Cybersecurity 2026

JAPAN Law and Practice Contributed by: Yoshifumi Onodera, Hiroyuki Tanaka, Naoto Shimamura and Rio Ichii, Mori Hamada

Mori Hamada & Matsumoto 16th Floor, Marunouchi Park Building 2-6-1 Marunouchi Chiyoda-ku

Tokyo Japan 100-8222

Tel: +81 3 6212 8330 Fax: +81 3 6212 8330

Email: info@morihamada.com Web: www.morihamada.com

1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy The Basic Act on Cybersecurity is Japan’s fundamen - tal law on cybersecurity, and the Act on the Protec - tion of Personal Information (APPI) is the country’s principal data protection law. On 16 May 2025, the Cyber Response Capabilities Enhancement Act and an Act to Amend the Related Laws (the “Active Cyber Defence Acts”), which enhance active cyberdefence, were approved for the government to proactively respond to the increasing threat posed by cyber- attacks. Pursuant to the APPI, personal data breaches are sub - ject to mandatory reporting and notification require - ments – see 2.3 Incident Response and Notification Obligations . The Active Cyber Defence Acts establish a framework for public-private collaboration in cybersecurity, per - mit the use of communications information for cyber - security, and authorise access to attackers’ servers for the purpose of neutralisation. The Unfair Competi - tion Prevention Act prohibits the infringement of trade secrets, and the Act on Prohibition of Unauthorised Computer Access outlaws unauthorised computer access. The Penal Code also includes penalties for some cybersecurity crimes. The Telecommunications Business Act requires telecommunications carriers to ensure the secrecy of communications.

Japan does not have specific regulations for secure software development. For more details on the laws cited above and other relevant laws, see 1.2 Cybersecurity Laws . 1.2 Cybersecurity Laws The Basic Act on Cybersecurity regulates the respon - sibility of the national and local governments for cybersecurity (Articles 4 and 5). It also stipulates the obligation of critical information infrastructure opera - tors, cyberspace-related business providers, and research institutions such as universities (Articles 6, 7 and 8) to exert efforts to ensure cybersecurity. The APPI, Japan’s principal data protection law, pro - vides the basic principles for the government’s regu - latory policies and authority, as well as requirements for private business operators who handle personal information (“handling operators”). Another important law is the Act on the Use of Num - bers to Identify a Specific Individual in Administrative Procedures (the “My Number Act”), which stipulates special rules for “My Number”– a 12-digit individual number assigned to each resident of Japan. The Active Cyber Defence Acts aim to enable the gov - ernment to respond proactively to the growing threat of cyber-attacks. They consist of four pillars: • public-private collaboration;

230 CHAMBERS.COM

Powered by