PIA system, method, and program

The PIA system addresses the lack of technology for supporting PIAs by automating the generation of risk information from handling data, thereby simplifying the PIA implementation process and enhancing privacy risk assessment accuracy.

WO2025134737A1PCT designated stage expired Publication Date: 2025-06-26CO CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/042444
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-19
Filing Date
2024-12-01
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

There is a lack of technology and services to support the implementation of Privacy Impact Assessments (PIA), which are essential for evaluating the risks of personal information handling and protecting individual rights and interests.

Method used

A PIA system that performs information processing to evaluate the impact on privacy caused by activities related to handling privacy-related data, including an acquisition unit for acquiring handling information and a risk information generation unit for generating and presenting risk information to users.

Benefits of technology

The PIA system facilitates the efficient implementation of PIAs by automatically generating appropriate risk information, thereby simplifying the process for entities lacking experience in PIA and improving the accuracy of privacy risk assessments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024042444_26062025_PF_FP_ABST
    Figure JP2024042444_26062025_PF_FP_ABST
Patent Text Reader

Abstract

Provided is a technology for assisting implementation of PIA. A PIA system (1) is for performing information processing for evaluating the influence, on privacy, of activity for handling privacy-related data related to privacy, and comprises: an acquisition unit (121) that acquires handling information representing the content of the privacy-related data that is handled in the activity; and a risk information generation unit (122) that generates, on the basis of the handling information, risk information pertaining to the risk about the influence of the activity on the privacy, and presents the risk information to a user.
Need to check novelty before this filing date? Find Prior Art

Description

PIA system, method, and program

[0001] The present disclosure relates to techniques for supporting Privacy Impact Assessments (PIAs).

[0002] Handling personal information of users and clients has become essential in conducting business. For example, Patent Document 1 discloses a personal information protection system that protects personal information of users in electronic commerce via the Internet, etc.

[0003] However, when handling personal information, there is a risk that the information may be leaked. Therefore, when managing personal information, it is important to evaluate the degree of risk involved in holding personal information. In this context, the concept of "Privacy Impact Assessment (PIA)" has been attracting attention in recent years.

[0004] A privacy impact assessment (hereinafter referred to as PIA) is a risk management method that assesses the impact in advance when starting or changing a business that involves the collection of personal information, etc., in order to reduce or avoid the risk of infringing on individuals' rights and interests. It is important to incorporate a process that takes into account the protection of personal information, etc. into the business lifecycle from the planning and design stage of the business.

[0005] Japanese Patent Application Laid-Open No. 2018-147333

[0006] However, at present, there are no services or technologies available to support the implementation of PIA, and so there is room for further study. For example, Patent Document 1 merely discloses a personal information protection system that protects users' personal information in electronic commerce transactions over the Internet, but does not disclose any technology to support the implementation of PIA.

[0007] The non-limiting embodiments of the present disclosure have been made in consideration of the above background, and contribute to providing technology for supporting the implementation of PIA.

[0008] A PIA system according to one aspect of the present disclosure is a PIA system that performs information processing to evaluate the impact on privacy of an activity that handles privacy-related data, and includes an acquisition unit that acquires handling information that represents the content of the privacy-related data handled in the activity, and a risk information generation unit that generates risk information regarding the risk of the activity impacting privacy based on the handling information and presents it to a user.

[0009] A method according to one aspect of the present disclosure includes the steps of: using a PIA system that performs information processing to evaluate the impact on privacy of an activity that handles privacy-related data related to privacy, acquiring handling information representing the content of the privacy-related data handled in the activity; and generating risk information regarding the risk of the impact on privacy of the activity based on the handling information and presenting the information to a user.

[0010] A computer program according to one aspect of the present disclosure is a program for causing a computer to function as the PIA system described above, and causes the computer to function as each of the above-mentioned units.

[0011] These comprehensive or specific aspects may be realized as a system, a method, an integrated circuit, a computer program, or a recording medium, or may be realized as any combination of a system, an apparatus, a method, an integrated circuit, a computer program, and a recording medium.

[0012] According to one aspect of the present disclosure, a technique for supporting the implementation of PIA can be provided.

[0013] Further advantages and benefits of certain aspects of the present disclosure will become apparent from the specification and drawings. Such advantages and / or benefits may be provided by some of the embodiments and features described in the specification and drawings, respectively, but not necessarily all of them may be provided to obtain one or more identical features.

[0014] 1 is a block diagram showing an example of the functional configuration of a PIA system. FIG. 2 is a diagram showing an example of an input screen for project management information. FIG. 3 is a diagram showing an example of an input screen for handling information. FIG. 4 is a diagram showing an example of risk information. FIG. 5 is a diagram showing an example of a screen for creating new risk information. FIG. 6 is a diagram showing an example of information included in a risk template. FIG. 7 is a diagram showing an example of map information related to risks. FIG. 8 is a diagram showing an example of a screen displaying risk countermeasure information. FIG. 9 is a diagram showing an example of a screen for accepting corrections to countermeasure-related information. FIG. 10 is a diagram showing an example of data flow information. FIG. 11 is a flowchart explaining an example of the operation of the PIA system. FIG. 12 is a block diagram showing an example of the physical configuration of each computer that constitutes the PIA system.

[0015] Hereinafter, an embodiment of the present disclosure will be described in detail with appropriate reference to the drawings. However, more detailed description than necessary may be omitted. For example, detailed description of already well-known matters or redundant description of substantially identical configurations may be omitted. This is to avoid unnecessary redundancy in the following description and to facilitate understanding by those skilled in the art. Note that the accompanying drawings and the following description are provided to enable those skilled in the art to fully understand the present disclosure, and are not intended to limit the subject matter described in the claims.

[0016] [Embodiment]

[0017] The PIA system 1 according to this embodiment will be described in detail below with reference to the drawings. The PIA system 1 is an information processing system for supporting a Privacy Impact Assessment (PIA). First, an overview of the Privacy Impact Assessment (hereinafter referred to as PIA) will be described.

[0018] <<PIA Overview>>

[0019] For example, when planning, building, or modifying an information system that involves the collection of personal information, PIA is conducted to assess the impact on the privacy of information providers in advance and to encourage the appropriate construction and operation of the information system.

[0020] In order to properly extract risks using PIA, specialized knowledge of various privacy-related laws and regulations, including the Act on the Protection of Personal Information, is required, making it difficult to implement.

[0021] Therefore, when implementing PIA, each implementing body tries to do so individually based on their own interpretation and judgment. However, when it comes to PIA, the guidebooks and ISO standards published by the government are difficult to read and understand, making it unclear where to start and making it difficult to translate into concrete action.

[0022] In addition, there is currently a lack of reference information on best practices for PIA, and there are no PIA benchmarks for similar businesses or services. Moreover, the information and data necessary for privacy risk analysis is scattered within organizations.

[0023] Furthermore, from the perspective of human resources, there is a shortage of people with the knowledge (legal and technical) necessary for privacy risk analysis, people who understand the need for and know-how of PIA, and people who can operate and manage PIA.

[0024] When conducting a PIA, the necessary information is first compiled, risks are assessed based on the compiled information, and countermeasures are compiled. A report summarizing the results of the PIA is then prepared, and the actual risk countermeasures are then implemented.

[0025] As an example, implementing a PIA includes the following processes: (1) Data mapping, (2) Data flow organization, (3) Risk identification, (4) Risk assessment, and (5) Risk countermeasure organization. An overview of each process is provided below. Note that each process described below is merely an example, and the processes included in a PIA and the content of each process are not limited to those described below.

[0026] (1) Data mapping: In the data mapping process, relevant documents (e.g., terms of use, privacy policies, contracts, etc.) are reviewed and basic information about the personal data to be utilized is organized.

[0027] (2) Data flow organization: The parties involved in handling personal data, processing flow, communication with users, etc. are organized.

[0028] (3) Risk identification: Legal regulations and rules related to this business field, such as the Personal Information Protection Act, guidelines, and related laws and regulations, are organized, and risks are extracted.

[0029] (4) Risk assessment: Identified risks are assessed on two axes, impact and likelihood, at multiple levels (e.g., four levels). Response policies for each risk (avoidance, reduction, retention, etc.) are also organized.

[0030] (5) Organizing risk countermeasures: Countermeasures for each risk (excluding retained risks) are organized.

[0031] After that, the results of the PIA are reported. That is, a report on the results of the PIA (e.g., PIA implementation report, related documents, etc.) is prepared and submitted. Furthermore, risk countermeasures are implemented. That is, countermeasures for each risk identified in the PIA are implemented, and the response status is managed.

[0032] <<PIA System 1 Overview>>

[0033] The PIA system 1 is a system that performs information processing to evaluate the impact on privacy of activities that handle privacy-related data.

[0034] Privacy-related data refers to specific data that is actually handled in various activities, such as data on customer purchasing behavior, personal information provided in a new service subscription campaign, or employee data submitted by employees at a company, and other actual individual data (raw data, processed data, etc.), but these are merely examples and are not particularly limited. Furthermore, the content of the data is not limited to text data or numerical data, but also includes image data, and the type of data is not particularly limited.

[0035] Furthermore, privacy-related data includes all data that should be handled with consideration for privacy. For example, privacy-related data is not limited to personal information that can identify an individual, but also includes personal data that constitutes a personal information database, which is a collection of information including personal information that is systematically organized so that specific personal information can be searched, as well as data about individuals that can be identified by device or browser IDs, or data about an individual's behavior or status, such as location information and purchase history. There are no particular limitations on this information, as long as it can be subject to PIA evaluation.

[0036] In addition, the Ministry of Economy, Trade and Industry has published the "Corporate Privacy Governance Guidebook for the DX Era," which includes a description of privacy impact assessments (PIAs) along with case studies as one of the privacy governance initiatives.

[0037] In addition, the Personal Information Protection Commission has also published "Points to Note in Accordance with the Significance and Implementation Procedures of PIA" and a "Data Mapping Toolkit" for the appropriate management of personal data, thereby supporting privacy governance in the private sector.

[0038] Furthermore, activities that handle privacy-related data include, for example, business activities that involve the collection of purchase history data via a purchasing-related information processing system, but are not necessarily limited to business activities such as commercial transactions, and various activities other than business activities may also be covered. For example, activities that handle any privacy-related data (hereinafter sometimes referred to as business activities, etc.), including various personal information and sensitive personal information, such as resident data collected through various administrative procedures provided by the national and local governments, children's data collected at schools, patient data collected at hospitals, and data on subscribers to nursing care insurance, may be subject to PIA in this disclosure.

[0039] Furthermore, when carrying out such activities, it is desirable to assess the impact on privacy in advance in order to reduce and avoid the risk of infringing on the rights and interests of individuals, and PIA System 1 is a system that supports this assessment. When developing or renovating various information processing systems that handle privacy-related data (e.g., purchase history management systems), the system is designed based on specifications that take into account the results of this assessment.

[0040] <<Configuration of PIA System 1>>

[0041] 1 is a block diagram showing an example of the functional configuration of a PIA system 1. The PIA system 1 is an information processing system configured with information processing devices. The PIA system 1 may be configured with one device or multiple devices. Furthermore, when an information processing device is configured with multiple devices, the devices do not need to be installed in the same space such as the same room, and may be installed in different rooms, different buildings, different regions, etc., and are not particularly limited.

[0042] 1, the PIA system 1 includes a server 10 and a user terminal 20. The server 10 is an example of an information processing device in the present disclosure. The server 10 and the user terminal 20 are communicatively connected via a network N1. The network N1 connecting the server 10 and the user terminal 20 is a wired local area network (LAN), a wireless LAN, the Internet, a public line network, a mobile data communication network, or a combination thereof.

[0043] (Configuration of user terminal 20)

[0044] 1, the user terminal 20 includes a storage unit 21 and a control unit 22. The control unit 22 acquires various information (input information) input via an input device by a user of the PIA system 1. Input by a user via an input device may be simply referred to as "input by the user."

[0045] The control unit 22 also displays various pieces of information (output information) transmitted from the server 10 in response to the transmission of information input by the user on a display device, thereby presenting the information to the user. Presenting information to the user by displaying it on a display device may be simply referred to as "presenting to the user." The storage unit 21 also stores information transmitted and received between the server 10 and the storage unit 21.

[0046] (Configuration of server 10)

[0047] The server 10 includes a storage unit 11 and a control unit 12 .

[0048] (Storage unit 11)

[0049] The storage unit 11 stores information to be transmitted and received between the user terminal 20 and the storage unit 11, as well as information to be transmitted and received between the user terminal 20 and other devices communicably connected via the network N1.

[0050] (Control unit 12)

[0051] The control unit 12 is composed of an acquisition unit 121, a risk information generation unit 122, a risk template management unit 123, a risk information correction reception unit 124, a countermeasure related information generation unit 125, a countermeasure related information correction reception unit 126, a correction impact identification unit 127, a correction update unit 128, a countermeasure update unit 129, a correction notification unit 130, a related document information reception unit 131, a handling information correction reception unit 132, a data flow management unit 133, and a data flow correction reception unit 134.

[0052] Note that this is merely one example of the functional configuration of the PIA system 1, and it is not necessary for all functional blocks to be included. For example, if there are functions that do not need to be provided depending on the user's needs, the configuration may include only the necessary combination of functional blocks.

[0053] <<Risk Assessment>>

[0054] The following describes the functions related to risk assessment by the PIA system 1.

[0055] Here, as an example of an activity that handles privacy-related data, information processing by the PIA system 1 for evaluating the impact of business activities that involve the collection of data related to customer purchases on privacy will be described. Note that, as mentioned above, the target of PIA is not limited to activities that involve the collection of purchase-related data.

[0056] In the PIA system 1, as an example, an activity that handles privacy-related data may be defined as a project. FIG. 2 is a diagram showing an example of a project management information input screen. In the example shown in FIG. 2, a business activity that manages purchasing data is defined as a purchasing data management PIA project. As shown in the business overview input field in FIG. 2, this project relates to an activity that combines the company's purchasing data with payment data received from credit card companies to understand the behavior of the company's members at other companies. Note that the projects that are the subject of this disclosure are not limited to those that manage purchasing data, and any project related to activities that handle privacy-related data is applicable, and are not particularly limited.

[0057] As an example of this embodiment, in the PIA system 1, the acquisition unit 121 acquires handling information that represents the content of privacy-related data handled in business activities, etc., and the risk information generation unit 122 generates risk information regarding the risks of the impact on privacy caused by business activities, etc. based on the handling information and presents it to the user.

[0058] (Handling information)

[0059] Handling information is information that represents the content of privacy-related data, which is specific data actually handled in various activities, and is information that is used to generate risk information, which will be described later. In this embodiment, examples of handling information include information that represents data set names and data items, such as "purchase data," "purchase store," "purchase date and time," and "purchased product." Note that the above-mentioned project management information (input information such as a business overview) may also be used as handling information to generate risk information.

[0060] Handling information is information that defines the content of privacy-related data, and may be various meta-information that indicates the data type, as well as the attributes, characteristics, structure, meaning, and relationships of the data (including how it is handled). Handling information is not limited to the name of a dataset or a data item; for example, as mentioned above, project-related input information may also be used as handling information. Here, "handled" includes, for example, actions such as collection, storage, use, provision, and disposal of data, but may also include other actions such as processing, and is not particularly limited.

[0061] FIG. 3 is a diagram showing an example of a handling information input screen. In the example shown in FIG. 3, information "purchase data" is entered in the data set name field as an example of handling information. Also in the example shown in FIG. 3, a specific purpose for using the data is entered in the purpose of use field as an example of handling information. Also in the example shown in FIG. 3, information "purchase store," "purchase date and time," and "purchased product" are entered in the data set item field as examples of handling information.

[0062] As shown in Figure 3, the dataset defined as "purchase data" includes the data items "purchase store," "purchase date and time," and "purchased product," and indicates that this dataset is used for the purposes of "data analysis (matching with customer information, purchase information, information held by the card company, etc.)," ​​"use in product planning and marketing, and analysis of purchasing information from competitors."

[0063] The dataset may also include other information such as data type, project type, etc. The project type is information that indicates the type of project, and is not particularly limited to any project type related to activities that handle privacy-related data, such as a project related to a smart city or a project related to an information bank.

[0064] (Acquisition unit 121)

[0065] For example, the input screen for handling information shown in Fig. 3 is displayed on the screen of the user terminal 20. When the user inputs the handling information as shown in Fig. 3 via the user terminal 20, the acquisition unit 121 acquires the handling information input from the user terminal 20.

[0066] Note that the configuration in which the acquisition unit 121 acquires handling information input by the user via the user terminal 20 is merely one example, and as described below, the information can also be acquired by other configurations.

[0067] (Risk Information)

[0068] Risk information includes, for example, risk items as information regarding the risk of business activities impacting privacy. Risk items are used to assess the risk of business activities impacting privacy. Risk items may be, for example, information that directly represents the risk content itself regarding the impact of business activities, etc. on privacy, or may represent items that require attention, and there are no particular limitations on the information used to assess risk. In addition to risk items, risk information may also include information such as risk levels and risk maps, as described below.

[0069] 4 is a diagram showing an example of presented risk information. In the example shown in Fig. 4, the risk information includes a risk item, a situation in which the risk item occurs, the possibility, impact, and risk level of the occurrence of the risk item, and a link to display countermeasures.

[0070] In the example shown in Figure 4, for example, a risk item is raised regarding business activities that manage purchasing data: "When integrating and analyzing your own company's personal data with that of other companies, it is necessary to obtain consent from the individual to provide the data to a third party." As the "situation" for this risk item is indicated as "collection," it indicates that it occurs in situations where privacy-related data corresponding to handling information (for example, purchasing data such as the store where the purchase was made, the date and time of purchase, and the purchased product) is "collected."

[0071] Furthermore, for this risk item, the "likelihood" is displayed as "4," the "impact" as "4," and the "risk level" as "8" in terms of risk occurrence. These values ​​numerically represent the risk assessment in order to make it easier to compare with other risk items and to recognize the degree of "likelihood," "impact," and "risk level" of risk occurrence. These "likelihood," "impact," and "risk level" values ​​may be set as default assessment values ​​predetermined for each risk item.

[0072] Also, for example, the impact may be evaluated in four stages of "4: Severe / 3: Large / 2: Medium / 1: Small," the likelihood of occurrence may be evaluated in four stages of "4: Always / 3: Often / 2: Sometimes / 1: Rarely," and the risk level may be evaluated in three stages ("3: Avoid / 2: Reduce / 1: Maintain") from the perspective of the impact and likelihood of occurrence. Note that the evaluation of the impact and likelihood of occurrence is not limited to four stages, and the risk level is not limited to three stages, and is not particularly limited.

[0073] Note that the display of "+1" for a countermeasure may indicate that one countermeasure has been added. For example, the "Countermeasure +1" may be configured to include a link to a page displaying the countermeasure, and the countermeasure may be displayed when the user clicks on the "Countermeasure +1" character portion. Details of risk countermeasures will be described later.

[0074] (Risk information generation unit 122)

[0075] The risk information generation unit 122 generates risk information (e.g., information such as that shown in Figure 4) regarding the risk of privacy impacts caused by various activities (e.g., business activities that manage purchasing data) based on handling information (e.g., purchasing data such as the purchase store, purchase date and time, and purchased items), and presents it to the user.

[0076] For example, for each piece of information representing a data set included in the handling information acquired by the acquisition unit 121, information representing risk items, etc. predetermined by a user, artificial intelligence, etc. (information on the risk content itself, the possibility and impact of the risk, etc.) may be associated and stored in the memory unit 11.

[0077] The risk information generation unit 122 may then read out information such as risk items corresponding to the data set contained in the handling information acquired by the acquisition unit 121, and generate risk information including information that defines or controls the display mode of the information such as risk items.

[0078] For example, for the data set "purchase data" included in the handling information, one or more risk items as shown in Figure 4, and for each risk item, the situation, possibility, impact, risk level, link information to countermeasures, etc. may be set in advance by the user.

[0079] If the risk information generation unit 122 determines that the handling information acquired by the acquisition unit 121 includes a data set of "purchasing data," it reads out from the storage unit 11 the risk items set for the "purchasing data," their situations, possibilities, degrees of impact, risk levels, link information for countermeasures, and the like, and generates list display information as risk information, such as that shown in Fig. 4, and presents it to the user. Note that the risk information is not limited to list display information, and may be information displayed for each individual risk item, and the display format is not particularly limited.

[0080] In addition, the configuration is not limited to one in which information such as one or more risk items as shown in Figure 4 is set in advance by a user or the like for the data set "Purchase Data," but may also be one in which information such as one or more risk items as shown in Figure 4 is set in advance by a user or the like according to the items of the data set included in one data set called "Purchase Data."

[0081] That is, when the data set is "purchase data," for example, the data set may include three items, "purchase store," "purchase date and time," and "purchased product," and the data set may include only two items, "purchase store" and "purchase date and time," and different information such as risk items may be set in advance by a user, etc. In this case, the risk information generation unit 122 may read out information such as risk items corresponding to the contents of the data items constituting the data set, which are included in the handling information acquired by the acquisition unit 121, and generate information representing the contents to be presented to the user as risk information.

[0082] Furthermore, for example, the risk information generation unit 122 may be configured to generate risk information using an artificial intelligence model (artificial intelligence function) such as a large-scale language model. For example, the risk information generation unit 122 may be configured to input prompt information including information such as a data set and a data flow (described later) contained in the handling information acquired by the acquisition unit 121 into a large-scale language model (not shown), receive risk-related information generated and output by the artificial intelligence function of the large-scale language model, and present the information to the user as risk information.

[0083] (large-scale language model)

[0084] Here, we will explain a large-scale language model as an example of an artificial intelligence model. A large-scale language model is a type of artificial intelligence used in the field of natural language processing, which statistically learns the probability distribution of words and sentences from huge amounts of text data and can generate natural language output like a human in response to a given input (such as a prompt).

[0085] More specifically, large-scale language models are a type of deep learning model based on a computational model called a neural network, which mimics the function of neurons in the human brain. A neural network has a multi-layer structure that receives a huge amount of input data and adjusts its parameters by learning patterns.

[0086] The large-scale language model is composed of a huge neural network consisting of a huge number of parameters, and is a model trained using a large amount of text data. As a result, the large-scale language model M has internal linguistic knowledge such as grammar, semantics, and context, and can generate appropriate output for a given input. The large-scale language model according to this embodiment is a model trained to generate appropriate risk information based on handling information, etc.

[0087] The large-scale language model may be, for example, a configuration contained within the server 10, or may be a configuration that utilizes functions provided by an external device that is communicatively connected via a network N1 or the like, and is not particularly limited.

[0088] (Risk template management unit 123)

[0089] In the PIA system 1, the risk template management unit 123 may manage risk templates including risk items used to evaluate risks regarding impacts on privacy. The risk information generation unit 122 may then select a risk template based on handling information and present the risk items included in the risk template or the risk template itself as risk information.

[0090] The risk template management unit 123 provides a function for managing risk templates. For example, the risk template management unit 123 can accept the registration of a new risk template and can also accept modifications to registered risk templates. Furthermore, when new risk information is registered, the risk template management unit 123 may, upon accepting a request from a user to read an existing risk template, display the risk template requested to be read as default information when registering new risk information.

[0091] The risk template may be set in accordance with various laws and regulations, such as the Act on the Protection of Personal Information. The risk template may also be set in accordance with various standards (e.g., ISO / IEC 29314 (PIA Guidelines), ISO / IEC 29184 (Notice and Consent for Online Services), JIS Q 15001 (P Mark), JIS Q 27001 (ISMS), JIS Q 31010 (Risk Management), JIS X 9250 (Privacy Framework)). Furthermore, the risk template may be set in accordance with guidelines related to privacy protection. These privacy risk templates may be preset by the user, for example.

[0092] Furthermore, risk templates are not necessarily set for each of the above-mentioned laws, regulations, standards, and guidelines, but may be set according to use cases, etc., and are not particularly limited. For example, a risk template regarding the provision of personal data to a third party may be created based on the Personal Information Protection Act to measure privacy risks when personal data is provided to a third party. Furthermore, a risk template regarding the use of pseudonymized information may be created based on the Personal Information Protection Act to measure privacy risks when pseudonymized information is jointly used. Alternatively, a risk template regarding the use of personal-related information may be created based on the Personal Information Protection Act to measure privacy risks when personal-related information is used.

[0093] Furthermore, a risk template for information bank services may be created based on the Act on the Protection of Personal Information, the Data Ethics Review Board's Operational Guidelines, etc. to assess privacy risks when operating information bank services. A risk template for medical information bank services may be created based on the Act on the Protection of Personal Information, the Data Ethics Review Board's Operational Guidelines, etc. to assess privacy risks when operating information bank services that handle sensitive personal information. These are merely examples, and users may add new risk templates for other use cases, etc., and the present invention is not particularly limited.

[0094] FIG. 5 is a diagram showing an example of a screen for creating new risk information. As shown in FIG. 5, a user can create new risk information from a risk template. For example, when a user selects one of the risk templates shown in FIG. 5 and presses the "Create from template" button, the risk template management unit 123 reads out the information of the selected risk template and displays it as default information on the new risk information registration screen. In the example shown in FIG. 5, risk templates with the template names "Provision of personal data to third parties," "Utilization of pseudonymized information," "Utilization of personal-related information," and "Information bank service" are registered.

[0095] 6 is a diagram showing an example of information included in a risk template. In the example shown in FIG. 6, information included in a risk template with the template name "Utilization of Pseudonymized Information" is displayed. This risk template is a template that includes information such as risks anticipated when utilizing pseudonymized information.

[0096] Specifically, as shown in Figure 6, the risk template for "utilization of pseudonymized information" includes risk items such as "Is there a possibility that unauthorized persons may gain unauthorized access to the shared use environment?", "Is there a risk of identifying individuals by accumulating and integrating pseudonymized information?", "Is there a risk that individuals may be identified from the segment information to be created?", "Is there a risk that unauthorized information will be accumulated in the shared use environment?", and "Does adding to a company's personal information or taking actions based on segment information constitute personal identification?". The example risk template shown in Figure 6 also includes information such as the risk scenario, likelihood of occurrence, impact, and risk level for each risk item.

[0097] For example, the risk information generation unit 122 may generate risk information by selecting a risk template that has been registered in advance in association with the handling information acquired by the acquisition unit 121. For example, in the PIA system 1, pseudonymized information is registered in advance by the user as one piece of information included in the handling information, and information is registered that associates the pseudonymized information with the risk template "Utilization of pseudonymized information" shown in Figure 6. Then, when the handling information acquired by the acquisition unit 121 is pseudonymized information, the risk information generation unit 122 can select the risk template associated with the pseudonymized information.

[0098] Note that the configuration may also be such that an artificial intelligence function such as a large-scale language model autonomously determines and selects a risk template that is highly relevant to handling information. For example, the risk information generation unit 122 may be configured such that when a prompt including handling information acquired by the acquisition unit 121 is input to a large-scale language model (not shown), a model that has learned about the relationship between handling information and risk templates outputs a risk template that is relevant to the handling information, and the risk information generation unit 122 selects the risk template output from the large-scale language model.

[0099] The risk information generation unit 122 then presents the risk items included in the risk template as risk information via the user terminal 20, as shown in Fig. 6, for example. Alternatively, the risk information generation unit 122 may be configured to first present information about the risk template (such as a list of related template names) as risk information. In this case, when a specific risk template is selected by the user from the list of risk templates, the risk items included in that risk template may be displayed.

[0100] In the PIA system 1, the risk template shown in FIG. 6 may be configured to have, for example, an edit button, and to accept modifications to the content by pressing the edit button.

[0101] (Risk information correction receiving unit 124)

[0102] In the PIA system 1, the risk information correction receiving unit 124 receives user corrections to the risk information presented by the risk information generating unit 122. For example, in the example shown in Fig. 4, an edit button (a pen-shaped graphic) is provided for each risk item, and when the user presses this edit button, a screen is displayed that receives additions or changes to information about the risk item. The risk information correction receiving unit 124 then receives user corrections to the risk information via this screen.

[0103] Other information such as the situation, possibility, impact, and risk level may also be similarly modified. Furthermore, a new add button for adding new risk items, etc. may be provided, and the user may press the new add button to accept input of new risk items, etc., and this is not a particular limitation. This allows exceptional risk items, etc. to be managed according to individual cases, allowing for more flexible risk management responses than just the content of typical risk information set in templates, etc.

[0104] (Risk map)

[0105] In addition, in the PIA system 1, the risk information generation unit 122 may display map information regarding risks as risk information by mapping risk items included in the risk information and used to evaluate the risk regarding the impact on privacy onto a map based on the impact of the risk and the likelihood of the risk occurring.

[0106] For example, as shown in Figure 4, risk information includes information on risk items, risk probability, and risk impact, and the risk information generation unit 122 can display map information by mapping this information on a map with the axes of risk impact and risk occurrence probability.

[0107] Fig. 7 is a diagram showing an example of map information related to risks. As an example, the risk information generation unit 122 generates the risk map (map information related to risks) shown in Fig. 7 as risk information and displays it via the user terminal 20. In the example of the risk map shown in Fig. 7, the horizontal axis corresponds to the likelihood of risk occurrence, and the vertical axis corresponds to the impact of the risk.

[0108] The likelihood of a risk occurring is the likelihood that the risk of the content of each risk item contained in the risk information will occur, and is evaluated on a four-point scale: "1. Very high," "2. Certain probability," "3. Somewhat high," and "4. Very high."

[0109] In addition, the risk impact level refers to the degree of impact of the risk of the content of each risk item included in the risk information, and is evaluated on a four-level scale: "1. Negligible," "2. Limited," "3. Serious," and "4. Severe."

[0110] In the example of Figure 7, the numbers displayed in the square frames are arranged in a matrix. For example, the number "1" displayed in the square at the bottom left indicates that there is one risk item whose likelihood of occurrence is rated as "1 very low" and whose impact is rated as "1 negligible."

[0111] Similarly, the number "8" displayed in the upper right box indicates that there are eight risk items whose likelihood of occurrence is rated as "4: Very High" and whose impact is rated as "4: Severe."

[0112] By displaying it as a matrix map in this way, the distribution of high-priority and low-priority risks for which countermeasures should be taken is presented in a visually easy-to-understand manner, allowing users to easily recognize the existence of risks.

[0113] 7 shows a list of risks to be "avoided." Risks to be "avoided" are risks included in the risk information that should be avoided, and some kind of countermeasure is required.

[0114] In the example shown in Figure 7, the risk to be avoided is "Is there a risk that individuals may be identified from the segment information to be created?" This risk could occur in the "provision" situation, and both the impact level is "4 (severe)" and the likelihood of occurrence is "4 (very high)." The response status for the risk is currently being addressed, and as "1 / 3" is displayed, there are three countermeasures to be taken, of which the first one has been completed. Risk countermeasures will be described later.

[0115] In the example shown in Figure 7, another risk to be avoided is "Will unnecessary information accumulate in the shared use environment?", which can occur in the "provision" situation and has a high impact level of "4 (severe)" and a high probability of occurrence of "4 (very high)." The response status for the risk has been completed, and as shown as "2 / 2," there are two countermeasures to be taken, and both have been completed.

[0116] In this way, by displaying a list of risk items to be "avoided" as risk information, users can recognize at a glance the high-priority risk items that they need to address, including the situation, impact, and likelihood of occurrence, and can even understand the response status, so they can take measures to address all high-risk risk items without missing anything.

[0117] <<Risk countermeasures>>

[0118] The following describes the functions related to risk countermeasures by the PIA system 1.

[0119] (Countermeasure related information generation unit 125)

[0120] In the PIA system 1, the countermeasure-related information generation unit 125 generates countermeasure-related information related to countermeasures for risk items included in risk information and used to evaluate the risk of the impact on privacy due to business activities, etc., and presents it to the user.

[0121] Countermeasure-related information includes, for example, information representing countermeasures for eliminating risks listed as risk items in the risk information generated by the risk information generation unit 122, or countermeasures for reducing risks.

[0122] 8 is a diagram showing an example of a screen on which risk countermeasure information is displayed. The countermeasure-related information generating unit 125 may generate, for example, a list of multiple risk countermeasures as the countermeasure-related information, as shown in FIG. 8. Furthermore, the countermeasure-related information generating unit 125 may generate, for example, information that represents only a countermeasure for a risk included in one risk item, or may generate information that represents all countermeasures for risks included in multiple risk items, and there are no particular limitations on the manner in which information is presented to the user.

[0123] For example, information representing risk countermeasures, etc., predetermined by a user, artificial intelligence, etc., may be stored in the storage unit 11 in association with risk items included in the risk information generated by the risk information generation unit 122. The countermeasure-related information generation unit 125 may then read information such as risk countermeasures corresponding to the risk items included in the risk information generated by the risk information generation unit 122 and generate information related to the risk countermeasures as countermeasure-related information. Note that the countermeasure-related information may only include information representing the risk countermeasure itself, or may include information such as a deadline for the risk response, and may further include information defining the display format of such information. The countermeasure-related information may include, for example, action content, associated risk, person in charge, response deadline, response status, status (not implemented, in progress, waiting for approval, completed), etc.

[0124] Furthermore, for example, the countermeasure-related information generation unit 125 may be configured to generate the countermeasure-related information by utilizing an artificial intelligence function such as a large-scale language model. For example, the countermeasure-related information generation unit 125 may be configured to input prompt information including information such as risk items included in the risk information generated by the risk information generation unit 122 into a large-scale language model (not shown), receive information related to risks generated and output by the artificial intelligence function of the large-scale language model, and present the information to the user as countermeasure-related information.

[0125] (Countermeasure Related Information Correction Receiving Unit 126)

[0126] In the PIA system 1, the countermeasure-related information correction receiving unit 126 receives user corrections to the countermeasure-related information generated by the countermeasure-related information generating unit 125. FIG. 9 is a diagram showing an example of a screen for receiving corrections to countermeasure-related information. For example, in the example shown in FIG. 9, as a countermeasure for the risk of "Will unnecessary information be accumulated in the shared use environment?", the countermeasure "Once the analysis is complete, all data created in the shared use environment will be deleted" is entered. The content of this input field can be modified by the user. In addition, corrections to the response period, responsible person, etc. can also be accepted. In other words, the countermeasure-related information correction receiving unit 126 receives user corrections to risk information via this screen.

[0127] <<Response to legal reforms, etc.>>

[0128] The following describes the functions of the PIA system 1 to respond to legal amendments and the like.

[0129] (Amendment Impact Identification Unit 127)

[0130] In the PIA system 1, the amendment impact identification unit 127 is a template containing risk items used to assess the risk of impact on privacy when amendments occur to at least one of privacy-related laws, regulations, standards, or guidelines, and can identify risk items included in the risk information that will be affected by the amendment or countermeasures (risk countermeasures) for risks related to the risk items based on a pre-amendment template set in accordance with at least one of privacy-related laws, regulations, standards, or guidelines before the amendment and a post-amendment template set in accordance with at least one of privacy-related laws, regulations, standards, or guidelines after the amendment, and present these to the user.

[0131] That is, the revision impact identification unit 127 can, for example, compare the risk templates before and after revision, and from the differences identify the risk items and risk countermeasures that will be affected by the revision, and present them to the user.

[0132] For example, risk items are set in risk templates in accordance with at least one of privacy-related laws, regulations, standards, or guidelines, but if laws, regulations, standards, or guidelines are revised, the content of the risk items that should be set in the risk templates will also change. Therefore, when comparing risk templates before and after revision, the content of the risk items set will be different.

[0133] Therefore, in the PIA system 1, for example, if a risk item that was not included before the revision is newly added after the revision, the revision impact identification unit 127 may identify the newly added risk item and present it to the user. Furthermore, the revision impact identification unit 127 may identify a risk countermeasure that has been set in association with the newly added risk item and present it to the user.

[0134] Alternatively, in the PIA system 1, for example, if a risk item that was included before the revision is deleted after the revision, the revision impact identification unit 127 may identify the deleted risk item and present it to the user. Furthermore, in the PIA system 1, for example, even if the risk items included in the risk template are the same before and after the revision, if the risk countermeasures set in association with the risk items have been changed before and after the revision, the changed risk countermeasures may be identified and presented to the user.

[0135] (Revised and updated section 128)

[0136] In the PIA system 1, the revision update unit 128 can update risk information for risk items affected by the revision identified by the revision impact identification unit 127 based on the revised template.

[0137] For example, the revision update unit 128 may regenerate risk information using the revised risk template. That is, the revision update unit 128 may regenerate risk information including risk items and the like included in the revised risk template and update the risk information by replacing the old risk information with the regenerated risk information.

[0138] (Countermeasure Update Unit 129)

[0139] In the PIA system 1, the countermeasure update unit 129 can update countermeasure-related information relating to countermeasures for risks regarding risk items identified by the revision impact identification unit and present it to the user.

[0140] For example, the countermeasure update unit 129 may regenerate the countermeasure-related information by using countermeasures (risk countermeasures) for risks that are set in association with the risk items included in the revised risk template. That is, the countermeasure update unit 129 may regenerate the countermeasure-related information including the risk countermeasures that are set in association with the risk items included in the revised risk template, and may update the countermeasure-related information by replacing the old countermeasure-related information with the regenerated countermeasure-related information.

[0141] (Revision Notification Department 130)

[0142] In the PIA system 1, when an amendment occurs to at least one of privacy-related laws, regulations, standards, or guidelines, the amendment notification unit 130 can notify information about the amendment.

[0143] For example, when at least one of privacy-related laws, regulations, standards, or guidelines is revised, information about the revision may be transmitted to the PIA system 1 from, for example, a server managed by a vendor of the PIA system 1. Then, upon receiving the information about the revision, the revision notification unit 130 notifies the user of the information about the revision via the user terminal 20.

[0144] << Information extraction from related documents >>

[0145] The function of extracting information from related documents by the PIA system 1 will now be described.

[0146] (Related document information receiving unit 131)

[0147] The PIA system 1 may further include a related document information receiving unit 131 that receives input of related document information regarding related documents related to business activities, etc., and the acquisition unit 121 may acquire handling information based on the related document information.

[0148] Related documents are various documents that contain information corresponding to the handling information, such as, but not limited to, terms of service, terms of service use, privacy policy, and service operation policy.

[0149] Incidentally, for a single business activity, multiple related documents are prepared, such as terms of service, terms of service use, privacy policy, and service operation policy, and the terms used to describe the information handled in each related document are not necessarily consistent.

[0150] For example, when the term "purchasing data" is used as handling information used by the PIA system 1 to generate risk information, one related document may express it as "purchasing data," just like the handling information, while another related document may express it as, for example, "purchasing data," "purchasing-related data," or "purchase history data." In other words, there may be variations in the way words that represent the same handling information used by the PIA system 1 to generate risk information are written in different ways in the related documents, and they may be expressed using different terms in each related document.

[0151] That is, as an example, handling information represents information used when generating risk information in the PIA system 1 (for example, a dataset set up for generating risk information), and information corresponding to handling information represents information that represents the same content as the handling information contained in each related document (for example, information extracted from the related document).

[0152] Note that the above is just one example. For example, if the terms "purchase data" and "purchase history data" have different meanings in each related document and need to be distinguished, each term may be mapped to different handling information.

[0153] Examples of information corresponding to handling information include, but are not limited to, information contained in related text that indicates, for example, the responsible department, name of personal information, item of personal information, purpose of use, whether or not it has been disclosed, whether or not it has sensitive personal information, medium, route / method of acquisition, storage location, storage method, access rights holder, expiration date of use, storage period, entrustment / provision / joint use, and return / disposal method.

[0154] The related document information related to the related document may be, for example, the related document itself. That is, the related document information receiving unit 131 may receive input of an electronic file such as a service terms of use. Note that the process by which the acquiring unit 121 acquires information corresponding to the handling information as handling information from an electronic file such as a service terms of use will be described later.

[0155] The related document information may also be an address from which the related document itself can be accessed (such as an internet URL or an address indicating a file storage location on an internal company network). In this case, the related document information receiving unit 131 receives an input of an address from which the related document itself can be accessed. The acquiring unit 121 may use this address to access the related document and acquire handling information.

[0156] The acquisition unit 121 may, for example, determine and extract information corresponding to the handling information from information included in the related documents input as related document information, and acquire the information as handling information. The acquisition unit 121 may, for example, extract information corresponding to the handling information included in the related documents using an artificial intelligence function such as the large-scale language model described above. The large-scale language model is a model that has been trained to determine and extract information handled in business activities, etc. from the related documents according to information that represents the content of the business activities, etc.

[0157] When PIA is performed for business activities that handle customer purchasing data, the large-scale language model can determine that the business activities handle purchasing data from project-related information such as the project name and business overview registered in the PIA system 1. Therefore, the acquisition unit 121 may use the large-scale language model to determine and extract information related to the purchasing data as information corresponding to the handling information from the related documents input as related document information.

[0158] The acquisition unit 121 may acquire information corresponding to the extracted usage information as it is as usage information. For example, when there is only one related document or when a consistent term is used in multiple related documents, the acquisition unit 121 may acquire, as it is, the information extracted by determining it as information corresponding to the usage information.

[0159] For example, the acquisition unit 121 may be configured to acquire, as handling information, information that has been determined to correspond to the handling information and extracted, by automatically registering the information as information to be input into the fields for the dataset name, dataset item, etc. in Fig. 3. In this case, for example, when a dataset editing screen with input items similar to those in Fig. 3 is launched, the acquired handling information is input as default information.

[0160] In addition, for example, even if there is variation in the expression of words expressing the same content in multiple related documents, if there is a word that expresses the same content with a frequency of use above a certain level, the acquisition unit 121 may extract information corresponding to the handling information and acquire it as handling information.

[0161] (Example of data mapping)

[0162] Data mapping refers to the process of organizing the data handled by a business across the entire business and visualizing the handling status, etc. This is done by creating a data mapping table, and the Personal Information Protection Commission has disclosed an example of a data mapping table. Items in a data mapping table include, but are not limited to, the name of the data, handling department, person in charge, number of people, data item, purpose of use, data classification, whether or not it is sensitive personal information, the person who owns the data, how the data was obtained, and consent to third-party provision.

[0163] Various methods are conceivable for automating data mapping, and all conceivable methods are applicable to the present disclosure, but as an example, the acquisition unit 121 may be configured to acquire handling information using data mapping information that lists a wide range of handling information candidates that may be used when implementing PIA. This configuration will be explained below using an example of business activities that handle customer purchase data.

[0164] The data mapping information may be in a tabular format, for example. An example using a data mapping table, which is data mapping information in a tabular format, will be described below, but the data mapping information does not necessarily have to be in a tabular format and is not particularly limited.

[0165] For example, when conducting PIA on business activities that handle customer purchasing data, the data set name "Purchase Data" and the data items "Purchase Store," "Purchase Date and Time," and "Purchased Item" may be listed in a data mapping table stored in memory unit 11 as candidates for handling information that may be used to generate risk information.

[0166] To automate data mapping, the acquisition unit 121 uses artificial intelligence functions such as a large-scale language model to determine whether the related documents contain information corresponding to the listed "purchase data," "purchase store," "purchase date and time," and "purchased product," and extracts the information. For example, even if the related documents contain terms such as "purchase-related data" or "purchase history data," the large-scale language model may determine that such terms correspond to the "purchase data" in the dataset in the PIA system 1 based on the context, etc.

[0167] Here, the acquisition unit 121 uses a large-scale language model to determine that the related documents do not contain information corresponding to the "purchase store," but do contain information corresponding to the "purchase data," "purchase date and time," and "purchase items," and extracts the information corresponding to the "purchase data," "purchase date and time," and "purchase items."

[0168] In this case, the acquisition unit 121 may register the "purchase data," "purchase date and time," and "purchased item" contained in the data mapping table in association with information corresponding to the "purchase data," "purchase date and time," and "purchased item" contained in the related document (for example, words such as "purchase data," "purchased date and time," and "purchased item"), and update the data mapping table.

[0169] The acquiring unit 121 may then acquire, as the handling information, "purchase data," "purchase date and time," and "purchased product," to which information corresponding to the handling information is mapped, from among the information listed as handling information candidates in the updated data mapping table. In this case, too, for example, when a data set editing screen with input items similar to those in FIG. 3 is launched, the acquired handling information may be input as default information.

[0170] Alternatively, for example, the acquisition unit 121 may be configured to generate a data mapping table by automatically determining and extracting items of the data mapping table from related documents based on summary information of the PIA (such as summary information of the project) included in a prompt input by the user, using an artificial intelligence function such as a large-scale language model, and is not particularly limited thereto.

[0171] (Example of existing system / DB integration)

[0172] Furthermore, the related document information may be information about related documents that has been previously input into an existing information processing system or database that cooperates with the PIA system 1. For example, as the related document information, information corresponding to handling information included in each related document may be associated with related documents such as terms of service and previously input into an existing information processing system or database that cooperates with the PIA system 1.

[0173] Furthermore, the related document information may be information corresponding to the handling information included in each related document that is input by the user to the PIA system 1 in association with the related document, such as the terms of use of the service, and stored in the storage unit 11. Alternatively, the storage unit 11 of the PIA system 1 may be configured to have information corresponding to the handling information included in each related document copied from an existing information processing system or database linked to the PIA system 1 in association with each related document.

[0174] The acquisition unit 121 also identifies a related document corresponding to the related document information that has been received as input, and acquires information corresponding to the handling information contained in the related document from the storage unit 11. Note that a storage device or database of an information processing system that cooperates with the PIA system 1 may function as the storage unit 11 of the PIA system 1, and is not particularly limited thereto.

[0175] Then, the acquisition unit 121 may, for example, map information corresponding to the handling information acquired from the memory unit 11 to the above-mentioned data mapping table, and acquire as handling information information that is mapped with information corresponding to the handling information from among the information listed as candidates for handling information in the data mapping table.

[0176] (Handling information correction receiving unit 132)

[0177] The PIA system 1 may further include a handling information correction receiving unit 132 that receives user corrections to the handling information acquired by the acquisition unit 121. For example, the handling information input screen shown in FIG. 3 displays "Create new dataset" and is a screen for newly registering examples of handling information, such as the name of a dataset, dataset items, and purpose of use. However, for example, when a user selects handling information already registered in the PIA system 1 and performs a process to request correction (e.g., pressing an edit button for specific handling information), an input screen similar to that shown in FIG. 3 may be displayed on the user terminal 20. In other words, the handling information correction receiving unit 132 may be configured to receive user corrections to the handling information via the input screen.

[0178] 3 may display, as default values, handling information acquired from an information processing system or database linked to the PIA system 1, or handling information acquired by a large-scale language model. In this case, too, the handling information correction receiving unit 132 may be configured to accept corrections to the handling information by the user via the input screen.

[0179] <<Data flow management>>

[0180] The following describes the functions related to data flow management by the PIA system 1.

[0181] The PIA system 1 may further include a data flow management unit 133 that manages data flow information that can identify at least one or more actions of collecting, storing, using, providing, processing, or disposing of privacy-related data in business activities, etc., and the subjects related to the actions. In this case, the risk information generation unit 122 can generate risk information based on the data flow information.

[0182] Fig. 10 is a diagram showing an example of data flow information managed by the data flow management unit 133. In the example shown in Fig. 10, the data flow information is a matrix table in which the vertical axis represents the content of the action and the horizontal axis represents the subject of the action, and handling information and the content and timing of specific actions are mapped to the matrix table.

[0183] As an example of data flow information managed by the data flow management unit 133, this matrix table makes it possible to identify at least one or more actions of collecting, storing, using, providing, processing, or disposing of privacy-related data in business activities, etc., and the entities related to those actions.

[0184] More specifically, in the example shown in Figure 10, the vertical axis of the matrix table of data flow information shows three items: "collection," "storage / use / provision," and "disposal," and the horizontal axis shows four items: "consumer (user)," "our company (PIA implementing entity)," "payment company (credit company)," and "data analysis contractor."

[0185] In the example shown in FIG. 10 , for example, it is possible to identify that "your company (PIA implementing entity)" will "collect" "purchase data" and "personal information" of "consumers (users)." It is also possible to identify that "purchase data" and "personal information" will "collect" when "consumers (users)" "pay at the register," "register as a member," or "register with a card company." It is also possible to identify that "your company (PIA implementing entity)" will "link and store the "purchase data" and "personal information" in a database," "pseudonymize and share," "provide data (share)," "send the results share," and "restore (integrate the results share) and utilize the results (product planning, etc.)." It is also possible to identify that "data analysis contractor" will "dispose of the data after sending the results."

[0186] Note that Figure 10 is merely an example of data flow information, and in addition to "storage, use, and provision" as types of actions that handle privacy-related data, for example, an action of "processing" may be added as an item on the vertical axis to distinguish between actions by companies that specialize in anonymizing data, and the information is not limited to the matrix table shown in Figure 10. Furthermore, data flow information does not necessarily have to be a matrix table, and there are no particular limitations on the display format.

[0187] As an example of managing data flow information, the data flow information is stored in the memory unit 11, and the data flow management unit 133 displays the matrix table shown in Figure 10 on the user terminal 20 in response to a display request from the user, for example.

[0188] The data flow management unit 133 may also generate data flow information from the data mapping information. For example, in the above-mentioned data mapping table, an example has been described in which information corresponding to handling information is extracted from documents related to business activities, etc., that are the subject of PIA, and mapped to handling information candidates. However, the data mapping table may also list, for each handling information candidate, what entities may be related and what actions may occur.

[0189] The data flow management unit 133 may then use, for example, a large-scale language model to extract from the relevant documents what entities are involved in the business activities, etc. that are the subject of the PIA, and what actions are occurring, and map this to the data mapping table described above.

[0190] Alternatively, for example, related document information may include information corresponding to the handling information contained in each related document, as well as information on which entities are involved and what actions will occur, which may be associated with related documents such as terms of service, and may be pre-entered into an existing information processing system or database that works with the PIA system 1, and stored in the memory unit 11.

[0191] The data flow management unit 133 may then obtain information from the related document information stored in the memory unit 11 indicating which entities are involved in the business activities, etc. that are the subject of the PIA, and what actions will occur, and map this information into the data mapping table described above.

[0192] As described above, by mapping to the data mapping table, it is possible to identify which entity will perform what action on which handling information, and therefore the data flow management unit 133 may generate data flow information (for example, a matrix table as shown in Figure 10) from this data mapping table.

[0193] The data flow information may be generated as information that represents the relationship between data processing flow (acquisition → storage → use → transfer → storage → use → deletion), players (individual users / service providers / service operators), processing steps (data type, processing content, collaboration destination, collaboration method), etc. Data flow information also makes it possible to determine whether or not data is provided to a third party.

[0194] The risk information generating unit 122 then generates risk information based on the data flow information. For example, the risk information generating unit 122 may generate risk information by selecting a risk template that is registered in advance in association with handling information included in the data flow information.

[0195] For example, in the PIA system 1, assume that a user has registered pseudonymized information in advance as one piece of information included in handling information, and that information is registered that associates the pseudonymized information with the risk template "Utilization of pseudonymized information" shown in Figure 6. Note that the number of associated risk templates is not limited to one, and multiple risk templates may be associated.

[0196] If the handling information included in the data flow information is pseudonymized information, the risk information generation unit 122 selects the risk template for "utilization of pseudonymized information" associated with the pseudonymized information.

[0197] Alternatively, the risk information generation unit 122 may generate risk information by selecting a risk template that has been pre-registered in association with, for example, the handling information contained in the data flow information, the content of the action on that handling information, and the subject of that action.

[0198] For example, in the PIA system 1, assume that a user has registered pseudonymized information in advance as one piece of information included in handling information, and that "storage, use, and provision" have occurred as actions on the pseudonymized information, and that the subject of the action is "our company (PIA implementing entity)," and that information is registered that associates the risk template for "utilization of pseudonymized information" shown in Figure 6 with this combination. Note that the number of associated risk templates is not limited to one, and multiple risk templates may be associated.

[0199] If the data flow information includes pseudonymized information as one of the pieces of information included in the handling information, and the actions taken on that pseudonymized information include "storage, use, and provision," and the subject of those actions is "our company (PIA implementing entity)," the risk information generation unit 122 selects the risk template for "utilization of pseudonymized information" associated with that combination.

[0200] (Data flow modification receiving unit 134)

[0201] The PIA system 1 may further include a handling information correction receiving unit that receives user corrections to the data flows managed by the data flow management unit. For example, when a user performs a process to request a correction (e.g., pressing an edit button for data flow information, not shown) on the data flow information display screen shown in Figure 10, an editing screen for correcting the data flow information may be displayed on the user terminal 20. In other words, the data flow correction receiving unit 134 may be configured to receive user corrections to the handling information via the input screen.

[0202] <<Example of processing flow in PIA system 1>>

[0203] An example of the operation of the PIA system 1 configured as described above will be described with reference to Fig. 11. Fig. 11 is a flowchart illustrating an example of the operation of the PIA system 1. Note that the flowchart shown in Fig. 11 is merely an example of the processing flow, and is not particularly limited, and for example, other steps may be included, the same steps may be executed repeatedly, the order of steps may be changed, or some steps may not be executed, depending on a user request.

[0204] In step S101, as one example, the control unit 22 of the user terminal 20 transmits the handling information input by the user to the server 10. As described in the above-described embodiment, as another example, a related document including information corresponding to the handling information may be specified by the user via the user terminal 20 and uploaded to the server 10.

[0205] In step S102, as one example, the acquisition unit 121 of the server 10 acquires the handling information by receiving it from the user terminal 20. As described in the above-described embodiment, as another example, the acquisition unit 121 may be configured to determine and extract information corresponding to the handling information from the uploaded related documents and set it as the handling information.

[0206] In step S103, as an example, the risk information generation unit 122 of the server 10 generates risk information including risk items, etc. based on the handling information acquired by the acquisition unit 121. The risk information generation unit 122 transmits the generated risk information to the user terminal 20.

[0207] In step S104, for example, the control unit 22 of the user terminal 20 presents risk information including risk items and the like included in the received risk information to the user. The user checks the presented risk information such as risk items. The user may check default values ​​of risk levels and the like included in the risk information, and consider the appropriateness of the risk levels in accordance with the actual activity content.

[0208] In step S105, as an example, the control unit 22 of the user terminal 20 accepts the results of user modifications and risk assessments regarding risk items, such as additions and deletions of risk items by the user, and risk levels modified by the user for each risk item, and transmits information representing the contents to the server 10.

[0209] In step S106, as an example, the server 10 stores the contents of the risk assessment and modifications made by the user to the risk information (such as additions and deletions of risk items made by the user and risk levels reset by the user for each risk item) in the storage unit 11. The risk information generation unit 122 of the server 10 then generates map information related to risks based on the modifications made by the user to the risk information and the contents of the risk assessment. For example, this risk map may be generated in response to a user request, and it is not necessarily required to generate a risk map.

[0210] In step S107, for example, the control unit 22 of the user terminal 20 presents the received map information regarding the risk to the user. The user checks the presented map information regarding the risk.

[0211] In step S108, for example, the control unit 22 of the user terminal 20 transmits information input by the user instructing the presentation of countermeasure-related information to the server 10. Note that the instruction to present the countermeasure-related information may be given, for example, in a step immediately after the presentation of the risk information is received in S104.

[0212] In step S109, for example, the countermeasure-related information generating unit 125 of the server 10 generates countermeasure-related information. As the countermeasure-related information, predetermined risk countermeasures may be displayed in various display modes depending on the content of the risk, or optimal risk countermeasures may be generated each time using an artificial intelligence function.

[0213] In step S110, for example, the control unit 22 of the user terminal 20 presents the received countermeasure-related information to the user. The user checks the presented countermeasure-related information. The user may check the risk countermeasures, etc. included in the countermeasure-related information and consider the appropriateness of the risk countermeasures, etc. in accordance with the actual activity content.

[0214] In step S111, for example, the user inputs information for modifying the risk countermeasure as needed, and the control unit 22 of the user terminal 20 transmits countermeasure-related information that reflects the modification content input by the user to the server 10. In the server 10, the modified countermeasure-related information is stored in the storage unit 11.

[0215] This completes the operation of the PIA system 1. As described above, the flowchart shown in Fig. 11 merely explains one example of the operation of the PIA system 1, and the operation of the PIA system 1 is not limited to this.

[0216] [Software implementation example]

[0217] The control block of the server 10 may be realized by a logic circuit (hardware) formed on an integrated circuit (IC chip) or the like, or may be realized by software. In the latter case, each of the server 10 and the user terminal 20 is configured using, for example, a computer (electronic calculator).

[0218] (Physical configuration of server 10)

[0219] FIG. 12 is a block diagram illustrating the physical configuration of a computer used as the server 10 and the user terminal 20. As shown in FIG.

[0220] 12, the server 10 can be configured by a computer including a bus 110, a processor 101, a main memory 102, an auxiliary memory 103, and a communication interface 104. The processor 101, the main memory 102, the auxiliary memory 103, and the communication interface 104 are connected to one another via the bus 110.

[0221] The processor 101 may be, for example, a CPU (Central Processing Unit), a microprocessor, a digital signal processor, a microcontroller, or a combination of these.

[0222] The main memory 102 may be, for example, a semiconductor RAM (random access memory).

[0223] The auxiliary memory 103 may be, for example, a flash memory, a hard disk drive (HDD), a solid state drive (SSD), or a combination thereof. The auxiliary memory 103 stores a program for causing the processor 101 to execute the above-described operations of the server 10. The processor 101 loads the program stored in the auxiliary memory 103 onto the main memory 102 and executes each instruction included in the loaded program.

[0224] The communication interface 104 is an interface that connects to the network N1.

[0225] In this example, the processor 101 and the communication interface 104 are examples of hardware elements that realize the control unit 12. The main memory 102 and the auxiliary memory 103 are examples of hardware elements that realize the storage unit 11.

[0226] (Physical configuration of user terminal 20)

[0227] 12, the user terminal 20 can be configured by a computer including a bus 210, a processor 201, a main memory 202, an auxiliary memory 203, a communication interface 204, and an input / output interface 205. The processor 201, the main memory 202, the auxiliary memory 203, the communication interface 204, and the input / output interface 205 are connected to one another via the bus 210. An input device 206 and an output device 207 are connected to the input / output interface 205.

[0228] The processor 201 may be, for example, a CPU, a microprocessor, a digital signal processor, a microcontroller, or a combination of these.

[0229] The main memory 202 may be, for example, a semiconductor RAM.

[0230] The auxiliary memory 203 may be, for example, a flash memory, an HDD, an SSD, or a combination thereof. The auxiliary memory 203 stores a program for operating the computer as the user terminal 20. The processor 201 loads the program stored in the auxiliary memory 203 onto the main memory 202 and executes each command included in the loaded program. The auxiliary memory 203 also stores various data referenced by the processor 201 to operate the computer as the user terminal 20.

[0231] The communication interface 204 is an interface for connecting to a network.

[0232] The input / output interface 205 may be, for example, a USB interface, a short-range communication interface such as infrared or Bluetooth (registered trademark), or a combination of these.

[0233] The input device 206 may be, for example, a keyboard, a mouse, a touchpad, a microphone, or a combination thereof. The output device 207 may be, for example, a display, a printer, a speaker, or a combination thereof.

[0234] In this example, the processor 201 and the communication interface 204 are examples of hardware elements that realize the control unit 22. The main memory 202 and the auxiliary memory 203 are examples of hardware elements that realize the storage unit 21.

[0235] Instead of storing the above-described programs in auxiliary memories 103 and 203, the programs may be recorded on an external recording medium and read from the external recording medium to be supplied to the corresponding computer. The external recording medium may be a computer-readable "non-transitory tangible medium," such as a tape, disk, card, semiconductor memory, or programmable logic circuit. The above-described programs may also be supplied to the computer via any transmission medium (such as a communications network or broadcast waves). Another aspect of the present invention may be realized in the form of a data signal embedded in a carrier wave, in which the programs are embodied by electronic transmission.

[0236] The present invention is not limited to the above-described embodiments, and various modifications are possible within the scope of the claims. Embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of the present invention.

[0237] <<Summary of the Disclosure>>

[0238] The following description will focus on the operation and effects of the PIA system according to one aspect of the present disclosure. All of the configurations described below can also be used as configurations of this embodiment.

[0239] A PIA system according to one aspect of the present disclosure is a PIA system that performs information processing to evaluate the impact on privacy of an activity that handles privacy-related data, and includes an acquisition unit that acquires handling information that represents the content of the privacy-related data handled in the activity, and a risk information generation unit that generates risk information regarding the risk of the activity impacting privacy based on the handling information and presents it to a user.

[0240] According to the above configuration, when conducting a PIA (assessment of the impact on privacy of activities that handle privacy-related data), the PIA system automatically generates appropriate risk information based on handling information, so that the entity conducting the PIA can easily conduct an appropriate PIA even if they have little experience with PIA.

[0241] In a PIA system according to one aspect of the present disclosure, it is preferable that the risk information generation unit presents to the user risk items used to assess the risk of the activity's impact on privacy as the risk information.

[0242] According to the above configuration, risk items are automatically presented when PIA is performed, allowing the user to efficiently evaluate risks.

[0243] It is preferable that a PIA system according to one aspect of the present disclosure further includes a risk template management unit that manages risk templates including risk items used to assess the risk of impact on privacy, and that the risk information generation unit selects the risk template based on the handling information and presents the risk items included in the risk template or the risk template as the risk information.

[0244] According to the above configuration, risk items and risk templates included in a risk template selected based on handling information are presented. That is, a list of risk items included in one or more selected templates may be presented, or a list of one or more risk templates that have been selected may be presented. This allows PIA to be performed using templates prepared in advance, which facilitates prior configuration in the PIA system and simplifies the work required to perform PIA.

[0245] In a PIA system according to one aspect of the present disclosure, it is preferable that the risk template management unit manages the risk template set in accordance with at least one of privacy-related laws, regulations, standards, guidelines, or the content of the activity.

[0246] According to the above configuration, risk templates are set according to privacy-related laws, regulations, standards, and guidelines, as well as use cases of activities (not limited to business activities) that handle privacy-related data. Note that risk templates do not need to be set for each law, regulation, etc. or use case, but may be set for each combination of these, and the setting unit is not particularly limited. This makes it possible to set appropriate risk templates that take into account various laws, regulations, etc. and situations.

[0247] In a PIA system according to one aspect of the present disclosure, it is preferable that the risk information generation unit presents to the user a risk level based on an assessment of at least either the impact of the risk or the likelihood of the risk occurring, as the risk information, in correspondence with risk items used to assess the risk of the activity's impact on privacy.

[0248] According to the above configuration, the risk information includes risk level information that indicates an evaluation of each risk item based on the impact of the risk, the likelihood of occurrence, etc. The risk level may be expressed numerically, for example, to relatively evaluate the degree of risk, and the manner of expression is not limited to numerical values ​​and may be expressed as a graph or the like, without any particular limitation. This allows the user to appropriately determine, for example, which risk item should be given priority.

[0249] In a PIA system according to one aspect of the present disclosure, it is preferable that the risk information generation unit presents a predetermined evaluation value for each risk item as the risk level.

[0250] According to the above configuration, for example, a pre-set default value is presented for the standard level of risk for each risk item, eliminating the need for the user to set it individually each time a PIA is performed, simplifying the work and making the implementation of a PIA more efficient.

[0251] It is preferable that the PIA system according to one aspect of the present disclosure further includes a risk information correction receiving unit that accepts user corrections to the risk information presented by the risk information generation unit.

[0252] According to the above configuration, the user can modify the risk information presented by the PIA system. Therefore, even if the content of the risk information presented by the PIA system is not necessarily appropriate due to the individual circumstances of the PIA, the user can reset the appropriate risk information, allowing the PIA to be implemented appropriately.

[0253] In a PIA system according to one aspect of the present disclosure, it is preferable that the risk information generation unit displays map information regarding risks as the risk information by mapping risk items included in the risk information and used to evaluate the risk regarding the impact on privacy onto a map based on the impact of the risk and the likelihood of the risk occurring.

[0254] According to the above configuration, the user can check the risk map as one of the modes of presentation of risk information. This allows the user to visually grasp the status of potential risks in business activities, etc. that are the subject of PIA, thereby raising awareness of risk countermeasures.

[0255] It is preferable that the PIA system according to one aspect of the present disclosure further includes a countermeasure-related information generation unit that generates countermeasure-related information related to risk countermeasures for risk items included in the risk information and used to assess the risk of the impact of the activity on privacy, and presents the information to the user.

[0256] According to the above configuration, countermeasure-related information for each risk item is generated and presented to the user. For example, when countermeasure-related information that has been previously associated with a risk item is presented, information corresponding to the presentation format (such as display item information or list display information included in an individual display, or audio information) may be generated. Furthermore, the countermeasure-related information may be generated using, for example, a large-scale language model based on risk information such as the risk item and the risk level. This automatically presents appropriate risk countermeasures to be implemented for each risk item, making it easy to implement PIA, including risk countermeasures.

[0257] In a PIA system according to one aspect of the present disclosure, it is preferable that the PIA system further includes a countermeasure-related information correction receiving unit that receives user corrections to the countermeasure-related information generated by the countermeasure-related information generating unit.

[0258] According to the above configuration, the user can modify the countermeasure-related information presented by the PIA system. Therefore, even if the content of the countermeasure-related information presented by the PIA system is not necessarily appropriate due to the individual circumstances of the PIA, the user can reset the appropriate countermeasure information, etc., and the PIA can be implemented appropriately.

[0259] Preferably, the PIA system according to one aspect of the present disclosure further comprises an amendment impact identification unit that identifies risk items included in the risk information that will be affected by the amendment or countermeasures for the risks of the risk items based on a pre-amendment template set in accordance with at least one of the privacy-related laws, regulations, standards, or guidelines before the amendment, which template includes risk items used to assess the risk of the impact on privacy when amendments are made to at least one of the privacy-related laws, regulations, standards, or guidelines, and presents the identified risk items to the user, based on a pre-amendment template set in accordance with at least one of the privacy-related laws, regulations, standards, or guidelines after the amendment.

[0260] According to the above configuration, for example, based on the differences between templates before and after the revision, risk items and risk countermeasures that have been changed due to the influence of legal revisions, etc. are identified and presented to the user, so that the user can easily understand the influence of legal revisions, etc. on PIAs that have already been implemented and can take appropriate measures as necessary.

[0261] It is preferable that a PIA system according to one aspect of the present disclosure further includes a revision update unit that updates the risk information, including risk items affected by the revision identified by the revision impact identification unit, based on the revised template.

[0262] According to the above configuration, if the risk items in a PIA that has already been implemented change due to legal changes, etc., the user can check risk information including risk items that reflect the contents of the legal changes, etc., so that the user can easily understand the minimum scope necessary to respond to the legal changes, etc., and can efficiently conduct a new risk assessment after the legal changes, etc.

[0263] It is preferable that a PIA system according to one aspect of the present disclosure further includes a countermeasure update unit that updates countermeasure-related information related to countermeasures for risks regarding the risk items identified by the amendment impact identification unit.

[0264] According to the above configuration, if risk response measures in a PIA that have already been implemented are changed due to the influence of legal amendments, etc., the user can check the risk response measures that reflect the contents of the legal amendments, etc., and can easily understand the minimum scope necessary to respond to the legal amendments, etc., and can efficiently implement further risk response measures after the legal amendments, etc.

[0265] It is preferable that the PIA system according to one aspect of the present disclosure further includes an amendment notification unit that notifies information regarding amendments when amendments occur to at least one of privacy-related laws, regulations, standards, or guidelines.

[0266] According to the above configuration, if a legal change or the like occurs, the user can be notified, and can therefore appropriately carry out risk assessments and risk responses that become necessary due to the legal change or the like.

[0267] It is preferable that a PIA system according to one aspect of the present disclosure further includes a related document information receiving unit that receives input of related document information regarding related documents related to the activity, and that the acquisition unit acquires the handling information based on the related document information.

[0268] According to the above configuration, handling information can be entered into the PIA system by, for example, uploading the relevant document itself, such as the terms of use of the service, or by entering the address, name, or file name of the relevant document on the network, so that even users with little experience with PIA can easily implement PIA.

[0269] In a PIA system according to one aspect of the present disclosure, it is preferable that the acquisition unit uses an artificial intelligence model to extract information corresponding to the handling information contained in the related document and acquire it as the handling information.

[0270] According to the above configuration, the functions of artificial intelligence such as large-scale language models are used to identify and extract information corresponding to handling information from related documents such as service terms of use, and the handling information used to generate risk information is automatically set, thereby reducing the burden on the user when implementing PIA.

[0271] In a PIA system relating to one aspect of the present disclosure, it is preferable that the memory unit pre-stores information corresponding to the handling information contained in the related document, and the acquisition unit acquires from the memory unit information corresponding to the handling information contained in the related document as the handling information.

[0272] According to the above configuration, information corresponding to the handling information contained in the related text is stored in a memory unit, including, for example, an associated information processing system or database, linked to the related document, and by reading out this information, the handling information used to generate risk information is automatically set, thereby reducing the burden on the user when implementing PIA.

[0273] It is preferable that the PIA system according to one aspect of the present disclosure further includes a handling information correction receiving unit that receives user corrections to the handling information acquired by the acquisition unit.

[0274] According to the above configuration, the user can modify the handling information used to generate risk information. Therefore, even if the content of the handling information automatically input into the PIA system is not necessarily appropriate, the user can reset the handling information, thereby enabling appropriate risk information to be generated.

[0275] Preferably, a PIA system according to one aspect of the present disclosure further includes a data flow management unit that manages data flow information that can identify at least one or more actions of collecting, storing, using, providing, processing, or disposing of the privacy-related data in the activity and the subjects associated with the actions, and the risk information generation unit generates the risk information based on the data flow information.

[0276] According to the above configuration, it is possible to manage data flows that can identify actions such as the collection of privacy-related data that occur in business activities, etc., and the entities involved, thereby generating detailed risk information according to the data flow, thereby improving the accuracy of PIA.

[0277] Preferably, the PIA system according to one aspect of the present disclosure further includes a data flow modification receiving unit that receives user modifications to the data flow information managed by the data flow management unit.

[0278] According to the above configuration, the user can modify the data flow information. Therefore, even if the content of the data flow automatically generated by the PIA system is not necessarily appropriate, the user can reconfigure the data flow, thereby generating appropriate risk information.

[0279] A method according to one aspect of the present disclosure includes the steps of: using a PIA system that performs information processing to evaluate the impact on privacy of an activity that handles privacy-related data related to privacy, acquiring handling information representing the content of the privacy-related data handled in the activity; and generating risk information regarding the risk of the impact on privacy of the activity based on the handling information and presenting the information to a user.

[0280] According to the above configuration, the same effects as those of the above-mentioned PIA system can be achieved.

[0281] A program according to one aspect of the present disclosure is a program for causing a computer to function as the PIA system described above, and causes the computer to function as each of the above-mentioned parts.

[0282] According to the above configuration, the same effects as those of the above-mentioned PIA system can be achieved.

[0283] One aspect of the present disclosure is useful in an information processing system for supporting a PIA.

[0284] 1 PIA system 10 Server 20 User terminal 11, 21 Memory unit 12, 22 Control unit 101, 201 Processor 102, 202 Main memory 103, 203 Auxiliary memory 104, 204 Communication interface 110, 210 Bus 121 Acquisition unit 122 Risk information generation unit 123 Risk template management unit 124 Risk information correction reception unit 125 Countermeasure related information generation unit 126 Countermeasure related information correction reception unit 127 Revision impact identification unit 128 Revision update unit 129 Countermeasure update unit 130 Revision notification unit 131 Related document information reception unit 132 Handling information correction reception unit 133 Data flow management unit 134 Data flow correction reception unit 205 Input / output interface 206 Input device 207 Output device

Claims

1. A PIA system that performs information processing to evaluate the impact of an activity that handles privacy-related data related to privacy on privacy, comprising: an acquisition unit that acquires handling information that indicates the content of the privacy-related data handled in the activity; and a risk information generation unit that generates risk information regarding the risk of the impact of the activity on privacy based on the handling information and presents the information to a user.

2. The PIA system of claim 1, wherein the risk information generation unit presents to the user, as the risk information, risk items used to evaluate the risk of the impact of the activity on the privacy.

3. The PIA system of claim 1, further comprising a risk template management unit that manages risk templates including risk items used to evaluate risks regarding the impact on privacy, wherein the risk information generation unit selects the risk template based on the handling information and presents the risk items included in the risk template or the risk template itself as the risk information.

4. The PIA system of claim 3, wherein the risk template management unit manages the risk templates set in accordance with at least one of privacy-related laws, regulations, standards, guidelines, or the content of the activity.

5. The PIA system of claim 1, wherein the risk information generation unit presents to the user a risk level based on an assessment of at least either the impact of the risk or the likelihood of the risk occurring, as the risk information, in correspondence with risk items used to assess the risk of the impact of the activity on the privacy.

6. The PIA system according to claim 5, wherein the risk information generation unit presents a predetermined evaluation value for each risk item as the risk level.

7. The PIA system of claim 1, further comprising a risk information correction receiving unit that accepts user corrections to the risk information presented by the risk information generation unit.

8. The PIA system of claim 1, wherein the risk information generation unit displays map information regarding risk as the risk information by mapping risk items contained in the risk information and used to evaluate the risk regarding the impact on privacy onto a map whose axes are the impact of risk and the possibility of risk occurrence.

9. The PIA system of claim 1, further comprising a countermeasure-related information generation unit that generates countermeasure-related information related to risk countermeasures for risk items included in the risk information and used to assess the risk of the impact of the activity on privacy, and presents the information to a user.

10. The PIA system according to claim 9, further comprising a countermeasure related information correction receiving unit that receives corrections by a user to the countermeasure related information generated by the countermeasure related information generating unit.

11. The PIA system of claim 1, further comprising an amendment impact identification unit that identifies risk items contained in the risk information that are affected by the amendment or countermeasures for the risks for the risk items based on a pre-amendment template set in accordance with at least one of the laws, regulations, standards, or guidelines related to privacy before the amendment, and a post-amendment template set in accordance with at least one of the laws, regulations, standards, or guidelines related to privacy after the amendment, the risk items including risk items used to evaluate the risk of the impact on privacy when amendments occur to at least one of the laws, regulations, standards, or guidelines related to privacy, and presents the identified risk items to a user, the countermeasures for the risks for the risk items, among the risk items contained in the risk information, based on the pre-amendment template set in accordance with at least one of the laws, regulations, standards, or guidelines related to privacy before the amendment.

12. The PIA system of claim 11, further comprising a revision update unit that updates the risk information, including risk items affected by the revision identified by the revision impact identification unit, based on the revised template.

13. The PIA system of claim 11, further comprising a countermeasure update unit that updates countermeasure-related information related to countermeasures against risks for the risk items identified by the amendment impact identification unit.

14. The PIA system of claim 1, further comprising an amendment notification unit that notifies information regarding amendments when amendments occur to at least one of privacy-related laws, regulations, standards, or guidelines.

15. The PIA system of claim 1, further comprising a related document information receiving unit that receives input of related document information regarding related documents related to the activity, wherein the acquisition unit acquires the handling information based on the related document information.

16. The PIA system of claim 15, wherein the acquisition unit uses an artificial intelligence model to extract information corresponding to the handling information contained in the related documents and acquires it as the handling information.

17. The PIA system described in claim 15, wherein the memory unit pre-stores information corresponding to the handling information contained in the related document, and the acquisition unit acquires from the memory unit the information corresponding to the handling information contained in the related document as the handling information.

18. The PIA system according to claim 15, further comprising a handling information correction receiving section that receives corrections by a user to the handling information acquired by the acquisition section.

19. The PIA system of claim 1, further comprising a data flow management unit that manages data flow information capable of identifying at least one or more actions of collecting, storing, using, providing, processing or disposing of the privacy-related data in the activity and the subject related to the action, wherein the risk information generation unit generates the risk information based on the data flow information.

20. The PIA system according to claim 19, further comprising a data flow modification receiving unit that receives user modifications to the data flow managed by the data flow management unit.

21. A method comprising the steps of: using a PIA system that performs information processing to evaluate the impact of an activity that handles privacy-related data related to privacy, obtaining handling information representing the content of the privacy-related data handled in the activity; and generating risk information regarding the risk of the activity affecting privacy based on the handling information and presenting the information to a user.

22. A program for causing a computer to function as the PIA system of claim 1, the program causing the computer to function as each of said parts.

Citation Information

Patent Citations

  • Enterprise Cyber ​​Security Risk Management and Resource Planning

    JP2020524870A

  • Cross framework validation of compliance, maturity and subsequent risk needed for; remediation, reporting and decisioning

    US20230259860A1