JAPAN Law and Practice Contributed by: Yoshifumi Onodera, Hiroyuki Tanaka, Naoto Shimamura and Rio Ichii, Mori Hamada
available telephone directories or car navigation sys - tems. The PPC Ordinance prescribes that a mandatory data breach report is required if a data breach includes per - sonal data (excluding advanced encryption or other measures that are necessary to protect the rights and interests of the individual): • containing “special care-required personal informa - tion”; • that is likely to cause property damage if used inappropriately; • that is likely to have been committed for an improper purpose (effective since April 2024, per - sonal information that is already or will be collected and expected to be treated as personal data is also Special care-required personal information is defined as personal information comprising a data principal’s race, creed, social status, medical history, criminal record, the fact of having been a victim of a crime, or other descriptions that may be prescribed by a cabi - net order as requiring special care in handling so as not to cause unfair discrimination, prejudice or other disadvantages to the data subject (Article 2.3). 2.4 State Responsibilities and Obligations Governmental authorities that have specific jurisdic - tion over some of the 15 critical information infra - structure sectors have issued specific guidelines, described below, concerning cybersecurity. For the healthcare industry, see 6.3 Cybersecurity in the Healthcare Sector . For the financial industry, see 3 Operational Resilience in the Financial Sector . The Ministry of Land, Infrastructure, Transport and Tourism (MLIT) has issued: included in this requirement); or • of more than 1,000 individuals. • Safety Guidelines for Ensuring Information Security for Air Transport Operators for aviation services; • Safety Guidelines for Ensuring Information Security in the Airport Sector for airport services; • Safety Guidelines for Ensuring Information Security for Railway Operators for railway services;
• Safety Guidelines for Ensuring Information Security for the Logistics Sector for logistics services (motor vehicle transportation); • Safety Guidelines for Ensuring Information Security for the Logistics Sector for logistics services (ware - house operations); • Safety Guidelines for Ensuring Information Security for the Logistics Sector for logistics services (ship operations); • Safety Guidelines for Ensuring Information Security for the Logistics Sector for water supply services; and • Safety Guidelines for Ensuring Information Security for the Logistics Sector for ports and harbours. The MLIT also issues information security counter - measure checklists for railway services, bus services, bus terminals, taxis, hotels, ferries, and airports and airport buildings. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation The FSA issued the Comprehensive Guidelines for the Supervision of Major Banks, etc (the “SMB Com - prehensive Guidelines”), which mention cybersecurity obligations, referring to the Guidelines on Cybersecu - rity for the Finance Sector (the “CSFS Guidelines”). The SMB Comprehensive Guidelines further include measures regarding operational resilience, which refers to the ability of financial institutions to con - tinue to maintain the minimum level of their critical operations even in the event of a system failure, ter - rorist attack, cyber-attack, infectious disease, natural disaster, or other event. The SMB Comprehensive Guidelines specify the actions to be taken by boards of directors and the authorities’ regulations to achieve operational resilience. These Guidelines do not have any extraterritorial scope of applicability. On 8 December 2025, a draft amendment to the SMB Comprehensive Guidelines was released, and public comments were invited until 13 January 2026. The
235 CHAMBERS.COM
Powered by FlippingBook