Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Policy-Driven PII Control for Your Company

Sponsored · Ship Features Fearlessly Turn features on and off without deploys. Used by thousands of Ruby developers. →
Avatar for hikae hikae
September 28, 2026

Policy-Driven PII Control for Your Company

OASEC 2026 https://oasec.org/

Avatar for hikae

hikae

September 28, 2026

More Decks by hikae

Other Decks in Technology

Transcript

  1. OASEC 2026 / GOVERNANCE Policy-Driven PII Control for Your Company

    Hikaru Egashira Security Engineer, freee K.K. 01
  2. PROBLEM AI agents cross data boundaries “confused deputyˮ Trust boundary

    Diverse data sources AI agent Personal data leak! Excessive authority Enforce guardrails within the harness-level safety layer. Agent harness · Harness engineering · The Confused Deputy 1988 02
  3. COVERAGE A structural taxonomy gap APPI Japan's law) OpenAI Privacy

    Filter Sensitive personal information 8-category label set Medical history Criminal records Beliefs No corresponding label Check which categories the model can represent. Privacy Filter Model Card · §6.1 · APPI · Article 23 03
  4. MODEL TAXONOMY The shipped label taxonomy OpenAI Privacy Filter OpenAI

    · Privacy Filter Model Card · p. 11, §6.1 04
  5. MODEL LIMITS The model card states the limits Check the

    stated limits and label scope. 3.2 Out-of-Scope and Misuse 4.2 Static Label Policy → Verify coverage against the policy. OpenAI · Privacy Filter Model Card · p. 7, §§3.2 and 4.2 05
  6. POLICY AND PIA Derive detection requirements from policy Legal requirements

    + internal policies DPIA / PIA Detection requirements Build or adapt detectors PPC PIA guidance Threat modeling for data protection 1. Which types of data leakage are legally harmful? APPI · PPC · PIA guidance 2021 2. Where might agents cross their trust boundaries? 06
  7. PIA GUIDANCE PPC PIA guidance Procedure headings from the table

    of contents ORIGINAL HEADINGS ENGLISH TRANSLATION Determine whether a PIA is needed Prepare the PIA Identify risks Evaluate risks Respond to risks Compile the PIA report PPC · PIA guidance 2021 · Contents, Section II · Cropped excerpts 07
  8. DERIVATION PROCESS The derivation process 1 Enumerate Data processing scope

    + regulated categories 2 Generate Synthetic datasets 3 Map Detection categories + handling rules 4 Build / adapt Detectors for the derived categories 5 Evaluate Residual risks after integration 08
  9. SYNTHETIC DATA Apply synthetic data methods to policy-derived categories APPLICATION

    TO POLICYDERIVED CATEGORIES Policy-derived categories OpenAI · Privacy Filter Model Card · p. 18, Table 7 · Cropped excerpts Template-based synthetic generation 09
  10. IMPLEMENTATION & DEMO One interface for PII detection Compare opf

    & our model by data-privacy-stack/presidio 1 ADAPT A FILTER · EntityRecognizer OpfRecognizer OPF.redact(text) → detected_spans 2 REGISTER or AppiOnnxRecognizer CPU ONNX → token labels → spans RecognizerRegistry.add_recognizer(...) 3 ANALYSE AND REPLACE AnalyzerEngine RecognizerResult[] AnonymizerEngine analyze(DOC, language="ja") entity_type · start · end · score anonymize(...) Demo source: opf_demo.py · appi_demo.py 10
  11. TAKEAWAYS Policy defines what the detector must cover. Derive requirements

    through PIA. Verify coverage against legal definitions. Define operational handling for legal requirements. 11
  12. Q&A / PRESIDIO Why we use Presidio Operators define handling

    under the applicable legal requirements. Presidio ML / NER models Operational handling Regex patterns Custom logic Operators apply handling rules under legal requirements. Detection results IN OUR ORGANISATION We combine regex patterns with other detection logic to address false positives and missed detections. Presidio Analyzer A1
  13. Q&A / IMPLEMENTATION PIA-derived categories, multiple implementation paths Presidio custom

    recognizers Combine logic per requirement PIA-derived categories spaCy / GiNZA NER pipelines Regex patterns Fine-tuned LLMs Microsoft Presidio · GiNZA · pleno-anonymize A2
  14. Q&A / OTHER JURISDICTIONS Derive requirements for each jurisdiction. APPI

    PDPA PIPL Japan Singapore China Policy PIA Detector implementation A3