Topics

EMOROCO CRM Lite

EMOROCO CRM Lite Personal Information Protection Law and ISMS Compliance Guide — Legal Compliance Design for Companies Securing Customer Data

Hello, this is Matsubara, CRM Evangelist.

"We want to implement a CRM system, but we are concerned about compliance with the Personal Information Protection Act."

"Although we have ISMS (Information Security Management System) certification, we have to go through an audit every time we introduce a new tool."

"As a company that has obtained P-mark certification, we have strict rules regarding the handling of customer data."

Since CRM systems handle customer data, compliance with laws and certifications such as the Personal Information Protection Act, ISMS, and P-Mark is a prerequisite for implementation.

This article outlines how EMOROCO CRM Lite can comply with requirements such as the Personal Information Protection Act and ISMS.


The relationship between the Personal Information Protection Act and CRM

The Personal Information Protection Act sets out rules for businesses to acquire, use, store, and provide personal information to third parties. CRM stores customer names, contact information, transaction history, and in some cases sensitive information (medical history, thoughts, etc.), so it is directly subject to the scope of application of the Act.

[Requirements under the Personal Information Protection Act that require particular attention in CRM operations]

① Clearly state the purpose of use
 → What is the purpose of collecting customer data?
   It needs to be made clear.

② Safety management measures
 → To prevent leakage, loss, or damage of personal data
   Organizational, human, physical, and technical measures

③ Restrictions on providing information to third parties
 → Distributing personal data to third parties (external systems, etc.) without consent
   Do not provide

④ Obligation to report leaks, etc.
 → In the event of a personal data breach,
   Reporting to the Personal Information Protection Commission and notifying the individual are required.

EMOROCO CRM Lite provides the technical and operational mechanisms to address these requirements.


EMOROCO CRM Lite's legal compliance features

① Access control through security roles (security management measures)

[What you can do with security roles]

- Set data access permissions by department, job title, and assigned customer.
- General staff can only view and edit information for their own assigned clients.
- Managers can view the entire team (editing is restricted).
- Immediately disable the former employee's account and block data access.

Clearly controlling "who can access which data and to what extent" is at the core of the "human security management measures" required by the Personal Information Protection Act.

② Recording of operation history using audit logs

[Content recorded in the audit log]

- Who viewed, edited, or deleted which record, and when?
• Data export history
Login and logout history

In the event of suspected unauthorized access or data breaches, audit logs serve as evidence to track "when, who, and what happened."
In ISMS and P-Mark internal audits, having evidence of operational history is an important evaluation item.

③ Self-hosting support (complete control over storage locations)

When "physical security measures" are required as part of the security management measures under the Personal Information Protection Act, it becomes crucial to have complete control over the location where data is stored within your company.

EMOROCO CRM Lite supports self-hosting (on-premises or self-managed Azure environment), so it can meet stringent requirements such as the following:

Requirements that can be handled by self-hosting:
We want to store the data on servers that are completely under our own control.
・We do not want to entrust our data to external cloud vendors.
ISMS certification provides an environment that can be fully managed in-house.
 What is needed

For more details, please refer to the " EMOROCO CRM Lite Self-Hosted and Azure Configuration Guide ".

④ Encryption and communication security (technical security management measures)

EMOROCO CRM Lite leverages standard Microsoft Azure security features and supports encryption during data storage and transmission.

Technical protection mechanisms:
• Encryption of communications (HTTPS/TLS)
- Database encryption
- Authentication integration with Azure Active Directory
• Secure management of connection information and API keys using Key Vault

⑤ Data backup and recovery (ensuring availability)

Regular backups are required as a security measure to prevent the loss or damage of personal data.
With the SaaS version, Arcus Japan manages backups as standard, while the self-hosted version allows for operation tailored to your company's backup policy.


Key points regarding CRM in ISMS (ISO27001) audits

This document outlines key points that are often questioned during internal audits and renewal reviews when companies that have obtained and maintain ISMS certification implement CRM.

[Items frequently checked during ISMS audits]

① Management of access rights
 → Security role settings status
   Is the principle of least authority being upheld?

② Recording and storing logs
 → How long are audit logs stored?
   Is there a system in place to verify this?

③ Data storage location
 → Cloud (Azure) or self-hosted?
   Can you clearly explain the storage location?

④ Vendor management
 → With CRM vendor (Arcus Japan)
   Consistency with contract details and contractor management regulations

⑤ Incident Response
 → What is the response flow in the event of a data breach, etc.?
   Is it well maintained?

EMOROCO CRM Lite's security roles, audit logs, and self-hosting capabilities provide concrete evidence to support these review criteria.


For companies that have obtained the P Mark (Privacy Mark)

The P-mark is a certification based on "JIS Q 15001," which is stricter than the Personal Information Protection Act.
When companies with P-mark certification select a CRM system, it is recommended that they pay particular attention to the following points:

[Points that P-mark certified companies should check when implementing CRM]

- The scope of employees who handle personal information
 Can it be clearly restricted (security role)?

• The purpose of acquiring and using personal information is
 Can it be tracked on the system?

- Contract with the outsourcing company (CRM vendor)
 The clauses regarding the handling of personal information
 Is it included?

• Data retention period and deletion rules
 Can it be implemented (deletion of unnecessary personal data)?

EMOROCO CRM Lite also provides a standard function for deleting unnecessary customer data (individual deletion and bulk deletion).


Realistic steps for small and medium-sized enterprises

Even small and medium-sized enterprises (SMEs) that lack a dedicated information security department like large corporations can comply with the Personal Information Protection Act and internal regulations by following these steps.

STEP 1: Designing security roles (during implementation)
 First, decide who has access to which data.

STEP 2: Clearly define the purpose of use (at the time of implementation)
 "What will we use customer data for in this CRM?"
 To be kept as an internal company document.

STEP 3: Regularly check audit logs (after operation begins)
 Make it a habit to check your operation history on a monthly basis.

STEP 4: Review (and implement) access permissions for employees who have left or transferred.
 At the time of retirement or transfer
 We will ensure that access permissions are updated immediately.

STEP 5: Implementation of data deletion rules (continuation)
 Regularly delete unnecessary customer data.
 Set rules

Summary — Ease of use and legal compliance can coexist.

When considering the implementation of a CRM system, "ease of use" and "security and legal compliance" are sometimes treated as conflicting issues.
However, if a CRM comes standard with security roles, audit logs, self-hosting support, and data deletion functionality, then these two features can coexist.

Using CRM to deepen customer relationships and properly protecting that customer data are integrated responsibilities that are presupposed by CRM 4.0.

When considering implementation, first organize your company's security requirements (Personal Information Protection Act, ISMS, P-Mark, etc.) and check which functions of EMOROCO CRM Lite address those requirements.

Click here for a 30-day free trial of EMOROCO CRM Lite.
Please contact us for inquiries regarding security and legal compliance.
Digitalization and AI Implementation Subsidy 2026 Compatible Tool Number: DL07-0022934
Product Info:https://www.emoroco.com/


Related article

Person who wrote this article
Shinsuke Matsubara

Arcus Japan Representative Director / CRM Consultant
Click here for detailed profile
He has worked as a system engineer, architect, and consultant at Accenture and other companies, an evangelist at Infragistics (Microsoft MVP for Dynamics CRM (now Microsoft MVP for Business Solutions)), and a solutions specialist at Microsoft (in charge of Dynamics CRM products).He currently leads a service team specializing in CRM, supporting CRM implementation and business launches for companies of all sizes.At the same time, he works as a CRM evangelist, spreading the idea of "true" CRM through events and article contributions.
Having learned CRM at Accenture, and having advocated and globally popularized CRM 2.0 (platform-based CRM) at Microsoft, he is a legitimate successor to CRM and the longest-serving active CRM expert (CRM consultant/CRM doctor), having received an award at Worldwide.
Since then, as a leading expert in CRM who advocates CRM 3.0 (Personalized CRM) and CRM 4.0 (Creative CRM), he has been interviewed and received numerous awards both domestically and internationally from publications such as The Wall Street Journal, Newsweek, TIME, WORLDCOM, Mainichi Shimbun (Weekly Economist), and Nippon Cultural Broadcasting. He has also been selected as a representative company of the Kansai business community by "Keizaikai" for four consecutive years.
book:Versatylist - How to become a "1 in 1" talent by age 35

Interview article
For requests for interviews, lectures, etc., please contact us using the contact information below.
TEL +06-6195-7501-XNUMX
Inquiry via form

Articles in the same category