Personal information management system and personal information transfer control method
The personal information management system addresses the challenge of cross-border data transfer by centrally managing information and adhering to domestic regulations, ensuring compliant and secure data transfers.
Patent Information
- Application Number
- JP2022047488
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-23
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2042-03-23
AI Technical Summary
Existing personal information management systems struggle to control the transfer of personal information across borders, failing to consider the transfer situation and regulations of the source country, leading to potential inadequate protection of personal information at the transfer destination.
A personal information management system and method that integrates first and second computers connected via a network, where the second computer centrally manages personal information and updates transfer control based on data localization information and domestic retention regulations, determining the appropriateness of storage status and controlling permission or prohibition of transfers across borders.
Enables controlled transfer of personal information by considering past transfer situations and country regulations, ensuring compliance with domestic retention laws and enhancing information protection.
Smart Images

Figure 0007784933000001 
Figure 0007784933000002 
Figure 0007784933000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a personal information management system and a personal information transfer control method, and is suitable for use in a personal information management system and a personal information transfer control method that control the transfer of personal information between countries from the perspective of personal information protection. [Background technology]
[0002] In recent years, countries around the world have been establishing laws regarding the protection of personal information, including the General Data Protection Regulation (GDPR) in Europe. Businesses that collect, store, access, update, or otherwise handle personal information are required to comply with these laws. Personal information is defined in many countries as information that can directly identify an individual, or information that can be combined with other information to identify an individual, and information such as name and address is considered to fall under this definition.
[0003] When it comes to handling personal information, strict regulations have been put in place, particularly with regard to the transfer of personal information overseas (cross-border), and companies that operate globally must exercise caution. Furthermore, with the rapid spread of cloud computing in recent years, information is no longer necessarily stored domestically, and there are cases where information is stored in various locations overseas, so caution is required in countries that require information to be stored domestically. Therefore, when transferring personal information overseas, it is possible to control whether transfers are permitted or prohibited as necessary to comply with the regulations of each country mentioned above.
[0004] For example, Patent Document 1 is a known technology for controlling the international transfer of personal information. According to Patent Document 1, when transferring personal information from the EU (European Union) to outside the EU, a list is maintained in which countries or companies to which the transfer can be made are registered in advance. When attempting to transfer personal information internationally, the list is referenced, and if the transfer is to a country or company on the list, the transfer is permitted, but if the transfer is to a country or company outside the list, the information is deleted or processed as necessary before being transferred. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Application Publication No. 2020-112922 Summary of the Invention [Problem to be solved by the invention]
[0006] However, as disclosed in the above-mentioned Patent Document 1, in the conventional technology that controls the transfer of personal information by referring to a simple list of registered recipients, it was difficult to control the transfer according to the previous transfer situation, such as permitting the initial transfer of personal information but prohibiting subsequent transfers. Furthermore, even if a recipient is permitted as a transfer destination, if the source country has domestic retention regulations, etc., it is possible that the personal information will not be adequately protected at the subsequent transfer destination unless the regulations of the source country are taken into consideration. However, with the above-mentioned conventional technology, it was not easy to control the transfer according to such regulations of the source country, and there was a problem that the transfer would be permitted if the recipient was registered in the recipient list.
[0007] The present invention has been made in consideration of the above points, and aims to propose a personal information management system and a method for controlling the transfer of personal information that can control whether to allow or prohibit the transfer of personal information overseas, taking into account the transfer situation to date and the transfer regulations of each country. [Means for solving the problem]
[0008] In order to solve such problems, the present invention provides a personal information management system for managing transfer control of personal information handled at bases in various countries, in which a plurality of first computers for managing personal information handled at their own bases and a second computer for centrally managing personal information managed by the plurality of first computers are connected via a network, the first computers have first management information in which information relating to personal information handled at their own bases is registered, the second computers have second management information in which information relating to each personal information managed by the plurality of first computers is registered, and data localization information indicating domestic data retention regulations established in each country, and the first computers store setting information for predetermined items relating to personal information handled at their own bases in the first management information. the second computer updates the second management information based on the setting information notified from the first computer; the second computer uses the data localization information and the second management information to determine the appropriateness of the storage status of the personal information by the first computer based on the viewpoint of domestic retention regulations that apply to the base of the first computer and notifies the first computer of the result of the determination; and the first computer controls permission or prohibition of transfer of the personal information to another first computer across borders based on the result of the determination of the appropriateness of the storage status of the personal information by the second computer.
[0009] In order to solve the above problem, the present invention provides a personal information transfer control method by a personal information management system that manages the transfer control of personal information handled at bases in various countries, wherein the personal information management system comprises a plurality of first computers that manage personal information handled at their own bases and a second computer that centrally manages the personal information managed by the plurality of first computers, connected via a network, the first computers having first management information in which information relating to the personal information handled at their own bases is registered, the second computers having second management information in which information relating to each personal information managed by the plurality of first computers is registered, and data localization information indicating domestic data retention regulations established in each country, and the first computers set setting information for predetermined items relating to the personal information handled at their own bases in the first management information, and the set setting information is stored in the second management information. A method for controlling personal information transfer is provided, comprising: a first step of notifying a second computer; a second step of the second computer updating the second management information based on the setting information notified from the first computer in the first step; a third step of, after the second step, the second computer using the data localization information and the second management information to determine the appropriateness of the storage status of the personal information by the first computer based on the perspective of domestic retention regulations applicable to the base of the first computer and notifying the first computer of the determination result; and a fourth step of the first computer controlling permission or prohibition of transfer of the personal information to another first computer across borders based on the determination result of the appropriateness of the storage status of the personal information by the second computer in the third step. [Effects of the Invention]
[0010] According to the present invention, when transferring personal information overseas, permission or prohibition of the transfer can be controlled by taking into consideration the state of transfers up to now and the transfer regulations of each country. [Brief explanation of the drawings]
[0011] [Figure 1] 1 is a block diagram showing an example of the configuration of a personal information management system 100 according to a first embodiment of the present invention. [Figure 2] FIG. 10 is a diagram illustrating an example of the data configuration of base information 161. [Figure 3] 10 is a diagram showing an example of the data configuration of personal information management information 162. FIG. [Figure 4] FIG. 10 is a diagram illustrating an example of the data configuration of transfer management information 163. [Figure 5] 10 is a diagram showing an example of the data structure of data type definition information 164. FIG. [Figure 6] FIG. 10 is a diagram illustrating an example of the data configuration of transfer type definition information 165. [Figure 7] FIG. 10 is a diagram illustrating an example of the data configuration of cloud information 166. [Figure 8] FIG. 10 is a diagram showing an example of the data structure of localization information 167 for each country. [Figure 9] FIG. 10 is a diagram showing an example of the data configuration of each country's transfer regulation information 168. [Figure 10] FIG. 10 is a diagram showing an example of the data configuration of country regulation level information 169. [Figure 11] FIG. 10 is a diagram showing an example of the data structure of each country's sufficiency information 170. [Figure 12] FIG. 10 is a diagram showing an example of the data configuration of each country's sensitivity information 171. [Figure 13] 10 is a diagram showing an example of the data configuration of transfer reason group information 172. FIG. [Figure 14] FIG. 10 is a diagram illustrating an example of the data configuration of transfer grounds information 173. [Figure 15] 10 is a diagram showing an example of the data configuration of personal information management information 114. FIG. [Figure 16] FIG. 10 is a diagram illustrating an example of the data configuration of relocation candidate information 117. [Figure 17] 10 is a flowchart illustrating an example of a processing procedure for setting personal information and transfer candidate information. [Figure 18] 10 is a flowchart showing an example of a processing procedure for determining restriction on personal information; [Figure 19] 10 is a flowchart illustrating an example of a processing procedure for controlling the transfer of personal information. [Figure 20]FIG. 10 is a sequence diagram illustrating an example of a processing procedure for personal information registration processing after a transfer completion notification is given. [Figure 21] 10 is a flowchart illustrating an example of a processing procedure for re-transfer determination processing. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
[0013] Note that the following description and drawings are examples for explaining the present invention, and have been omitted or simplified as appropriate for clarity of explanation. Furthermore, not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention. The present invention is not limited to the embodiments, and all application examples consistent with the concept of the present invention are included in the technical scope of the present invention. Those skilled in the art can make various additions and modifications to the present invention within the scope of the present invention. The present invention can also be implemented in various other forms. Unless otherwise specified, each component may be plural or singular.
[0014] In the following explanation, various types of information may be described using expressions such as "table," "list," "data," etc., but the various types of information may also be expressed in data structures other than these. To indicate that they are not dependent on the data structure, "XX table," "XX list," etc. may be referred to as "XX information" or "XX data." When describing the content of each piece of information, expressions such as "identification information," "identifier," "name," "ID," and "number" are used, but these are interchangeable.
[0015] In addition, in the following explanation, when describing elements of the same type without distinguishing between them, reference signs or common numbers in reference signs will be used, and when describing elements of the same type with distinction between them, the reference signs of those elements will be used or an ID assigned to those elements will be used instead of the reference signs.
[0016] Furthermore, although the following description may describe processing performed by executing a program, the program is executed by at least one processor (e.g., a CPU) to perform a predetermined process using storage resources (e.g., memory) and / or interface devices (e.g., communication ports) as appropriate, and therefore the processor may be the subject of the processing. Similarly, the subject of the processing performed by executing a program may be a controller, device, system, computer, node, storage system, storage device, server, management computer, client, or host having a processor. The subject of the processing performed by executing a program (e.g., a processor) may include a hardware circuit that performs part or all of the processing. For example, the subject of the processing performed by executing a program may include a hardware circuit that performs encryption and decryption, or compression and decompression. The processor operates as a functional unit that realizes a predetermined function by operating in accordance with the program. Apparatuses and systems including a processor are apparatuses and systems that include these functional units.
[0017] A program may be installed on a device such as a computer from a program source. The program source may be, for example, a program distribution server or a computer-readable storage medium. When the program source is a program distribution server, the program distribution server includes a processor (e.g., a CPU) and storage resources, and the storage resources may further store a distribution program and a program to be distributed. The processor of the program distribution server may then execute the distribution program, causing the processor of the program distribution server to distribute the program to be distributed to other computers. In the following description, two or more programs may be realized as one program, and one program may be realized as two or more programs.
[0018] (1) First embodiment (1-1) System configuration 1 is a block diagram showing an example of the configuration of a personal information management system 100 according to a first embodiment of the present invention. The personal information management system 100 is a computer system including one or more base servers 101, one or more client terminals 141, and one or more management servers 151. The base server 101, the client terminals 141, and the management server 151 are connected to a network via their respective interfaces (I / Fs 104, 144, 154) and are configured to be able to communicate with each other.
[0019] The base server 101 is a computer such as a server having a memory 102, a CPU 103, an I / F 104, and a storage area 119. There are no particular limitations on the number and locations of the base servers 101 installed, but it can be considered that, for example, one or more base servers 101 are installed for each base (or each country) of a business or the like that handles personal information using the personal information management system 100. For the bases and countries, it is recommended to refer to the base information shown in FIG. 2.
[0020] The CPU 103 is, for example, a processor, and performs overall control of the base server 101. Specifically, for example, the CPU 103 receives operation requests from external devices (base servers 101 other than the CPU 103 itself, the client terminal 141, the management server 151, etc.) via the I / F 104, executes operations (data processing) requested by the external devices, transmits data processing results to the external devices, transmits data processing requests to the external devices, and so on.
[0021] The memory 102 is, for example, a main storage device that stores programs and data. The memory 102 is connected to the CPU 103 and the I / F 104.
[0022] 1, memory 102 has a collaboration unit 105, an information management unit 106, a relocation control unit 107, base information 111, data type definition information 112, relocation type definition information 113, personal information management information 114, relocation basis group information 115, relocation basis information 116, relocation candidate information 117, and cloud information 118. Of these components, collaboration unit 105, information management unit 106, and relocation control unit 107 are programs stored in memory 102, and predetermined functions are realized by the programs being executed by CPU 103. The other components shown in memory 102 are data other than the programs.
[0023] The storage area 119 is, for example, an auxiliary storage device, and stores information (specifically, personal information, etc.) of a database or the like held by the base server 101. The storage area 119 may be realized by a cloud or an externally connected storage device, etc.
[0024] The client terminal 141 is a computer having a memory 142, a CPU 143, and an I / F 144. The client terminal 141 is a computer used by the base server 101 or a user to give instructions and perform operations, and its location is not particularly limited.
[0025] The CPU 143 is, for example, a processor, and performs operations such as sending operation requests to external devices (such as the base server 101 and the management server 151) and receiving operation results from the external devices via the I / F 144. The memory 142 is, for example, a main storage device, and stores programs and data. The memory 142 is connected to the CPU 143 and the I / F 144. The memory 142 also has a linking unit 145 that is realized by a program.
[0026] The management server 151 is a computer such as a server having a memory 152, a CPU 153, an I / F 154, and a storage area 174. The management server 151 is a computer having a function of managing the transfer of personal information held by each base server 101, and there are no particular restrictions on the location or number of installations of the management server 151.
[0027] The CPU 153 is, for example, a processor, and performs overall control of the management server 151. Specifically, for example, the CPU 153 receives operation requests from external devices (management servers 151 other than itself, client terminals 141, base servers 101, etc.) via the I / F 154, executes operations (data processing) requested by the external devices, transmits data processing results to the external devices, transmits data processing requests to the external devices, and so on.
[0028] The memory 152 is, for example, a main storage device that stores programs and data. The memory 152 is connected to the CPU 153 and the I / F 154.
[0029] As shown in FIG. 1, memory 152 includes a linking unit 155, an information management unit 156, a restriction determination unit 157, base information 161, personal information management information 162, transfer management information 163, data type definition information 164, transfer type definition information 165, cloud information 166, country localization information 167, country transfer restriction information 168, country restriction level information 169, country sufficiency information 170, country sensitivity information 171, transfer basis group information 172, and transfer basis information 173. Of these components, linking unit 155, information management unit 156, and restriction determination unit 157 are programs stored in memory 152, and predetermined functions are realized by the CPU 153 executing these programs. The other components shown in memory 152 are data other than the programs.
[0030] The storage area 174 is, for example, an auxiliary storage device, and stores information (specifically, personal information, etc.) of a database or the like held by the management server 151. The storage area 174 may be realized by a cloud or an externally connected storage device, etc.
[0031] (1-2) Software configuration The following provides a detailed explanation of the software configuration of the personal information management system 100. Specifically, the information stored in the memory 152 of the management server 151, the information stored in the memory 102 of the base server 101, and the information stored in the memory 142 of the client terminal 141 will be explained in order.
[0032] (1-2-1) Data other than programs in the management server 151 First, information other than programs among the information stored in memory 152 of management server 151 will be described with reference to FIGS.
[0033] 2 is a diagram showing an example of the data configuration of the base information 161. The base information 161 is information indicating the base of a business operator or the like that handles personal information.
[0034] The base information 161 shown in FIG. 2 is composed of data items of base ID 201, base name 202, and location country 203. Base ID 201 indicates an ID that identifies each base. Base name 202 indicates the name of each base. Location country 203 indicates the country in which each base is located. Note that, for simplicity, the term "country" is used in the explanation of this invention, but the subject referred to by this "country" is not limited to a country as a nation, and may be considered to include regions (for example, the European Union (EU)), etc.
[0035] 3 is a diagram showing an example of the data configuration of the personal information management information 162. The personal information management information 162 is information for managing personal information in the management server 151, and holds records for each personal information unit.
[0036] The personal information management information 162 shown in FIG. 3 is composed of the data items management ID 301, acquisition country 302, date and time 303, base ID 304, data ID 305, data type 306, data location 307, address 308, cloud ID 309, domestic retention 310, and original ID 311.
[0037] Management ID 301 indicates an ID that identifies personal information (hereinafter referred to as target data in the explanation of FIG. 3) that is to be managed by management server 151. Acquisition country 302 indicates the acquisition country where the target data was acquired. Date and time 303 indicates the acquisition date and time of the target data. Base ID 304 indicates which base the target data belongs to by using a base ID (base ID 201 in FIG. 2).
[0038] Data ID 305 indicates how the target data is held at the location indicated by location ID 304, and more specifically, is indicated by an intra-location identification ID (data ID 1501 in FIG. 15) assigned to the target data at the location. Data type 306 indicates the data type of the target data by a data type ID (data type ID 501 in FIG. 5). The data type is defined by data type definition information 164 shown in FIG. 5.
[0039] Data location 307 indicates an overview of the storage location of the target data (inside the base, in the cloud, etc.). Address 308 indicates the details of the storage location of the target data by the address of the storage destination. Cloud ID 309 indicates the identification ID of the cloud (cloud ID 701 in FIG. 7) when the target data is stored in the cloud. For example, if the value of data location 307 is "home base", the target data is stored in storage area 119 of the base server 101 located in the home base. Also, if the value of data location 307 is "backup", this means that the target data is initially stored in a temporary storage area, etc., but is then moved to the address indicated by address 308 by performing a process such as data copying. The address indicated by address 308 is the address of the storage area where the target data is currently stored, but if the data storage location is changed due to backup, it is updated to the backup destination address.
[0040] Domestic Retention 310 indicates whether domestic retention of the target data is required by national law, etc., and, if domestic retention is required, whether it can be accommodated with the current storage status of the target data. Specifically, for example, if the value of Domestic Retention 310 is "-", it means that domestic retention of the target data is not required. If the value of Domestic Retention is "10", it means that domestic retention of the target data is required at the relevant location and can be accommodated with the current data storage status. If the value of Domestic Retention is "11", it means that domestic retention of the target data is required at the relevant location but cannot be accommodated with the current data storage status. If the value of Domestic Retention is "20", it means that domestic retention of the target data is required at a location other than the relevant location (the location that holds the original target data, such as the source of the target data transfer) and can be accommodated with the current data storage status. If the value of Domestic Retention is "21", it means that domestic retention of the target data is required at a location other than the relevant location (the location that holds the original target data, such as the source of the target data transfer), but cannot be accommodated with the current data storage status.
[0041] The source ID 311 indicates whether the target data is data that has been brought in by transfer, and if the target data is data that has been brought to the current base by transfer, it indicates the identification ID (management ID 301) of the data that is the source of the target data. Specifically, for example, if the value of the source ID 311 is "-", this means that the target data is not data that has been brought in by transfer. Also, if the value of the source ID 311 is "d5", this means that the target data is data that has been brought in by transfer, and that the data that is the source of the target data (the first source of the transfer if a multi-stage transfer has been performed) is data that is managed by the management server 151 with the identification ID (management ID 301) of "d5".
[0042] 4 is a diagram showing an example of the data configuration of the transfer management information 163. The transfer management information 163 is information for managing the history of transfers of personal information, and has a record for each transfer.
[0043] The transfer management information 163 shown in Figure 4 is composed of the data items of transfer ID 401, transfer source 402, transfer source data ID 403, transfer destination 404, transfer destination data ID 405, data type 406, transfer reason 407, transfer type 408, date and time 409, number of transfers 410, and management ID 411.
[0044] The transfer ID 401 indicates an ID that identifies the transfer of the management target. The transfer source 402 indicates the transfer source site with a site ID (site ID 201 in FIG. 2). The transfer source data ID 403 indicates the intra-site identification ID (data ID 1501 in FIG. 15) assigned by the management server 151 to the transferred data when it was managed at the transfer source site before the transfer. The transfer destination 404 indicates the transfer destination site with a site ID (site ID 201 in FIG. 2). The transfer destination data ID 405 indicates the intra-site identification ID (data ID 1501 in FIG. 15) assigned by the management server 151 to the transferred data when it was managed at the transfer destination site after the transfer. The data type 406 indicates the data type of the transferred data with a data type ID (data type ID 501 in FIG. 5). The data type is defined by the data type definition information 164 shown in FIG. 5.
[0045] The transfer basis 407 indicates the transfer basis of the transferred data using a basis ID (basis ID 1401 in FIG. 14). The transfer basis is specified in the transfer basis information 173 shown in FIG. 14. The transfer type 408 indicates the transfer type of the transferred data using a transfer type ID (transfer type ID 601 in FIG. 6). The transfer type is specified in the transfer type definition information 165 shown in FIG. 6. The date and time 409 indicates the date and time when the transferred data was transferred. The number of transfers 410 indicates the number of times the transferred data has been transferred in the past. Specifically, for example, if the value of the number of transfers 410 is "0", this means that the target transferred data has not been transferred before and this is the first transfer. If the value of the number of transfers 410 is "1", this means that the target transferred data has been transferred once before this transfer and this transfer is a re-transfer of the transferred data.
[0046] The management ID 411 indicates the identification ID (management ID 301 in FIG. 3) of the source data that is managed by the management server 151 in correspondence with the source data ID 403. The management ID 411 is set by the management server 151 when a notification of completion of the transfer is received from the source base, and is then used to match data between the management server 151 and the destination base (base server 101).
[0047] 5 is a diagram showing an example of the data configuration of the data type definition information 164. The data type definition information 164 is information that defines the classification of data held in storage areas 119, 174 of a database or the like held by the base server 101 or the management server 151. Various information including personal information is stored in the storage areas 119, 174, and each computer (management server 151, base server 101, client terminal 141) of the personal information management system 100 can grasp, based on the data type definition information 164, 112, what classification of data is included in the information stored in the storage areas.
[0048] The data type definition information 164 shown in Fig. 5 is configured to have data items of data type ID 501 and content 502. Data type ID 501 indicates an ID (data type ID) that identifies the classification of data. Content 502 indicates the content of the data classification. For example, in Fig. 5, the data type ID for data that includes "name" is defined as "p1," and the data type ID for data that includes "address" is defined as "p2." In this case, if the target information includes name and address, the data type of the information is assigned multiple classifications (data type IDs), such as "p1" and "p2."
[0049] 6 is a diagram showing an example of the data configuration of the transfer type definition information 165. The transfer type definition information 165 is information that defines a data transfer method.
[0050] The transfer type definition information 165 shown in Figure 6 is composed of data items: transfer type ID 601 and content 602. Transfer type ID 601 indicates an ID (transfer type ID) that identifies the classification of data transfer methods. Content 602 indicates the content of the classification of data transfer methods. For example, in Figure 6, a transfer method with a transfer type ID of "t1" indicates a transfer method in which data is sent to the transfer destination without leaving it at the transfer source. Furthermore, a transfer method with a transfer type ID of "t2" indicates a transfer method in which data is sent to the transfer destination while remaining at the transfer source by copying, etc.
[0051] 7 is a diagram showing an example of the data configuration of the cloud information 166. The cloud information 166 is information for managing various types of information regarding clouds that can be used by the personal information management system 100 as data storage destinations.
[0052] The cloud information 166 shown in FIG. 7 is configured to have the data items of a cloud ID 701, a cloud vendor 702, a service name 703, a contact point 704, and data locations 705 and 706.
[0053] Cloud ID 701 indicates the identification ID (cloud ID) of the cloud that stores data. Cloud vendor 702 indicates the vendor of the cloud identified by cloud ID 701 (hereinafter referred to as the cloud). Service name 703 indicates the type of service provided by the vendor of the cloud. For example, if the value of service name 703 is "email," it means that the cloud provides an email service, and if the value of service name 703 is "storage," it means that the cloud provides a data storage service. Contact point 704 indicates the location (e.g., country name) of the contact point set up for the service provided by the cloud. Data location 705 indicates an overview of the data storage location of the service provided by the cloud (e.g., a wide area such as Asia or North America), and data location 706 indicates the details of the data storage location (e.g., country or city).
[0054] 8 is a diagram showing an example of the data configuration of the country localization information 167. "Country localization" refers to the regulations on data localization (obligation to maintain data domestically) established by each country. Country localization information 167 is information that manages the details of these country localization regulations.
[0055] The country localization information 167 shown in Figure 8 is composed of data items of country 801 and sensitivities 802 to 805. Country 801 indicates the name of the country. Sensitivities 802 to 805 are data items corresponding to sensitivities "s1," "s2," "s3," ... defined in country sensitivity information 171 of Figure 12, which will be described later, and indicate whether or not each country has data localization restrictions for data corresponding to each sensitivity. For example, in the case of Figure 8, in a record where the value of country 801 is "medium," the values of sensitivity 803 and 804 are "yes," which indicates that localization restrictions (obligation to retain data domestically) are imposed on data with sensitivities s2 and S3 in China.
[0056] 9 is a diagram showing an example of the data configuration of each country's transfer restriction information 168. "Transfer restrictions of each country" refers to restrictions imposed by each country on the transfer of data. The transfer restriction information 168 of each country is information that manages the content of these transfer restrictions of each country.
[0057] The country transfer regulation information 168 shown in Figure 9 is composed of data items of country 901 and sensitivities 902 to 905. Country 901 indicates the name of the country. Sensitivities 902 to 905 are data items corresponding to sensitivities "s1," "s2," "s3," ... defined in country sensitivity information 171 in Figure 12, which will be described later, and indicate which transfer basis group of regulations each country has for data that falls under each sensitivity. The transfer basis group is defined in transfer basis group information 172 in Figure 13, which will be described later.
[0058] 10 is a diagram showing an example of the data configuration of the country regulation level information 169. The country regulation level information 169 is information for managing the level of regulation regarding personal information protection in each country.
[0059] 10 is configured with data items of level 1001 and country 1002. Level 1001 indicates the required level of personal information protection, and in this example, the higher the level value, the higher the required level of personal information protection (i.e., the stricter the regulations). Country 1002 indicates the country corresponding to each level of personal information protection.
[0060] The restriction level of each country (the value of level 1001) can be automatically calculated by the management server 151 based on the information in the country localization information 167, the country transfer restriction information 168, and the country sensitivity information 171. An example of a specific method for calculating the restriction level is shown below.
[0061] For the localization information 167 for each country shown in Figure 8, the management server 151 assigns a score to each column (each sensitivity). For example, sensitivity "s1" is assigned 1 point, sensitivity "s2" is assigned 2 points, sensitivity "s3" is assigned 3 points, etc. Then, the management server 151 refers to Figure 8 and counts the points if there are restrictions on sensitivity, and calculates the total score for each row (each country). In this case, China is assigned 6 points and Japan is assigned 0 points.
[0062] Furthermore, for the sensitivity information 171 for each country shown in Fig. 12, the management server 151 calculates points based on the variation in sensitivity. For example, if there is one type of variation, it is assigned 1 point, if there are two types, it is assigned 2 points, if there are three types, it is assigned 3 points, etc. The management server 151 then calculates the points for each country by referring to Fig. 12. For example, the sensitivity for the United States is assigned 1 point because there is only one type, "s1," and the sensitivity for Europe is assigned 2 points because there are two types, "s1" and "s2."
[0063] Furthermore, for the transfer restriction information 168 of each country shown in Figure 9, the management server 151 determines a score for each column (each sensitivity). For example, if a restriction exists in each column (i.e., if a value from any group is registered), one point is added for each, and the total score is calculated. Note that, as a variation of the score calculation, the more elements of the transfer basis that make up a group, the more variations in the transferable basis are considered to be available and the easier it is to transfer, and the lower the score (i.e., the weaker the restriction).
[0064] In this way, management server 151 can calculate the score for each country from the information in each country's localization information 167, each country's transfer restriction information 168, and each country's sensitivity information 171. Management server 151 then calculates a total score for each country by aggregating the scores calculated from each piece of information, and determines the restriction level for each country according to this total score, so that the higher the score of a country, the higher the restriction level.
[0065] In addition to the above, the control level of each country may also be calculated based on the amount of the fine imposed upon a violation. In this case, the management server 151 stores in the memory 152 information on the amount of the fine imposed upon a violation for each country, and by referring to the information on the amount of the fine, adds points to calculate the control level for countries with higher fines imposed upon a violation.
[0066] Fig. 11 is a diagram showing an example of the data configuration of country sufficiency information 170. Country sufficiency information 170 is information that indicates the adequacy certification relationship between countries regarding the transfer of personal information. When personal information is transferred across borders, it is said that the transfer is approved without making any special arrangements for the personal information (i.e., without changing the way the personal information is handled).
[0067] The adequacy information 170 for each country shown in FIG. 11 is configured with data items of country 1101 and sufficiency target country 1102. Country 1101 indicates a country, and sufficiency target country 1102 indicates a country that has granted adequacy certification to the country shown in country 1101. In other words, for the country shown in country 1101, the country shown in sufficiency target country 1102 is a country that is subject to sufficiency. For example, in FIG. 11, in a record where the value of country 1101 is "Japan," "UK, Europe" is registered as the value of sufficiency target country 1102. This record indicates that data can be transferred internationally from Japan to the UK or the EU based on adequacy certification.
[0068] 12 is a diagram showing an example of the data configuration of country sensitivity information 171. "Country sensitivity" refers to the degree of caution in data handling required in each country (data sensitivity) for each data type defined in data type definition information 164. Country sensitivity information 171 is information that manages this country sensitivity.
[0069] The sensitivity information 171 for each country shown in FIG. 12 is configured with data items of country 1201 and data types 1202 to 1205. Country 1201 indicates a country. Data types 1202 to 1205 are data items corresponding to the respective data types (data type ID 501) "p1," "p2," "p3," ... defined in the data type definition information 164 of FIG. 5, and indicate the sensitivity of the data for the relevant data type. For example, in the case of FIG. 12, in a record in which the value of data type 1201 is "Europe" indicating the EU, when the values of data types 1202 to 1204 are looked at, the data sensitivity of data type "p1" is "s1," the data sensitivity of data type "p2" is "s1," and the data sensitivity of data type "p3" is "s2." Here, if "s2" is more sensitive than "s1," then data of data type "p3" requires more careful handling than data of data types "p1" and "p2."
[0070] Fig. 13 is a diagram showing an example of the data configuration of transfer basis group information 172. The transfer basis group information 172 is information for managing groups (transfer basis groups) formed from combinations of transfer basis defined in transfer basis information 173 in Fig. 14, which will be described later. The transfer basis group indicates requirements that must be met in transfers between countries.
[0071] The transfer basis group information 172 shown in Fig. 13 is configured with the data items of group ID 1301 and content 1302. Group ID 1301 indicates an ID that identifies a transfer basis group. Content 1302 indicates a combination of transfer reasons that make up a transfer basis group using basis ID 1401 shown in Fig. 14. For example, if the value of group ID 1301 in Fig. 13 is "Gr2", the value of content 1302 is "g1 or g2". This indicates that if the data to be transferred belongs to the transfer basis group "Gr2", it must satisfy at least either "g1" or "g2" as its transfer basis.
[0072] Fig. 14 is a diagram showing an example of the data configuration of the transfer basis information 173. The transfer basis information 173 shown in Fig. 14 is configured to have data items of basis ID 1401 and content 1402. The basis ID 1401 indicates an ID that identifies the basis for transfer. The content 1402 indicates the content of the basis for transfer. For example, in Fig. 14, if the value of the basis ID 1401 is "g1", the value of the content 1402 is "consent". This indicates that obtaining consent is one of the conditions for transfer.
[0073] (1-2-2) Programs in the Management Server 151 Next, a description will be given of the programs stored in the memory 152 of the management server 151. As described above, the linking unit 155, the information management unit 156, and the restriction determination unit 157 are realized by the programs stored in the memory 152.
[0074] The coordinating unit 155 exchanges data with other computers (such as the base server 101 and the client terminal 141) via the network. For ease of explanation, when the coordinating unit 155 exchanges data with other computers at the request of another functional unit within its own computer, the "other functional unit" may be referred to as the processing entity, rather than the coordinating unit 155. This also applies to the coordinating unit 105 of the base server 101.
[0075] Based on the information related to the personal information notified from the base server 101, the information management unit 156 registers information for grasping the personal information in the management server 151, and registers information for grasping the personal information transferred from one base server 101 to another base server 101. The destination for registering this information is data other than the program in the memory 152, as detailed in (1-2-1).
[0076] The restriction determination unit 157 determines whether or not restriction is required for the personal information data to be transferred upon receiving a request from the base server 101. More specifically, the restriction determination unit 157 determines whether or not localization is applied to the personal information data to be transferred, whether or not the data is being stored, and whether or not the data should be transferred again.
[0077] (1-2-3) Data other than programs in the base server 101 Next, information other than the program among the information stored in the memory 102 of the base server 101 will be described.
[0078] The information held by the base server 101 in memory 102 includes a plurality of pieces of data similar to the information of the same name held by the above-mentioned management server 151 in memory 152 (at least data having a similar data configuration), and detailed description of this information will be omitted. Specifically, the base information 111 is similar to the base information 161 exemplified in Fig. 2, the data type definition information 112 is similar to the data type definition information 164 exemplified in Fig. 5, the transfer type definition information 113 is similar to the transfer type definition information 165 exemplified in Fig. 6, the transfer basis group information 115 is similar to the transfer basis group information 172 exemplified in Fig. 13, the transfer basis information 116 is similar to the transfer basis information 173 exemplified in Fig. 14, and the cloud information 118 is similar to the cloud information 166 exemplified in Fig. 7.
[0079] For example, this information may be distributed to each base as information with the same names (base information 161, data type definition information 164, transfer type definition information 165, cloud information 166, transfer basis group information 172, transfer basis information 173) defined or held in the management server 151, and the base server 101 of each base may store it in the memory 102 and use it. Note that with regard to the transfer basis group information 115, instead of distributing the same content as the transfer basis group information 172 from the management server 151 to each base, information limited to transfer basis groups related to personal information held individually by each base may be distributed from the management server 151 to the base server 101. Furthermore, as another example, information independently collected by the base server 101 may be aggregated in the management server 151, and after consistency is achieved in the management server 151, the information may be distributed to the base server 101 of each base as appropriate.
[0080] Examples of information that the base server 101 independently stores in the memory 102 include personal information management information 114 and transfer candidate information 117.
[0081] Fig. 15 is a diagram showing an example of the data configuration of personal information management information 114. Personal information management information 114 is similar to personal information management information 162 (see Fig. 3) held by management server 151, but differs from personal information management information 162, which is information for aggregating and centrally managing personal information from all bases, in that personal information management information 114 is information for managing personal information handled at its own base.
[0082] 15 is configured to have data items of data ID 1501, acquisition country 1502, date and time 1503, data type 1504, data location 1505, address 1506, cloud ID 1507, domestic retention 1508, management ID 1509, and transfer ID 1510. Acquisition country 1502, date and time 1503, data type 1504, data location 1505, address 1506, cloud ID 1507, and domestic retention 1508 are similar to the data items of the same names that are included in personal information management information 162 in FIG. 3, and detailed description thereof will be omitted.
[0083] The data ID 1501 indicates an ID for identifying personal information (hereinafter referred to as target data in the explanation of FIG. 15) that is to be managed by the base server 101.
[0084] The management ID 1509 indicates the management ID of the target data by the management server 151. The management ID 1509 is assigned by the management server 151, and corresponds to the management ID 301 included in the personal information management information 162 in Fig. 3. For example, when the base server 101 notifies the management server 151 of information relating to an overview of the target data (personal information), the management ID is assigned by the management server 151, and is returned to the base server 101 and set as the management ID 1509.
[0085] The transfer ID 1510 indicates a transfer ID for identifying the transfer of the target data. For example, when the base server 101 notifies the management server 151 of information about the completion of the transfer of the target data (personal information), the transfer ID is assigned by the management server 151, returned to the base server 101, and set as the base ID 1510.
[0086] 16 is a diagram showing an example of the data configuration of the transfer candidate information 117. The transfer candidate information 117 is information for managing transfer candidates to other bases for personal information held at the own base.
[0087] The transfer candidate information 117 shown in FIG. 16 is configured to have the data items of a candidate ID 1601, a target ID 1602, a transfer destination 1603, a data location 1604, an address 1605, a cloud ID 1606, a transfer reason group 1607, and a purpose 1608.
[0088] Candidate ID 1601 indicates the identification ID of the transfer candidate. Target ID 1602 indicates the identification ID of the personal information to be transferred using an internal identification ID (data ID 1501 in FIG. 15). Transfer destination 1603 indicates the transfer destination location using an internal ID (location ID 201 in FIG. 2). Data location 1604 indicates an overview of the storage location of the personal information at the transfer destination (within the location, cloud, etc.). Address 1605 indicates the details of the storage location of the personal information at the transfer destination using the storage address. Cloud ID 1606 indicates the identification ID of the cloud (cloud ID 701 in FIG. 7) if the personal information to be transferred is stored in the cloud. Transfer basis group 1607 indicates a transfer basis group consisting of a combination of transfer basis that must be satisfied in the transfer using its identification ID (group ID 1301 in FIG. 13). Purpose 1608 indicates the purpose of handling the personal information regarding the transfer (e.g., storing information at a location other than the own location, analysis, etc.).
[0089] (1-2-4) Program on the base server 101 Next, a description will be given of the programs stored in the memory 102 of the base server 101. As described above, the collaboration unit 105, the information management unit 106, and the relocation control unit 107 are realized by the programs stored in the memory 102.
[0090] The linking unit 105 exchanges data with other computers (such as the management server 151 and the client terminal 141) via the network.
[0091] Based on the information relating to the personal information notified from the client terminal 141, the information management unit 106 performs registration of information for grasping the personal information within the base server 101, etc.
[0092] The transfer control unit 107 cooperates with the management server 151 and the client terminal 141, etc., and controls the transfer of personal information related to its own base (i.e., personal information managed by the base server 101) in accordance with the decision by the management server 151 to permit or prohibit the transfer.
[0093] (1-2-5) Program in the client terminal 141 Next, a description will be given of the programs stored in the memory 142 of the client terminal 141. As described above, the linking unit 145 is realized by the programs stored in the memory 142.
[0094] The linking unit 145 links with external computers such as the base server 101, and transmits requests for setting, protecting, or extracting personal information in response to user operations. The linking unit 145 also receives response results from the external computers.
[0095] (1-3) Processing The following describes the processing executed by the personal information management system 100 according to this embodiment based on the above-described hardware and software configurations. The processing described below is executed when a request for execution of setting processing related to personal information is made from the client terminal 141 to the base server 101.
[0096] (1-3-1) Setting process of personal information and transfer candidate information FIG. 17 is a flowchart showing an example of the processing procedure for setting personal information and transfer candidate information. The processing shown in FIG. 17 is processing executed by the base server 101 when, for example, a user operates the client terminal 141 to register certain personal information in the base server 101 of the user's own base. In the processing shown in FIG. 17, when a request is made to register personal information, a request is made to register transfer candidate information related to that transfer candidate, but the request to register the transfer candidate information may be made at a different timing from the request to register personal information. In that case, of the various processing described below, the processing related to the registration of transfer candidate information may be executed separately. The processing shown in FIG. 17 can also be applied when changing (updating) the content of registered personal information or transfer candidate information.
[0097] 17, first, the coordinating unit 105 receives a request for setting (registration, update, etc.) personal information and its transfer candidate information from the client terminal 141 (step S101). In step S101, the coordinating unit 105 also receives from the client terminal 141 the personal information and transfer candidate information to be set.
[0098] Next, based on the request in step S501, the information management unit 106 uses the received personal information and transfer candidate information to update the information stored in the memory 102 (personal information management information 114, transfer candidate information 117), and transmits information related to the update to the management server 151 (step S102). The management server 151, which has received the information transmitted in step S102, executes the processing shown in Fig. 18, which will be described later.
[0099] The processing content of the information management unit 106 in step S102 will be described in detail.
[0100] For example, when a request is made to register personal information, in the personal information management information 114 of FIG. 15, the base server 101 (information management unit 106) assigns a new identification ID (data ID 1501) to the personal information requested to be registered based on information from the client terminal 141, and registers information regarding the personal information, such as the country from which the data was acquired (acquisition country 1502), the acquisition date and time (date and time 1503), the data type (data type 1504), an overview of the storage location (data location 1505), and the detailed address of the storage location (address 1506).
[0101] Also, for example, when a request is made to register transfer candidate information, in the transfer candidate information 117 of Fig. 16, the base server 101 (information management unit 106) assigns a new identification ID (candidate ID 1601) to the transfer candidate information requested to be registered based on information from the client terminal 141, and registers information regarding the transfer candidate information, such as the transfer target (target ID 1602), transfer destination (transfer destination 1603), an overview of the data storage location of the transfer destination (data location 1604), and a detailed address of the storage destination (address 1605).Then, the above updated (registered) information and the base information of the base server 101 are transmitted from the base server 101 to the management server 151, and the information on the management server 151 side is updated by the processing shown in Fig. 18, which will be described later.
[0102] Next, the information management unit 106 updates predetermined data items in the personal information management information 114 and the transfer candidate information 117 based on the response information from the management server 151 (step S103). The predetermined data items are, for example, domestic retention 1508 and management ID 1509 in the personal information management information 114, and transfer basis group 1607 in the transfer candidate information 117.
[0103] 15, the information management unit 106 sets the result of the determination by the management server 151 as to whether or not data localization support is required in the domestic storage 1508. The management server 151 determines whether or not data localization support is required based on the values of the acquisition country 1502 and the data type 1504 received from the base server 101 in step S102, and notifies the base server 101 of the determination result (steps S205, S208, and S209 in FIG. 18, which will be described later). In addition, the information management unit 106 sets the value of the management ID 301, which the management server 151 assigned to the target personal information by the processing in FIG. 18, in the management ID 1509.
[0104] 16, the information management unit 106 sets the relocation basis group determined by the management server 151 to the relocation basis group 1607. The relocation basis group is determined by the management server 151 based on the value of the acquired country 1502 received from the base server 101 in step S102, information on the relocation candidate destination, and the like, and the determination result is notified to the base server 101 (steps S205, S208, and S209 in FIG. 18, which will be described later).
[0105] By executing the processing of FIG. 17 as described above, the base server 101 can appropriately set the requested personal information and candidate transfer destination information in its own memory 102 while cooperating with the management server 151.
[0106] (1-3-2) Personal information regulation and judgment processing Fig. 18 is a flowchart showing an example of the processing procedure for determining restrictions on personal information. The processing shown in Fig. 18 is executed by the management server 151 when it receives a notification of personal information or transfer candidate information from the base server 101 (step S102 in Fig. 17), and determines whether the personal information needs to be held domestically and whether the storage status of the personal information is appropriate.
[0107] According to FIG. 18, first, the cooperation unit 155 receives personal information and relocation candidate information from the base server 101 (step S201).
[0108] Next, the information management unit 156 updates the personal information management information 162 based on the information received in step S201 (step S202). Specifically, the information management unit 156 assigns an identification ID (management ID) for managing the personal information newly registered in the base server 101 in the management server 151 to the personal information management information 162 shown in Fig. 3, and sets the management ID 301. Furthermore, the information management unit 156 sets data items 302 to 309 of the record in which the new management ID is set, based on the personal information received in step S201. Note that the value of the identification ID (data ID 1501 in Fig. 15) used to identify the personal information in the base server 101 is set in the data ID 305.
[0109] Next, the restriction determination unit 157 determines whether the personal information notified from the base server 101 needs to be held domestically based on the acquisition country 302, data type 306, data location 307, and original ID 311 (step S203). The value of domestic holding 310 is determined and set through multiple processes from step S203 onwards.
[0110] The processing of step S203 will be specifically described in detail. First, the restriction determination unit 157 identifies the sensitivity to which the type of personal information (data type 306) corresponds in the acquisition country (acquisition country 302) by referring to the sensitivity information for each country 171 in FIG. 12. For example, if the acquisition country is "Japan" and the type is "p1," the sensitivity is identified as "s1" according to FIG. 12. Next, the restriction determination unit 157 identifies whether localization support is required for the data of the identified sensitivity in the acquisition country by referring to the transfer restriction information for each country 168 in FIG. 8. For example, if the acquisition country is "Japan" and the sensitivity is "s1" as in the above example, the corresponding value is "-" according to FIG. 8, and it is determined that localization support is not required. Note that if the corresponding value in FIG. 8 is "Yes," it is determined that localization support is required.
[0111] As described above, if the restriction determination unit 157 determines that localization support (domestic storage) is not required (NO in step S203), "-" is set in domestic storage 310, and the process proceeds to step S209, which will be described later. On the other hand, if the restriction determination unit 157 determines that localization support (domestic storage) is required (YES in step S203), "Yes" is set in domestic storage 310, and the process proceeds to step S204.
[0112] In step S204, the restriction determination unit 157 determines whether the storage status of the personal information notified by the base server 101 is appropriate. If it is determined that the storage status of the personal information is appropriate (YES in step S204), the process proceeds to step S205, and if it is determined that the storage status of the personal information is not appropriate (NO in step S204), the process proceeds to step S209.
[0113] The process of step S204 will be specifically described in detail. The restriction determination unit 157 first checks whether the original ID 311 is registered or not, and performs the following process depending on the check result.
[0114] If the value of original ID 311 is unregistered, restriction determination unit 157 determines that the data (personal information) is not data brought in by transfer but newly registered data. At this time, restriction determination unit 157 identifies the country where the data is located based on information on base ID 304, data location 307, and cloud ID 309. If the country matches the country from which the data was acquired (acquisition country 302), restriction determination unit 157 determines that localization support is required for its own base and that such support is possible with the current data storage status (YES in step S204), and sets the value of domestic retention 310 to "10." Note that if the value of data location 307 is "cloud," restriction determination unit 157 can identify the country where the data is located by referencing the value of data location 706 in FIG. 7 using cloud ID 309 as a key. On the other hand, if the country where the identified data is located does not match the country from which the data was acquired (acquisition country 302), the regulation determination unit 157 determines that localization support is necessary for its own base, but that the current data storage status does not allow for this support (NO in step S204), and sets the value of domestic retention 310 to "11".
[0115] In other words, if the value of original ID 311 is not registered, the regulation determination unit 157 determines whether the current storage status of the personal information data held at the notified base (own base) in step S201 is appropriate by checking whether the current storage location of the data complies with the perspective of domestic retention, and if it determines that it is appropriate, it sets the value of "10" to domestic retention 310, and if it determines that it is inappropriate, it sets the value of "11" to domestic retention 310.
[0116] If the value of original ID 311 has been registered, restriction determination unit 157 determines that the data (personal information) has been transferred. In this case, restriction determination unit 157 checks whether the storage location of the transferred data complies with the domestic storage requirement in the same manner as when the value of original ID 311 is unregistered. Furthermore, restriction determination unit 157 periodically inquires of the base holding the data indicated by original ID 311 (i.e., the base holding the original personal information of the transferee) about the data storage status, such as the data storage location (data location 307), and uses the results of the inquiry to determine whether data localization is required in the same manner as described when the value of original ID 311 is unregistered. This determination is made to confirm whether the data at the transfer source needs to be stored domestically.
[0117] Then, the regulation determination unit 157 determines whether the current data storage conditions are appropriate based on the results of checking whether the storage location of the data brought in by the transfer is in compliance with the viewpoint of domestic retention, and further determines the value to be set in domestic retention 310 based on the results of checking whether the data from the transfer source needs to be held domestically.
[0118] Specifically, the restriction determination unit 157 determines that the current data storage status is appropriate when the storage location of the data brought by transfer conforms to the viewpoint of domestic retention (YES in step S204). At this time, if the restriction determination unit 157 confirms that domestic retention is necessary for the data at the transfer source, it sets the value of domestic retention 310 to "20", and if it confirms that domestic retention is not necessary for the data at the transfer source, it sets the value of domestic retention 310 to "10". Furthermore, the restriction determination unit 157 determines that the current data storage status is inappropriate when the storage location of the data brought by transfer does not conform to the viewpoint of domestic retention (NO in step S204). At this time, if the restriction determination unit 157 confirms that domestic retention is necessary for the data at the transfer source, it sets the value of domestic retention 310 to "21", and if it confirms that domestic retention is not necessary for the data at the transfer source, it sets the value of domestic retention 310 to "11".
[0119] The original ID 311 is registered (set) when the personal information to be managed is data that has been brought in through transfer, and its value is set to the identification ID (i.e., data ID 301 of the source data) that the management server 151 assigned for management purposes to the source data held by the source base server 101.
[0120] Specifically, the management server 151 (information management unit 156 or restriction determination unit 157) determines whether the data to be newly registered this time (identifiable from the base ID 304 and data ID 305) matches the data identified from the transfer destination 404 and transfer destination data ID 405 in the transfer management information 163 in Fig. 4. If matching data is registered in the transfer management information 163, the value of the management ID 411 corresponds to the identification ID in the base server 101, which is the original transfer source of the data to be registered this time, and therefore the management server 151 sets the value of this management ID 411 to the original ID 311.
[0121] The processing from step S204 onwards will be explained. To summarise the explanation so far, if it is determined that the personal information notified in step S201 needs to be held domestically (YES in step S203) and that the current data storage status is appropriate (YES in step S204), the processing of step S205 is carried out. On the other hand, if it is determined that the personal information notified in step S201 does not need to be held domestically (NO in step S203) or that the current data storage status is inappropriate (NO in step S204), the processing of step S209 is carried out.
[0122] In step S205, the management server 151 (information management unit 156 or restriction determination unit 157) transmits the value of domestic retention 310 (domestic retention flag) and information on the basis of transfer to the base server 101 that transmitted the personal information in step S201.
[0123] The above-mentioned "information on the basis of transfer" is collected information on the basis of transfer when there is a possibility that the target personal information will be transferred in the future. Specifically, when the data ID (data ID 305, data ID 1501) of the personal information received from the base server 101 in step S201 matches the target ID 1602 of the transfer candidate information received from the base server 101, the management server 151 can determine that the personal information is likely to be transferred in the future. In this case, the management server 151 collects information on the basis of transfer and transmits it to the base server 101. More specifically, the management server 151 identifies the sensitivity of the data based on the personal information management information 162 in Figure 3 (particularly the acquisition country 302 and data type 306) and the country sensitivity information 171 in Figure 12, identifies the transfer basis required for the identified sensitivity from the country transfer restriction information 168 in Figure 9 and the transfer basis group information 172 in Figure 13, and sends information indicating the identification result (for example, the value of the basis group such as "Gr2") to the base server 101.
[0124] After the processing of step S205, the restriction determination unit 157 periodically inquires of the base (such as the base from which the original transfer occurred) that holds the personal information data about the data storage status, such as the data storage location (data location 307), and monitors the status (step S206). Then, upon receiving the inquiry result, the restriction determination unit 157 determines the appropriateness of the storage status using the same procedure as in step S204 described above (step S207). If the restriction determination unit 157 determines that the storage status is appropriate (YES in step S207), the restriction determination unit 157 returns to step S206 and continues monitoring. On the other hand, if the restriction determination unit 157 determines that the storage status is inappropriate (NO in step S207), the restriction determination unit 157 notifies the base server 101 that the storage status should be corrected and that the transfer of the data is prohibited (step S208). At this time, the restriction determination unit 157 may update the value of the domestic retention 310 (domestic retention flag) of the target data to a specific value that suits the status. In step S208, a flag or the like indicating the notification content may be transmitted, or a value corresponding to the notification content may be transmitted.
[0125] The processing in steps S206 and S207 is to continuously monitor whether data that requires data localization support is being held in an appropriate storage state. This is because even if the current storage state is determined to be appropriate (YES) in step S204, it is necessary to check that the storage state does not change until the data is transferred, and it is also necessary to check the storage state of the original data after the transfer.
[0126] Also, in step S209, similar to step S205, the management server 151 (information management unit 156 or regulation determination unit 157) transmits the value of domestic retention 310 and information on the basis of transfer to the base server 101 that transmitted the personal information in step S201.
[0127] By executing the process of FIG. 18 as described above, the management server 151 enables the personal information stored in each base server 101 to be stored in accordance with the data localization of each country.
[0128] (2) Second embodiment A second embodiment of the present invention will be described using the personal information management system 100 described in the first embodiment. In this embodiment, when transferring personal information overseas, it is possible to determine whether to transfer the information while taking into consideration the transfer status up to now and the transfer regulations of each country, and based on the result of this determination, it is possible to execute control such as permitting or prohibiting the transfer.
[0129] In the personal information management system 100 according to this embodiment, when the base server 101 receives a request to transfer personal information from the client terminal 141, it determines whether the requested transfer is a re-transfer, and if it is a re-transfer, it controls whether to permit or prohibit the transfer in cooperation with the management server 151. The process for performing such control will be described in detail below.
[0130] (2-1) Transfer control processing of personal information Fig. 19 is a flowchart showing an example of a processing procedure for personal information transfer control processing. The processing shown in Fig. 19 is processing executed by the base server 101 at the current base when a user operates the client terminal 141 to transfer (move or copy) certain personal information from the current base to another base. Note that the processing in Fig. 19 can be executed when the processing shown in Figs. 17 and 18 in the first embodiment has been completed. In the following description, to avoid confusion between the base servers 101, the base server 101 at the current base that is the transfer source may be referred to as "base server 101A," and the base server 101 at the base that is the transfer destination may be referred to as "base server 101B."
[0131] 19, first, the linking unit 105 of the base server 101A receives a personal information transfer request from the client terminal 141 (step S301). The transfer request received in step S301 specifies the personal information to be transferred and the transfer method. The transfer method is indicated, for example, by the value of the transfer type ID 601 described in the first embodiment with reference to FIG. 6.
[0132] Next, the base server 101A (e.g., the information management unit 106) determines whether the personal information specified in the transfer request can be adapted to data localization (step S302). Specifically, the base server 101A refers to the domestic retention 1508 of the personal information management information 114 stored in its own memory 102 (see FIG. 15), and determines that data localization can be adapted if the value of the domestic retention 1508 of the personal information specified in the transfer request is "-" or "20", or if the value of the domestic retention 1508 of the personal information specified in the transfer request is "10" and the transfer type specified in the transfer request is a transfer method in which data remains in the country (transfer source), such as "t2". In addition, the base server 101A determines that data localization is not possible if the value of the domestic retention of personal information 1508 specified in the transfer request is "11" or "21", or if the value of the domestic retention of personal information 1508 specified in the transfer request is "10" and the transfer type specified in the transfer request is "t2" or another transfer method in which data does not remain in the country (transfer source).
[0133] If it is determined in step S302 that data localization is not possible (domestic storage NG) (NO in step S302), the base server 101A notifies the client terminal 141 of the transfer refusal and presents an alternative transfer method (step S309), and completes the process. Presenting an alternative transfer method means, for example, presenting transfer types such as "t2" and "t3" as alternatives when it is determined that the transfer is rejected in a transfer request in which the transfer type "t1" is specified.
[0134] If it is determined in step S302 that data localization is possible (domestic storage OK) (YES in step S302), the base server 101A determines whether there are any problems with the transfer from viewpoints other than data localization (step S303). Specifically, the base server 101A (e.g., the information management unit 106) determines whether the transfer basis specified in the current transfer request is appropriate. The determination of appropriateness is made based on the information in the transfer candidate information 117 in FIG. 16. For example, in FIG. 16, the transfer target (target ID 1602) with "02" must satisfy the transfer basis group "Gr2" in the transfer. Here, according to the transfer basis group information 115 in FIG. 13, the transfer basis group "Gr2" is composed of the transfer basis "g1" or "g2." Therefore, if the transfer basis specified in the current transfer request is "g1" or "g2," the base server 101A can determine that the transfer basis is appropriate (there is no problem).
[0135] If it is determined in step S303 that there is a problem with the relocation (relocation NG) (NO in step S303), the base server 101A notifies the client terminal 141 of the refusal of the relocation, stating that the relocation grounds are inappropriate, and further presents an alternative relocation ground to make the relocation possible (step S309), and terminates the processing.
[0136] If it is determined in step S303 that there is no problem with the transfer (transfer OK) (YES in step S303), the base server 101A determines whether the requested transfer corresponds to a re-transfer (step S304). The determination of whether it corresponds to a re-transfer can be made by referring to the personal information management information 114. Specifically, if transfer ID 1510 has already been registered in the record of data ID 1501 that corresponds to the transfer target, it is determined to be a re-transfer of data brought in during transfer, and if not registered, it is determined not to be a re-transfer.
[0137] If re-transfer is not required in step S304 (NO in step S304), the base server 101A (transfer control unit 107) transfers the personal information in accordance with the transfer request (step S307).
[0138] If relocation is required in step S304 (YES in step S304), the base server 101A inquires of the management server 151 about whether relocation is required (step S305). Upon receiving the inquiry in step S305, the management server 151 executes relocation determination processing, which will be described later with reference to Fig. 21, and returns the determination result to the base server 101A.
[0139] The base server 101A checks whether the response from the management server 151 permits the re-transfer (step S306). If the response from the management server 151 indicates that the re-transfer is OK (YES in step S306), the base server 101A (transfer control unit 107) transfers the personal information in accordance with the transfer request (step S307). If the response from the management server 151 indicates that the re-transfer is OK (NO in step S306), the base server 101A notifies the client terminal 141 that the transfer is rejected and presents an alternative transfer method (step S309), and ends the process.
[0140] After the transfer of the personal information in step S307 is completed, the base server 101A notifies the client terminal 141, the management server 151, and the base server 101B of the transfer destination that the transfer has been completed (step S308), and the process ends.
[0141] By executing the process shown in Figure 19 as described above, base server 101A, which receives a transfer request from client terminal 141, works in cooperation with management server 151 to determine whether the personal information to be transferred is transferable, and if it is determined that the personal information is transferable, it can transfer the personal information to base server 101B.
[0142] (2-2) Information registration process after transfer completion notification Fig. 20 is a sequence diagram showing an example of the processing procedure for personal information registration processing after a transfer completion notification is sent. The processing shown in Fig. 20 is processing executed by the management server 151 and the transfer destination base server 101B after a transfer completion notification is sent from the base server 101A in step S309 in Fig. 19. As will be explained in detail below, upon receiving the personal information transfer completion notification, the management server 151 and base server 101B update the information they manage.
[0143] 20, first, the base server 101A of the transfer source transmits a transfer completion notification to the base server 101B of the transfer destination and the management server 151 (step S401). Step S401 corresponds to step S309 in FIG.
[0144] In the transfer completion notification in step S401, information on the transferred data (values of data items other than data ID 1501, domestic retention 1508, and transfer ID 1510 in the record of the corresponding data in personal information management information 114 in FIG. 15) is sent from base server 101A to base server 101B. These data are handed over to personal information management information 114 held by base server 101B, and, as will be described later, values of predetermined items are changed and updated as necessary.
[0145] In addition, in the notification of completion of the transfer in step S401, the base server 101A sends to the management server 151 information such as the identification ID (data ID 1501) and management ID (management ID 312) of the transferred data from the personal information management information 114, which is information necessary for the management server 151 to generate transfer management information 163 regarding the transferred data.
[0146] In the base server 101B, when the cooperation unit 105 receives the notification of the end of the transfer, the cooperation unit 105 waits until it receives a notification of the transfer ID and the management ID from the management server 151 (step S402).
[0147] Meanwhile, in management server 151, when link unit 155 receives a transfer completion notification (step S403), information management unit 156 updates transfer management information 163 that it manages based on the received information (step S404). Specifically, information management unit 156 assigns a new transfer ID (transfer ID 401) for this transfer in transfer management information 163 of Fig. 4, and registers new values for data items other than transfer destination data ID 405 based on the information received from base server 101A.
[0148] Here, the information management unit 156 determines whether the data registered in this transfer (data identified by the transfer source 402 and transfer source data ID 403) has been transferred before, based on the values of the transfer destination 404 and transfer destination data ID 405 in the transfer management information 163. For example, if the already registered transfer destination 404 and transfer destination data ID 405 include data that matches the data registered in this transfer (transfer source 402, transfer source data ID 403), it can be determined that this data has been transferred before. In this case, the value obtained by adding "1" to the value of the transfer count 410 registered for the matched data (transfer destination 404, transfer destination data ID 405) as described above is set as the transfer count. As a result, for example, if "1" is set in the transfer count 410, this indicates that one transfer has been performed before this transfer.
[0149] In addition, with regard to the management ID 411, the information management unit 156 sets the value of the management ID 312 of the personal information management information 114, which is managed in association with the data ID (data ID 1501) to be transferred and which was sent from the base server 101A when notifying the completion of the transfer, to the management ID 411.
[0150] As described above, when the update of the transfer management information 163 regarding the data transferred this time is completed, the information management unit 156 transmits the updated values of the transfer ID 401 and management ID 411 to the transfer destination base server 101B (step S405).
[0151] Next, the information management unit 106 of the base server 101B assigns a new identification ID (data ID 1501) for managing the newly transferred data at its own base, and sets values for data items other than domestic retention 1508 to transfer ID 1510 of the personal information management information 114 based on the information received from the base server 101A of the transfer source in step S402. Furthermore, the information management unit 106 sets the value of transfer ID 401 received from the management server 151 in step S405 to transfer ID 1510. Note that the information management unit 106 may provisionally set the value of management ID 411 received from the management server 151 in step S405 to management ID 1509. The value of management ID 1509 is officially set in step S410, which will be described later.
[0152] Then, if there is no change request from the client terminal 141 for the information set as described above, the base server 101B updates the personal information management information 114 with the set information and transmits the updated information (for example, data ID 1501, etc.) to the management server 151 (step S407). If there is a change request from the client terminal 141 for a predetermined data item, the base server 101B sets the requested value in the data item to update the personal information management information 114, and then transmits the updated information to the management server 151.
[0153] Next, in the management server 151, the information management unit 156 updates the transfer management information 163 and the personal information management information 162 based on the information received from the base server 101B in step S407 (step S408).
[0154] Specifically, when updating the transfer management information 163, the information management unit 156 sets the value of the identification ID (data ID 1501) newly assigned by the base server 101B to the transfer destination data ID 405 in the record of the transfer management information 163 in which the value of the transfer ID 401 is set, based on the updated transfer ID 401 described above and the identification ID (data ID 1501) newly assigned by the base server 101B.
[0155] Furthermore, in updating the personal information management information 162, the information management unit 156 assigns a new identification ID (management ID 301) in the personal information management information 162 for the transferred data managed by the base server 101B of the transfer destination, and registers the new information based on the information received from the base server 101B in step S407. At this time, for each of the data items from acquisition country 302 to cloud ID 309, the information received from the base server 101B in step S407 can be set, and the domestic retention 310 and original ID 311 can be set as appropriate using the same procedures as those described in steps S102 and S103 of Fig. 17.
[0156] Then, the management server 151 notifies the base server 101B of at least the management ID 301 newly assigned to the personal information management information 162 and the value of domestic retention 310 (domestic retention flag) from the information updated in step S408 (step S409), and terminates the processing on the management server 151 side.
[0157] Next, in the base server 101B, the information management unit 106 updates the data items of the personal information management information 114 that were not set or provisionally set in step S407 based on the information transmitted from the management server 151 in step S409 (step S410). Specifically, the information management unit 106 sets the value of the management ID 301 newly assigned by the management server 151 as a formal value in the management ID 1509, and sets the value of the domestic retention 310 (domestic retention flag) set by the management server 151 in the domestic retention 1508.
[0158] By executing the process shown in FIG. 20 as described above, the transfer destination base server 101B and management server 151 can newly register management information on their own computers for the personal information transferred from base server 101A to base server 101B while understanding the transfer status (relationship between the transfer source and transfer destination, number of transfers, etc.) and whether the information is held domestically.
[0159] (2-3) Re-transfer decision process Fig. 21 is a flowchart showing an example of the processing procedure for the re-relocation determination processing. The processing shown in Fig. 21 is processing executed by the management server 151 (mainly the restriction determination unit 157) when an inquiry about whether or not to re-relocate is received from the base server 101A in step S305 of Fig. 19.
[0160] 21, first, the management server 151 receives an inquiry about whether or not to relocate from the base server 101A of the relocation source (step S501). The process of step S501 corresponds to the process of step S305 in FIG.
[0161] Next, the restriction determination unit 157 of the management server 151 determines whether or not the data inquired about in step S501, i.e., the data to be re-transferred, requires domestic retention based on the value of domestic retention 310 in the personal information management information 162 (step S502). If it determines that domestic retention is not required (NO in step S502), the process proceeds to step S504, which will be described later. If it determines that domestic retention is required (YES in step S502), the process proceeds to step S503.
[0162] In step S503, the restriction determination unit 157 determines whether the storage status of the data inquired about in step S501, i.e., the data to be re-transferred, is appropriate. If it is determined that the storage status of the data is inappropriate (NO in step S503), the process proceeds to step S511, which will be described later. If it is determined that the storage status of the data is appropriate, the process proceeds to step S504.
[0163] In step S503, the restriction determination unit 157 can determine the appropriateness of the storage conditions of the data in a manner similar to that described in S204 of FIG. 18. Specifically, the restriction determination unit 157 identifies the original data based on the value of the original ID 311 associated with the data to be re-transferred (identifying a record in which the "value of the original ID 311" is set in the management ID 301 in the personal information management information 162), and queries the base server 101 that holds the original data (the base ID 304 of the identified record) to determine whether the original data continues to be held as before. If the base server 101 associated with the original data continues to hold the original data, the restriction determination unit 157 determines that the storage conditions of the data to be re-transferred are appropriate (YES in step S502). On the other hand, if the base server 101 associated with the original data does not continue to hold the original data, the restriction determination unit 157 determines that the storage conditions of the data to be re-transferred are inappropriate (NO in step S502).
[0164] If it is determined that the storage conditions of the data to be re-transferred are appropriate, the regulation determination unit 157 extracts information on the basis of the previous transfer and the current transfer, as well as information on the regulation levels of the original transfer country and the final transfer destination country, based on the inquiry information received in step S501 (step S504).
[0165] Specifically, the restriction determination unit 157 identifies which data is being re-transferred this time from among the previous transfer destination data (identified from the combination of the transfer destination 404 and transfer destination data ID 405 in the transfer management information 163 shown in FIG. 4), and extracts the previous transfer basis by referencing the value of the transfer basis 407 associated with the identified transfer destination data. For example, if the data being re-transferred this time has data ID "6001" at base "k6," the information on the transfer destination data that matches this (the combination of the transfer destination 404 and transfer destination data ID 405 matches) corresponds to a record with a transfer ID of "i1" set in the transfer management information 163 of FIG. 4. Therefore, this transfer destination data is identified as data that was brought from the transfer source base "k5" to the transfer destination base "k6" using transfer basis "g1" before this re-transfer. Furthermore, the restriction determination unit 157 identifies the initial source country based on the value of the acquisition country 302 managed by the management server 151 for the data to be re-transferred this time, and identifies the final destination country from the destination information specified in the inquiry from the base server 101 about whether or not to re-transfer. Then, the restriction determination unit 157 identifies the respective restriction levels for the source country and destination country identified as described above based on the country restriction level information 169 shown in Fig. 10. For example, if the destination country is "UK", the restriction level is determined to be "4".
[0166] Next, the restriction determination unit 157 determines whether or not to re-transfer the inquired data based on the information identified in step S504 (step S505). Specifically, when the transfer basis for this re-transfer is "sufficiency" (according to the transfer basis information 173 in Fig. 14, the basis ID is "g3"), the restriction determination unit 157 refers to the sufficiency information 170 for each country shown in Fig. 11, and determines based on the sufficiency target countries 1102 whether the current re-transfer destination country is included as a sufficiency target country for the initial transfer source country.
[0167] If the country to which the re-relocation is to be carried out this time is included in the sufficiency target countries, the restriction determination unit 157 determines that the re-relocation is appropriate (YES in step S505), and notifies the base server 101, which inquired about the propriety of the re-relocation, that the re-relocation is OK (step S506).
[0168] On the other hand, if the destination country for this relocation is not included in the sufficiency target countries, and the restriction level of the final destination country is lower than that of the original source country, the restriction determination unit 157 determines that the relocation is inappropriate (NO in step S505), and notifies the base server 101, which inquired about the propriety of the relocation, that the relocation is not permitted, the reason for this, and the corrective measures required for the relocation (step S507). Upon receiving the notification in step S507, the base server 101 may forward the notification content to the client terminal 141 and request that the necessary corrective measures be implemented. If the client terminal 141 instructs the base server 101 to implement the necessary corrective measures and the base server 101 implements them, the base server 101 notifies the management server 151 that the implementation of the corrective measures has been completed.
[0169] After sending the notification in step S507, the restriction determination unit 157 checks whether the base server 101 has taken the necessary corrective measures (step S508). If the base server 101 has taken the necessary corrective measures (YES in step S508), the process proceeds to step S506, where the restriction determination unit 157 notifies the base server 101 that relocation is OK. If the base server 101 has not taken the necessary corrective measures (NO in step S508), the process proceeds to step S511, which will be described later.
[0170] Here, a supplementary explanation will be given regarding the notification of corrective measures. Specifically, the management server 151 identifies the base that holds the original data of the data to be re-transferred. The management server 151 then provides the base server 101 at that base with the identification ID of the data to be transferred (the data ID 305 of the personal information management information 162) and the purpose of the transfer (the purpose 1608 of the transfer candidate information 117 provided by the base server), and requests, as a notification of corrective measures, that the base server 101 reach an agreement, such as by concluding a contract, with the final transfer destination based on the provided information (step S507). Thereafter, when the management server 151 receives a response indicating that the agreement is possible from the base server 101 that holds the original data, the management server 151 determines that "correction is necessary" (YES in step S508) and notifies the base server 101 that inquired about whether to proceed with the re-transfer that the re-transfer is OK (step S506).
[0171] In the above explanation, the implementation of corrective measures is determined based on the response result that indicates that an agreement is possible, but the management server 151 may determine the implementation of corrective measures by other methods. For example, the management server 151 may create a template contract document that includes a description of the data to be transferred (information including the identification ID of the data, etc.), the purpose of the transfer, and handling rules after the transfer, and transmit the created contract document from the management server 151 to the base server 101 that holds the original data and the base server 101 at the final transfer destination, and when it receives electronic signatures from these base servers 101, it may determine YES in step S508 and notify that the re-transfer is OK.
[0172] Furthermore, if the transfer basis for this re-transfer is other than "sufficiency" (e.g., if the basis ID is "g2" according to the transfer basis information 173 in FIG. 14), except when the initial and final transfer basis are both the same binding corporate rules (provisions for handling personal information within the same corporate group), the restriction determination unit 157 compares the restriction level of the final destination country with that of the initial source country, as described above. If the restriction level of the final destination country is lower than that of the final destination country, the restriction determination unit 157 determines that the re-transfer is inappropriate (NO in step S505), and notifies the base server 101 that inquired about the re-transfer that the re-transfer is not permitted, the reason for this, and the corrective measures required for the re-transfer (step S507). Thereafter, if the corrective measures are taken (YES in step S508), the management server 151 notifies the base server 101 that inquired about the re-transfer that the re-transfer is permitted (step S506).
[0173] After step S506, the management server 151 periodically monitors the storage status of the original data of the data to be re-transferred and determines the appropriateness of the storage status (steps S509, S510), similar to steps S206 to S208 in FIG. 18, and if the storage status is inappropriate (NO in step S510), notifies the base server 101 that data transfer is prohibited (step S511).
[0174] 21 as described above, the management server 151 can determine whether or not to proceed with the re-transfer, taking into consideration the transfer status of the re-transfer across multiple countries and the regulations of the source country, and can notify the inquiring base server 101 of the propriety of the re-transfer. Specifically, for example, if the source country has strict regulations regarding the protection of personal information, but the destination country does not have such strict regulations, it becomes possible to control whether to permit or prohibit the transfer, taking into consideration the regulations of the original source country, so that the personal information is adequately protected at the destination country.
[0175] (3) Other embodiments The following describes a modified example of the personal information management system 100 according to the first and second embodiments of the present invention. In this modified example, when regulatory information such as localization regulations of each country is changed, the management server 151 requests the base server 101 of the affected base to change the personal information settings.
[0176] Specifically, for example, if new data localization regulations are added in a certain country, the management server 151 identifies data whose data acquisition country corresponds to the above country based on the acquisition country 302 of the personal information management information 162 shown in Figure 3.
[0177] If the original ID 311 for the identified data is not registered in the corresponding record of the personal information management information 162, the management server 151 determines the appropriateness of the data storage status from the personal information management information 162 in a manner similar to step S204 of Figure 18, and if there is a change in the domestic retention as a result of the determination, sets the domestic retention flag of the new determination result to domestic retention 310, sends the new domestic retention flag to the base server 101 of the base where the identified data is stored, requesting an information update, and also requesting that transfer control be performed based on the updated domestic retention flag thereafter.
[0178] On the other hand, if the original ID 311 is registered in the corresponding record of the personal information management information 162 for the identified data, the management server 151 determines the appropriateness of the storage status of the original data in the same manner as described above for the record in the personal information management information 162 whose management ID 301 value matches the value of the original ID 311, i.e., the record of the original data, and if there is a change in the domestic retention status as a result of the determination, sets the domestic retention flag of the new determination result to domestic retention 310, and transmits a new domestic retention flag in the same manner as described above to the base server 101 of the base that stores the data whose original ID 311 value is registered in original ID 311, requesting an information update and requesting that transfer control be performed based on the updated domestic retention flag thereafter. Furthermore, the management server 151 transmits a new domestic retention flag in the same manner as described above to the base server 101 that stores the original data, and if the content of the domestic retention flag indicates that domestic retention is not possible, requests that the data storage status be corrected, such as by backing up the data at its own base. Thereafter, if a corrective response is received from the base server 101 storing the original data, the management server 151 determines that the data storage status is appropriate, generates a domestic retention flag corresponding to the correction content, and sends the generated domestic retention flag to the base server 101 storing the original data and to computers related to the base server 101 (for example, the base server 101 storing data transferred from the base server 101), requesting an update of domestic retention 1508 in the personal information management information 114 stored by each base server 101.
[0179] By executing the processing of this modified example as described above, in the personal information management system 100, when regulatory information such as localization regulations of each country is changed, the management server 151 requests the base server 101 affected by the change in regulatory information to change the settings of the personal information, and can also update the settings of the information managed by the management server 151 itself.
[0180] According to each embodiment of the present invention described above, for example, in a computer system (personal information management system 100) comprising a client terminal (client terminal 141), a first computer (base server 101), and a second computer (management server 151), the first computer comprises base information (base information 111) defining the base of the first computer or other computers, data type definition information (data type definition information 112) defining the type of information held by the computer, transfer type definition information (transfer type definition information 113) defining the method of transferring information, personal information management information (personal information management information 114) for managing personal information held by the first computer, transfer basis group information (transfer basis group information 115) consisting of a combination of transfer basis, transfer basis information (transfer basis information 116) defining the transfer basis, transfer candidate information (transfer candidate information 117) defining data that may be transferred in the future, and cloud information (cloud information) defining the cloud used by the computer. The second computer stores location information (location information 161) that defines the location of its own computer or other computers, data type definition information (data type definition information 164) that defines the type of information held by the computer, transfer type definition information (transfer type definition information 165) that defines the method of transferring information, personal information management information (personal information management information 162) for managing personal information held by other computers, transfer basis group information (transfer basis group information 172) that consists of a combination of transfer basis, transfer basis information that defines the transfer basis (transfer basis information 173), and cloud information that defines the cloud used by the computer. The information storage system includes: data storage information 166) for managing computer data transfers; transfer management information (transfer management information 163) for managing computer data transfers; country localization information (country localization information 167) for managing the domestic retention regulations (data localization) of each country; country transfer regulation information (country transfer regulation information 168) for managing the transfer regulations of each country; country regulation level information (country regulation level information 169) for defining the regulation level of each country; country sufficiency information (country sufficiency information 170) for defining the sufficiency certification information of each country; and country sensitivity information (country sensitivity information 171) for defining the sensitivity of information of each country.
[0181] In such a computer system, the first computer sets personal information and transfer candidates based on requests from client terminals and notifies the second computer of this information. The second computer determines the appropriateness of the personal information storage status of the first computer based on the received information and regulatory information from each country and notifies the first computer of the determination result. The first computer sets the determination result from the second computer in the personal information management information of the first computer and controls whether to permit or prohibit the transfer of the data in accordance with the determination result. Furthermore, the second computer regularly monitors the storage status of personal information on the first computer that must be retained domestically, and if the storage status becomes inappropriate, notifies the second computer of a prohibition on transfer, etc. Furthermore, the first computer inquires of the second computer regarding whether or not to retransfer the personal information, and the second computer determines whether or not to retransfer the personal information based on the relationship between the grounds for the transfer and the regulatory information of the country from which the personal information was obtained, and if it determines that the retransfer is inappropriate, it either notifies the first computer of a transfer prohibition, or notifies the computer that holds the original data of the data to be transferred and the final transfer destination computer of the formation of agreement on the transfer, and determines whether to prohibit or permit the transfer based on the responses from these computers, and notifies the first computer of the above-mentioned decision result.The first computer then controls whether to permit or prohibit the retransfer of the data based on the decision result of the second computer.
[0182] By being equipped with the above-described configuration, the computer system (personal information management system 100) of the present invention is able to control the transfer of personal information overseas, taking into consideration the previous transfer situation and the regulations of the country from which the personal information is transferred, and is able to perform appropriate transfer control even in cases such as re-transfers across multiple countries. [Explanation of symbols]
[0183] 100 Personal Information Management System 101 Branch Server 102,142,152 memory 103,143,153 CPU 104,144,154 I / F 105,145,155 Collaboration Department 106,156 Information Management Department 107 Relocation Control Unit 111,161 Location Information 112,164 Data type definition information 113,165 Transfer Type Definition Information 114,162 Personal information management information 115,172 Transfer Basis Group Information 116,173 Transfer basis information 117 Relocation Candidate Information 118,166 Cloud Information 119,174 storage area 141 client terminals 151 Management Server 157 Regulatory Judgment Department 163 Transfer Management Information 167 Country Localization Information 168 Country Transfer Regulation Information 169 National Regulation Level Information 170 Country adequacy information 171 Country Sensitivity Information
Claims
1. A personal information management system that manages the transfer control of personal information handled at bases in each country, a plurality of first computers that manage personal information handled at their own locations and a second computer that centrally manages the personal information managed by the plurality of first computers are connected via a network; the first computer has first management information in which information relating to personal information handled at the first computer's own base is registered; the second computer has second management information in which information relating to each personal information managed by the plurality of first computers is registered, and data localization information indicating domestic data retention regulations established in each country; the first computer sets setting information for predetermined items related to personal information handled at its own base in the first management information, and notifies the second computer of the set setting information; the second computer updates the second management information based on the setting information notified from the first computer; the second computer uses the data localization information and the second management information to determine the appropriateness of the storage status of the personal information by the first computer based on the perspective of domestic retention regulations applicable to the base of the first computer, and notifies the first computer of the result of the determination; The first computer controls whether to permit or prohibit the transfer of the personal information to another first computer across borders based on the result of the judgment by the second computer on the appropriateness of the storage status of the personal information. A personal information management system characterized by:
2. the personal information setting information notified by the first computer to the second computer includes at least information indicating the country in which the personal information was obtained, the type of the personal information, and the location where the personal information is stored; The second computer uses the data localization information to determine whether domestic retention of data at the base of the first computer is necessary, and if domestic retention is necessary, further uses the second management information to determine whether the first computer is storing the personal information in a form that complies with domestic retention regulations, thereby determining the appropriateness of the storage status of the personal information by the first computer.
2. The personal information management system according to claim 1.
3. The second computer If it is determined that the domestic retention of the data at the base of the first computer is unnecessary, or that the domestic retention of the data at the base of the first computer is necessary but the first computer stores the personal information in a form that complies with domestic retention regulations, it determines that the storage status of the personal information by the first computer is appropriate; If it is determined that the data must be retained domestically at the base of the first computer but the first computer does not store the personal information in a format that complies with domestic retention regulations, the storage status of the personal information by the first computer is determined to be inappropriate.
3. The personal information management system according to claim 2.
4. When the first computer receives a request to transfer the personal information it manages to the other first computer, Based on the result of the judgment by the second computer on the appropriateness of the storage status of the personal information and whether the requested transfer is a transfer type that leaves data at the transfer source, if it is judged that domestic retention of the personal information at the own base is unnecessary, or that domestic retention of the personal information at the own base is necessary and can be accommodated, the transfer of the personal information is permitted.
4. The personal information management system according to claim 3.
5. When a request is made to transfer personal information to the other first computer, the first computer determines whether the designated transfer of personal information constitutes a re-transfer, and if so, inquires of the second computer about whether or not to proceed with the re-transfer; Upon receiving the inquiry, the second computer, in determining whether or not to re-transfer, if the personal information to be transferred needs to be retained domestically and is able to do so, will check the storage status of the personal information of the previous transfer source with the specific first computer that manages the personal information of the previous transfer source, and if the storage status is appropriate, will determine that the re-transfer is appropriate and notify the first computer of the result of this determination; When the first computer receives a judgment result from the second computer that the retransfer is appropriate, the first computer authorizes the transfer of personal information to the other first computer.
4. The personal information management system according to claim 3.
6. The second computer Calculate the regulatory level of each country regarding the transfer of personal information based on the existence of domestic retention regulations, the number of types of personal information, and the existence of transfer regulations in each country; In determining whether or not to re-transfer, the appropriateness of the re-transfer shall be further determined based on the basis of the transfer, the country in which the personal information was obtained, the regulations in the country in which the personal information was obtained, and the relative levels of regulations between the country in which the personal information is obtained and the country in which the re-transfer is located; Even if it is determined that the re-transfer is inappropriate, the Company will request the specific first computer that manages the personal information of the previous transfer source and the first computer of the re-transfer destination to reach an agreement on the handling of personal information, and if it receives a response that such agreement can be reached, it will determine that the re-transfer is appropriate.
6. The personal information management system according to claim 5.
7. The second computer will periodically assess the appropriateness of the storage of the personal information by the first computer, and if it determines that the storage is inappropriate, will notify the first computer of a prohibition on the transfer of the personal information.
3. The personal information management system according to claim 2.
8. The second computer periodically determines the appropriateness of the storage status of the personal information by the first computer and the appropriateness of the storage status of the personal information of the previous transfer source by the specific first computer.
7. The personal information management system according to claim 6.
9. A personal information transfer control method using a personal information management system that manages transfer control of personal information handled at bases in various countries, The personal information management system comprises a plurality of first computers that manage personal information handled at its own location, and a second computer that centrally manages the personal information managed by the plurality of first computers, which are connected via a network; the first computer has first management information in which information relating to personal information handled at the first computer's own base is registered; the second computer has second management information in which information relating to each personal information managed by the plurality of first computers is registered, and data localization information indicating domestic data retention regulations established in each country; a first step in which the first computer sets setting information of predetermined items related to personal information handled at its own base in the first management information and notifies the second computer of the set setting information; a second step in which the second computer updates the second management information based on the setting information notified from the first computer in the first step; a third step, after the second step, in which the second computer uses the data localization information and the second management information to determine the appropriateness of the storage status of the personal information by the first computer based on the viewpoint of domestic retention regulations that apply to the base of the first computer, and notifies the first computer of the determination result; a fourth step in which the first computer controls permission or prohibition of transfer of the personal information to another first computer across borders based on the result of the judgment by the second computer in the third step on the appropriateness of the storage status of the personal information; A personal information transfer control method comprising:
Citation Information
Patent Citations
Personal information management system, personal information management method and program
JP2020021133A
Server device and data transfer method
JP2020112922A
Method and system for data localization-compliant blockchain processing and storage
US20210026841A1
Centralized database system with geographically partitioned data
US20210294822A1