Japanese companies taking privacy seriously and taking out insurance to cover losses

Japanese companies taking privacy seriously and taking out insurance to cover losses

The Asahi Shimbun website has a very interesting story from Japan about the reaction of Japanese businesses to highly-publicised leaks of personal information. While some of these practices may seem to go overboard, they really are prudent since a large number of Japanese customers don't appear to be shy about complaining about mishandling of personal information. If you don't need it, don't collect it in the first place. If you no longer need it, destroy it. I haven't heard about specific privacy insurance in Canada yet, but it may not be too far off ...

PLUGGING THE HOLES: Data patrol

Companies are scrambling to protect themselves against potentially disastrous information leaks.

`A leak of data even on dozens of customers would bring an unrecoverable blow to us.'

EXECUTIVE, Food company in Tokyo

Every morning, an executive of a Tokyo food maker heads to the paper shredder and destroys documents. The measure, he says, is essential in protecting the company.

He is not hiding evidence from investigators. His action is part of efforts spreading nationwide to prevent data leaks that could lead to financial disaster.

The shredded documents at the food company are delivery order slips that contain customers' names, addresses and phone numbers.

The company decided to destroy all personal information, except e-mail addresses, as soon as a product's delivery is confirmed. Keeping a large amount of personal data ``means an increased risk,'' the executive says.

``Unlike a major company with physical strength, credibility is all that smaller firms like ours can count on,'' said the executive of the food maker, with a work force of several dozen employees. ``A leak of data even on dozens of customers would bring an unrecoverable blow to us.''

Prior to the full implementation of the personal information protection law next April, businesses are stepping up efforts to prevent information leaks.

Workers are educated on the importance of data protection. And many companies are now seeking ``data leak insurance'' to cover potential damages from lawsuits.

The law, which already regulates administrative entities, will be extended to cover private businesses with personal data on 5,000 or more people. Violators face a maximum six-month prison term or a fine of up to 300,000 yen.

But the real risks, as the Tokyo food maker fears, is a loss of credibility-and potentially huge compensation payments.

Businesses have a reason to be concerned. Videotape and CD rental chains, for example, have membership information on thousands of customers.

According to the Japan Network Security Association, compensation for a data leak varies from 1,000 yen to 1.5 million yen per customer, depending upon what information was leaked and how the company dealt with its aftermath.

Based on past court decisions, the association estimates a leak of an e-mail address could cost a company 4,000 yen. But the compensation amount soars to 300,000 yen per person if the name, address and legal domicile are leaked.

If all the 1.55 million victims in 57 leakage cases reported last year had sued, the total compensation could have reached 28 billion yen, according to the association.

The Compact Discs & Video Rental Trade Association of Japan is preparing guidelines for its 1,100 members on how to handle personal data.

Member stores often use a driver's license to confirm the identity of a customer. But the license also carries the holder's permanent and current addresses.

``If data are leaked and 100 customers file complaints, the business would be thrown into confusion,'' said an association official.

The association advises its members to black out the permanent domicile on the license's photocopy. But ``many shops count on part-time workers so teaching them is a major challenge,'' said the official.

Concerns over repercussions from data leaks have provided a business opportunity for non-life insurers, which have come out this year with new products to cover damages from information leaks.

``The responses are extraordinary,'' said an official of Mitsui Sumitomo Insurance Co., which has sold about 100 policies a month since it made the new product available in June.

The insurance covers compensation payments up to 300 million yen, even if the leak was an intentional act of an employee.

A series of large-scale leak cases this year prompted businesses to get insured.

A leak at Internet service provider Softbank BB Corp. affected 6.6 million customers.

Information of 1.16 million customers was leaked in the Sanyo Shinpan case, while the figure in the Cosmo Oil case was 920,000.

Victims are increasingly bringing their cases to court. After residents' register data were taken out and circulated from Uji city in Kyoto Prefecture, three residents sued the city government.

A court ordered the city to pay a total of 45,000 yen to the plaintiffs. The ruling was finalized in 2002.

TBC, an aesthetic salon, has been hit with a group lawsuit demanding 1 million yen in compensation for each plaintiff. Data on 50,000 clients, including vital statistics, were leaked, and some of the information was posted on the Internet.

The Japan Network Security Association says the possibility is high that many more victims will join group lawsuits if the compensation amounts rise to hundreds of thousands of yen per person.

``We hope each company will find out how much their personal data are worth before hammering out steps against information leaks,'' an association official said.(IHT/Asahi: September 8,2004) (09/08)

0 comments:

Post a Comment

  • Health Care Reform Explained from B... Dan Roam at the Back of the Napkin Blog sums up the current health care reform effort in this four part health care series, Healthcare Napkins All. Great back of the...
  • Why We Need A Health Care Revolutio... Dr. Val Jones' road to revolution provides her personal perspective on the current state of our health care system and why we all need to work for change.Don't miss the...
  • The important lesson from sandcastl... As I return to West Virginia after a week spent at the beach -- this post by Jim Carrol, Futurist, Trends & Innovation Expert, caught my attention. Much of my week on...
  • A little Nick: I'm a liberal an... Law blogger posts online: Don't miss reading this post by my favorite hospital blogging CEO, Nick Jacobs over at Nick's Blog. Much of what Nick has to say strikes a chord with me and this post is...
  • Executive Order Impacts Health Care... Law blogger posts online: President Bush signed an Executive Order on August 22 requiring federal agencies to do more to inform public health care consumers about the cost and quality of health...
  • eHealthWV: West Virginia EHR Public... Law blogger posts online: As a part of West Virginia's participation in the Health Information Security and Privacy Collaborative (HISPC), West Virginia Medical Institute and its partners launch...
  • Physicians vs. Patient: Rating-Perm... Interesting post from the WSJ Health Blog on Medical Justice's new ratings-permission contracts (press release on service).This new service offered by Medical Justice...
  • Just when you thought it was safe: ... Law blogger posts online: I’ve blogged previously about just how much I hate browser toolbars and nothing much has changed in the four years that have passed. Call me nosey, but when I’m...
  • Governor Manchin Approves Cardiac C...The West Virginia Health Care Authority website indicates today that Governor Manchin approved the final revised certificate of need Cardiac Catheterization Standards.
  • A Law Actually Interview with… Litt... Next up in the interview chair is Gemma from Little Tiny Pieces. Little Tiny Pieces is an interesting name?  What it inspired it; does it have any hidden meanings?...
  • Let the voting commence!... Law blogger posts online: Yes, after two long weeks of nominations, the shortlist for the 2010 Blawggies has been decided and voting for the awards can officially begin! The polls will remain...
  • Is blogging good for your health?... Law blogger posts online: Is blogging good for your health?This Boston Globe article, Cancer blogs become part of treatment, indicates that blogging about your condition has a positive impact.The...
  • ADVANCE Magazine - Article on EHRs ... Recently I was interviewed for an article looking at the legal issues involved in the developing world of EHRs and PHRs written by Beth Walsh for ADVANCE Magazine. The...