Information processing systems, programs, user terminals
The system addresses user concerns by storing consent information and allowing users to verify the basis for personal data use, enhancing transparency and reducing anxiety over misuse.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- THE JAPAN RES INST
- Filing Date
- 2025-02-10
- Publication Date
- 2026-05-21
AI Technical Summary
Users often forget their consent for handling personal information by companies, leading to anxiety over misuse, and lack clarity on which companies are using their data, especially in advertising mails.
A system that stores user consent information linked to the handling company, allowing users to request and receive disclosure of the basis for using their personal information through various communication channels.
Enables users to verify the legitimacy of personal information use by companies, reducing anxiety and ensuring transparency in data handling practices.
Smart Images

Figure 0007863645000001 
Figure 0007863645000002 
Figure 0007863645000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to an information processing system, a program, and a user terminal.
Background Art
[0002] When a customer accesses the web page of a business operator who provides a service, there is a known technology in which a personal information disclosure button for disclosing personal information necessary for providing the service is displayed on the screen of the customer terminal.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] By the way, business operators such as companies generally use users' personal information by obtaining consent for the handling of personal information. However, when a user receives a direct mail from a business operator, the user may not remember having consented to the handling of personal information by the business operator. This may be due to factors on the user side such as misunderstanding by the user, and the user may feel anxious that the personal information is being misused. In addition, for the confirmation of the use of personal information by a company, there is a description that it is used for the advertising of the company's group companies and related companies, but the specific names of the group companies and related companies are not described. Therefore, there is a possibility that advertising mail from a company for which the user does not remember directly permitting the use of personal information may be received, and it is not clear which of the large amount of advertising mail has been permitted.
[0005] Therefore, in one aspect, an object of the present invention is to provide a mechanism in which when personal information is used based on consent for the handling of personal information, a user can receive disclosure of the basis for the use. [Means for solving the problem]
[0006] In one aspect, when user consent is obtained for the handling of personal information, a storage unit stores the consent information related to said consent, linked to the user and the business operator involved in said handling. When a user requests disclosure of the basis for using personal information, The system includes a processing unit that, based on the data in the aforementioned storage unit, discloses to the user the basis for the use of personal information. picture, The aforementioned request can be generated in association with a transmission sent to the user or a call addressed to the user. An information processing system is provided. [Effects of the Invention]
[0007] In one respect, the present invention makes it possible to provide a mechanism that allows users to receive disclosure of the basis for the use of their personal information when it is used based on their consent to the handling of personal information, whether the company has directly authorized the use of the information or has indirectly authorized it as a group company or affiliate in any service or advertising. [Brief explanation of the drawing]
[0008] [Figure 1] This is a schematic diagram of the overall configuration of an information processing system according to one embodiment. [Figure 2] This figure shows an example of a consent screen used when a user gives their consent. [Figure 2A] This figure shows another example of a consent screen used when a user gives their consent. [Figure 3] This figure shows an example of data in the consent information storage unit. [Figure 4] This figure shows an example of data stored in the personal information storage unit. [Figure 5] This is a diagram showing an example of direct mail. [Figure 5A] This figure shows another example of direct mail. [Figure 6] This is a timing chart that provides a schematic overview of the operation of an information processing system. [Figure 7]It is a diagram showing an example of a disclosure request transmission screen. [Figure 8] It is a diagram showing an example of the display of the inbox of an email service used by a certain user. [Figure 9] It is a diagram showing another example of the display of a similar inbox. [Figure 10] It is a timing chart schematically showing the operation of the information processing system (an operation different from that of FIG. 6). [Figure 11] It is a table diagram showing an example of specific character string information that may be held on the user terminal side. [Figure 12] It is a table diagram showing another example of specific character string information that may be held on the user terminal side. [Figure 13] It is a flowchart showing an example of processing in the user terminal at the registration stage of a specific character string. [Figure 14] It is a flowchart showing an example of processing in the user terminal at the time of an incoming call. [Figure 15] It is a flowchart showing a preferred example of the registered name display process in step S1304 of FIG. 14. [Figure 16] It is an explanatory diagram of FIG. 15 and an explanatory diagram of the display method of the connection performance count. [Figure 17] It is a flowchart showing an example of processing of the company terminal that may be executed at the time of personal information registration. [Figure 18] It is a diagram showing an example of data in the personal information storage unit. [Figure 19] It is a flowchart showing an example of processing of the company terminal that may be executed at the time of using personal information.
Embodiments for Carrying Out the Invention
[0009] Hereinafter, each embodiment will be described in detail with reference to the accompanying drawings.
[0010] FIG. 1 is a schematic diagram of the overall configuration of an information processing system 1 according to an embodiment.
[0011] Information processing system 1 is a system that implements the personal information usage basis disclosure service described below. The personal information usage basis disclosure service allows users to request and receive disclosure of the basis for the use of their personal information by a third party (such as a company) via, for example, a user terminal 21. An example of the personal information usage basis disclosure service will be explained in detail later.
[0012] The information processing system 1 includes a user terminal 21, a server device 100, and a corporate terminal 150. Some or all of the functions of the server device 100 may be implemented by the corporate terminal 150.
[0013] The user terminal 21, the server device 100, and the corporate terminal 150 are connected via network 4. The user terminal 21 and the server device 100 can communicate with each other via network 4. Hereafter, unless otherwise specified, "user" refers to a user of the personal information usage disclosure service.
[0014] Network 4 may include, for example, a mobile phone wireless network, the internet, a VPN (Virtual Private Network), a WAN (Wide Area Network), a wired network, or any combination thereof.
[0015] The user terminal 21 may be, for example, a smartphone or tablet, but it may also be a wearable device (e.g., a smartwatch, ring, etc.), a remote control, etc. Furthermore, the user terminal 21 does not need to be a portable device; it may be a fixed device such as a desktop personal computer.
[0016] The user terminal 21 comprises a communication unit 22, a display unit 24, an input unit 26, and a processing unit 28. The communication unit 22 performs various communications via the network 4. The display unit 24 may be a liquid crystal display or an organic EL (Electro-Luminescence) display, etc. The input unit 26 may be a keyboard or a touch panel, but it may also be an input unit that enables gesture input or voice input. The processing unit 28 implements various functions that can be realized by the user terminal 21.
[0017] The user receives the personal information usage basis disclosure service by interacting with the server device 100 through the screen of the personal information usage basis disclosure service application, which can be displayed on the display unit 24 (described later).
[0018] The server device 100 executes the application according to this embodiment (hereinafter referred to as the "Personal Information Use Basis Disclosure Service App"). In this embodiment, the server device 100 executes the Personal Information Use Basis Disclosure Service App which runs on a web browser. The server device 100 may include a web server, a cloud server, etc.
[0019] The user described below can launch a web browser via their user terminal 21 and run the Personal Information Use Basis Disclosure Service app on the browser. The Personal Information Use Basis Disclosure Service app is an application for the Personal Information Use Basis Disclosure Service, and may require registration of account information such as a user ID and password as a condition of use. In the following, "user" refers to a user linked to account information.
[0020] In the modified version, the personal information usage basis disclosure service application may be implemented as a native application installed and running on the user terminal 21, instead of or in addition to a web application that can be operated on a browser.
[0021] The server device 100 can be operated by the operator. For example, the operator's administrator can access the server device 100, and the operator's administrator may perform various inputs necessary for maintaining the personal information usage basis disclosure service application.
[0022] In this embodiment, as shown in Figure 1, the server device 100 includes a consent information acquisition unit 110, a usage justification request processing unit 111, and a consent information storage unit 120. The consent information acquisition unit 110 and the usage justification request processing unit 111 can be implemented by the CPU of the server computer executing a program. The consent information storage unit 120 can be implemented by the storage device of the server computer.
[0023] The consent information acquisition unit 110 acquires consent information from the user regarding the handling of personal information. Figure 2 shows an example of a consent screen (screen on the display unit 24) when a user gives consent. The consent screen is a screen generated by the corresponding company (the company that uses the personal information). For example, when a user receives some service through a company, they register as a user (account registration, etc.). At this time, the user gives consent regarding the handling of personal information through a consent screen as shown in Figure 2. In this case, when the user gives consent through the consent screen, the consent information acquisition unit 110 may acquire the consent content etc. described on the consent screen from the user and / or the company. In this embodiment, the consent event ID is issued on the company terminal 150 side and supplied to the server device 100. As shown in Figure 2A, the company may also request consent for the use of personal information by group companies and affiliated companies. If group companies or affiliated companies are later asked to confirm consent for the use of personal information, they can present the fact of consent given at this time as evidence.
[0024] The consent information acquisition unit 110 may be implemented by a corresponding corporate terminal 150. In this case, the server device 100 may be omitted.
[0025] When the consent information acquisition unit 110 acquires consent information, it stores the consent information in the consent information storage unit 120. Figure 3 shows an example of the data in the consent information storage unit 120. Figure 3 shows data related to one user. The consent information storage unit 120 stores consent information for each user. In other words, the consent information is stored in association with the user.
[0026] The consent may include whether or not to allow the sending of direct mail (for example, campaign information).
[0027] In the example shown in Figure 3, each time a user gives consent, the consent event ID, consent date and time, handling company information, consent content, consent-acquiring company information, and relationship with the consent-acquiring company are stored. The consent date and time represents the date and time when consent was given. The granularity of the date and time is arbitrary; for example, it can be in units of hours, minutes, and seconds, or just the date. The company information represents the company that gave consent regarding the handling of the user's personal information through a consent screen as shown in Figure 2. The consent content represents the content stated on the consent screen for the handling of personal information. In the example shown in Figure 3, the consent content is managed in the form of image data (for example, an image based on a screenshot), but it may be in other formats. The consent-acquiring company information is the company information that gave consent from the user, and the relationship with the consent-acquiring company indicates the relationship between the handling company and the consent-acquiring company. In the example shown in Figure 3, if ABC Agency Co., Ltd., a subsidiary of ABC Corporation, handles the user's personal information based on the consent obtained from the user, a record is added as shown in the second record of Figure 3. If ABC Agency Co., Ltd. is requested by the user to disclose the basis for the consent, this record is referenced.
[0028] The consent information storage unit 120 may be implemented by a corresponding corporate terminal 150 (or a separate server device accessible by the corporate terminal 150). In this case, the server device 100 may be omitted.
[0029] The usage justification request processing unit 111 discloses the justification for the use of personal information based on the data in the corporate terminal 150. The usage justification request processing unit 111 discloses the justification for the use of personal information in response to a disclosure request from the user. A disclosure request from the user may be made by sending an email to a specific email address, accessing a specific URL (Uniform Resource Locator) and making a prescribed input on that URL, etc.
[0030] Furthermore, some or all of the functions of the usage justification request processing unit 111 may be implemented by the corresponding enterprise terminal 150. In the latter case, the server device 100 may be omitted.
[0031] The corporate terminal 150 is a terminal under the control of a company that uses users' personal information. The corporate terminal 150 may be in the form of a server or in the form of a personal computer that can be operated by the company's employees.
[0032] The corporate terminal 150 includes a personal information storage unit 152, a direct mail generation unit 154, and a direct mail transmission unit 156.
[0033] The personal information storage unit 152 stores personal information relating to users who have consented to the handling of their personal information. The personal information may be stored in association with a consent event ID, as shown in Figure 4. Note that the personal information shown in Figure 4 pertains to a single user, and the personal information storage unit 152 may manage personal information for each user (corresponding personal identifier).
[0034] The direct mail generation unit 154 uses the personal information stored in the personal information storage unit 152 to generate direct mail to be sent to the corresponding user. In this case, the recipient users may be, for example, only users who have indicated "yes" to receiving direct mail. Figure 5 shows an example of direct mail. In this embodiment, the direct mail includes predetermined information 500 that enables a request for disclosure of the basis for the use of personal information. In the example shown in Figure 5, the predetermined information 500 includes a consent event ID. Alternatively, as shown in Figure 5A, an inquiry code may be included in the mailing. This may be a QR code, barcode, or a sequence of alphanumeric characters. If it is an electronic object (electronic medium), an inquiry link or inquiry button may be displayed. It is also conceivable that the presence of such an inquiry code or link / button could be used as a criterion for sending mailings to users. The QR code may be read or the link may be clicked to directly display the event ID without the user having to input it.
[0035] The direct mail sending unit 156 sends the direct mail generated by the direct mail generation unit 154 to the corresponding user. In this case, the direct mail sending unit 156 may use the personal information stored in the personal information storage unit 152 to set the recipient's address (e.g., email address).
[0036] By analyzing the data in the consent information storage unit 120 shown in Figure 3, it becomes possible to find out which group companies or affiliated companies will use your personal information if you consent to the use of your personal information for the purpose of using a service or application provided by a certain company. For example, if you consent to the use of your personal information for the purpose of using a new service or application provided by a certain company, it is possible to display a list of which companies may potentially use your personal information, either before or after consent. In the example in Figure 3, if you consent to the use of your personal information when using ABC Corporation's services or applications, you can be informed that ABC Agency may also use your personal information.
[0037] Next, the operation of the information processing system 1 will be described with reference to Figures 6 and 7.
[0038] Figure 6 is a timing chart that schematically shows the operation of the information processing system 1. Figure 6 shows the processing related to a corporate terminal 150 belonging to one company, but the same may apply to other companies.
[0039] In step S310, the user and the company reach an agreement regarding the handling of the user's personal information. In this case, the user transmits personal information to the company terminal 150 via the user terminal 21.
[0040] In step S311, the enterprise terminal 150 stores the user's personal information obtained through step S310. At this time, the enterprise terminal 150 issues a consent event ID and stores the personal information in the personal information storage unit 152 in association with the consent event ID (see Figure 4).
[0041] In step S312, the enterprise terminal 150 sends consent information to the server device 100, associated with the consent event ID.
[0042] In step S313, the server device 100 stores the consent information in the consent information storage unit 120, associating it with the consent event ID (see Figure 3).
[0043] Subsequently, for example, if there is an opportunity such as a campaign announcement, in step S320, the company sends direct mail to the user. Specifically, the company sends direct mail to the user terminal 21 of the corresponding user via the company terminal 150. The direct mail includes predetermined information 500, including the consent event ID, as described above.
[0044] Here, suppose the user feels uneasy about the direct mail they received. For example, a long time may have passed since they gave their consent in step S310, and they may have forgotten the details of the consent process with the company in question. In this case, the user can use the consent event ID listed in the direct mail to request disclosure about the basis for the use of their personal information. The user accesses the URL listed in the direct mail. Figure 7 shows an example of a disclosure request submission screen, specifically a web screen G700 on the accessed URL. In this case, the user can generate and submit a disclosure request by entering the consent event ID in the consent event ID input field G702 on web screen G700 and operating the request button BT700. The disclosure request is sent to the server device 100 in association with the consent event ID (step S322).
[0045] In step S323, when the server device 100 receives a disclosure request, it extracts the consent information associated with the consent event ID associated with the disclosure request from the consent information storage unit 120 as the basis for use.
[0046] In step S324, the server device 100 transmits the extracted consent information (basis for use) to the corresponding user 21.
[0047] In step S325, the user terminal 21 displays the received justification for use. The manner in which the justification for use is displayed is arbitrary, but for example, it may be the consent screen shown in Figure 2 or a display showing the date and time of consent. This allows the user to confirm the justification for the direct mail. As a result, the user may recall, for example, the status of their consent, and can effectively confirm the justification for the use of their personal information.
[0048] In the embodiments described above, the materials sent to the user using personal information are in the form of electronic direct mail, but are not limited to this. For example, unlike email, they may be SMS (Short Message Service) or SNS (Social Networking Service) direct messages or messengers addressed to a telephone number. They may also be in the form of paper direct mail, or in other forms (e.g., gifts or presents). For example, a printed document with a QR code printed on it may be enclosed in a paper direct mail. In this case, the QR code may include information indicating the basis for using the personal information, or information relating to how to access that information or an access link. This allows the user to access information indicating that it was created based on information to which the user has consented (approved). Alternatively, it may be a telephone call. In this case, the information indicating the basis for using the personal information may be played back as a voice message in response to user input.
[0049] Next, other preferred embodiments will be described with reference to Figures 8 and 9.
[0050] In another preferred embodiment, the user can determine whether an email was sent based on information they have consented to, based on whether a specific string registered by the user (a keyword registered by the user) is inserted in a designated location in the email. This mechanism will be explained in detail below.
[0051] Figure 8 shows an example of how a user's email inbox looks. Figure 9 shows another example of a similar inbox.
[0052] In the example shown in Figure 8, the subject line of an email received from the sender "XX Bank" contains a specific string "KGW001" registered by the user. The string "KGW001" may be highlighted, for example, with square brackets, as shown in Figure 8. This allows the user to easily determine whether or not the string "KGW001" is present.
[0053] Here, the string "KGW001" is information that the user enters (registers) when they consent to the handling of their personal information. For example, the string "KGW001" may be a string that the user enters themselves when giving consent as described above, referring to Figure 2 or Figure 2A. When a company or other entity obtains consent, it inserts this string into a designated place in the email when sending an email or other message to the user. The company or other entity may maintain a database that stores the string corresponding to each user.
[0054] In this way, users can determine that emails containing the string "KGW001" in the subject line are based on information they have agreed to. For example, in the example shown in Figure 8, the subject line of an email received from "XX Bank" contains the specific string "KGW001" registered by the user, so it is easy to determine that the email was sent based on information the user has agreed to. On the other hand, the subject line of an email received from "EFG Store" does not contain the specific string registered by the user, so it is easy to determine that the email was not sent based on information the user has agreed to.
[0055] Here, a specific string may contain only characters, but it may also include symbols or images (pictograms, emojis, etc.) in place of or in addition to characters.
[0056] In the example shown in Figure 8, the specific string "KGW001" is inserted into the subject line as a designated location in the email. However, as shown in Figure 9, the rule could be such that a specific string registered by the user is inserted into a part of the body of the email. Such rules may be customizable for each user. In either case, it is desirable that the specific string registered by the user be inserted into the first part of the body (for example, the beginning) where it becomes visible before transitioning to a screen that displays the entire message. For example, by referring to the area displayed by the preview function of a messaging app, it is possible to understand that the message was sent based on information the user has agreed to before viewing the entire message.
[0057] Next, further preferred embodiments will be described with reference to Figure 10 and subsequent figures.
[0058] Figure 10 is a timing chart that schematically shows the operation of information processing system 1 (operation different from that shown in Figure 6). Figure 10 shows the processing related to a corporate terminal 150 belonging to one company, but the same may apply to other companies.
[0059] The operation shown in Figure 10 differs from the operation shown in Figure 6 in that step S320 is changed to step S320A, and steps S326 and S327 are added.
[0060] In step S320A, for example, if there is an opportunity such as a campaign announcement, the company sends a pre-call short message to the candidate phone number before making a call (step S327). Specifically, the company sends a short message to the candidate phone number via the company terminal 150. The short message includes predetermined information 500, including the consent event ID, as described above. The short message may also include a message indicating that a representative would like to call the user directly afterward.
[0061] The user confirms the basis for use on the user terminal 21 (step S325), and if they determine that there are no problems with making the call, they send a permission notification to the corporate terminal 150 via the user terminal 21 (step S326).
[0062] When the company representative receives a permission notification from the user via the company terminal 150, they make a call to the recipient of the short message (the phone number of the candidate to call) (step S327).
[0063] This system allows users to verify the basis for their use before receiving a call. As a result, the number of times they receive a call without knowing the reason for their use decreases, improving convenience for both companies and users.
[0064] Furthermore, a method for pre-notifying whether a call is based on authorized information may be used, such as sending a message via tone signal. Before speaking with the user on the phone, a specific string of characters is sent via tone signal to confirm that the call is based on information authorized by the user. Alternatively, a URL (Uniform Resource Locator) or the like that provides access to an information source that shows how the phone number was obtained may also be sent. The technique for sending a message via tone signal to a user terminal 21 such as a smartphone is optional, but for example, the method described in Japanese Patent Application Publication No. 2014-093638, whose contents may be incorporated into this specification by reference herein, may be used.
[0065] Here, in the mechanism described above with reference to Figure 10, the prior short message preferably includes the specific string described above with reference to Figures 8 and 9, that is, the specific string registered by the user (a string registered by the user). The position in which the specific string is placed in the short message is arbitrary, but for example, it may be at the beginning or nearby. In this case, the user can easily skip the processing steps S322 to S325 in Figure 10 and proceed with the sending of the permission notice in step S326, thereby improving convenience.
[0066] Furthermore, in the mechanism described above with reference to Figure 10, the user terminal 21 may also store specific string information registered by the corresponding user, as shown in Figure 11 or Figure 12. For example, such specific string information may be stored as part of the address book in the user terminal 21 (e.g., an electronic address book where telephone numbers and / or email addresses can be registered). In this case, the specific string may be included as part of the registered name associated with the telephone number. Figure 11 shows the string information when the user registers individual specific strings for each consenting party (licensing party). In this case, the user can easily determine the caller of the phone call that will follow the short message based on the differences between the strings contained in the short message. On the other hand, Figure 12 shows the string information when the user registers a common specific string "KGWALL" for each consenting party (licensing party). In this case as well, the user can easily determine, based on the specific string contained in the short message, that the phone call that will come when responding to the short message and sending a permission notification is based on information that the user has consented to (accepted).
[0067] Next, referring to Figures 13 to 16, and then to Figure 10, we will explain an example of the operation of the user terminal 21 related to the mechanism described above.
[0068] Figure 13 is a flowchart showing an example of processing at the user terminal 21 during the registration stage of a specific string.
[0069] In step S1200, the user terminal 21 determines whether or not it has received any SMS short message.
[0070] In step S1202, the user terminal 21 displays the predetermined information 500 and inquiry code as described above, referring to Figure 5 and Figure 5A, and also displays an address registration OK button.
[0071] In step S1204, the user terminal 21 determines whether the address registration OK button has been pressed. If the result is "YES", the process proceeds to step S1206; otherwise, the process may terminate after a certain period of waiting time. Note that pressing the address registration OK button may be accompanied by the input of a specific corresponding string.
[0072] In step S1206, the user terminal 21 registers the telephone number in the address book using a registration name that includes a specific string (labeled "keyword" in Figure 13). Note that if a common specific string is used as shown in Figure 12, the user may not need to specify the specific string.
[0073] Figure 14 is a flowchart showing an example of processing at the user terminal 21 when an incoming call is received.
[0074] In step S1300, the user terminal 21 is in a waiting state for incoming calls.
[0075] In step S1302, the user terminal 21 determines whether or not an incoming call has been received. If the determination result is "YES", the process proceeds to step S1304.
[0076] In step S1304, the user terminal 21 performs a registered name display process based on the incoming phone number. The registered name display process may simply be a process that displays the registered name, but a preferred specific example will be described later with reference to Figure 15. At this time, the user can answer the call by operating the answer button. Alternatively, the user can reject the call by not operating the answer button. The user terminal 21 may also display a button for automatic notification that the call will not be answered.
[0077] In step S1306, the user terminal 21 determines whether it has accepted (answered) the call. If the result is "YES", the process proceeds to step S1308; otherwise, the process terminates.
[0078] In step S1308, the user terminal 21 counts up the number of times the current phone number has been connected and stores (adds) the number of connections associated with the registered name. That is, it increments the counter for the number of connections associated with the registered name (which contains a specific string) related to the current phone number by "1".
[0079] In step S1310, the user terminal 21 returns to the incoming call waiting state after the line is disconnected.
[0080] Figure 15 is a flowchart showing a preferred example of the registration name display process in step S1304 of Figure 14. Figure 16 is an explanatory diagram of Figure 15, illustrating the method for displaying the number of connections.
[0081] In step S1500, the user terminal 21 determines whether it has connected to the same phone number at least once. If the result is "YES", proceed to step S1502; otherwise, proceed to step S1504.
[0082] In step S1502, the user terminal 21 displays the registered name of the incoming phone number along with the number of previous connections. The display method is arbitrary, but for example, it may be displayed in combination with a specific string, as shown in Figure 16. In the example shown in Figure 16, if the specific string is "KGW001" and the number of previous connections is k, then "00k" is added. This makes it easy for the user to understand how many times they have connected in the past. For example, if they have connected multiple times in the past, they can assume that they can receive the call with confidence, thus improving convenience.
[0083] In step S1504, the user terminal 21 displays the registered name of the incoming phone number. For example, if the registered name for the current phone number contains the specific string "KGW001", the string "KGW001" may be output in a form that does not include the number of connections made. Alternatively, information indicating that it is the first call, such as "000", may also be output. Furthermore, if the registered name for the current phone number does not contain the specific string, only the registered name for the current phone number may be output. Alternatively, warning information may also be output.
[0084] Thus, according to the process shown in Figures 13 to 15, for the company, it becomes possible to make a call after confirming the identity of the user by sending a specific string related to the user via short message (SMS, etc.) before making the call. For the user, it becomes possible to receive a call after confirming that permission has been obtained via short message (SMS, etc.) to use their information (phone number). Furthermore, this process may include a means to automatically register a specific string in the name field of the address book. In addition to a specific string, a QR code or other information that allows reference to the basis for its use may also be sent along with the message.
[0085] Next, referring to Figures 17 to 19, and then to Figure 10, an example of the operation of the enterprise terminal 150 related to the mechanism described above will be explained.
[0086] Figure 17 is a flowchart showing an example of processing performed by the corporate terminal 150 when personal information is registered (see step S311 in Figure 10). Figure 18 is a diagram showing an example of data in the personal information storage unit 152.
[0087] In step S170, the corporate terminal 150 obtains personal information from the user.
[0088] In step S172, the corporate terminal 150 requests confirmation of the content and use of the personal information obtained in step S170. This confirmation request is made to the user and may include a request for a specific string that may be obtained in the next step S174.
[0089] In step S174, the enterprise terminal 150 obtains a specific string of characters from the user to be presented when using personal information.
[0090] In step S176, the enterprise terminal 150 associates a specific string obtained in step S174 with each user's personal identifier and stores it in the personal information storage unit 152 (see Figure 18).
[0091] Figure 19 is a flowchart showing examples of processes that may be performed on a corporate terminal 150 when personal information is used (see steps S320A and S327 in Figure 10).
[0092] In step S190, the enterprise terminal 150 identifies the personal identifier of the personal information to be used.
[0093] In step S192, the enterprise terminal 150 obtains a specific string associated with the identified personal identifier. This specific string associated with the identified personal identifier can be obtained from the personal information storage unit 152.
[0094] In step S194, the corporate terminal 150 uses the personal information corresponding to the personal identifier, along with the acquired specific string. For example, in step S320A of Figure 10, when the corporate terminal 150 sends a short message to a candidate phone number, it may include a specific string in part of the short message (e.g., the title). This is not limited to short messages and can be similarly applied to phone calls, emails, etc.
[0095] Although each embodiment has been described in detail above, the invention is not limited to any particular embodiment, and various modifications and changes are possible within the scope described in the claims. Furthermore, it is possible to combine all or more of the components of the embodiments described above. [Explanation of Symbols]
[0096] 1. Information Processing System 4 Network 21 User terminals 22 Communications Department 24 Display section 26 Input section 28 Processing Unit 100 Server Devices 110 Consent information acquisition department 111 Handling of Requests for Validation 120 Consent information storage unit 150 enterprise terminals 152 Personal information storage section 154 Direct Mail Generation Section 156 Direct Mail Department 500 Specific Information
Claims
1. A storage unit that stores consent information related to the user's consent when the user's consent to the handling of personal information is obtained, linked to the user and the business operator involved in the handling of the personal information. The system includes a processing unit that, upon receiving a request from a user for disclosure of the basis for the use of personal information, discloses the basis for the use of personal information to the user based on the data in the storage unit, An information processing system capable of generating the aforementioned request in association with a transmission sent to a user or a telephone call addressed to a user.
2. The information processing system according to claim 1, wherein the transmitted material includes direct mail via paper or electronic media.
3. The request includes information that can identify the transmittance, The information processing system according to claim 1, wherein the processing unit obtains or generates the basis for use based on the identification result of the transmitted object and the data in the storage unit.
4. The information processing system according to any one of claims 1 to 3, wherein the transmitted item based on the consent information includes, in the title or the first part of the body, registration information registered by the user, and the registration information includes one of characters, symbols, and images.
5. If the content of the consent includes that the business operator's affiliates may also use the personal information, the information processing system according to claim 1, wherein the consent information is further stored in the storage unit linked to the user and the affiliates.
6. When a user enters their consent regarding the handling of personal information, the consent information related to the said consent is sent to the server. When a user enters a request for disclosure of the basis for the use of personal information in connection with a transmission sent to the user or a phone call addressed to the user, the request is sent to the server. A program that causes a computer to perform a process that outputs the basis for the use of personal information transmitted from the server in response to the aforementioned request.
7. A user terminal that is connected to a server that stores consent information regarding the handling of personal information when the user's consent to the handling of personal information is entered, When a user enters a request for disclosure of the basis for the use of personal information in connection with a transmission sent to the user or a phone call addressed to the user, the request is sent to the server. A user terminal that outputs the basis for the use of personal information transmitted from the server in response to the aforementioned request.