Policy on the protection of specific personal information of business partners, etc.

NTT Urban Development Corporation

Our company will handle the personal identification numbers and specific personal information of business partners, etc. (hereinafter, the personal identification numbers and specific personal information of business partners, etc. will be collectively referred to as "specific personal information of business partners, etc.") in accordance with the "NTT Group Information Security Policy," and in accordance with the following policy.

1. Handling of specific personal information of business partners, etc.

  • Purpose of use of specific personal information of business partners, etc. at our company
    The purposes for which specific personal information of business partners, etc. held by our company will be used are as follows:
    ①Administrative work related to the preparation of payment records for remuneration, fees, contract fees, and prize money
    ②Administrative work related to the preparation of payment records for real estate usage fees, etc.
    ③Administrative work related to the preparation of payment records for the consideration for the acquisition of real estate, etc.
    ④Administrative work related to the preparation of payment records for intermediary fees for the sale and purchase of real estate, etc. or lending When we receive specific personal information of business partners, etc. that has been directly provided in writing by business partners, etc., we will clearly state the purpose of use each time, except in cases falling under any of the items of Article 21, Paragraph 4 of the Act on the Protection of Personal Information (hereinafter referred to as the "Personal Information Protection Act").
    However, this does not apply in cases falling under Article 18, Paragraph 3, Items 1 or 2 of the Personal Information Protection Act as read in accordance with Article 30, Paragraph 3 of the Act on the Use of Numbers to Identify Specific Individuals in Administrative Procedures (hereinafter referred to as the "Number Act").
  • Provision of specific personal information of business partners, etc. to third parties
    We will not provide specific personal information of business partners or other third parties. However, in cases stipulated in each item of Article 19 of the Numbering Act, we may provide necessary specific personal information to related third parties or receive necessary specific personal information from related third parties without obtaining the prior consent of the individual.
  • Regarding the joint use of specific personal information held by us, such as business partners
    We will not share specific personal information of business partners, etc. that we have received from business partners, etc. with any specific parties.
  • Procedures for disclosure of specific personal information of business partners, etc. that we have kept
    We will respond to requests for disclosure of specific personal information of business partners, etc. that we hold.
    • Documents required for requests for disclosure, etc.
      When making a request for disclosure, etc., please download the following request form, attach the necessary documents to the designated request form, and submit it by mail or in person at our office.
      • "Request for disclosure of specific personal information, etc."
        (There will be a separate handling fee of 1,000 yen (including consumption tax). If sending by mail, please send by registered cash mail.)
      • ・“Specific Personal Information, etc. Correction Request Form”
        ・“Specific personal information, etc. suspension of use/deletion request form”
        ・“Request for suspension of provision of specific personal information, etc. to third parties”
        ・Attachment "Official documents that can verify your identity"

      However, this does not apply to requests for disclosure based on other laws and regulations, such as the Companies Act.

    • Billing address
      NTT Urban Development Corporation Information Security Management Office Information System Department
      • *Regarding the handling of specific personal information of business partners, etc. acquired in response to "requests for disclosure, etc."
        The purpose of use of specific personal information of business partners, etc. received in response to a request for disclosure, etc. will be limited to the scope necessary for the request for disclosure, etc.
      • The results of the requested matters will be responded to and notified in a prescribed format in person or by mail to the address designated by the requester (mail that can only be received by the requester). However, if the requester has agreed to a method (the requester has specified that responses and notifications be sent by fax or email), that method will be used. In the case of a face-to-face meeting, responses and notifications will be given verbally instead of in a prescribed format if the requester agrees.
      • The claim procedure can be carried out by a representative, but a power of attorney and a copy of the representative's official certificate are required.
      • We may not comply with all or part of a disclosure request if there is a risk that disclosing the specific personal information of business partners, etc. in question would significantly impede the proper performance of business operations.
  • Inquiries regarding specific personal information of our business partners, etc.
    For inquiries regarding the handling of specific personal information of our business partners, etc., please contact us by letter or email at the address below. Please note that we are unable to accept inquiries in person at our office.
    • NTT Urban Development Corporation Information Security Management Office Information System Department
    • Address:Akihabara UDX, 4-14-1 Sotokanda, Chiyoda-ku, Tokyo 101-0021
    • メール:personal-information@ntt-us.com

2. Compliance with the law

  • When handling specific personal information of business partners, etc., we will comply with the Personal Information Protection Act, the Number Act, and related laws and regulations, as well as the guidelines of the relevant government ministries and agencies and industry guidelines.

3. Safety management measures

  • When handling specific personal information of business partners, etc., we will take appropriate organizational, personal, physical, and technical security control measures.
  • Organizational security control measures
    We have established an organizational management system that includes the establishment of a management system with committees and management officers in each organization, the development of internal regulations, the creation of statements such as management ledgers and process management tables, and continuous improvement.
  • Personnel safety management measures
    We will inform and raise awareness among all employees who handle specific personal information of business partners, etc., regardless of whether they are executives, full-time employees, or temporary staff, of the importance of protecting specific personal information of business partners, etc., and will conclude confidentiality agreements with them and conduct the necessary audits and supervision to ensure their effectiveness.
  • Physical safety control measures
    We will take various measures, such as controlling access to buildings and floors where specific personal information of business partners, etc. is handled, preventing theft, etc., taking measures against damage to specific personal information of business partners, etc. due to fire or lightning strikes, etc., and locking systems and documents when they are taken out, transported, or stored.
  • Technical safety control measures
    We will take technical management measures such as access management including authentication, authority management, control and recording when accessing personal data, countermeasures against malicious software and viruses in the system, measures for transfer and transmission such as encryption and clarification of responsibility, and monitoring of information systems.

4. Continuous improvement of the management system

  • We will review our management system and regulations periodically, continuously, and flexibly, and will constantly improve our management system in a timely and appropriate manner in line with changes in technology and legal systems, and will proactively work to protect specific personal information of business partners, etc.