SB C&S Corp. (hereinafter the “Company”) strives for thorough compliance with the Act on the Protection of Personal Information (Act No. 57, 2003), Act on the Use of Numbers to Identify a Specific Individual in the Administrative Procedure (Act No. 27, 2013), and Personal Information Protection Management System – Requirements (JIS Q 15001) and endeavors to execute the following respective items in order to protect personal information.
The Company will prepare learning materials pertaining to the treatment of personal data, distribute the same to all employees and dispatched employees of the Company, and execute training at least once a year for all employees and dispatched employees of the Company who handle personal data.
The Company will prepare internal regulations pertaining to the treatment of personal data indicating a clear policy pertaining thereto. The Company will also make it clear inside the Company that the Company will adopt a severe attitude on personal data leakage and implement the proper measures against leakage, including disciplinary actions, in accordance with the Rules of Employment.
The Company will deploy a personal information protection manager, assign the Chief Information Security Officer to that post, and prepare a system clearing the roles to execute compliance with the laws, regulations, and guidelines, establishment of internal regulations, preparation of inspection system, and supervision of treatment of personal data.
The Company will control access to personal data, restrict the removal of personal data, and implement measures to prevent wrong access from the outside and other necessary and appropriate measures to prevent leakage, loss, or damage to personal data and to control the safety of personal data. Also, personal data will be kept only for the period of time (including the period provided for in the laws and regulations) required to accomplish the purposes of use.
The Company will prepare a system to audit the organizations of the Company as to whether the protection of personal data is properly carried out or not. In addition, since the inspection utilizing access log is considered effective to find out a leaker of personal data and prevent leakage by exerting a deterrent effect thereof, the Company will study an execution method of such inspection.
The Company will collect personal information by identifying the purposes of use and utilizing legal and fair means, such as documents that include application forms, computer displays that include websites, or verbal. The Company will also properly use, provide, and publish its retained personal information, taking the contents and size of businesses into consideration. When the Company receives any personal information from a third party, the Company will treat such personal information in compliance with the Act on the Protection of Personal Information and other related laws, respecting the principles penetrating protection of personal information of the provider of personal information, and in accordance with terms and conditions of a contract to be executed between such provider and the Company.
The Company will continuously review and improve actions pertaining to the protection of personal information set forth in the above clauses 1 to 7.
The Company may revise the whole or part of the Action Guidelines for the Protection of Personal Information. Material revisions will be notified on the Company’s website or other accessible means.
“Personal information”, “personal data” and “retained personal data” as used in the Action Guidelines for the Protection of Personal Information shall have those meanings defined in the Act on the Protection of Personal Information respectively. The covered principal of these information or data shall include, but shall not be limited to, customers, employees of client companies, and employees of the Company. The Action Guidelines for the Protection of Personal Information is applied to all personal information in the possession of the Company unless otherwise notified herein.
– The Action Guidelines for the Protection of Personal Information is in force as of April 1, 2014.
– Revised as of December 1, 2015.
– Revised as of May 1, 2017.
– Revised as of April 1, 2022.
SB C&S Corp.
President & CEO
Yasuo Mizoguchi