information corresponding to the handling information is discriminated and extracted from relevant documents such as service usage agreements, so that the handling information used for generating risk information is automatically set. Therefore, the burden on the user when implementing PIA can be reduced.

[0271] In the PIA system according to one aspect of the present disclosure, it is preferable that the storage unit stores in advance information corresponding to the handling information included in the relevant document, and the acquisition unit acquires, as the handling information, information corresponding to the handling information included in the relevant document from the storage unit.

[0272] According to the above configuration, information corresponding to the handling information included in the relevant article is stored in the storage unit including, for example, an information processing system or a database to be linked to the relevant document. By reading out these information, the handling information used for generating risk information is automatically set. Therefore, the burden on the user when implementing PIA can be reduced.

[0273] The PIA system according to one aspect of the present disclosure preferably further includes a handling information correction reception unit that receives correction by the user for the handling information acquired by the acquisition unit.

[0274] According to the above configuration, since the user can modify the handling information for generating risk information, for example, even when the content of the handling information automatically input into the PIA system is not necessarily appropriate, the user can re-set the handling information, so that appropriate risk information can be generated.

[0275] The PIA system according to one aspect of the present disclosure further includes a data flow management unit that manages data flow information capable of identifying at least one or more of the acts of collecting, storing, using, providing, processing, or discarding the privacy-related data in the above activities and the entities related to the acts, and the risk information generation unit generates the risk information based on the data flow information, which is preferable.

[0276] According to the above configuration, since it is possible to manage the data flow for identifying the acts such as collection of privacy-related data generated in business activities and the like and the entities thereof, detailed risk information corresponding to the data flow is generated, so that the accuracy of PIA can be improved.

[0277] The PIA system according to one aspect of the present disclosure preferably further includes a data flow modification reception unit that receives modification by the user for the data flow information managed by the data flow management unit.

[0278] According to the above configuration, since the user can modify the data flow information, for example, even when the content of the data flow automatically generated by the PIA system is not necessarily appropriate, the user can re-set the data flow, so that appropriate risk information can be generated.

[0279] A method according to an aspect of the present disclosure uses a PIA system that performs information processing for evaluating the impact on privacy in activities related to handling privacy-related data related to privacy, and obtains handling information representing the content of the privacy-related data handled in the activity; and based on the handling information, generates risk information regarding the risk of the impact on the privacy by the activity and presents it to the user.

[0280] According to the above configuration, the same effects as those of the above-described PIA system are achieved.

[0281] A program according to an aspect of the present disclosure is a program for causing a computer to function as the above-described PIA system, and causes the computer to function as each part.

[0282] According to the above configuration, the same effects as those of the above-described PIA system are achieved.

Industrial Applicability

[0283] An aspect of the present disclosure is useful for an information processing system for supporting PIA.

Explanation of Signs

[0284] 1 PIA system 10 Server 20 User terminal 11, 21 Storage unit 12, 22 Control unit 101, 201 Processor 102, 202 Main memory 103, 203 Auxiliary memory 104, 204 Communication interface 110, 210 Bus 121 Acquisition unit 122 Risk information generation unit 123 Risk template management unit 124 Risk information correction reception unit 125 Countermeasure-related Information Generation Unit 126 Countermeasure-related Information Modification Reception Unit 127 Amendment Impact Identification Unit 128 Amendment Update Unit 129 Countermeasure Update Unit 130 Amendment Notification Unit 131 Related Document Information Reception Unit 132 Handling Information Modification Reception Unit 133 Data Flow Management Unit 134 Data Flow Modification Reception Unit 205 Input / Output Interface 206 Input Device 207 Output Device

Claims

1. A PIA system for performing information processing to evaluate the impact on privacy of activities involving handling privacy-related data related to privacy, comprising: an acquisition unit that acquires handling information representing the content of the privacy-related data handled in the activity; a risk information generation unit that generates risk information regarding the risk of the impact on the privacy of the activity based on the handling information and presents it to the user.

2. The PIA system according to claim 1, wherein the risk information generation unit presents to the user, as the risk information, risk items used for evaluating the risk of the impact on the privacy of the activity.

3. further comprising a risk template management unit that manages a risk template including risk items used for evaluating the risk of the impact on the privacy; The PIA system according to claim 1, wherein the risk information generation unit selects the risk template based on the handling information and presents, as the risk information, the risk items included in the risk template or the risk template.

4. The PIA system according to claim 3, wherein the risk template management unit manages the risk template set according to at least one of privacy-related regulations, standards, guidelines, or the content of the activity.

5. The PIA system according to claim 1, wherein the risk information generation unit presents to the user, as the risk information, a risk level based on an evaluation of at least one of the degree of impact of the risk or the likelihood of occurrence of the risk, in association with the risk items used for evaluating the risk of the impact on the privacy of the activity.

6. The PIA system according to claim 5, wherein the risk information generation unit presents, as the risk level, an evaluation value predetermined for each of the risk items.

7. The PIA system according to claim 1, further comprising a risk information correction reception unit that receives corrections by the user for the risk information presented by the risk information generation unit.

8. The risk information generation unit maps, with respect to risk items included in the risk information and used for evaluating risks regarding impacts on privacy, to a map with the axis of the degree of risk impact and the possibility of risk occurrence, and displays map information regarding risks as the risk information, for the PIA system according to claim 1.

9. The PIA system according to claim 1, further comprising a countermeasure-related information generation unit that generates countermeasure-related information related to countermeasures against risks for risk items included in the risk information and used for evaluating risks regarding impacts on privacy by the activity, and presents the countermeasure-related information to a user.

10. The PIA system according to claim 9, further comprising a countermeasure-related information correction reception unit that receives corrections by a user for the countermeasure-related information generated by the countermeasure-related information generation unit.

11. When a correction occurs regarding at least any one of privacy-related laws, regulations, standards, or guidelines, a template including risk items used for evaluating risks regarding impacts on privacy, the pre-correction template set according to at least any one of the privacy-related laws, regulations, standards, or guidelines before correction, and the post-correction template set according to at least any one of the privacy-related laws, regulations, standards, or guidelines after correction, and further comprising a correction impact identification unit that identifies risk items affected by the correction or countermeasures against risks for the said risk items included in the risk information and presents them to a user, for the PIA system according to claim 1.

12. The PIA system according to claim 11, further comprising a correction update unit that updates the risk information including the risk items affected by the correction identified by the correction impact identification unit based on the post-correction template.

13. The PIA system according to claim 11, further comprising a countermeasure update unit that updates countermeasure-related information related to countermeasures against risks for the risk items identified by the correction impact identification unit.

14. The PIA system according to claim 1, further comprising a correction notification unit that notifies information regarding the correction when a correction occurs with respect to at least any one of privacy-related laws and regulations, standards, or guidelines.

15. further comprising a related document information reception unit that receives input of related document information regarding related documents related to the activity, The acquisition unit acquires the handling information based on the related document information. The PIA system according to claim 1.

16. The acquisition unit extracts information corresponding to the handling information included in the related document using an artificial intelligence model and acquires the information as the handling information. The PIA system according to claim 15.

17. The storage unit stores in advance information corresponding to the handling information included in the related document, The acquisition unit acquires, from the storage unit, information corresponding to the handling information included in the related document as the handling information. The PIA system according to claim 15.

18. The PIA system according to claim 15, further comprising a handling information correction reception unit that receives correction by a user for the handling information acquired by the acquisition unit.

19. further comprising a data flow management unit that manages data flow information capable of identifying at least any one or more of the acts of collecting, storing, using, providing, processing, or discarding the privacy-related data in the activity and the entity related to the act, The risk information generation unit generates the risk information based on the data flow information. The PIA system according to claim 1.

20. The PIA system according to claim 19, further comprising a data flow correction reception unit that receives correction by a user for the data flow managed by the data flow management unit.

21. Regarding an activity of handling privacy-related data related to privacy, using a PIA system that performs information processing for evaluating the impact on privacy by the activity, a step of acquiring handling information representing the content of the privacy-related data handled in the activity; a step of generating risk information regarding the risk of the impact on privacy by the activity based on the handling information and presenting it to the user.

22. A program for causing a computer to function as the PIA system according to claim 1, the program for causing a computer to function as each of the above-described units.

Citation Information

Patent Citations

  • Personal information protection system, and personal information protection method

    JP2018147333A