詳細検索

[Complete explanation] Revision points of JIS Q 15001:2023 and practical measures to be taken in the P mark examination

Avatar
by 菊池
2 min read

[Complete explanation] Revision points of JIS Q 15001:2023 and practical measures to be taken in the P mark examination
Translated from 日本語 • View original
菊池
菊池

Hello! This is Kikuchi, an analyst at Colorkrew Security. In 2023, JIS Q 15001 (Requirements for Personal Information Protection Management Systems) was revised and the latest version, "JIS Q 15001:2023", was issued. This standard is also used as a standard for the Privacy Mark (P Mark) scheme, and in particular, audits from October 2024 onwards must comply with this new standard. Since it is a review once every two years, many companies may not be able to respond yet. In this article, we will discuss the main changes in JIS Q 15001:2023 and the responses that companies should take.

Key Changes to JIS Q 15001:2023

1. Improved Alignment with ISO/IEC 27701

  • By aligning with international standards (ISO/IEC 27701:2019), we will create a more international personal information protection system.
  • Terminology and chapter structure are organized into a format that is close to ISO and easy to respond to global needs.

2. Strengthening PDCA and Risk Response

  • Emphasis on the importance of management involvement and internal control.
  • Risk assessment is an essential element of "evaluation of the effectiveness of countermeasures→ improvement".

3. Clarification of Outsourcing Management

  • Clearly stated contractual and audit requirements when outsourcing the handling of personal information.
  • Clarify the responsibility for confirming safety management measures and selecting contractors.

4. Strengthening the description of the person's rights

  • Clearer requirements for policies for the exercise of rights by individuals, such as disclosure, correction, and deletion.
  • Need to have a quick response flow and records.

 

Screening Response from October 2024 onwards

Response Schedule

Checklist: Check Your Readiness

✔Obtained the full text of JIS Q 15001:2023 and confirmed the contents internally

✔ Revised risk assessment procedures and evaluation items

✔ Updated contracts and audit methods with contractors

✔ Revised the flow of personal correspondence (disclosure, correction, etc.)

✔ Strengthening the education and internal audit system

 

Conclusion

The transition to JIS Q 15001:2023 is an opportunity to go beyond formality and aim to build a more effective personal information protection system.

From October 2024 onwards, compliance with the new standard will be mandatory, so it is essential for companies planning to acquire or renew the standard to prepare and disseminate information internally.

Related Links

Related Articles