Information processing system, program, and user terminal
The system addresses user concerns by storing consent information and providing transparent disclosure of personal data use, enhancing user trust through clear communication of consent practices.
Patent Information
- Application Number
- JP2025020195
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-15
- Filing Date
- 2025-02-10
- Publication Date
- 2025-08-27
- Estimated Expiration
- 2045-02-10
AI Technical Summary
Users often feel uneasy about the misuse of their personal information due to unclear handling practices by companies, especially when receiving unsolicited advertisements, as they may not recall providing consent and are unaware of which companies are using their data.
An information processing system that stores consent information associated with users and businesses, allowing users to request and receive disclosure of the basis for personal information use, including direct mail notifications with consent event IDs and specific character strings for verification.
Enables users to confirm the basis for personal information use, reducing uncertainty and improving transparency in data handling practices, thereby enhancing user trust and convenience.
Smart Images

Figure 2025125532000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing system, a program, and a user terminal. [Background technology]
[0002] 2. Description of the Related Art There is a known technique in which, when a customer accesses a web page of a business from which the customer wishes to receive a service, a personal information disclosure button for disclosing personal information required for the provision of the service is displayed on the screen of the customer's terminal. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-85676 Summary of the Invention [Problem to be solved by the invention]
[0004] Generally, businesses such as companies use users' personal information by obtaining consent to the handling of that information. However, when a user receives direct mail from a business, the user may not recall having agreed to the handling of personal information with that business. While this may be due to user misunderstanding or other factors on the user's side, the user may feel uneasy about the misuse of their personal information. Furthermore, while a company's confirmation of the use of personal information may state that the information will be used for advertising purposes for the company's group companies or affiliated companies, the specific names of those group companies or affiliated companies are not listed. As a result, users may receive advertising from companies they have not directly authorized to use their personal information, and it may be difficult to know which of the numerous advertising emails they have authorized.
[0005] Therefore, in one aspect, the present invention aims to provide a mechanism that allows users to receive disclosure of the basis for the use of personal information when it is used based on consent for the handling of personal information. [Means for solving the problem]
[0006] In one aspect, a storage unit that, when a user consents to the handling of personal information, stores consent information regarding the consent in association with the user and a business operator involved in the handling; An information processing system is provided, comprising: a processing unit that discloses the grounds for use of personal information to a user based on the data in the storage unit. [Effects of the Invention]
[0007] In one aspect, the present invention makes it possible to provide a system that enables users to obtain disclosure of the basis for the use of personal information when it is used based on consent for the handling of personal information for any service or advertisement, whether the company has obtained direct permission or indirect permission as a group or affiliated company. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is a schematic diagram of the overall configuration of an information processing system according to an embodiment; [Figure 2] FIG. 10 is a diagram showing an example of a consent screen when a user gives consent. [Figure 2A] FIG. 10 is a diagram showing another example of the consent screen when the user gives consent. [Figure 3] FIG. 10 is a diagram illustrating an example of data in a consent information storage unit. [Figure 4] FIG. 10 is a diagram illustrating an example of data in a personal information storage unit. [Figure 5] FIG. 10 is a diagram showing an example of direct mail. [Figure 5A] FIG. 10 is a diagram showing another example of direct mail. [Figure 6] 1 is a timing chart schematically illustrating the operation of the information processing system. [Figure 7] FIG. 10 is a diagram illustrating an example of a disclosure request transmission screen. [Figure 8]FIG. 10 is a diagram showing an example of a display of an inbox of an electronic mail service used by a certain user. [Figure 9] FIG. 10 is a diagram showing another example of a similar inbox display. [Figure 10] 7 is a timing chart schematically showing an operation of the information processing system (an operation different from that in FIG. 6). [Figure 11] FIG. 10 is a table showing an example of specific character string information that may be held on the user terminal side. [Figure 12] FIG. 10 is a table showing another example of specific character string information that may be held on the user terminal side. [Figure 13] 10 is a flowchart illustrating an example of processing in a user terminal at the stage of registering a specific character string. [Figure 14] 10 is a flowchart illustrating an example of processing in a user terminal when a call arrives. [Figure 15] 15 is a flowchart showing a preferred example of the registered name display process in step S1304 of FIG. [Figure 16] FIG. 15 is an explanatory diagram of a method for displaying the actual number of connections. [Figure 17] 10 is a flowchart illustrating an example of processing that may be executed by a company terminal when registering personal information. [Figure 18] FIG. 10 is a diagram illustrating an example of data in a personal information storage unit. [Figure 19] 10 is a flowchart illustrating an example of processing that may be executed by a company terminal when personal information is used. DETAILED DESCRIPTION OF THE INVENTION
[0009] Each embodiment will be described in detail below with reference to the accompanying drawings.
[0010] FIG. 1 is a schematic diagram of the overall configuration of an information processing system 1 according to an embodiment.
[0011] The information processing system 1 is a system that realizes the personal information use basis disclosure service described below. The personal information use basis disclosure service is a service that enables a user to request and receive disclosure of the basis for the use of their personal information by a third party (such as a company) via, for example, a user terminal 21. An example of the personal information use basis disclosure service will be described in detail later.
[0012] The information processing system 1 includes a user terminal 21, a server device 100, and a company terminal 150. Note that some or all of the functions of the server device 100 may be realized by the company terminal 150.
[0013] The user terminal 21, the server device 100, and the company terminal 150 are connected via a network 4. The user terminal 21 and the server device 100 can communicate with each other via the network 4. In the following, unless otherwise specified, a user refers to a user of the personal information use basis disclosure service.
[0014] The network 4 may include, for example, a wireless communication network for mobile phones, the Internet, a Virtual Private Network (VPN), a Wide Area Network (WAN), a wired network, or any combination of these.
[0015] The user terminal 21 is, for example, a smartphone or a tablet, but may also be a wearable terminal (for example, a smart watch, a ring, etc.), a remote control, etc. Furthermore, the user terminal 21 does not need to be a portable terminal, and may also be a fixed terminal such as a desktop personal computer, etc.
[0016] The user terminal 21 includes a communication unit 22, a display unit 24, an input unit 26, and a processing unit 28. The communication unit 22 performs various communications via the network 4. The display unit 24 may be a liquid crystal display, an organic EL (Electro-Luminescence) display, or the like. The input unit 26 is a keyboard, a touch panel, or the like, but may also be an input unit that allows gesture input or voice input. The processing unit 28 realizes various functions that can be realized by the user terminal 21.
[0017] The user receives the personal information use basis disclosure service by exchanging various information with the server device 100 via the screen of the personal information use basis disclosure service app that can be displayed on the display unit 24 (described later).
[0018] The server device 100 executes an application according to this embodiment (hereinafter referred to as a "personal information use basis disclosure service app"). In this embodiment, the server device 100 executes a personal information use basis disclosure service app that runs on a web browser. The server device 100 may include a web server, a cloud server, etc.
[0019] A user, as described below, can launch a web browser via his / her user terminal 21 and run the personal information use basis disclosure service app on the browser. The personal information use basis disclosure service app is an app for the personal information use basis disclosure service, and may require registration of account information such as a user ID and password as a condition of use. In the following, a user refers to a user linked to account information.
[0020] In a modified example, the personal information use basis disclosure service app may be realized as a native application that is installed and runs on the user terminal 21, instead of or in addition to a web application that can be operated on a browser.
[0021] The server device 100 can be operated by the operator. For example, the server device 100 can be accessed by an administrator on the operator side, and various inputs required for maintaining the personal information use basis disclosure service app can be performed by the administrator on the operator side.
[0022] 1, the server device 100 includes a consent information acquisition unit 110, a usage basis request processing unit 111, and a consent information storage unit 120. The consent information acquisition unit 110 and the usage basis request processing unit 111 can be realized by the CPU of the server computer executing a program. The consent information storage unit 120 can be realized by a storage device of the server computer.
[0023] The consent information acquisition unit 110 acquires consent information regarding the handling of personal information from a user. FIG. 2 is a diagram showing an example of a consent screen (a screen on the display unit 24) when a user gives consent. The consent screen is a screen generated by a corresponding company (a company that uses the personal information). For example, a user performs user registration (such as account registration) when receiving a service through a company. At this time, the user gives consent regarding the handling of personal information via the consent screen as shown in FIG. 2. In this case, when the user gives consent via the consent screen, the consent information acquisition unit 110 may acquire the consent details, etc., described on the consent screen from the user and / or the company. In this embodiment, a consent event ID is issued by the company terminal 150 and provided to the server device 100. As shown in FIG. 2A, the company may request consent for the use of personal information by group companies or affiliated companies. If the group companies or affiliated companies are later asked to confirm consent for the use of personal information, the consent at this time is presented as evidence.
[0024] The consent information acquisition unit 110 may be realized by a corresponding company terminal 150. In this case, the server device 100 may be omitted.
[0025] When the consent information acquisition unit 110 acquires the consent information, it stores the consent information in the consent information storage unit 120. Fig. 3 shows an example of data in the consent information storage unit 120. Fig. 3 shows data related to one user. The consent information storage unit 120 stores consent information for each user. That is, the consent information is stored in association with the user.
[0026] The consent may include whether or not direct mail (for example, sending campaign information) can be sent.
[0027] In the example shown in FIG. 3, each time a user gives consent, the consent event ID, the consent date and time, handling company information, consent details, consent-obtaining company information, and relationship with the consent-obtaining company are stored. The consent date and time represent the date and time when consent was given. The granularity of the date and time is arbitrary, for example, it may be in units of hours, minutes, and seconds, or just the date. The company information represents the company that obtained consent regarding the handling of the user's personal information via the consent screen shown in FIG. 2. The consent details represent the content written on the consent screen for handling personal information. In the example shown in FIG. 3, the consent details are managed in the form of image data (e.g., image based on a screenshot), but may also be in other formats. The consent-obtaining company information is the company information that obtained consent from the user, and the relationship with the consent-obtaining company represents the relationship between the handling company and the consent-obtaining company. In the example shown in FIG. 3, if ABC Agency Co., Ltd., a subsidiary of ABC Co., Ltd., handles the user's personal information based on the user's consent, a record like the second record in FIG. 3 is added. This record is referenced when ABC Agency Co., Ltd. is requested by the user to disclose the basis.
[0028] The consent information storage unit 120 may be realized by the corresponding company terminal 150 (or an individual server device accessible by the company terminal 150). In this case, the server device 100 may be omitted.
[0029] The use basis request processing unit 111 discloses the use basis of personal information based on data in the company terminal 150. The use basis request processing unit 111 discloses the use basis of personal information in response to a request for disclosure from a user. A request for disclosure from a user may be realized by sending an email to a specific email address, by accessing a specific URL (Uniform Resource Locator) and entering a specific input on the URL, or the like.
[0030] Note that some or all of the functions of the usage basis request processing unit 111 may be realized by the corresponding company terminal 150. In the latter case, the server device 100 may be omitted.
[0031] The company terminal 150 is a terminal under the control of a company that uses personal information of users. The company terminal 150 may be in the form of a server or a personal computer that can be operated by employees of the company.
[0032] The company terminal 150 includes a personal information storage unit 152 , a direct mail generation unit 154 , and a direct mail transmission unit 156 .
[0033] The personal information storage unit 152 stores personal information related to users who have agreed to the handling of their personal information. The personal information may be stored in association with an agreed event ID, as shown in Fig. 4. Note that the personal information shown in Fig. 4 is personal information related to one user, and the personal information storage unit 152 may manage personal information for each user (corresponding personal identifier).
[0034] The direct mail generation unit 154 uses the personal information stored in the personal information storage unit 152 to generate direct mail to be sent to the corresponding user. In this case, the recipient users may be, for example, only users who have enabled direct mail. FIG. 5 shows an example of direct mail. In this embodiment, the direct mail includes predetermined information 500 that enables a request for disclosure of the basis for use of personal information. In the example shown in FIG. 5, the predetermined information 500 includes a consent event ID. Alternatively, as shown in FIG. 5A, the transmission may include an inquiry code. This may be a QR code, a barcode, or a string of alphanumeric characters. For electronic materials (electronic media), an inquiry link or inquiry button may be displayed. The presence of such an inquiry code or link / button may be used as a criterion for sending a transmission to a user. The QR code may be read or the link may be clicked to directly display the event ID without the user having to enter it.
[0035] The direct mail sending unit 156 sends the direct mail generated by the direct mail generating unit 154 to the corresponding user. In this case, the direct mail sending unit 156 may use personal information in the personal information storage unit 152 to set the destination address (e.g., email address, etc.).
[0036] By analyzing the data in the consent information storage unit 120 shown in Figure 3, if a user consents to the use of their personal information to use a service or app provided by a certain company, it becomes possible to know which group companies or affiliated companies will use their personal information. For example, if a user consents to the use of their personal information to use a new service or app provided by a certain company, it is possible to display a list of companies that may use their personal information before or after consent. In the example of Figure 3, a user who consents to the use of their personal information can be notified that if they consent to the use of their personal information to use a service or app provided by ABC Co., Ltd., their personal information may also be used by ABC Agency.
[0037] Next, the operation of the information processing system 1 will be described with reference to FIGS.
[0038] Fig. 6 is a timing chart that schematically shows the operation of the information processing system 1. Fig. 6 shows the processing related to the company terminal 150 of one company, but the processing may be similar for other companies.
[0039] In step S310, an agreement is formed between the user and the company regarding the handling of the user's personal information. In this case, the user transmits personal information and the like to the company terminal 150 via the user terminal 21.
[0040] In step S311, the company terminal 150 stores the personal information of the user obtained through step S310. At this time, the company terminal 150 issues an agreed event ID and stores the personal information in the personal information storage unit 152 in association with the agreed event ID (see FIG. 4).
[0041] In step S312, the company terminal 150 transmits the consent information to the server device 100 in association with the consent event ID.
[0042] In step S313, the server device 100 stores the consent information in association with the consent event ID in the consent information storage unit 120 (see FIG. 3).
[0043] Thereafter, for example, when there is an opportunity to inform about a campaign, the company sends a direct mail to the user in step S320. Specifically, the company sends the direct mail to the user terminal 21 of the corresponding user via the company terminal 150. As described above, the direct mail includes predetermined information 500 including the consent event ID.
[0044] Here, suppose the user feels uneasy about the direct mail they received. For example, it is assumed that a long time has passed since they provided consent in step S310, and they no longer remember forming consent with the corresponding company. In this case, the user can use the consent event ID included in the direct mail to make a disclosure request regarding the basis for use of personal information. The user accesses the URL included in the direct mail. FIG. 7 shows an example of a web screen G700 on the accessed URL as an example of a disclosure request transmission screen. In this case, the user can generate and transmit a disclosure request by entering the consent event ID in the consent event ID input field G702 on the web screen G700 and operating the request button BT700. The disclosure request is associated with the consent event ID and transmitted to server device 100 (step S322).
[0045] In step S323, when the server device 100 receives the disclosure request, it extracts the consent information associated with the consent event ID from the consent information storage unit 120 as the basis for use based on the consent event ID associated with the disclosure request.
[0046] In step S324, the server device 100 transmits the extracted consent information (grounds for use) to the corresponding user 21.
[0047] In step S325, the user terminal 21 displays the received basis for use. The basis for use may be displayed in any manner, for example, the consent screen shown in FIG. 2 or a display mode showing the consent date and time. This allows the user to confirm the basis for the direct mail. As a result, the user may remember, for example, the circumstances of consent, and can effectively confirm the basis for use of their own personal information.
[0048] In the above-described embodiment, the transmission using personal information is in the form of electronic direct mail, but is not limited to this. For example, instead of email, it may be in the form of SMS (Short Message Service) or SNS (Social Networking Service) DM (Direct Message) or messenger addressed to a phone number. It may also be in the form of paper direct mail, or in a form other than direct mail (e.g., a gift or present). For example, a printed matter with a QR code or the like may be enclosed in paper direct mail. In this case, the QR code may include information indicating the basis for use of the personal information and information regarding a method or an access link for accessing the information. This allows the user to access the basis information that shows that the information was created based on information agreed (accepted) by the user. It may also be a phone call. In this case, information indicating the basis for use of the personal information may be played back as a voice message in response to a user operation.
[0049] Next, another preferred embodiment will be described with reference to FIGS.
[0050] In another preferred embodiment, the user can determine whether an email has been sent based on information that the user has agreed to (approved), based on whether a specific character string registered by the user (a keyword registered by the user) is inserted in a predetermined portion of the email. This mechanism will be described in detail below.
[0051] Fig. 8 is a diagram showing an example of the display of an inbox of an e-mail service used by a certain user, and Fig. 9 is a diagram showing another example of the display of a similar inbox.
[0052] In the example shown in Figure 8, the subject of an incoming email from sender "XX Bank" contains a specific character string "KGW001" registered by the user. The character string "KGW001" may be highlighted by using corner brackets or the like to make it stand out, as shown in Figure 8. This allows the user to easily determine whether the character string "KGW001" is present.
[0053] Here, the character string "KGW001" is information that the user inputs (registers) when agreeing to the handling of personal information. For example, the character string "KGW001" may be a character string that the user inputs when giving consent as described above with reference to FIG. 2 and FIG. 2A. After obtaining consent, the company or the like inserts the character string into a predetermined location in an email or the like when sending the email or the like to the user. The company or the like may maintain a database that stores character strings corresponding to each user.
[0054] In this way, the user can determine that an e-mail containing the character string "KGW001" in the subject line is based on information to which the user has consented (accepted). For example, in the example shown in Figure 8, the subject line of the received e-mail from sender "XX Bank" contains the specific character string "KGW001" registered by the user, so it can be easily determined that the e-mail was sent based on information to which the user has consented (accepted). On the other hand, the subject line of the received e-mail from sender "EFG Shoten" does not contain the specific character string registered by the user, so it can be easily determined that the e-mail was not sent based on information to which the user has consented (accepted).
[0055] Here, the specific character string may include only characters, but may also include symbols or images (pictorial symbols, pictograms, etc.) instead of or in addition to characters.
[0056] In the example shown in FIG. 8, a specific string "KGW001" is inserted in the subject as a predetermined portion of the email. However, as shown in FIG. 9, a rule may be set such that a specific string registered by the user is inserted in part of the body of the email. Such a rule may be set (customizable) for each user. In either case, it is desirable that the specific string registered by the user is inserted in the first half (e.g., the beginning) of the body of the email, which is visible before transitioning to a screen for viewing the entire body of the email. For example, by referring to the area displayed by the preview function of a messaging app, the user can understand that the message was sent based on the information the user consented to before viewing the entire message.
[0057] Next, still another preferred embodiment will be described with reference to FIG. 10 onwards.
[0058] Fig. 10 is a timing chart showing an outline of the operation (different from that shown in Fig. 6) of the information processing system 1. Fig. 10 shows the processing related to the company terminal 150 of one company, but the processing may be similar for other companies.
[0059] The operation shown in FIG. 10 differs from the operation shown in FIG. 6 in that step S320 is changed to step S320A, and steps S326 and S327 are added.
[0060] In step S320A, for example, there is an opportunity to announce a campaign, and the company sends a preliminary short message to the phone number of the call candidate before calling the user (step S327). Specifically, the company sends the short message to the phone number of the call candidate via company terminal 150. As described above, the short message includes predetermined information 500 including the consent event ID. The short message may include a message stating that the person in charge would like to call the user directly later.
[0061] The user checks the grounds for use on the user terminal 21 (step S325), and if it is determined that there is no problem with the call, transmits a permission notice to the company terminal 150 via the user terminal 21 (step S326).
[0062] When the company employee receives the permission notice from the user via the company terminal 150, the employee calls the destination of the short message (the telephone number of the call candidate) (step S327).
[0063] This system allows users to confirm the grounds for use before accepting a call, reducing the chances of accepting a call without knowing the grounds, improving convenience for both companies and users.
[0064] The method of notifying in advance whether a call is based on authorized information may involve sending a message using a tone signal. Before talking to the user on the phone, a specific character string may be sent using a tone signal to confirm that the call is based on information authorized by the user. Alternatively, a URL (Uniform Resource Locator) or the like that can access an information source that explains how the phone number was obtained may be sent. The technology for sending a message using a tone signal to a user terminal 21 such as a smartphone is arbitrary, but the method described in Japanese Patent Application Laid-Open No. 2014-093638, the contents of which may be incorporated herein by reference, may be used, for example.
[0065] In the system described above with reference to Fig. 10, the advance short message preferably includes the specific character string described above with reference to Figs. 8 and 9, i.e., the specific character string registered by the user. The specific character string may be placed at any position in the short message, for example, at the beginning or nearby. In this case, the user can skip the steps S322 to S325 in Fig. 10 and easily perform the operation of transmitting the permission notice in step S326, thereby improving convenience.
[0066] Furthermore, in the system described above with reference to FIG. 10, the user terminal 21 may store specific character string information registered by the corresponding user himself / herself, as shown in FIG. 11 or 12. For example, such specific character string information may be stored as part of an address book (e.g., an electronic address book in which telephone numbers and / or email addresses can be registered) in the user terminal 21. In this case, the specific character string may be included as part of a registered name linked to a telephone number. FIG. 11 shows character string information in a case where a user registers a specific character string individually for each consenting party (permissioning party). In this case, the user can easily understand the caller of the call waiting after the short message based on the differences between the character strings included in the short message. On the other hand, FIG. 12 shows character string information in a case where a user registers a specific character string "KGWALL" common to each consenting party (permissioning party). In this case, the user can also easily determine, based on the specific character string included in the short message, that the call that comes when an acceptance notification is sent in response to the short message is based on the information to which the user consented (approved).
[0067] Next, with reference to FIGS. 13 to 16, an example of the operation of the user terminal 21 according to the mechanism described above with reference to FIG. 10 will be described.
[0068] FIG. 13 is a flowchart showing an example of processing in the user terminal 21 at the stage of registering a specific character string.
[0069] In step S1200, the user terminal 21 determines whether or not any SMS short message has been received.
[0070] In step S1202, the user terminal 21 displays the predetermined information 500 and the inquiry code as described above with reference to FIG. 5 and FIG. 5A, and also displays an address registration OK button.
[0071] In step S1204, the user terminal 21 determines whether the address registration OK button has been operated. If the determination result is "YES," the process proceeds to step S1206; otherwise, the process may wait for a certain period of time before ending. Note that operating the address registration OK button may involve inputting a corresponding specific character string.
[0072] In step S1206, the user terminal 21 registers the telephone number in the address book using a registered name that includes a specific character string (represented as "keyword" in FIG. 13). Note that, if a common specific character string is used as shown in FIG. 12, it may not be necessary for the user to specify the specific character string.
[0073] FIG. 14 is a flowchart showing an example of processing in the user terminal 21 when an incoming call arrives.
[0074] In step S1300, the user terminal 21 is in an incoming call waiting state.
[0075] In step S1302, the user terminal 21 determines whether or not there is an incoming call. If the determination result is "YES", the process proceeds to step S1304.
[0076] In step S1304, the user terminal 21 executes a registered name display process based on the incoming telephone number. The registered name display process may be a process that simply displays the registered name, but a preferred example will be described later with reference to FIG. 15. At this time, the user can answer the call by operating the answer button. Alternatively, the user can reject the call by not operating the answer button. The user terminal 21 may also display a button for automatically notifying the user that the call will not be answered.
[0077] In step S1306, the user terminal 21 determines whether or not the process to receive the call has been accepted (answered). If the determination result is "YES", the process proceeds to step S1308; otherwise, the process ends.
[0078] In step S1308, the user terminal 21 counts up the number of connection attempts for the current telephone number, and stores (adds) the number of connection attempts in association with the registered name. That is, the counter for the number of connection attempts associated with the registered name (including the specific character string) for the current telephone number is incremented by "1."
[0079] In step S1310, the user terminal 21 returns to the call waiting state after disconnecting the line.
[0080] Fig. 15 is a flowchart showing a preferred example of the registered name display process in step S1304 of Fig. 14. Fig. 16 is an explanatory diagram of Fig. 15, and is an explanatory diagram of a method for displaying the actual number of connection attempts.
[0081] In step S1500, the user terminal 21 determines whether the number of connection attempts for the same telephone number is 1 or more. If the determination result is "YES", the process proceeds to step S1502, otherwise the process proceeds to step S1504.
[0082] In step S1502, the user terminal 21 displays the number of past connections along with the registered name of the incoming telephone number. The display method is arbitrary, but for example, as shown in FIG. 16, it may be displayed in combination with a specific character string. In the example shown in FIG. 16, if the specific character string is "KGW001" and the number of past connections is k, 00k is added after it. This allows the user to easily understand how many times the connection has been made so far. For example, if the user has connected multiple times in the past, the user can determine that they can receive calls with confidence, improving convenience.
[0083] In step S1504, the user terminal 21 displays the registered name of the incoming telephone number. For example, if the registered name associated with the current telephone number includes the specific character string "KGW001," the specific character string "KGW001" may be output without including the actual number of connections. Alternatively, information indicating that this is the first time, such as "000," may be output together. Furthermore, if the registered name associated with the current telephone number does not include the specific character string, only the registered name associated with the current telephone number may be output. Alternatively, information indicating a warning may be output together.
[0084] According to the processes shown in Figures 13 to 15, the company can make a call by sending a specific character string related to the corresponding user via short message (SMS, etc.) before making a call and receiving confirmation that the user is the person in question. The user can receive a call by receiving a short message (SMS, etc.) and receiving confirmation that permission to use the information (telephone number) has been obtained. Note that this process may further include a means for automatically registering the specific character string in the name field of the address book. Furthermore, a QR code or the like that can refer to the basis for use, in addition to the specific character string, may be sent together with the message.
[0085] Next, with reference to FIGS. 17 to 19, an example of the operation of the company terminal 150 according to the mechanism described above with reference to FIG. 10 will be described.
[0086] 17 is a flowchart showing an example of processing that may be executed by company terminal 150 when registering personal information (see step S311 in FIG. 10). FIG.
[0087] In step S170, the company terminal 150 acquires personal information from the user.
[0088] In step S172, the company terminal 150 requests confirmation of the content and use of the personal information acquired in step S170. This confirmation request is made to the user and may include a request for a specific character string that may be acquired in the next step S174.
[0089] In step S174, the company terminal 150 acquires from the user a specific character string to be presented when personal information is used.
[0090] In step S176, company terminal 150 associates the specific character string obtained in step S174 with each user's personal identifier and stores the associated character string in personal information storage unit 152 (see FIG. 18).
[0091] FIG. 19 is a flowchart showing an example of processing that may be executed by the company terminal 150 when personal information is used (see step S320A and step S327 in FIG. 10).
[0092] In step S190, the company terminal 150 identifies the personal identifier of the personal information to be used.
[0093] In step S192, the company terminal 150 acquires a specific character string associated with the identified personal identifier. The specific character string associated with the identified personal identifier can be acquired from the personal information storage unit 152.
[0094] In step S194, the company terminal 150 uses the personal information corresponding to the personal identifier together with the acquired specific character string. For example, when sending a short message to the phone number of the call candidate in step S320A of Fig. 10, the company terminal 150 may include a specific character string in a part of the short message (for example, in the title). Note that this is not limited to short messages, and can be similarly applied to telephone calls, emails, etc.
[0095] Although each embodiment has been described in detail above, it is not limited to the specific embodiment, and various modifications and changes are possible within the scope of the claims. It is also possible to combine all or a plurality of components of the above-described embodiments. [Explanation of symbols]
[0096] 1. Information Processing Systems 4 Network 21 User terminal 22 Communications Department 24 Display section 26 Input section 28 Processing section 100 Server device 110 Consent information acquisition department 111 Usage basis request processing unit 120 Consent information storage unit 150 corporate devices 152 Personal information storage unit 154 Direct Mail Generation Department 156 Direct Mail Sending Department 500 Prescribed Information
Claims
1. a storage unit that, when consent is obtained from a user regarding the handling of personal information, stores consent information regarding the consent in association with the user and a business operator involved in the handling; and a processing unit that discloses the basis for use of personal information to a user based on the data in the storage unit.
2. the processing unit performs the disclosure when receiving a request for the disclosure from a user; The information processing system according to claim 1 , wherein the request from the user can be generated in association with a transmission to be sent to the user or a call addressed to the user.
3. The information processing system according to claim 2 , wherein the transmission includes direct mail or the like via paper or electronic media.
4. the request from the user includes information that can identify the transmission; The information processing system according to claim 2 , wherein the processing unit acquires or generates the basis of use based on the result of identifying the transmission and data in the storage unit.
5. An information processing system as described in any one of claims 2 to 4, wherein the transmission based on the consent information includes registration information registered by the user in the title or the first half of the body, and the registration information includes one of characters, symbols, and images.
6. When the user's consent to the handling of personal information is entered, consent information regarding the consent is sent to the server; transmitting a request to the server when the request is entered by the user in association with a transmission to be sent to the user; A program that causes a computer to execute a process that outputs the basis for use of personal information transmitted from the server in response to the request.
7. A user terminal communicably connected to a server that stores consent information regarding the consent when the consent of the user to the handling of personal information is input, transmitting a request to the server when the request is entered by the user in association with a transmission to be sent to the user; A user terminal that outputs the basis for use of personal information transmitted from the server in response to the request.
Citation Information
Patent Citations
Individual information distribution method, individual information distribution system and individual information distribution provider device
JP2016091067A
Terminal device, information management device, data management method, and computer program
JP2018156312A
Information processing system, information processing method and program
JP2019139773A
Program, information processing apparatus, and information processing method
JP2021051694A
Personal information account banking
JP2016085676A