JAPAN Law and Practice Contributed by: Yoshifumi Onodera, Hiroyuki Tanaka, Naoto Shimamura and Rio Ichii, Mori Hamada
Definition of Data Security Incident, Breach or Cybersecurity Event The APPI stipulates mandatory obligations to report data breach incidents to the PPC and to notify affect - ed data subjects in cases where their rights or inter - ests are likely to be infringed (Article 26). The PPC Ordinance defines a data security incident or breach as the actual or possible occurrence of the leakage, loss or damage of or to personal data. The details of the requirements are discussed below. There is also a special rule for “My Number” under the My Number Act. There is no general regulation to impose a mandatory reporting obligation for cyber - security events that do not involve a personal data breach. However, there are various regulations gen - erally mandating certain types of service providers to report all incidents affecting their services to the authorities. This reporting obligation also covers cas - es where service failure results from a cyber-attack. For example, under the Telecommunications Busi - ness Act, if an incident occurs and causes the sus - pension or deterioration of the quality of services for more than the prescribed number of hours and affects a certain number of users specified by the relevant ordinance, the telecommunications business operator must report the incident to MIC. Furthermore, MIC has the authority to issue orders to improve the business practices of licensed telecommunications service pro - viders. Another example is financial institutions; many laws regulating financial sectors oblige them to report material service failure to the authorities. Data Elements Covered Breach of data security is applicable to personal data. The APPI defines personal data as personal informa - tion that is contained in a personal information data - base (Article 16.3), which is a collection of information (including personal information) that is systematically organised to enable a computer or some other means to search for particular personal information. However, this term excludes the collection of information that a cabinet order indicates as having little possibility of harming an individual’s rights or interests considering how that collection uses personal information (Article 16.4). Examples of collections of information that are excluded from this definition include commercially
they have entrusted the handling of personal data (eg, third-party vendors) take appropriate measures to ensure security control over the personal data (Arti - cle 25). Under the Economic Security Promotion Act, impor - tant critical infrastructure businesses are individually designated by the competent ministry as Specified Essential Infrastructure Service Providers. They are required to take measures to reduce or eliminate risk factors among parties involved in the supply chain. Some of the requirements include establishing meas - ures to: • prevent unauthorised changes to specified critical facilities; • prevent service interruptions; • confirm any legal or contractual violations by par - ties involved in the supply chain; and • prevent unintended changes by subcontractors. On 16 May 2025, the Act on the Protection of Eco - nomic Security Information took effect, introducing a security clearance system under which information designated by the government as important to nation - al security, including information concerning critical infrastructure and supply chains of critical goods, may be handled only by persons who require access to it and whose reliability has been confirmed. 2.3 Incident Response and Notification Obligations The Cybersecurity Policy for Critical Infrastructure Protection provides for the reporting obligations of critical information infrastructure operators in the fol - lowing instances: • if there is a legal reporting requirement by law or regulation; • if the operator has determined that an incident has had a serious impact on people’s lives or the operator’s services and that information must be shared; and • in other cases where the operator has determined that information must be shared.
234 CHAMBERS.COM
Powered by FlippingBook