Cybersecurity 2026

JAPAN Law and Practice Contributed by: Yoshifumi Onodera, Hiroyuki Tanaka, Naoto Shimamura and Rio Ichii, Mori Hamada

3.5 International Data Transfers For offshoring, please note that there are special restrictions on the transfer of personal data to foreign countries. In principle, the APPI requires the transferor to obtain the prior consent of individuals whose per - sonal data will be transferred to third parties located in foreign countries (Article 28). In other words, over - seas transfer restrictions will apply if a foreign com - pany transfers user data to another company outside Japan. Conversely, if it transfers user data to a com - pany in Japan, these overseas transfer restrictions will not apply. The overseas transfer restrictions apply even where outsourcing would otherwise qualify as an exception to local third-party data transfer restric - tions. The data subjects’ consent to overseas data transfers is not necessary if the following apply: • the foreign country is designated by the PPC as a country with a data protection regime with a level of protection equivalent to that of Japan (only EEA member countries and the UK have been desig - nated to date); • the third-party recipient has an equivalent system of data protection that meets the standards pre - scribed by the ordinance issued by the PPC (the “PPC Ordinance”) – ie, either of the following: (a) there is assurance, by appropriate and reason - able methodologies, that the recipient will treat the disclosed personal data in accordance with the spirit of the requirements on handling personal data under the APPI; or (b) the recipient has been certified under an inter - national arrangement, recognised by the PPC, regarding its system of handling personal data. The implementation of the PPC Ordinance is set out in the PPC Guidelines, which provide that “appropriate and reasonable methodologies” include agreements between the data importer and exporter, or inter-group privacy rules, which ensure that the data importer will treat the disclosed personal data in accordance with the spirit of the APPI. With respect to PPC-recognised international frameworks, to date, the PPC Guidelines have identified only the APEC Cross Border Privacy Rules (CBPR) as a recognised international framework on the handling of personal data.

amendment aims to strengthen measures to address cyber-risks related to online banking services and includes additional details on recommended fraud prevention measures, such as implementation of phishing-resistant multi-factor authentication. 3.2 ICT Service Provider Contractual Requirements Not limited to the financial sector, when a handling operator entrusts personal data, it must exercise the necessary and appropriate supervision over the entrusted person to ensure security control over the entrusted personal data (Article 25 of the APPI). Handling operators must supervise the entrustees to ensure that the same levels of security control are tak - en as those imposed on the operators under the APPI. If a handling operator uses cloud services, this may not be considered as entrustment and therefore the above-mentioned obligation under Article 25 of the APPI may not apply. Instead, businesses that use cloud services must still take appropriate security control over the personal data stored in cloud services as part of their own duties. The APPI does not provide for data portability rights. 3.3 Key Operational Resilience Obligations The SMB Comprehensive Guidelines require busi - nesses to report to the authorities when they become aware of a computer system failure or a cyberse - curity incident, when they are recovering from such incidents, and when they have identified the cause of an incident. Where the business detects that a cyber- attack will or is highly likely to have an impact on cus - tomers or business, a report is required even if a sys - tem failure or incident does not occur. For details on the SMB Comprehensive Guidelines, see 3.1 Scope of Financial Sector Operational Resilience Regula- tion . 3.4 Operational Resilience Enforcement The FSA may impose administrative disposition on financial businesses that have violated or may be at risk of violating laws or regulations. Such disposition includes on-site inspections and orders to improve business operations.

236 CHAMBERS.COM

Powered by