Machine Translated by Google
Notes Healthy Children Foundation General Incorporated Foundation
privacy policy
(the purpose)
Article 1 These regulations are based on Article 53 of the Articles of Incorporation of Notes Healthy Children's Foundation (hereinafter referred to as the "Foundation").
In accordance with Paragraph 2, personal information (Act on the Protection of Personal Information, Article 2, Paragraph 1 and "Administrative Procedures
Article 2 of the Act on the Use of Numbers to Identify Specific Individuals (hereinafter referred to as the ``Numbers Act'')
Refers to the personal information stipulated in Paragraph 3, and includes specific personal information stipulated in Article 2, Paragraph 8 of the Number Act. below
We have established rules that officers and employees of the Foundation should comply with regarding the proper handling of
The purpose is to appropriately protect and manage personal information.
(definition)
Article 2 The terms used in these regulations are as follows.
(1) Personal information
"Personal information" is personal information stipulated in Article 2, Paragraph 1 of the Personal Information Protection Act, which is related to a living individual.
information, and it is possible to identify a specific individual by the name, date of birth, and other descriptions contained in the information.
Information that can be easily compared with other information, thereby identifying a specific individual
(including things).
(2) Personal number
"Individual number" is a number obtained by converting the resident record code pursuant to the provisions of Article 7, Paragraph 1 or Paragraph 2 of the Number Act.
, and is designated to identify the person whose resident record code is recorded.
(3) Specific personal information
“Specific personal information” refers to personal information that includes an individual number.
(ÿ) Specific personal information, etc.
“Specific personal information, etc.” refers to the combination of specific personal information and related information.
(ÿ) Me
“Person” means a specific living individual who is identified or can be identified by the personal information concerned.
(6) Officers, employees, etc.
“Officers, employees, etc.” refers to all directors, auditors, councilors, and employees belonging to the Foundation.
(7) Person responsible for personal information management
Machine Translated by Google
"Personal Information Management Officer" is a person appointed by the Chairman who is responsible for complying with laws and regulations regarding personal information protection.
The person shall have responsibility and authority regarding the plan.
(Scope of application)
Article 3 These regulations apply to all officers and employees. In addition, even after retirement, employees may continue to work while still in office.
Personal information obtained or accessed shall be subject to these regulations.
(Personal information management person)
Article 4 At this foundation, the president shall be the person in charge of personal information management.
2. The personal information management officer shall ensure the proper implementation and operation of these regulations, and shall ensure that personal information is not leaked to outside parties.
shall be responsible for managing the information to ensure that it is not misused, misused, or tampered with.
(Acquisition of personal information)
Article 5 Personal information shall be acquired by lawful and fair methods, and shall not be acquired by deception or other illegal means.
should not be done.
2. When acquiring personal information directly from the person, the person (or the person's guardian if the person is a minor;
Below, it is referred to as "the person, etc." ), the following matters or matters of equivalent or greater content shall be submitted in writing or in writing.
The notification must be made by an alternative method and the consent of the person, etc. must be obtained.
(1) Name of the Foundation, name and contact information of the person in charge of personal information management
(2) Purpose of use of personal information
(Purpose of use and use of personal information)
Article 6 When handling personal information, the purpose of use shall be clearly determined in advance, and the purpose of use shall be clearly determined in advance.
The purpose of use shall be within the scope necessary for the operations of the Foundation and for which the consent of the person, etc. has been obtained.
Must be within.
(Provision of personal information)
Article 7 Personal information must not be provided to third parties except as provided by law.
2. Notwithstanding the provisions of the preceding paragraph, in order to carry out the business of the Foundation, some or all of the work, etc. shall be conducted by a third party.
If it is necessary to outsource the work to a subcontractor, the person concerned must obtain prior consent from the subcontractor who meets the following conditions:
Personal information may be provided to the subcontractor within the scope of the purpose of use specified.
Machine Translated by Google
(1) Be a person who engages in business activities that are appropriate in terms of socially accepted standards.
(2) Regarding the protection of personal information, there are regulations that are equivalent or superior to these regulations, and they are not being properly operated and implemented.
be a person who is
(3) We have concluded appropriate provisions regarding the protection of personal information with the Foundation, and we expect to comply with these provisions.
be a person who is accepted
3. When outsourcing the work mentioned in the preceding paragraph, consent must be obtained in advance from the personal information manager.
4. Pursuant to the provisions of Paragraph 2 of this Article, if the task of handling personal information is outsourced to a third party, the Foundation shall
We will confirm and provide guidance in a timely manner to ensure that the appropriate management obligations of personal information imposed on outsourcing contractors are complied with.
To be.
(Ensuring accuracy of personal information)
Article 8 Personal information shall be managed to keep it accurate and up-to-date within the scope necessary to achieve the purpose of use.
must be managed.
(security management)
Article 9 The personal information manager shall, in order to safely manage personal information, prevent unauthorized access, leakage, and destruction of personal information.
Efforts shall be made to prevent loss or damage.
2. The personal information manager shall, as necessary, establish necessary and appropriate measures for the safe management of personal information.
The regulations shall be complied with by all officers and employees handling such personal information.
(Supervision of officers, employees, etc.)
Article 10 The personal information management officer shall be responsible for officers and employees who handle personal information, etc., in order to ensure the safe management of personal information, etc.
The necessary and appropriate guidance and supervision must be provided regularly to such personnel.
(Erasure/disposal of personal information, etc.)
Article 11 Personal information, etc. that no longer needs to be retained must be immediately deleted or destroyed.
Must be.
(Duty to report and investigate, etc.)
Article 12 Officers, employees, etc. shall act if they learn that personal information has been leaked to an external party or if they are concerned that there is a risk of such leakage.
If such information is found, the person responsible for personal information management must be notified immediately.
Machine Translated by Google
2. When the personal information management officer receives a report from an officer or employee regarding the leakage of personal information to the outside,
shall immediately investigate the facts.
(Report and countermeasures)
Article 13 The personal information management officer shall, as a result of the factual investigation pursuant to the preceding article, determine whether personal information has been leaked to an external party.
If it is confirmed that the
No.
A. Scope of leaked information
B. Leak destination
C. Date and time of leak
D. Other facts discovered through the investigation
2. The personal information management officer shall, after consulting with related organizations, take concrete measures and countermeasures against the leak.
In addition, measures must be taken to prevent recurrence.
(Right regarding self-information)
Article 14 If the person requests disclosure of his or her information, in principle, the request shall be made within a reasonable period of time.
shall comply with the following. In addition, if there is incorrect information as a result of disclosure and correction or deletion is requested.
In principle, the company will respond within a reasonable period of time, and if corrections or deletions are made,
The recipient of the personal information shall be notified within the scope.
(Right to refuse use or provision of personal information)
Article 15 Use of personal information already held by the Foundation from the person in question
Or, if provision to a third party is refused, we will comply with this request. However, any of the following
This does not apply if applicable.
(1) In accordance with the provisions of laws and regulations
(2) When it is necessary to protect important interests such as the life, health, property, etc. of the person or the public.
(Processing of complaints)
Article 16 The secretariat will be in charge of handling complaints regarding the Foundation's handling of personal information.
2. The personal information management officer will develop and provide support necessary to achieve the objectives set forth in the preceding paragraph.
Machine Translated by Google
(revised and abolished)
Article 17 Amendment or abolition of these regulations shall be made through a resolution of the Board of Directors.
Supplementary Provisions
These regulations will come into effect from April 3, 2020.