- #Security measures
- #securitygovernance
- #InformationSecurity
- #DX
- #EMOROCO CRM Lite
- #CreativeCRM
- #Arcus Japan
- #CRM4.0
- #Corporate Psychology
- #Corporate Psychology
- #CRMDoctor
- #CRM・xRM
- #EMOROCO
- #Artificial Intelligence/Machine Learning (AI/ML)
- #Customer/Sales Strategy (SFA)
- #Customer Service Call Center (CS)
- #Marketing Automation (MA)
- #CustomerExperience
- #HAVE
- #Field Service (FS)
- #CRM
EMOROCO CRM Lite Personal Information Protection Law and ISMS Compliance Guide — Legal Compliance Design for Companies Securing Customer Data
Hello, this is Matsubara, CRM Evangelist.
"We want to implement a CRM system, but we are concerned about compliance with the Personal Information Protection Act."
"Although we have ISMS (Information Security Management System) certification, we have to go through an audit every time we introduce a new tool."
"As a company that has obtained P-mark certification, we have strict rules regarding the handling of customer data."
Since CRM systems handle customer data, compliance with laws and certifications such as the Personal Information Protection Act, ISMS, and P-Mark is a prerequisite for implementation.
This article outlines how EMOROCO CRM Lite can comply with requirements such as the Personal Information Protection Act and ISMS.
The relationship between the Personal Information Protection Act and CRM
The Personal Information Protection Act sets out rules for businesses to acquire, use, store, and provide personal information to third parties. CRM stores customer names, contact information, transaction history, and in some cases sensitive information (medical history, thoughts, etc.), so it is directly subject to the scope of application of the Act.
① Clearly state the purpose of use
→ What is the purpose of collecting customer data?
It needs to be made clear.
② Safety management measures
→ To prevent leakage, loss, or damage of personal data
Organizational, human, physical, and technical measures
③ Restrictions on providing information to third parties
→ Distributing personal data to third parties (external systems, etc.) without consent
Do not provide
④ Obligation to report leaks, etc.
→ In the event of a personal data breach,
Reporting to the Personal Information Protection Commission and notifying the individual are required.
EMOROCO CRM Lite provides the technical and operational mechanisms to address these requirements.
EMOROCO CRM Lite's legal compliance features
① Access control through security roles (security management measures)
- Set data access permissions by department, job title, and assigned customer.
- General staff can only view and edit information for their own assigned clients.
- Managers can view the entire team (editing is restricted).
- Immediately disable the former employee's account and block data access.
Clearly controlling "who can access which data and to what extent" is at the core of the "human security management measures" required by the Personal Information Protection Act.
② Recording of operation history using audit logs
- Who viewed, edited, or deleted which record, and when?
• Data export history
Login and logout history
In the event of suspected unauthorized access or data breaches, audit logs serve as evidence to track "when, who, and what happened."
In ISMS and P-Mark internal audits, having evidence of operational history is an important evaluation item.
③ Self-hosting support (complete control over storage locations)
When "physical security measures" are required as part of the security management measures under the Personal Information Protection Act, it becomes crucial to have complete control over the location where data is stored within your company.
EMOROCO CRM Lite supports self-hosting (on-premises or self-managed Azure environment), so it can meet stringent requirements such as the following:
We want to store the data on servers that are completely under our own control.
・We do not want to entrust our data to external cloud vendors.
ISMS certification provides an environment that can be fully managed in-house.
What is needed
For more details, please refer to the " EMOROCO CRM Lite Self-Hosted and Azure Configuration Guide ".
④ Encryption and communication security (technical security management measures)
EMOROCO CRM Lite leverages standard Microsoft Azure security features and supports encryption during data storage and transmission.
• Encryption of communications (HTTPS/TLS)
- Database encryption
- Authentication integration with Azure Active Directory
• Secure management of connection information and API keys using Key Vault
⑤ Data backup and recovery (ensuring availability)
Regular backups are required as a security measure to prevent the loss or damage of personal data.
With the SaaS version, Arcus Japan manages backups as standard, while the self-hosted version allows for operation tailored to your company's backup policy.
Key points regarding CRM in ISMS (ISO27001) audits
This document outlines key points that are often questioned during internal audits and renewal reviews when companies that have obtained and maintain ISMS certification implement CRM.
① Management of access rights
→ Security role settings status
Is the principle of least authority being upheld?
② Recording and storing logs
→ How long are audit logs stored?
Is there a system in place to verify this?
③ Data storage location
→ Cloud (Azure) or self-hosted?
Can you clearly explain the storage location?
④ Vendor management
→ With CRM vendor (Arcus Japan)
Consistency with contract details and contractor management regulations
⑤ Incident Response
→ What is the response flow in the event of a data breach, etc.?
Is it well maintained?
EMOROCO CRM Lite's security roles, audit logs, and self-hosting capabilities provide concrete evidence to support these review criteria.
For companies that have obtained the P Mark (Privacy Mark)
The P-mark is a certification based on "JIS Q 15001," which is stricter than the Personal Information Protection Act.
When companies with P-mark certification select a CRM system, it is recommended that they pay particular attention to the following points:
- The scope of employees who handle personal information
Can it be clearly restricted (security role)?
• The purpose of acquiring and using personal information is
Can it be tracked on the system?
- Contract with the outsourcing company (CRM vendor)
The clauses regarding the handling of personal information
Is it included?
• Data retention period and deletion rules
Can it be implemented (deletion of unnecessary personal data)?
EMOROCO CRM Lite also provides a standard function for deleting unnecessary customer data (individual deletion and bulk deletion).
Realistic steps for small and medium-sized enterprises
Even small and medium-sized enterprises (SMEs) that lack a dedicated information security department like large corporations can comply with the Personal Information Protection Act and internal regulations by following these steps.
First, decide who has access to which data.
STEP 2: Clearly define the purpose of use (at the time of implementation)
"What will we use customer data for in this CRM?"
To be kept as an internal company document.
STEP 3: Regularly check audit logs (after operation begins)
Make it a habit to check your operation history on a monthly basis.
STEP 4: Review (and implement) access permissions for employees who have left or transferred.
At the time of retirement or transfer
We will ensure that access permissions are updated immediately.
STEP 5: Implementation of data deletion rules (continuation)
Regularly delete unnecessary customer data.
Set rules
Summary — Ease of use and legal compliance can coexist.
When considering the implementation of a CRM system, "ease of use" and "security and legal compliance" are sometimes treated as conflicting issues.
However, if a CRM comes standard with security roles, audit logs, self-hosting support, and data deletion functionality, then these two features can coexist.
Using CRM to deepen customer relationships and properly protecting that customer data are integrated responsibilities that are presupposed by CRM 4.0.
When considering implementation, first organize your company's security requirements (Personal Information Protection Act, ISMS, P-Mark, etc.) and check which functions of EMOROCO CRM Lite address those requirements.
Click here for a 30-day free trial of EMOROCO CRM Lite.
Please contact us for inquiries regarding security and legal compliance.
Digitalization and AI Implementation Subsidy 2026 Compatible Tool Number: DL07-0022934
Product Info:https://www.emoroco.com/
Related article
- EMOROCO CRM Lite Self-Hosted and Azure Configuration Guide: On-Premise Design for Companies That Don't Want to Take Data Outside the Company
- Multi-Tenant Design Guide: How to Deploy EMOROCO CRM Lite to Group Companies, Agencies, and Franchises
- An honest guide to what EMOROCO CRM Lite can and cannot do.
- Systematize agency management with EMOROCO CRM Lite
- EMOROCO CRM Lite Multilingual Support and Global Expansion Guide
Related articles and pages
Person who wrote this article
Articles in the same category
-
Why you should invest in CRM now [Series 3] Why "any CRM will do" […] -
Why you should invest in CRM now [Series 2] Another invisible crisis […] -
Why you should invest in CRM now [Series 1] What companies that survive recessions do […] -
Risks of managing customer information in Excel — Losing a computer can lead to other problems […] -
Japanese companies' customer information is being targeted from all over the world — now, CRM is being used to […] -
Mutual Aid and Welfare System Utilization Guide — EMOROCO CRM[…]



