Handling of Personal Information
(March 2023 version)

This booklet describes the practices of The Tokyo Star Bank, Limited (the “Bank” or “us” or “we” or “our”) regarding the handling of our customers’ (or “you” or “your”) personal information based on the Act on the Protection of Personal Information (the “Personal Information Protection Act”) and the Act on the Use of Numbers to Identify a Specific Individual in Administrative Procedures (the “My Number Act”). This information is also available on our website (https://www.tokyostarbank.co.jp).
Under this booklet, the term “personal information” means information regarding a living person and includes names, birthdates, and other information (including any information that is presented or recorded in documents, diagrams, or electronic devices, or expressed through speech, movement, or other method) that enables the identification of a specific individual as well as individual identification codes as provided under the Personal Information Protection Act.

1. Privacy Statement

In order to ensure the strict handling of personal information (including the Individual Numbers and personal information containing such Individual Numbers, collectively referred to as “Specific Personal Information”) received from our customers from the standpoint of protecting personal information, we have established the following policy regarding the protection of personal information, familiarized all of our officers and employees with the contents of this policy, and shall endeavor to properly protect personal information pursuant to this policy.

(1) Purposes of Use of Personal Information

The Bank shall obtain and use necessary personal information of our customers to conduct accurate transactions with you and to inform you about improved products and services. The Bank handles Individual Numbers solely within the scope stipulated by applicable law.

(2) Restrictions Based on Purposes of Use

The Bank shall not use personal information received from our customers beyond the scope necessary to achieve the purposes of use described above. Furthermore, the Bank shall clearly express the purposes of use of our customers’ personal information. For example, with regard to customers’ responses to survey questions, the Bank shall indicate that they would be used for data collection. In this manner, the Bank shall make efforts to limit the use of customers’ personal information for the specific purpose for which it was obtained.

(3) Types of Information Collected

The information that the Bank receives from our customers includes names, addresses, telephone numbers and email addresses, as well as (i) identification numbers that are assigned to applicable individuals under certain documents or for the use of certain services, such as Individual Numbers and license numbers, and (ii) parts of an individual’s physical features such as DNA, fingerprints, and voiceprints that have been digitized for use on electronic devices, either of which may be used to identify an individual (collectively, “Individual Identification Codes”). The Bank may retain records related to customer transactions and inquiries in the form of writing, or voice, video or electronic recording.

(4) Prohibition of Improper Use

The Bank shall not use customers’ personal information in a manner not recognized as appropriate according to social norms or that violate the intent of applicable laws and regulations or social standards.

(5) Proper Acquisition

The Bank shall obtain our customers’ personal information in a proper and lawful manner and to the extent necessary to perform our services, in which case the Bank shall specify and accurately inform our customers of the purposes of use of such personal information, and shall not obtain such personal information through deception or other wrongful means. Furthermore, the Bank shall obtain Individual Numbers solely within the scope stipulated by applicable law. Regarding our customers who apply for loans, please note that the Bank may contact the personal credit information agencies to obtain relevant information thereof.

(6) Assurance of Accuracy of Personal Information and Proper Deletion Thereof

The Bank shall endeavor to keep the details of personal information accurate and up-to-date to the extent necessary for achieving the purposes of use, and requests your cooperation in this regard. If there have been any changes to your personal information requiring notice to the Bank, please submit a written notice to our branches. When personal data related to our customers’ personal information are no longer needed for use, or are retained beyond a certain period of time under applicable law, the Bank shall make efforts to delete such data without delay. When deleting personal data or discarding any device, electronic media, or the like that contains personal data, such shall be done in an unrecoverable manner. Moreover, a record of the deletion or disposal shall be retained.

(7) Security Measures for Protection of Personal Data

The Bank shall take necessary and appropriate measures (including “organizational security management measures”, “personal security management measures”, “physical security management measures”, “technical security management measures”, and “ascertainment of the external environment”) in order to prevent any illegal access to, or leakage, loss, damage, or falsification of, personal information received from our customers and to otherwise protect personal data, such as by establishing the basic policies/operating standards related to security management as well as the structure related to the execution of security management measures.

(8) Supervision of Officers and Employees

With respect to all of our officers and employees who handle our customers’ personal information, the Bank shall establish a proper internal control structure that ensures the security of personal data, clarifies roles and responsibilities thereunder, disseminates information regarding security obligations, and provides necessary education/training and appropriate supervision.

(9) Supervision over Service Providers

The Bank shall rigorously manage our service providers, who we engage to handle our customers’ personal information, such as by entering into an agreement therewith regarding the protection of personal information and/or by supervising such service providers as needed or appropriate, in order to ensure the security of such personal information. Even in cases where such service providers outsource their services to a subcontractor, the Bank shall have such service providers rigorously manage such subcontractor in the handling of personal information in the same manner as when the Bank outsources our services to such service providers.

(10) Establishment and Ongoing Improvement of Compliance Programs

In order to make all of our officers and employees aware of the importance of protecting personal information and to ensure the proper protection and use of personal information, the Bank shall establish, implement, and make ongoing improvements to the compliance programs related to the protection of personal information in conformance with the Personal Information Protection Act, the My Number Act, and other applicable law regarding the protection of personal information.

(11) Restrictions on Provision to Third Parties

The Bank shall not, without your consent, provide your personal information to any third party other than as set forth in the Personal Information Protection Act. If the customer is a minor, adult ward, conservatee, or person subject to limited guardianship, who does not have the ability to determine the consequences of consenting to certain handling of personal information, the Bank shall obtain consent from such customer’s guardian, legal representative, or the like; provided, however, that the Bank may provide your personal information to a third party without your consent in the following cases: consent is required to protect your life, body, or property and obtaining your consent is determined to be difficult; the handling of personal information is outsourced to the extent necessary to achieve the purposes of use; or in the case of business succession or joint use of such personal information with a separately specified person. Specific Personal Information shall not be provided to any third party notwithstanding the customer’s consent/refusal unless as otherwise provided in the My Number Act.

(12) Notice and Public Announcement of the Purposes of Use

The Bank shall publicly announce in advance the purposes of use of personal information received from our customers. If we subsequently change such purposes of use, we will promptly provide notice or publicly announce the amended purposes of use.

(13) Request for Disclosure or the Like of Personal Information

If you request for notice regarding the purposes of use, or for disclosure, correction, addition, omission, suspension of use or deletion, or for suspension of provision to third parties, of retained personal data related to your personal information or of information related to records of provision to third parties, the Bank shall, after asking about the circumstances of such request, notify you of the required procedures. Upon completion of such procedures, the Bank shall promptly provide notice regarding the purposes of use, disclose, correct, add, omit, suspend the use or delete, or suspend the provision to third parties, of such retained personal data (the “Requested Act”); provided, however, that the Bank may not be able to perform the Requested Act based on the Personal Information Protection Act or other reason. If it is deemed that it would be difficult to perform the Requested Act in whole or in part, or to implement a disclosure via methods requested by you, the Bank shall promptly notify you of such. If a Request for Action is made with respect to the Individual Number, the Bank’s reply shall be limited to whether or not such information is in our possession.

(14) Complying with Personal Information Related Laws

The Bank shall comply with the applicable laws, guidelines, and the like related to the Protection of Personal Information Act, My Number Act, and other personal information protections in relation to the personal information you provide to us.

(15) Use of Bank’s Internet Services

The Bank may use cookie technology to improve our customer service; provided, however, that the Bank shall not retain any privacy related information of our customers such as their names or contact details. A cookie is technology that enables a web server to identify the user from his/her prior visit by storing a certain file in the user’s personal computer (terminal) when the use accesses a website on the web server. The Bank’s cookies are readable only by our website, and do not contain any information through which a third party can contact the user by his/her telephone number, email, postal address, or the like. A user can delete the cookies stored in his/her computer and avoid storing cookies by changing the browser settings thereof.

(16) Inquiries Related to Personal Information

If you have any questions, comments, or requests concerning the Bank’s handling of personal information, please contact us at the call center or our branches, who will respond to you in a prompt and proper manner.

Contact: Branch
Call Center (Privacy Statement Inquiry Desk)
TEL:050-3152-0743
Service Hours: 9 a.m. to 5 p.m. on weekdays

(17) Point of Contact for Complaints

The Bank has a point of contact for receiving complaints concerning the Bank’s handling of personal information.

Contact: Customer Relations Office (our dedicated help desk for inquiries regarding the handling of personal information)
TEL:03-6230-9048
Service Hours: 9 a.m. to 5 p.m. on weekdays

(18) Accredited Personal Information Protection Organizations of which the Bank is a Member

The Bank is a member of the following personal information protection organizations that were accredited under the Personal Information Protection Act.
The following organizations manage complaints and provide consultation services concerning their member entity’s handling of personal information.

(19) Management of Personal Information Leakage Incidents

If there is a personal information leakage incident or the like, the Bank shall immediately report to the relevant competent authority. Furthermore, in order to prevent the occurrence of any secondary damage or similar incident, the Bank shall promptly notify our customers involved in such incident regarding the relevant facts, recurrence prevention measures, and the like.

2. Purposes of Use of Personal Information

Pursuant to the Personal Information Protection Act and the My Number Act, the Bank shall use your personal information in providing the services under item (1) below to the extent necessary to achieve the purposes of use listed in item (3) below.

(1) The Bank’s Services

The Bank is licensed to provide banking services under the Banking Act. The banking services include the following:

  1. aAcceptance of deposits, domestic exchange, money exchange, provision of loans, foreign exchange, and services incidental thereto;
  2. bOver-the-counter sales of public bonds, mutual fund sales, insurance sales, brokerage services involving financial instruments, trust services, corporate bond services, and other services that banks are permitted to provide under applicable law, and services incidental thereto;
  3. cOther services that banks are permitted to provide, and services incidental thereto
    (including services of which the banks would be allowed to provide in the future).

(2) Personal Information Obtained by the Bank

The Bank shall obtain our customers’ personal information in a proper and lawful manner to the extent necessary to provide our services. The personal information that may be obtained includes the items listed below. In order to ensure the proper operation of our businesses in the financial sector, the Bank may, with the customer’s consent, obtain sensitive information as set forth in the Guidelines Regarding the Protection of Personal Information in the Financial Sector (issued by the Personal Information Protection Commission and the FSA) (which means “special care-required personal information” as set forth under the Personal Information Protection Act and information related to one’s membership in a labor union, lineage, domicile, healthcare, and sexual activity (but excludes special care-required information for these items); provided, however, that “sensitive information” excludes information that has been disclosed to the public by the person in question, a national or local authority, media organizations such as broadcasting organizations, newspapers, or news agencies (including foreign media organizations), foreign governments, government agencies, local government, or international organizations, or information that is externally apparent and can be obtained through looking at/filming the person in question) to the extent necessary to perform our services; provided, however, that the Bank shall not obtain, use, or provide to third parties such information unless required under applicable law. Notwithstanding the customer’s consent/refusal, the handling of Individual Numbers shall be limited to the scope as set forth under applicable law.

  1. aYou and your family members’ personal information provided by you (or your agent) through submission of various application forms, contract documents, supplementary documents, and the like (including documents submitted post-contract execution such as the “Notice of Change” form) or other methods (including requests made via electronic means or telephone or in person). The above also includes personal information received through loan consultations, requests for materials, surveys, or the like;
  2. bPersonal information retained by the Bank related to all of your transactions with the Bank including past and future transactions;
  3. cPersonal information received in a proper and lawful manner from the Bank’s partner companies or the like;
  4. dPersonal information contained in an official gazette, telephone directory, certificate of company registration, residential map, or the like, which is published or sold;
  5. eA copy of the customer’s certificate of residence (“jyuminhyou”) (including a document containing records of previous addresses (“koseki no fuhyou”)) requested and obtained by the Bank from the relevant local authority as required in providing our services;
  6. fIndividual Numbers for the preparation of statutory documents or the like;
  7. gPersonal information provided by a joint user such as the local electronic clearing house or a third party such as the personal credit information agency;
  8. hContents of telephone calls or dialogue related to meetings with customers (recordings may be made to improve the quality of the response and to confirm the content); and
  9. iImages recorded on surveillance cameras that enable identification of the person in question.
Scope of Sensitive Information
  • Race
  • Criminal record
  • Creed
  • Healthcare
    • Medical history
    • Physical, intellectual, or mental disability, or the like
    • Results of medical examination or the like
    • Medical guidance, treatment, or prescription by a physician or the like
    • Other matters (e.g., use of over-the-counter medication based on self-diagnosis rather than physician’s diagnosis)
  • Social status
  • The fact of having suffered damage or harm due to a crime
  • Criminal proceedings
  • Juvenile proceedings
  • Membership in a labor union
  • Lineage
  • Domicile
  • Sexual activity

(3) Purposes of Use of Personal Information

The Bank shall use personal information for the following purposes to the extent permitted by applicable law:

  1. aTo accept applications for financial instruments and services (e.g., applications for account openings related to various financial instruments);
  2. bTo conduct solicitation, sales, and marketing activities related to securities, financial instruments, and services under the Financial Instruments and Exchange Act;
  3. cTo verify identities based on applicable law and confirm eligibility for using financial instruments and services;
  4. dTo manage on-going transactions (e.g., managing maturity for deposit and loan transactions);
  5. eTo make decisions on loan applications and on-going loan facilities;
  6. fTo determine the appropriateness of providing financial instruments and services (e.g.,decisions based on the principle of suitability);
  7. gTo provide third parties with personal information to the extent required to properly perform our services (e.g., providing such information to the personal credit information agencies of which the Bank is a member in connection with our credit business);
  8. hWhen the Bank is engaged by other business operators to process all or part of the personal information, to properly perform such service;
  9. iTo exercise the rights and perform the obligations under contracts entered into with customers or applicable law;
  10. jTo conduct research and development of financial instruments and services through market research, data analyses, surveys, and the like;
  11. kTo inform our customers of financial instruments and services by sending direct mail or other means;
  12. lTo inform our customers of products and services of our partner companies or the like (including reports on the results of transactions, deposit balances, and the like);
  13. mTo cancel various transactions and manage matters after cancellation of such transactions;
  14. nTo perform services for which the Bank was engaged by densai.net Co., Ltd.
  15. oTo ensure the smooth distribution of electronically recorded monetary claims (“denshi kiroku saiken”);
  16. pTo have participating financial institutions make credit decisions (The term “participating financial institutions” means financial institutions are part of the “Densai” network due to entering into a services agreement with Densai Net);
  17. qTo otherwise perform customer transactions in a proper and smooth manner; and
  18. rNotwithstanding the purposes of use of personal information described above, the Bank shall use Individual Numbers only for the following purposes:
    1. aTo process applications and notifications for account openings related to financial instrument transactions;
    2. bTo prepare statutory documents pertaining to financial instrument transactions;
    3. cTo prepare statutory documents pertaining to overseas transfers or the like;
    4. dTo perform procedures related to the application of the tax-free savings scheme or the like;
    5. eTo prepare tax reporting documents or the like pertaining to non-taxable, asset-building savings (such as for home loans/pension) (“zaikei”);
    6. fTo prepare statutory documents upon transfer of a negotiable certificate of deposit; and
    7. gTo perform procedures related to the assignment of numbers to savings accounts.
  • *In accordance with the Ordinance for Enforcement of the Banking Act and other applicable law, the Bank will never use or provide to any third party any information provided by the personal credit information agencies concerning the abilities of persons seeking funds to repay their borrowings for any other than investigating the solvency of such persons.
  • *In accordance with the Ordinance for Enforcement of the Banking Act and other applicable law, the Bank will never use or provide to any third party any information regarding race, criminal record, religion, healthcare, lineage, or domicile or other special non-public information for any purpose other than to ensure proper business or for other purposes recognized as necessary.
  • *The Bank will not abuse its superior bargaining position to condition the provision of credit on the customer’s consent to the Bank’s use of such customer’s personal information other than for the Bank’s credit business for which such information was obtained. Thus, the customer may reject the Bank’s request to use his/her personal information other than for such business.

3. Use of and Information Registration with Personal Credit Information Agencies (Not Applicable to Specific Personal Information)

  1. (1)In accordance with the Personal Information Protection Act, the Bank obtains your consent (through loan applications, contracts, and the like) regarding the use of and information registration with personal credit information agencies in relation to your personal information as described below.
  1. aIf a customers’ personal information is registered with a personal credit information agency of which the Bank is a member or with a personal credit information agency that partners with such agency (such personal information to include contract details,
    repayment status, and the like registered by members of such agencies, information regarding dishonored bills/checks registered by such agencies, and information regarding bankruptcy or the like contained in the official gazette), the Bank shall use such information to assist in our investigation regarding the customer’s solvency or new address (“Credit Transaction Related Decision-Making”); provided, however that,
    pursuant to Article 13-6-6 of the Enforcement Regulations of the Banking Act,
    information regarding the customer’s solvency may be used only for the purpose of investigating the customer’s solvency (hereinafter, the same shall apply).
  2. bThe following personal information (including its history) shall be registered with the personal credit information agencies of which the Bank is a member, and such information shall be used by members of such agencies as well as of their partner credit information agencies to assist in their Credit Transaction Related Decision-Making.
Registered Information Registration Period
Personal information such as name, birthdate, gender, address (including whether mail reaches the person in question), telephone number and work address The period of time in which any of the following information remains registered
Contract details such as the borrowing amount, the borrowing date, and the final repayment date, and the repayment status (including facts about delinquency, subrogation (“daii-bensai”), compulsory collection procedures, debt assignment, cancellation, full repayment, and the like) During the contract term and for a period not exceeding five years from the date of contract termination (if repayment is not made in full by that date, from the date of completion of repayment)
The date on which we made use of the personal credit information agency of which we are a member, and the details of the relevant contract or application related thereto A period not exceeding one year from date of such use
Information published in official gazettes A period not exceeding 7years from the date of ruling for the commencement of bankruptcy proceedings or the like
The fact that a complaint has been made regarding the registered information and investigation is being conducted in relation thereto During the period in which such investigation is conducted
Information reported by the person in question such as regarding lost/stolen identification documents A period not exceeding five years from the date on which such information was reported
  1. (2)In accordance with the Personal Information Protection Act, we jointly use our personal data as follows with personal credit information agencies of which we are a member; provided,however, that with respect to contracts entered into after the Personal Information Protection Act was fully implemented (on April 1, 2005), we make sure to obtain the customer’s consent regarding the matters described in Section (1) above.
  1. aPersonal data items for joint use:

    Information posted in official gazettes (e.g., names, addresses, facts regarding bankruptcy including the bankruptcy date)

  2. bScope of joint users:

    Members of the Personal Credit Information Center of the Japanese Bankers Association (“JBA”), and the JBA

    • Note: The Personal Credit Information Center of the JBA is a personal credit information agency established and operated by the JBA. The following entities are eligible for membership:
    1. aOfficial members of the JBA;
    2. bBanks other than those who fall under item (a) above or financial institutions that are regarded as banks under applicable law;
    3. cGovernment-related financial institutions or their equivalent;
    4. dCredit guarantee associations established under the Credit Guarantee Association Act(Act No. 196 enacted on August 10, 1953); and
    5. eEntities engaging in the retail credit business that have been recommended by any member who falls under items (a) through (c) above.
  3. cPurposes of use:

    For members of the Personal Credit Information Center of JBA to make Credit Transaction Related Decision-Making

  4. dName of the person responsible for managing personal data:
    Japanese Bankers Association (in Japanese),
    1-3-1 Marunouchi, Chiyoda-ku, Tokyo
    The representative of the above is recorded on the following website: “4. Privacy Policy” - “(1 Joint Use of Official Gazette Information” - “D. Name of the person responsible for managing personal data”.
  1. (3)In addition to the above, the above personal information may be mutually provided to or used by the personal credit information agencies of which the Bank is a member, as well as members of personal credit information agencies who are partners of personal credit information agencies of which the Bank is a member, to the extent required to ensure the protection and appropriate use of information such as by (i) keeping such information accurate and up-to-date, (ii) addressing complaints, and (iii) enabling the personal credit information agencies to monitor their members regarding compliance with applicable rules.
  1. (4)The Bank is a member of the following personal credit information agencies. The criteria for becoming a member, names of the members, and the like are posted on their respective websites. Please note that disclosures of information registered with the personal credit information agencies are made by the respective agencies (and not by the Bank).
    1. aThe personal credit information agencies of which the Bank is a member:
    Personal Credit Information Center of JBA (in Japanese)
    TEL 03-3214-5020
    Information: This is a personal credit information agency whose members are mainly financial institutions and their affiliates.
    Japan Credit Information Reference Center Corp. (JICC) (in Japanese)
    TEL 0570-055-955
    Information: This is a personal credit information agency whose members are mainly companies that engage in the credit business (including money-lending, credit sales, leasing, guarantees, and financial institution’s business).
    1. bPersonal credit information agencies that partner with the agency:

      The Personal Credit Information Center, JICC, and the Credit Information Center (CIC) are mutual partners.

    Credit Information Center (CIC)
    TEL 0120-810-414
    Information: This is a personal credit information agency whose members are mainly companies that engage in the credit business which includes installment sales or the like.

4. Providing Personal Data to Third Parties

The Bank will provide personal data related to your personal information to third parties in the following cases. Moreover, excluding where stipulated by the Protection of Personal Information Act, your consent will be obtained in advance.

  1. 1If the provision to third parties of personal data obtained by the Bank is reasonably expected in order to complete a transaction, such as in the following cases:
    1. aThe provision of information regarding the results of account transfer services to billing organizations;
    2. bThe provision of sender information to the transfer recipient;
    3. cThe provision of information regarding account balances to partner companies who provide asset-building savings (zaikei) related services;
    4. dThe provision of information on the insurance application or the like to insurers (life insurance/non-life insurance companies) in connection with loan transactions;
    5. eIn relation to loan transactions, the provision of information to a credit guarantee company, credit card company, or consumer finance company, of whom the primary obligor has designated to be his/her guarantor;
    6. fThe provision of information to a credit guarantee association in loan transactions;
    7. gThe provision of information to outside real estate appraisers for appraisal of collateral in loan transactions;
    8. hThe provision of information regarding the primary obligor’s outstanding loan balance and the like to a joint and several guarantor in loan transactions;
    9. iThe provision of information to real estate companies and other companies who act as partners in certain types of loans (“teikei” loans) such as home loans for the former and business loans for the latter;
    10. jThe provision of information to the national and local governmental authorities in relation to subsidized loans or the like; and
    11. kThe provision of information to a third party to the extent required in cases where the delivery of a product/service is premised on the provision of personal data to such third party as a matter of course.
  2. 2In cases where under loans or the like are transferred to other business operators or the like in the form of an assignment or securitization, the personal data of primary obligor and joint and several guarantor are to be provided, to the extent necessary for such debt assignment or securitization, to an assignee or special purpose company or the like established for the purpose of such debt assignment or securitization, in order to facilitate the management, collection, and the like of such debts;
  3. 3When information is to be provided to counterparties, rating agencies, accounting firms, and/or the like during preliminary consultation or due diligence related to a debt assignment or the like to the extent necessary for such person or persons to perform their tasks (including cases in which the debt assignment is ultimately not executed);
  4. 4When information on the application for purchase, termination, or the like of mutual funds, insurance, bonds, stocks, or other financial instruments is to be provided to providers of such financial instruments in order to deliver such financial instruments to our customers in an accurate manner;
  5. 5With respect to Specific Personal Information, when provision to third parties is stipulated under applicable law; and
  6. When such provision is otherwise determined to be necessary in light of the Personal Information Protection Act or other applicable law (including submission of materials or the like to competent authorities, the Securities and Exchange Surveillance Commission, and stock exchanges).
  • Note regarding the provision of information related to the necessary measures when providing personal data to third parties in foreign countries:
    The Bank may provide personal data to third parties in foreign countries (where such is limited to entities that have established the structures required to continually enact the appropriate measures stipulated by the Protection of Personal Information Act) pursuant to the provisions of the Protection of Personal Information Act. The Bank, in addition to enacting measures required to secure ongoing implementation of the appropriate measures by the third party, shall provide information regarding the relevant required measures at your request, pursuant to the Enforcement Regulations for the Protection of Personal Information Act.

5. Outsourcing of Handling of Personal Data

The Bank may outsource the handling of personal data related to our customers’ personal information to the extent necessary for the achievement of the purposes of use thereof, such as in the following cases. The Bank shall, as needed, properly supervise the service providers that we engage to perform such services.

  1. 1Services related to the printing/sending of bank statements;
  2. 2Services related to external transactions such as foreign exchange transactions;
  3. 3Services related to printing/sending of direct mail;
  4. 4Services related to the operation and maintenance of information systems;
  5. 5Services related to the appraisal of real estate collateral;
  6. 6Services related to obtaining Individual Numbers; and
  7. 7Storage/disposal of ledgers related to our business.

6. Joint Use of Personal Data (Excluding Specific Personal Information)

The Bank shall jointly use the personal data related to our customers’ personal information with the following parties:

(1) Personal credit information agencies:

As noted in Paragraph (4) of Section 3 (Use of and Information Registration with Personal Credit Information Agencies (Not Applicable to Specific Personal Information))

(2) The Bank’s group companies

  1. aPersonal data items subject to joint use:

    Personal data related to personal information as set forth in Paragraph (2) of Section 2 (Purposes of Use of Personal Information)

  2. bScope of joint users:

    The Bank, and Tokyo Star Business Finance, Ltd. (“TSBF”)

  3. cPurposes of use:

    For our group companies’ integrated sales and solicitation efforts (including marketing andproduct development) related to financial instruments and services, and for integrated riskmanagement with respect to our group

  4. dName of the person responsible for managing personal data:

    The Tokyo Star Bank, Limited; Head Office: 2-3-5 Akasaka, Minato-ku, Tokyo
    Representative Executive Officer and President (CEO)


    Bank's website with company information (in Japanese)

(3) Electronic clearing houses or the like

If bills/checks become dishonored, the bearers and their banks or the like will suffer considerable damage. Therefore, the Bank takes actions such as refraining from transactions for a certain period of time if there is an order for suspension of business due to the dishonored bills/checks. Such being the case, the personal data of (i) customers who are the drawers or the underwriters of the dishonored bills/checks and (ii) customers who have consulted with the Bank regarding the opening of a checking account will be provided to the electronic clearing houses or the like and will be used jointly as follows:

  1. aPersonal data items subject to joint use:

    Information regarding dishonored bills/checks, which means information related to the drawers of dishonored bills/checks (or for bills of exchange, the underwriters; the same shall apply hereinafter) or persons requesting to open a checking account, as follows:

    1. aThe name of the drawer (or, if the entity is a company, its name and the name and title of its representative);
    2. bThe trade name (“yago”) of the drawer, if any;
    3. cThe address (or if the entity is a company, its location) (including postal code);
    4. dThe name of the person requesting the opening of a checking account (or, if the entity is a company, its name, the name and title of its representative, and its trade name, if any);
    5. eThe birthdate;
    6. fOccupation;
    7. gThe amount of capital (only if the entity is a company);
    8. hThe type and amount of the relevant bill/check;
    9. iWhether the drawer has ever had a bill/check dishonored (the first such event) or whether a notice of (or order for) suspension of business has ever been issued;
    10. jThe exchange date (or presentation date);
    11. kThe paying bank, including the name of its division/branch;
    12. lThe intermediary bank, including the name of its division/branch;
    13. mThe reason the bill/check was dishonored; and
    14. nThe date on which the drawer became subject to an order for suspension of business.
    • (Note: If there is any discrepancy between the information under items (a) through (c) above that are indicated on a dishonored bill/check and the information notified to the paying bank, the information presented on such bill/check shall be included.)
  2. bScope of joint users:
    1. aThe local electronic clearing houses;
    2. bFinancial institution participants to the local electronic clearing houses (in Japanese);
    3. cThe Personal Credit Information Center established and operated by the JBA; and
    4. dThe local bankers’ associations (including their centers that provide information regarding those who became subject to an order for suspension of business) who are special members of the JBA.
  3. cPurposes of use:

    To ensure the smooth distribution of bills/checks, and to assist in the financial institutions’ Credit Transaction Related Decision-Making

  4. dName of the person responsible for managing personal data:

    Japanese Bankers Association
    1-3-1 Marunouchi, Chiyoda-ku, Tokyo 100-8126
    Representative Name (in Japanese)

6-2. Joint Use of Personal Data (Excluding Specific Personal Information) (Added July 31, 2018)

The Bank jointly uses personal data in order to strengthen the coordination between our group entities and to manage operations and risks on a group-wide basis as follows.

  1. aPersonal data items subject to joint use:

    Personal data related to personal information as set forth in Paragraph (2) of Section 2 (Purposes of Use of Personal Information)

  2. bScope of joint users:

    The Bank, Parent companies of the Bank (including CTBC Bank Co., Ltd. and CTBC Financial Holding Co., Ltd.); and consolidated subsidiaries of the Bank (TSBF).

  3. cPurposes of joint use:

    For operations and internal management (including regarding compliance and risk) purposes appropriate for our group such as in:

    • The management of various risks;
    • Internal audits and inspections;
    • Operations management; and
    • Other internal management and operations related tasks
  4. dName of the person responsible for managing personal data:

    The Tokyo Star Bank, Limited; Head Office: 2-3-5 Akasaka, Minato-ku, Tokyo
    Representative Executive Officer and President (CEO)


    Bank's website with company information (in Japanese)

7. Request for Discontinuation of Sales Promotion Activities

When the Bank receives a request from the customer for discontinuation of our sales promotion activities, we will proceed without delay to discontinue such activities with respect to such customer.

(1) Activities that may be discontinued:

  1. aMailing the Bank’s advertisement and printed materials (including enclosures of our partners’ advertisement and printed materials in our mail); provided, however, that the Bank cannot discontinue the delivery of materials enclosed with “Star One” bank statements or content printed on the blank spaces of transactional documents such as loan repayment schedules;
  2. bSending emails containing advertisement of the Bank (including its partners);
  3. cAdvertising the Bank (including its partners) through telephone calls; and
  4. dProviding advertisement and printed materials of the Bank’s partners.

(2) Procedures for discontinuation:

Such requests shall be accepted at the call center or our branches. If you are making such request in person, please bring your registered seal.

8. Request for Disclosure or the Like of Retained Personal Data

The Bank shall accept your request for notice regarding the purposes of use, or for disclosure, correction, addition, omission, suspension of use, or deletion, or for suspension of provision to third parties, of retained personal data related to your personal information ore records of provision to third parties (a “Request for Action”).

(1) Requesting procedure (when you yourself are making the request)

If you yourself are making a Request for Action in person at our branches, please bring your identification document(s) and seal (or registered seal if you have an account with us). You will fill out the necessary items in the “Personal Information: Request for Action Form” at the reception desk.
While such form is available at our branches, it can also be delivered to you by post by contacting the call center or our branches.

(2) Requesting procedure (when your agent is making the request)

  1. aHow to obtain the power of attorney

    If your agent is making the Request for Action, you will fill out the necessary items in our designated “Power of Attorney” form before your agent proceeds with such request at our branches. While the “Power of Attorney” form and “Personal Information: Request for Action Form (for Agent)” are available at our branches, they can also be delivered to you by post by contacting the call center or our branches.

  2. bStatutory agents

    In the case that the statutory agent for a minor or adult ward is making the Request for Action, the Power of Attorney may be substituted with a certificate of residence (“jyuminhyou”) for the former and certificate of registered matters (“touki jikou shoumeishou”) issued by the Legal Affairs Bureau for the latter. Please contact our branches for details.

  3. cAgent’s identity verification

    We will verify the identity of the agent who visits our branches. Thus, such agent needs to bring his/her identification document(s) and seal (or registered seal if such agent has an account with us).

  4. dPower of attorney

    The Power of Attorney requires your signature/seal as the person granting his/her authority to an agent. In connection therewith, if you have an account with us, you must use your registered seal.

  5. eCaution

    For the protection of personal information, the Bank shall confirm with you regarding the Power of Attorney and details of the request made.

(3) Point of Contact

Any Request for Action shall be accepted at our branches or by post. If requesting by post, please enclose the Personal Information: Request for Action Form (or, if the requester is your agent, the Personal Information: Request for Action Form (for Agent) and the Power of Attorney), copy of identification document(s) (as stipulated in Section 8(4)), and service fee (as stipulated in Section 8(7)) and send them to the following address.

Mailing Address
“Personal Information: Request for Action Form Enclosed”
Personal Information Handling Office, Operations Center, The Tokyo Star Bank, Limited
9F Keio Seiseki Sakuragaoka Shopping Centre C Building, 1-7-5 Sekido, Tama-shi, Tokyo 206-0011

(4) Customer identification documents

  1. aValid customer identification documents
    If presenting originals at the counter:
    One original, unexpired certified document issued by an official agency that contains your photo such as a driver’s license, passport, or an Individual Number card; orTwo types of original, unexpired certified documents issued by an official agency that do not contain your photo, such as a health insurance card, pension book (“nenkin techou”), or welfare book (“fukushi techou”).
    If submitting by post:
    A copy of one original, unexpired certified document issued by an official agency that contains your photo such as a driver’s license, passport, or an Individual Number card; orCopies of two types of original, unexpired certified documents issued by an official agency that do not contain your photo, such as a health insurance card, pension book(“nenkin techou”), or welfare book (“fukushi techou”).
  2. Caution:

    The Bank will only accept unexpired identification documents.
    If you have any questions about customer identification, please contact the call center or our branches.

(5) Items that may be disclosed (personal information identifiable as “retained personal data”)

Retained personal data that may be disclosed are as follows:
Branch code, Name, Address, Gender, Birthdate, Home telephone number, Email address, Alternative telephone number, Type of work, Employer’s name, Work telephone number, Type of deposit account, Date of opening of deposit account, Type of loan transaction, Loan commencement date, Name of outsourced agency providing lending related services (e.g., Japan Housing Finance Agency)

Please specify in detail any information requested under the Request for Action that is not listed above. However, please note that the Bank may not be able to accommodate your request in some cases. If a Request for Action is made with respect to the Individual Number, the Bank’s reply shall be limited to whether or not such information is in our possession.

(6) Request for suspension of use or the like

The Bank shall accept requests for suspension of use or deletion of retained personal data only if the Bank has obtained or handled such data in an inappropriate manner.

(7) Service fee

The Bank will charge a specified service fee in connection with your request for notice regarding the purposes of use or for disclosure of retained personal data. Such fee shall be paid upon submission of the Personal Information: Request for Action Form at the Bank’s reception desk. If you have an account with us, you may pay such fee through a bank transfer. Please note that if requesting by post, we do not accept payment by cash. Please visit our homepage or our branches for details regarding the service fee.

(8) Responses to requests

We will respond to your Request for Action by sending it to you via a method of your choosing. Please note that our response to any such request made by your agent will also be sent to you. Please also note that we may not be able to accommodate your Request for Action pursuant to the Personal Information Protection Act or the like, in which case we will notify you to that effect. Even in such a case, please note that we will not be able to refund service fees that were already paid.

9. How to Make a Complaint

The Bank has a point of contact for receiving complaints concerning the Bank’s handling of personal information. Please contact the below when making a complaint.

Contact:
Customer Relations Office (our dedicated help desk for inquiries regarding the handling of personal information)
TEL: 03-6230-9048
Service Hours: 9 a.m. to 5 p.m. on weekdays

10. Accredited Personal Information Protection Organizations of which the Bank is a Member

The Bank is a member of the following personal information protection organizations that were accredited under the Personal Information Protection Act.
The following organizations manage complaints and provide consultation services concerning their member entity’s handling of personal information.

All relevant transactions are executed solely on the basis of Japanese language contracts and explanatory materials. This document has been translated for reference purposes only. The Bank shall have no liability for any damages or other harm arising from any errors or omissions in this translation.