Personal data distribution management system and method thereof
The personal data distribution management system addresses the challenge of secure and compliant data distribution by using pseudonymization and re-consent procedures, reducing information leakage and ensuring GDPR compliance.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- OSAKA UNIVERSITY
- Filing Date
- 2024-10-16
- Publication Date
- 2026-05-12
AI Technical Summary
Existing data management systems lack a comprehensive mechanism for distributing personal data while ensuring information security, compliance with GDPR, and protecting personal information, particularly in systems where data distribution management devices and source data storage units are individually arranged.
A personal data distribution management system comprising a provider data management device, data distribution management device, and relay processing device, which processes and manages personal data through pseudonymization, catalog creation, and re-consent procedures to ensure secure data distribution and compliance with GDPR.
The system effectively reduces the risk of information leakage and ensures compliance with GDPR by managing personal data distribution through pseudonymization and re-consent processes, maintaining security and privacy.
Smart Images

Figure 0007857036000001 
Figure 0007857036000002 
Figure 0007857036000003
Abstract
Description
Technical Field
[0001] The present invention relates to a technology for managing the circulation of personal data collected from multiple individuals, namely personal data circulation management technology.
Background Art
[0002] In realizing data-driven economic growth and social transformation, the utilization of big data is crucial. Among big data, particular attention has been focused on personal data. By using personal data, for example, it is possible to contribute to various benefits for people such as medical progress and health improvement. Also, services targeted at each individual can use the personal data of the target individual to construct higher-quality services that are more personalized to the individual. It is expected that highly effective marketing can be achieved by using personal data.
[0003] On June 9, 2017, in "Future Investment Strategy 2017", the Cabinet decided to promote three specific measures to facilitate data circulation and utilization across industries and sectors in Japan. These measures are: (1) cooperation and utilization of industrial data, (2) utilization of personal data, and (3) promotion of digital transformation in the private sector. In Japan, in order to appropriately utilize and protect personal data and strike a balance between the two, mechanisms such as Personal Data Stores (PDS), information banks, and data trading markets have been proposed. In 2019, cases of information banks and data trading markets have gradually emerged. PDS and information banks are mechanisms that encourage the consent of the individual for personal data and the conversion into big data, and the data trading market is positioned as an important mechanism for matching to promote circulation and utilization.
[0004] Personal data is acquired by companies each time an individual uses their services, and is often managed and stored in information systems managed by the company. However, there is a common social understanding that personal data is inherently personal, and that individuals should be able to accumulate and manage their own data and be aware of its existence. Therefore, the flow of personal data is being explored in a direction that starts with the individual (data portability). A Personal Data Store (PDS) was conceived as a system that allows individuals to consolidate and manage the personal data they have provided to companies and easily set usage conditions for each data type. According to the Personal Information Protection Act and guidelines, prior consent from the individual is essential when a company uses personal data, and a PDS is a mechanism that systematically realizes this consent. The PDS itself is a system that systematically realizes consent and does not include a mechanism for data distribution. For companies, obtaining consent from each individual regarding the use of their personal data and collecting it is costly. An information bank is a mechanism in which individuals set the usage conditions for their own personal data in advance and then entrust some or all of their data to a business operator that operates an information bank. By integrating with PDS (Personal Data Systems), it is also possible to act as an agent for rights management performed by individuals using PDS and similar systems. Information banks can handle all aspects of third-party provision, from negotiating pricing to combining different data sets.
[0005] In the European Union, the General Data Protection Regulation (GDPR), a set of rules concerning the processing and transfer of personal data, was established in April 2016. While the GDPR, which is creating a global trend, requires renewed consent when providing data to third parties, the fact that the purpose of use and all users of the data are entrusted to the information bank means that it is essentially only blanket consent. Looking at the global context, renewed consent when providing data to third parties is essential. Furthermore, regarding the management of "health and medical data" and "financial data" (credit card numbers, bank account numbers), which are classified as sensitive information under the revised Personal Information Protection Act, by information banks is excluded from the "Guidelines for Certification of Information Trust Functions ver. 1.0," and is still under consideration, as evidenced by the public comment period in June 2019. The "data trading market" is a data buying and selling mechanism that matches the supply and demand of individuals who directly manage their personal data in their own PDS, information banks that manage data on behalf of individuals, and companies (and platforms that are collections of multiple companies) that have a need to collect personal data for the purpose of effectively utilizing their own industrial data. The functions of this market are expected to include price formation and presentation associated with data trading, detailed trading conditions, standardization of trading targets, and credit guarantees for transactions. In the distribution of personal data, it is useful to create a data trading market mechanism that includes a re-consent process, taking a global perspective and complying with the revised Personal Information Protection Act and GDPR.
[0006] Incidentally, in recent years, various systems have been proposed to facilitate the distribution of individuals' personal data. For example, Patent Document 1 describes a personal data provision system comprising a business operator that acquires individuals' personal data, a purchasing company, and an intermediary that intervenes between the business operator and the purchasing company, mediating applications from the purchasing company and the provision of the personal data subject to the application. By assigning a temporary ID to the individual, anonymity can be ensured for the intermediary and the purchasing company. Patent Document 2 describes an intermediary device that is interposed between multiple information bank devices that store personal data and a data utilization device to support requests for usage data from the data utilization device. Patent Document 3 describes a personal data management system comprising a management server equipped with a user information storage unit and a requesting server that requests user information.
[0007] This document describes a personal data management system comprising a management server equipped with a user information storage unit and a requesting server that requests user information. [Prior art documents] [Patent Documents]
[0008] [Patent Document 1] Japanese Patent Publication No. 2018-128884 [Patent Document 2] Patent No. 6592213 [Patent Document 3] Patent No. 6566278 [Overview of the project] [Problems that the invention aims to solve]
[0009] The data management systems, data provision systems, and intermediary devices described in Patent Documents 1 to 3 include a source data storage unit for storing personal data, but do not include a distribution management device for creating and storing catalogs to promote the distribution of personal data. Moreover, when adopting a system configuration in which a data distribution management device and multiple source data storage units are individually arranged, it is not easy to design the entire system to ensure information security for personal data, comply with GDPR, and protect personal information.
[0010] The present invention has been made in view of the above, and provides a personal data distribution management system and method that perform data distribution management that can reduce the risk of information leakage of personal data.
[0011] Furthermore, the present invention provides a personal data distribution management system and method that protects personal information such as real names and enables data distribution management in compliance with the GDPR. [Means for solving the problem]
[0012] The personal data distribution management system according to the present invention comprises, individually, at least one provider data management device, a data distribution management device, and a relay processing device, all connected on a network. The provider data management device includes a database that stores personal data of an individual measured by a measuring instrument, attribute information related to the individual and the measurement, as source data associated with the individual's real name information. The data distribution management device includes a request reception means for receiving data usage requests from data user terminals. The relay processing device, based on the data usage requests received by the request reception means, selects personal data of an individual corresponding to the data usage request from the database of each provider data management device, removes the corresponding individual's real name information, and outputs it to the data user terminal.
[0013] Furthermore, the personal data distribution management system according to the present invention comprises, separately, at least one provider data management device and a data distribution management device, connected on a network. The provider data management device includes a database that stores personal data of an individual measured by a measuring instrument, attribute information related to the individual and the measurement, as raw data associated with the individual's real name information. The data distribution management device includes catalog management means that takes in the raw data, excluding the personal data, stored in the database of each provider data management device, centralizes it, and edits it to generate a data catalog.
[0014] Furthermore, the personal data distribution management method according to the present invention comprises, individually, at least one provider data management device, a data distribution management device, and a relay processing device, all connected on a network. The data distribution management device's request reception means generates and stores as source data, associating the personal data of an individual measured by a measuring instrument, attribute information related to the individual and the measurement, with the individual's real name information. The data distribution management device receives data usage requests from data user terminals. The relay processing device, based on the data usage requests received by the data distribution management device, selects the personal data of the individual corresponding to the data usage request from the database of each provider data management device, removes the corresponding individual's real name information, and outputs it to the data user terminal.
[0015] Furthermore, the personal data distribution management method according to the present invention comprises, separately, at least one provider data management device and a data distribution management device, connected on a network. The provider data management device creates raw data by associating an individual's personal data measured by a measuring instrument, attribute information related to the individual and the measurement, with the individual's real name information, and stores it in a database. The catalog management means of the data distribution management device takes in the raw data, excluding the personal data, stored in the database of each provider data management device, centralizes it, and edits it to generate a data catalog.
[0016] According to these inventions, the data circulation management device captures the original data excluding personal data and generates a data catalog. Also, based on a data usage request received from the outside, the relay processing device outputs data excluding the real name information of individuals from the databases of each source data management device to the data user terminal. By these means, it becomes possible to perform data circulation management that reduces the risk of information leakage of personal data and individuals' real name information from the databases of each source data management device to the outside.
Effect of the Invention
[0017] According to the present invention, it becomes possible to perform data circulation management that reduces the risk of information leakage of personal data and individuals' real name information.
Brief Description of the Drawings
[0018] [Figure 1] It is a configuration diagram showing an embodiment of a personal data circulation management system according to the present invention. [Figure 2] It is a configuration diagram showing an embodiment of a source data management device. [Figure 3] It is a configuration diagram showing an embodiment of a data circulation management device. [Figure 4] It is a configuration diagram showing an embodiment of a user terminal. [Figure 5] It is a memory map diagram showing an example of items of original data. (A) shows items of data providers and items of email addresses, and (B) includes items such as items of individuals' real names and individuals' attribute information. [Figure 6] It is an explanatory diagram showing an example of name-matching processing. (A) is a name-matching table, and (B) is a secondary pseudonym table. [Figure 7] It is an explanatory diagram showing an example of catalog management processing. (A) is a comprehensive data catalog, and (B) is an edited catalog. [Figure 8] It is a chart showing an example of selection items for a data usage request. [Figure 9]A diagram for explaining the final anonymization process. (A) shows a data catalog, (B) shows an example of rearrangement, and (C) shows the data for provision. [Figure 10] It is a flowchart showing an example of the naming process performed by the data circulation management device. [Figure 11] It is a flowchart showing an example of the re-consent process performed by the data circulation management device. [Figure 12] It is a flowchart showing an example of the re-consent procedure process I performed by the data provider device. [Figure 13] It is a flowchart showing an example of the re-consent procedure process II performed by the data provider device.
Embodiments for Carrying Out the Invention
[0019] FIG. 1 is a configuration diagram showing an embodiment of a personal data circulation management system according to the present invention. In FIG. 1, the personal data circulation management system 1 includes a data providing side 10, a data circulation management device 30, and a relay processing device 40 that functions as a platform, and is capable of data communication via a network 50 such as the Internet respectively. The personal data circulation management system 1 is connectable to a user terminal 100 via the network 50.
[0020] The data provider 10 includes at least one or more source data management devices 11, 12, 13, ... as source data management devices that collect and store a group of datasets. The source data management devices 11, 12, 13, ... are envisioned to be corporations, companies, university corporations, organizations, and individuals, and in this embodiment, they are hospital units, and may also include medical department units. In this embodiment, personal data for individuals or in diagnosis may include, for example, heart rate, blood pressure, and other vital data, as well as data types such as purchase history information within the hospital. Furthermore, in this embodiment, it is assumed that the entities of the data provider 10 and the user terminal 100 are members of the organization of this system, but this is not necessarily required. Members are assigned an ID and password, and based on these, they can receive services such as data viewing and data usage requests.
[0021] Here, we will explain the overview of the data distribution management process performed by the personal data distribution management system 1. The provider data management devices 11, 12, 13, ... which constitute the data provider side 10, each collect personal data from multiple individuals (e.g., patients, medical examinees). Various types of personal data are expected. Each type of collected personal data is stored in association with real name information at each provider data management device 11, 12, 13, ... unit of the data provider side 10.
[0022] Meanwhile, the data distribution management device 30 functions as a data trading marketplace, creating a promotional data catalog to promote data distribution (buying and selling of personal data) and making it available for viewing on the network 50. In this state, when the data distribution management device 30 receives a data usage request from a third party via the network 50, it searches for personal data corresponding to the content of the usage request, and after processing re-consent procedures with the relevant parties and individuals, provides the data to the user under predetermined conditions (benefits). Benefits may include money, points, various services, and other considerations.
[0023] In this case, in order to prevent the identification of individuals, first and second forms of pseudonymization will be performed, and when providing personal data, further re-assignment (pseudonymization for provision) will be performed to anonymize it so that it cannot be restored, and it will be provided to third parties along with the actual data. Furthermore, when obtaining renewed consent from individuals who provided personal data as a condition for third-party use of the data, if it is necessary to obtain renewed consent from those involved in data collection, an efficient renewed consent procedure will be carried out in accordance with the prescribed priority. Details are provided below.
[0024] Figure 2 is a configuration diagram showing one embodiment of the provider data management device 11. Since the provider data management devices 11, 12, 13, ... have the same configuration, the provider data management device 11 will be used as a representative example for the following description. The provider data management device 11 includes a control unit 110 which is composed of a processor (CPU). The control unit 110 is connected to a display unit 1101 which displays images, an operation unit 1102 which inputs information and gives instructions from the outside, and a provider data DB 1103 which stores predetermined data.
[0025] In this embodiment, the measuring device 21 measures various vital data from an individual as personal data. The measuring device 21 includes, for example, various sensors, instruments, and devices such as a heart rate monitor, blood pressure monitor, or MRI for measuring (imaging) the inside of the body. The personal terminal 22 includes personal computers, smartphones, and other various mobile information and communication terminals, and exchanges information using SNS (Social Network System), SMS (Short Message Service), or email.
[0026] The provider data DB 1103 stores a control program that controls the provider data management process performed by the control unit 110, as well as raw data including personal data, which is the actual data of multiple individuals measured by the measuring instrument 21. Figure 5 is a memory map showing an example of raw data items. Figure 5(A) shows an item of the data provider, which in this embodiment is one of the dataset units, for example, hospital "A". Next is an item for hospital A, in this embodiment, the email address. Furthermore, as shown in Figure 5(B), following the item of the individual's real name, there are items for the individual's gender, age, email address, address, primary pseudonym, information account, and actual data (personal data) as personal attribute information. The primary pseudonym is identification information that is automatically assigned to the individual's real name, typically according to appropriate rules, when raw data is created at hospital "A". The information account is an account for managing individuals on the system and includes location information. This information account is a place where benefits are stored, which is updated each time an individual's personal data is provided.
[0027] Furthermore, the source data may include additional information fields as needed. In this embodiment, there are fields for attribute information of those involved in the measurement, such as the rights holder, the collector, and their email addresses. Information account fields may also be provided for the rights holder and collector. A rights holder might be, for example, a provider of measuring instruments or measurement locations, while a collector would be someone who performed the measurement work. Other attribute information could include data type, measuring instrument (model name, etc.), and various other measurement conditions (e.g., measurement date and time, measurement location). While the benefits are generally borne by the data user, the data distribution management device 30 may partially bear the costs or provide advance payments. The content of the benefits may be predetermined, or they may be determined through negotiation each time a data usage application is made.
[0028] The control unit 110 functions as a data reception unit 111, a data management unit 112, and a re-consent processing unit 113 when a control program is executed by the processor.
[0029] The data reception unit 111 processes the registration of various data into the individual-level source data table shown in Figure 5, either via the operation unit 1102 or automatically depending on the item. For example, personal data may be linked to the individual's primary pseudonym and the measurement results of the measuring instrument 21 may be automatically entered. In this case, consent from each individual, and as necessary from the rights holders and data collectors, shall be obtained for the use (primary use) of personal data by the data provider 10 or by hospital "A".
[0030] The data management unit 112 performs the following data management based on the source data illustrated in Figure 5. The data management unit 112 creates source data (primary pseudonym, personal data) consisting of a primary pseudonym and actual personal data, excluding real name information, as data to upload (or link) to the relay processing unit 40. Note that this source data (primary pseudonym, personal data) may be held by the source data management device 11, in addition to being held by the relay processing unit 40.
[0031] Furthermore, the data management unit 112 creates a data matching table (primary pseudonym, real name) consisting of pairs of primary pseudonyms and real names, excluding personal data, as data to be submitted to the data distribution management device 30. In addition, the data management unit 112 creates a data catalog (provider, attribute information including data type, measuring instrument and other measurement conditions, and number of data) linked to the primary pseudonym, excluding personal data, as data to be submitted to the data distribution management device 30. The data management unit 112 creates the data when the provider data management device 11 is started up, or at other appropriate times, and sends each created data to the data distribution management device 30. The data matching table is stored in the data matching data DB 341 of the data distribution management device 30. The data catalog is stored in the data catalog DB 342 of the data distribution management device 30.
[0032] The re-consent processing unit 113 executes the re-consent processing handled by the provider data management device 11. The re-consent processing is a procedure for obtaining consent forms for data use (secondary use) from the individual whose personal data corresponds to the request, and, if necessary, from the provider, the rights holders of the attribute information, and the collectors, when a data use request is made from a third-party user terminal 100. The re-consent processing is carried out by instructions from the data distribution management device 30, as described later, and is typically done electronically via the network 50, but in some cases other means of communication may be applied.
[0033] In this embodiment, the re-consent procedure is carried out according to a predetermined priority order. That is, the priority order is provider, rights holder and collector, and finally individual. When the re-consent processing unit 113 receives an electronic re-consent application form, it operates the operation unit 1102 to mark the checkboxes indicating consent or non-consent, which are provided for each required unit in the re-consent application form, and sends a reply instruction.
[0034] If the data provider data management device 11 does not consent, the re-consent processing unit 113 terminates the re-consent processing. If consent is given, the re-consent application forms for the rights holders and collectors, which were simultaneously transmitted, are sent via email to the relevant rights holders and collectors in this embodiment, and the unit waits for a response (reply). The re-consent processing unit 113 terminates its work for responses from rights holders and collectors that do not consent, and for responses that do consent, it sends individual re-consent application forms via email to the relevant individuals, and waits for a response (reply). By setting such priorities, the re-consent procedure can be carried out efficiently. In addition, rights holders, collectors, and individuals are given various forms of benefits for re-consenting, for example, by transferring funds to the information account shown in Figure 5 as described above. Other forms of re-consent and methods for processing re-consent will be described later.
[0035] Figure 3 is a configuration diagram showing one embodiment of the data distribution management device 30. The data distribution management device 30 includes a control unit 31 which is composed of a processor (CPU). The control unit 31 is connected to a display unit 32 which displays images, an operation unit 33 which receives information input and instructions from the outside, a data matching DB 341 which stores data for matching, and a data catalog DB 342 which stores data catalogs. The control program for data distribution management may be written to the program storage area in these memories.
[0036] The control unit 31 functions as a name matching processing unit 311, a catalog management unit 312, a usage request reception unit 313, and a pseudonymization processing unit 314 for provision, when a control program is executed by the processor.
[0037] As shown in Figure 6, the name matching processing unit 311 creates secondary kana from the name matching table (primary kana, real name) stored in the name matching data DB 341 and stores it in the name matching data DB 341. More specifically, the name matching processing unit 311 unifies (integrates) the name matching tables (primary kana, real name) from the provider data management devices 11, 12, 13, ... (see Figure 6(A)), performs a name matching process that matches the real name with the primary kana, creates a secondary kana integrated from the primary kana, and stores the created secondary kana table (see Figure 6(B)) in the name matching data DB 341. When transmitting this name matching table (primary kana, real name) to the data distribution management device 30, the risk of leakage of real name data during transmission is suppressed by using a network other than network 50 from the provider data management devices 11, 12, 13, ... or by using a different communication method. In the example in Figure 6, the primary pseudonym ID-a1 of the individual who received treatment at hospital "A" and the primary pseudonym ID-b5 of the individual who received treatment at hospital "B" are the same person whose real name matches, and in Figure 6(B), they are assigned a common secondary pseudonym ID1. Note that the secondary pseudonym may be, for example, a series of personal identification numbers. Alternatively, the secondary pseudonym table in Figure 6(B) could be a table of the format (secondary pseudonym, real name).
[0038] As shown in Figure 7, the catalog management unit 312 centralizes and integrates the data catalogs from each provider data management device 11, 12, 13, ... stored in the data catalog DB 342 to create a comprehensive data catalog. In Figure 7, the data catalogs linked to the primary kana (attribute information including provider and data type, and number of data) are associated with the secondary kana by referring to Figure 6(B) and edited based on the data type item (see Figure 7(B)). The comprehensive data catalog portion is then provided on the network 50 for viewing. The data catalog can be sorted based on some or all of the data items within the viewing range, thereby providing convenience for users in selecting items. In addition to providing the data catalog on the network 50, it is also possible to use it for sales by people or by placing it on other media.
[0039] The request reception unit 313 receives a request for use from the user terminal 100 and executes processing according to the request. The request is specified based on data items, for example, as shown in Figure 8. In the example in Figure 8, other attribute information including data type, data provider, and measuring instrument is assumed. As an example of a request for other attribute information, it may also include gender and age group from personal attribute information. The request reception unit 313 selects the persons to whom re-consent is to be requested from the request. For example, if the request includes a data provider, the re-consent process only needs to be performed on the data management device of that provider. If no specific recipient is designated, all persons are included. The request reception unit 313 transmits the request information to the target data management device, via the relay processing device 40 in this example, and instructs it to perform the re-consent process. The selection of the target rights holders, collectors, and individuals may be performed by the aforementioned re-consent processing unit 113, or it may be processed by the request reception unit 313 and transmitted in association with the re-consent process instruction.
[0040] The provision-use pseudonym processing unit 314 creates provision-use data to be provided to users who have requested its use by editing the original data linked to secondary pseudonyms, excluding the real name field, which has been uploaded to the relay processing unit 40 described later. More specifically, the provision-use pseudonym processing unit 314 performs the following processes: deleting individuals who have not given their consent to the re-consent application from the primary pseudonym and secondary pseudonym tables in Figure 6(B); reassigning the remaining secondary pseudonyms to report pseudonyms after deletion; and extracting secondary pseudonyms associated with report pseudonyms from the original data uploaded to the relay processing unit 40 to create provision-use data.
[0041] The reassignment process for reporting kana names involves, for example, as shown in Figures 9(A), 9(B), and 9(C), applying a predetermined sorting process to the remaining secondary kana names associated with the data catalog after deletion, and then replacing them with individual identification information, for example, from top to bottom (see the table in Figure 9(B)). The individual identification information is expected to be character codes assigned according to predetermined rules, such as sequential numbers. In Figure 9(B), individuals assigned secondary kana ID2 (with attribute information: a, c, ...) are those who disagree (see Figure 9(A), response result: disagree), and after reassignment, they are deleted as shown in the provision table in Figure 9(C). The provision data shown in Figure 9(C) has been edited by the relay processing device 40 based on the reassignment table in Figure 9(B). The edited provision data is sent from the relay processing device 40 to the user terminal 100.
[0042] Figure 4 is a configuration diagram showing one embodiment of the user terminal 100. The user terminal 100 includes a control unit 101 composed of a processor (CPU). The control unit 101 is connected to a display unit 1001 for displaying images, an operation unit 1002 for inputting information and giving instructions from the outside, and a storage unit 1003 for temporarily storing data to be provided. The storage unit 1003 also stores a control program (installed application program) for processing personal data usage. The user terminal 100 does not need to be a dedicated machine for this system; as long as it can communicate via the network 50, it can be applied to a general-purpose personal computer device by installing the application program. A mobile terminal may also be used.
[0043] The control unit 101 functions as a browsing processing unit 102 and a request processing unit 103 when a control program is executed by the processor.
[0044] The browsing processing unit 102 sends a request to the relay processing unit 40 or the data distribution management device 30 to view the data catalog, and receives the data catalog in a viewable format under predetermined conditions (for example, being a member).
[0045] The request processing unit 103 transmits an electronic request form (application form) containing the selected items related to the personal data to be used to the data distribution management device 30 via the relay processing unit 40. Note that the processing for viewing the data provided in response to the request, such as via email, is the same as for general email, so no explanation is provided.
[0046] Next, we will explain the procedures for name matching, re-consent processing, and re-consent procedure processing.
[0047] Figure 10 is a flowchart showing an example of the name matching process performed by the control unit 31 of the data distribution management device 30. First, the control unit 31 confirms a predetermined timing for catalog creation by timing using a built-in timer, etc., and receives source data (primary pseudonym, real name) and data catalog (primary pseudonym, data type, attribute information, number of data) from each data provider's source data management device 11, 12, 13, ... (step S1). Next, the control unit 31 unifies the source data (primary pseudonym, real name) from all data providers and assigns the same secondary pseudonym to each primary pseudonym with the same real name according to a predetermined rule (step S3). Then, based on the assigned secondary pseudonyms, the control unit 31 creates and saves a secondary pseudonym table (secondary pseudonym, primary pseudonym) as shown in Figure 6(B) (step S5).
[0048] Figure 11 is a flowchart showing an example of the re-consent process performed by the control unit 31 of the data distribution management device 30. First, the control unit 31 determines whether there is a request for use (step S11). If there is no request for use, it exits this flow. If there is a request for use, it extracts the relevant data provider, data type, and attribute information from the request form and issues procedural instructions to the data provider (step S13). At this point, data providers that are no longer applicable are excluded.
[0049] Next, the control unit 31 determines whether or not there has been a response from the data provider to the request for use (step S15). Then, the control unit 31 deletes the data for which consent has not been given by referring to the secondary pseudonym table, and reassigns the remaining secondary pseudonyms to pseudonyms for use (step S17). By reassigning to pseudonyms for use, the individuals in the data for use are anonymized. Furthermore, by reassigning to pseudonyms for use, there is no guarantee that the same pseudonym assigned to an individual in each request for use is the same person, so individuals cannot be identified even if the data is used multiple times. If the data provider itself responds with a refusal, all subsequent rights holders, collectors, and individuals are treated as having refused consent.
[0050] Figure 12 is a flowchart showing an example of the re-consent procedure processing I performed by the control unit 110 of the provider data management device 11. When the control unit 110 receives an instruction for re-consent procedure processing from the data distribution management device 30 via the relay processing device 40, it inputs consent or refusal to the re-consent application form to its own data provider via the operation unit 1102. If it refuses, it simply returns the form and does not proceed to this flow.
[0051] On the other hand, if consent is given, the control unit 110 determines whether the data type selected in the request for use includes the rights holders and data collectors in the attribute information of the measurement participants (Step #1). If there are no such individuals, the control unit 110 exits this flow; however, if there are such individuals, it sends a re-consent form via email to the relevant rights holders and data collectors (Step #3).
[0052] Next, the control unit 110 determines whether responses have been received from all relevant interest holders and collectors (step #5). The control unit 110 waits for responses from all relevant interest holders and collectors, and after excluding those who did not consent, sends a revised consent form by email to the remaining relevant individuals (step #7). The control unit 110 determines whether responses have been received from all relevant individuals (step #9). Then, the control unit 110 sends the response results back to the data distribution management device 30 (step #11).
[0053] Next, other embodiments of re-consent to which the present invention can be applied will be described. The embodiments described above treated each re-consent as a separate re-consent and determined whether or not to consent in response to a user's request for use, but the present invention is not limited thereto, and a form of blanket re-consent in which prior permission is granted may also be adopted.
[0054] Note that comprehensive re-consent may include partial comprehensive re-consent and partial bulk re-consent. Comprehensive re-consent means pre-approving (setting) re-consent for all data items (including attribute information items, etc.) of the source data shown in Figure 5. Partial comprehensive re-consent means pre-approving re-consent for one or more specific data items of the source data. Partial bulk re-consent means pre-approving re-consent for multiple specific data items of the source data as a single unit.
[0055] The items for which comprehensive re-consent can be set correspond to the data items in the source data that are the target of the user's request for use. Referring to Figure 5(B), these may include "data type," "actual data," as well as "gender," "age," "measuring instrument," and various items within "other measurement conditions." "Data provider" may also be included. Specifically, for example, a "re-consent" item is set in conjunction with each of the aforementioned target data items. The "re-consent" item is set to alternate between two options, for example, "comprehensive" and "each time." The re-consent processing unit 113 of the provider data management device 11 then refers to the settings of each of these comprehensive re-consent items when a re-consent request is made. Details are explained in Figure 13. Alternatively, other configuration methods may include providing separate options for comprehensive re-consent, partial comprehensive re-consent, and partial bulk re-consent, where comprehensive re-consent is a binary choice, partial comprehensive re-consent is set by logical OR of the entered desired items, and partial bulk re-consent is set by logical AND of the entered desired items.
[0056] The data management unit 112 of the provider data management device 11 receives and responds to requests for comprehensive re-consent from individuals, rights holders, and collectors, selecting "comprehensive" or "on a case-by-case" (including cancellation from "comprehensive") for the "re-consent" item. Each comprehensive re-consent item may be set at the time of actual data acquisition, or it may be possible to change it at any point thereafter. The data management unit 112 of the provider data management device 11 may also make it possible to rewrite the comprehensive re-consent item for an individual by assigning an ID or similar to the individual in advance, or by granting the authority to accept rewriting of the setting content from the individual's email address.
[0057] Figure 13 is a flowchart showing an example of the re-consent procedure process II performed by the control unit 110 of the provider data management device 11. Figure 13 shows the re-consent procedure with added processing corresponding to the settings of the comprehensive re-consent items compared to the flowchart in Figure 12. Specifically, it differs in that steps #23 to #37 have been added or modified, while the other processing is the same.
[0058] In step #23, the system searches for rights holders and data collectors who have given comprehensive re-consent, partial comprehensive re-consent, or partial bulk re-consent for the requested data type. One or more of the found individuals then bypass steps #25 and #27 and proceed to step #29, where they are processed as having given consent. Meanwhile, rights holders and data collectors who gave individual re-consent in step #25 are sent a re-consent form and their response is awaited (step #27). Finally, those who gave comprehensive re-consent and those who gave individual re-consent are combined and the process proceeds to step #31.
[0059] Next, in step #31, excluding those who do not consent, the relevant individuals are searched for those who have given comprehensive re-consent, partial comprehensive re-consent, or partial bulk re-consent for the requested data type. Then, one or more individuals found are bypassed in steps #33 and #35 and proceed to step #37, where the found individuals are processed as having given consent. Meanwhile, in step #33, individuals who have given individual re-consent are sent a re-consent form and await their response (step #35). Then, individuals who have given comprehensive re-consent and those who have given individual re-consent are combined and proceed to step #39. In this way, by obtaining comprehensive re-consent in advance, the process can be streamlined by eliminating the need to send and receive consent forms from individuals.
[0060] Furthermore, the source data may include not only (pseudonyms for provision, personal data), but also items relevant to the request for use, and some attribute information of the individual, such as gender and age.
[0061] In this system 1, real name information and actual data are held only in their respective source data management devices 11, 12, 13, ..., while the data distribution management device 30 corresponding to the trading market does not hold actual data, and the relay processing device 40 does not hold real name information. By distributing the source data in this way, the security risk is significantly reduced compared to when the data is held in a single location and information is leaked. Furthermore, since neither the data distribution management device 30 nor the relay processing device 40 simultaneously holds real name information and actual data, individuals' personal data cannot be identified from these devices. In addition, if each device is managed by a different organization, individual legal damage is minimized.
[0062] As described above, the personal data distribution management system according to the present invention comprises, individually, at least one provider data management device, a data distribution management device, and a relay processing device, all connected on a network. The provider data management device includes a database that stores personal data of an individual measured by a measuring instrument, attribute information related to the individual and the measurement, as source data associated with the individual's real name information. The data distribution management device includes a request reception means for receiving data usage requests from data user terminals. The relay processing device, based on the data usage requests received by the request reception means, selects personal data of an individual corresponding to the data usage request from the database of each provider data management device, removes the corresponding individual's real name information, and outputs it to the data user terminal.
[0063] Furthermore, the personal data distribution management system according to the present invention comprises, separately, at least one provider data management device and a data distribution management device, connected on a network. The provider data management device includes a database that stores personal data of an individual measured by a measuring instrument, attribute information related to the individual and the measurement, as raw data associated with the individual's real name information. The data distribution management device includes catalog management means that takes in the raw data, excluding the personal data, stored in the database of each provider data management device, centralizes it, and edits it to generate a data catalog.
[0064] Furthermore, the personal data distribution management method according to the present invention comprises, individually, at least one provider data management device, a data distribution management device, and a relay processing device, all connected on a network. The data distribution management device's request reception means generates and stores as source data, associating the personal data of an individual measured by a measuring instrument, attribute information related to the individual and the measurement, with the individual's real name information. The data distribution management device receives data usage requests from data user terminals. The relay processing device, based on the data usage requests received by the data distribution management device, selects the personal data of the individual corresponding to the data usage request from the database of each provider data management device, removes the corresponding individual's real name information, and outputs it to the data user terminal.
[0065] Furthermore, the personal data distribution management method according to the present invention comprises, separately, at least one provider data management device and a data distribution management device, connected on a network. The provider data management device creates raw data by associating an individual's personal data measured by a measuring instrument, attribute information related to the individual and the measurement, with the individual's real name information, and stores it in a database. The catalog management means of the data distribution management device takes in the raw data, excluding the personal data, stored in the database of each provider data management device, centralizes it, and edits it to generate a data catalog.
[0066] According to these inventions, the data distribution management device takes in raw data excluding personal data and generates a data catalog. The relay processing device outputs data excluding the individual's real name information from the database of each provider data management device to the data user terminal based on a data usage request received from an external source. This makes it possible to manage data distribution while reducing the risk of information leakage from the database of each provider data management device to external parties, including personal data and the individual's real name information.
[0067] Furthermore, in the present invention, it is preferable that the catalog management means makes the generated data catalog viewable on the network. With this configuration, the catalog is efficiently published.
[0068] Furthermore, the present invention preferably includes a data provider data management device that, in response to receiving a data usage request, identifies an individual possessing the requested personal data, transmits inquiry information regarding permission to provide the data to the individual's information and communication terminal, and receives a response regarding permission to provide the data. The data distribution management device also preferably includes a data output control device that controls the output of personal data of individuals who have responded that they do not consent to providing the data. With this configuration, the provision of personal data is controlled based on permission to provide the data. In addition, since real name information is removed when personal data is provided to the user, the user will not be able to link real name information with personal data.
[0069] Furthermore, the present invention prefers that the re-consent processing means performs a first inquiry process that instructs the information and communication terminals of those involved in the measurement to inquire about permission to provide data, and a second inquiry process that instructs the information and communication terminals of individuals whose personal data was measured by the measuring instrument used by those involved in the measurement, in which the participants responded with consent to provide data, to inquire about permission to provide data. With this configuration, the first inquiry process executes an inquiry to those involved in the measurement, and the second inquiry process is performed on individuals whose personal data was measured by those participants who responded with consent to provide data in the first inquiry process. Considering that the number of individuals is larger than the number of people involved in the measurement, setting a priority to obtain the results of the participants first in the first inquiry process enables more efficient re-consent processing compared to making inquiries uniformly to everyone, or from individuals to participants.
[0070] Furthermore, in the present invention, it is preferable that the source data management device has multiple source data management devices on the network. With this configuration, the distributed placement of source data is performed more effectively.
[0071] Furthermore, in the present invention, it is preferable that the provider data management device assigns a primary pseudonym to each individual's real name, and the data distribution management device includes a name matching processing means that centralizes the real names of each individual stored in each provider data management device and performs a name matching process that assigns a common secondary pseudonym to the common real name. With this configuration, when the original data of each data provider management device is centralized, a centralized pseudonym, i.e., a secondary pseudonym, is also set.
[0072] Furthermore, in the present invention, it is preferable that the name matching processing means obtains the real name and primary kana from each of the provider data management devices, performs name matching processing by comparing the real name and the primary kana, and generates the unified secondary kana from the primary kana. With this configuration, the unified secondary kana is generated from the primary kana by name matching processing by comparing the real name and the primary kana.
[0073] Furthermore, in the present invention, it is preferable that the data output control means performs the process of deleting individuals who have not given their consent to the re-consent request from the secondary pseudonym table, and the process of reassigning the remaining secondary pseudonyms after deletion to the pseudonyms for reporting. With this configuration, even for the same data item, the pseudonym for reporting changes depending on the status of non-consent at the time of the request for use, and the same pseudonym for reporting does not necessarily refer to the same person, thereby maintaining anonymity.
[0074] Furthermore, the present invention includes a comprehensive re-consent item in the database that allows the user to select and set whether to give comprehensive re-consent or re-consent each time for a predetermined data item in the source data, the provider data management device includes a data management unit that receives settings for the comprehensive re-consent item and changes the setting content, and the re-consent processing unit preferably omits sending the inquiry information regarding permission or denial of data provision if the setting content of the comprehensive re-consent item corresponding to the data item for which use has been requested is permission, thereby granting permission for data provision. With this configuration, the process of obtaining a written agreement can be omitted for those who have given comprehensive consent, making the process efficient and quick.
[0075] Furthermore, in the present invention, it is preferable that the data distribution management device makes the generated data catalog viewable on the network. This allows the catalog to be published efficiently. [Explanation of Symbols]
[0076] 1. Personal Data Distribution Management System 11,12,13 Data management device provided by the provider 110 Control Unit 113 Re-consent processing 1103 Data DB (Database) for Provision 21 Measuring instruments 22 Personal terminals 30 Data Distribution Management Device 31 Control Unit 311 Data Matching Processing Unit 312 Catalog Management Department (Catalog Management Methods) 313 Service Request Reception Department (Means for Receiving Service Requests) 314 Provisioning Kana encoding processing unit (data output control means) 341 Data database for data matching 342 Data Catalog DB 40 Relay Processing Unit 50 Networks 100 User terminals (data user terminals)
Claims
1. The system comprises, individually, at least one source data management device, a data distribution management device, and a relay processing device, all connected to a network. The at least one provider data management device is A database that stores as source data, corresponding to an individual's personal data measured by a measuring instrument, their name, and a primary pseudonym associated with the said name, The system comprises a data management unit that manages the transmission of data to the data distribution management device and the relay processing device, The data distribution management device includes a first storage unit that receives and stores a first data table created by the data management unit, which has pairs of personal names and pseudonyms assigned to correspond to those personal names, excluding the items of personal data. The relay processing device includes a second storage unit that stores a second data table, created by the data management unit, which has pairs of the individual's personal data and the pseudonym, excluding the individual's name, by either updating or linking. The data distribution management device includes a request reception unit that receives data usage requests from data user terminals via the network, and when the request reception unit receives a data usage request, it uses the second data table to select the personal data of the individual corresponding to the data usage request, extracts a pseudonym corresponding to the selected personal data of the individual from the first data table to generate data for provision, and outputs it to the data user terminal.
2. A network comprising, individually, at least one source data management device, a data distribution management device, and a relay processing device, The above-mentioned data management device stores in a database the personal data of an individual measured by a measuring instrument, the individual's name, and the primary pseudonym associated with the individual's name as source data. The data distribution management device receives a first data table, which is created in the data management unit of the provider data management device, excluding the personal data items, and which has pairs of personal names and pseudonyms assigned to the personal names, and stores it in the first storage unit. The relay processing device stores in the second storage unit, by either updating or linking, a second data table created by the data management unit, which contains pairs of the individual's personal data and the pseudonym, excluding the individual's name item. A personal data distribution management method comprising: when a data usage request from a data user terminal is received by the data distribution management device via the network at the data usage request reception unit, the second data table is used to select the personal data of the individual corresponding to the data usage request, and a pseudonym corresponding to the selected personal data of the individual is extracted from the first data table to generate data for provision, which is then output to the data user terminal.
3. The network is equipped with multiple source data management devices, data distribution management devices, and relay processing devices, each connected to a network. Each of the aforementioned plurality of data management devices for data providers is: A database that stores as source data, corresponding to an individual's personal data measured by a measuring instrument, their name, and a primary pseudonym associated with the said name, The system comprises a data management unit that manages the transmission of data to the data distribution management device and the relay processing device, The data distribution management device includes a first storage unit that receives and stores each first data table, which is created by each data management unit for each provider data management device, and which has pairs of personal names and primary pseudonyms assigned to correspond to the personal names, excluding the personal data items. The relay processing device includes a second storage unit that stores each second data table, which is created by each data management unit for each of the source data management devices, and which has pairs of the individual's personal data and the primary pseudonym, excluding the individual's name, by either updating or linking. The data distribution management device includes a name matching processing unit that unifies the individual names in each of the first data tables, creates a third data table that assigns a common secondary kana to common individual names, and further stores this table in the first storage unit. The data distribution management device includes a request reception unit that receives data usage requests from data user terminals via the network, and when the request reception unit receives a data usage request, it selects the personal data of the individual corresponding to the data usage request using the second data tables, extracts secondary pseudonyms corresponding to the selected personal data of the individual from the third data table to generate data for provision, and outputs it to the data user terminal.
4. The personal data distribution management system according to claim 3, wherein the name matching processing unit obtains the personal name and primary pseudonym from each of the provider data management devices, performs a name matching process by matching the personal name and the primary pseudonym, and generates a unified secondary pseudonym from the primary pseudonym.