JAPAN Trends and Developments Contributed by: Yasushi Kudo, Yukiko Konno and Takayuki Inukai, Nagashima Ohno & Tsunematsu
Nagashima Ohno & Tsunematsu JP Tower, 2-7-2 Marunouchi Chiyoda-ku Tokyo 100-7036 Japan Tel: +81 3 6889 7396 Fax: +81 3 6889 8396 Email: yasushi.kudo@nagashima.com Web: www.nagashima.com/lawyers/yasushi_kudo/
Cybersecurity Trends and Regulatory Enforcement in Japan (2025) In 2025, a series of cyber-incidents occurred in Japan, including Distributed Denial-of-Service attacks tar - geting critical infrastructure, such as telecommuni - cations and finance, as well as ransomware attacks against a major beverage manufacturer and a leading e-commerce company. These incidents resulted in large-scale personal data breaches and partial sus - pension of business transactions. As supply chains become increasingly complex, the risk that damage from cyber-incidents will affect not only a company’s own corporate group but also its entire supply chain – including contractors and business partners – has become more pronounced. Based on these circumstances in Japan, this article examines recent actions taken by the relevant authori - ties to address cyberthreats to personal data, enhance cybersecurity resilience, and mitigate cybersecurity supply chain risks. Recent Enforcement and Administrative Guidance by the PPC Since 2024, the Personal Information Protection Com - mission (PPC) has published quarterly summaries of its enforcement activities and the processing status of data breach reports. The PPC’s active enforcement trend continued through the first half of fiscal year 2025. During this period, 62.1% of reported breaches involved sensitive personal data, followed by “breach - es caused by unjust purposes, such as unauthorised access” at 21.2%.
The following reflects the volume of regulatory actions processed by the PPC. • Breach report processing: 7,733 cases in FY2024 H1, 11,323 cases in FY2024 H2, and 8,933 cases in FY2025 H1. • Guidance and advice: 203 cases in FY2024 H1, peaking at 395 in FY2024 H2, with 236 cases in FY2025 H1. • Recommendations: while no recommendations or orders were issued in FY2024 H1, the PPC issued one recommendation in FY2024 H2. By FY2025 H1, this increased to two recommendations and one formal administrative order. • Monitoring activities: in FY2025 H1, the PPC conducted 11 collections of information and two on-site inspections. Case studies of administrative guidance and implications for businesses The PPC has frequently issued guidance regarding deficiencies in measures for managing the security of personal data under the Act on the Protection of Personal Information (APPI), particularly in cases involving unauthorised access. For instance, in a case where a ransomware attack led to a public finding of inadequate security, the following failures were high - lighted, among others. • Technical: failure to update VPN devices and insuf - ficient password strength. • Organisational: lack of formalised rules for data storage, no password policy regarding length/char - acter complexity, and a failure to conduct regular audits or inspections.
239 CHAMBERS.COM
Powered by FlippingBook