JAPAN Law and Practice Contributed by: Yoshifumi Onodera, Hiroyuki Tanaka, Naoto Shimamura and Rio Ichii, Mori Hamada
1.3 Cybersecurity Regulators The regulator tasked with enforcing and implement - ing the APPI is the Personal Information Protection Commission (PPC”, which has the following powers under the law: • to require handling operators to report or submit materials regarding their handling of personal information (Article 146), which the APPI defines as information about living individuals that can identify specific individuals or contains what is referred to in the law as an “individual identification code” (Article 2.1); • to enter a handling operator’s offices or other locations to investigate, make enquiries, or view records or other documents (Article 146); • to provide guidance or advice to handling opera - tors (Article 147); • to recommend that handling operators cease any acts constituting a violation of the APPI and take other necessary measures to correct the violation (Article 148.1); • to order handling operators to take necessary measures to implement the PPC’s recommenda - tions and to rectify certain violations of the APPI (Articles 148.2 and 148.3); and • when the PPC issues orders pursuant to Articles 148.2 and 148.3, and handling operators violate the order, the PPC may publicly announce the vio - lation (Article 148.4). The National Police Agency and the Public Prosecu - tors Office are responsible for the criminal investiga - tion and prosecution of cybercrimes. Among the non-regulatory government authorities that are also directly involved with cybersecurity, the Information-technology Promotion Agency of Japan (IPA) and the National Cybersecurity Office (NCO) are particularly notable. The NCO was formerly known as the National Center for Incident Readiness and Strat - egy for Cybersecurity (NISC) and was established in July 2025 as its enhanced successor. The IPA regularly publishes important guidelines and provides informa - tion on cybersecurity. The more important guidelines include the Cybersecurity Management Guidelines for small and mid-sized companies on information securi - ty, and guidelines on preventing insider data breaches.
The Instalment Sales Act requires businesses handling credit card numbers to take necessary and appropri - ate measures to prevent the leakage, loss or damage of or to those credit card numbers (Article 35-16). The Payment Services Act requires prepaid payment instrument issuers, funds transfer service providers, and virtual currency exchange service providers to take necessary and appropriate measures to prevent the leakage, loss or damage of or to information per - taining to their respective businesses (Articles 21, 49 and 63-8). Sector-specific regulators impose additional informa - tion security obligations on some industries includ - ing the financial and healthcare sectors. For the financial sector, the Financial Services Agency (FSA) has issued the Comprehensive Guidelines for the Supervision of Major Banks, etc, which provide for cybersecurity obligations of financial institutions. For details on cybersecurity guidelines in finance, see 3. Operational Resilience in the Financial Sector . As for the healthcare industry, an enforcement order on the Medical Care Act requires hospitals, clinics and birthing centres to take appropriate steps to ensure cybersecurity (Article 14.2) and an enforcement order of the Act on Securing Quality, Efficacy and Safety of Products Including Pharmaceuticals and Medical Devices also requests pharmacies to do the same (Article 11.2). Further, various ministries have issued other relevant guidelines: • the Ministry of Health, Labour and Welfare (MHLW) issued the Guidelines on Safety Management of Medical Information Systems (last amended in May 2023); • the Ministry of Economy, Trade and Industry (METI) and MIC jointly issued the Guidelines on Safety Management for Providers of Information Systems and Services Handling Medical Information (last amended in July 2023); • MIC published comprehensive measures for the security of the internet of things (IoT) (July 2016); and • MIC published guidelines on the application of the Telecommunications Business Act to reports of serious accidents (volume 7, December 2023).
232 CHAMBERS.COM
Powered by FlippingBook