JAPAN Trends and Developments Contributed by: Yasushi Kudo, Yukiko Konno and Takayuki Inukai, Nagashima Ohno & Tsunematsu
• Human: employees were unable to access storage rules at all times, and appropriate security training was not provided. Businesses in Japan, especially those handling sub - stantial volumes of personal information are recom - mended to regularly review these PPC reports and continuously update their technical, organisational, and human security measures as well as implement measures to supervise their contractors. Furthermore, the Ministry of Internal Affairs and Com - munications (MIC) issued administrative guidance to a mobile carrier regarding a breach of the secrecy of communications. In this instance, although a third party obtained user IDs and passwords – making pri - vate communications accessible – the carrier failed to verify the breach promptly, delaying the initial report by more than three months. Discussion On The “Three-Year Review” Of The APPI When the APPI was amended in 2020, a supplemen - tary provision was included requiring the regulatory regime to be reviewed every three years to keep pace with technological changes. Pursuant to this mandate, the PPC is currently conducting its latest review, which includes significant proposals such as the introduction of an administrative surcharge system. As part of this process, the PPC released its “Future Directions for Consideration” in January 2025, fol - lowed by public comments in April. In March, it published the “Conceptual Approach to Institutional Challenges.” In January 2026, the PPC released the “Policy for Institutional Reform” (the “Reform Policy”), expressing its intent to submit an amendment bill to the Diet as early as possible this year. Key discussions on the “Three-Year Review” relevant to cybersecurity The Reform Policy generally aligns with previous dis - cussions. Key points regarding cybersecurity include the following. • Introduction of a surcharge system: to deter malicious violations involving large-scale data, a surcharge system will be introduced. However,
deficiencies in measures for managing the security of personal data are not currently listed as targets for surcharges, unless the incident also involves the designated illegal acts. • Relaxation of notification requirements: the obliga - tion to notify affected individuals may be relaxed in cases where there is a low risk of harming the rights and interests of those individuals. • Streamlining breach reporting: the PPC is consid - ering exempting businesses from “prompt prelimi - nary reports” if they have their systems verified by a third party. Additionally, for minor errors, busi - nesses may be allowed to submit consolidated reports at fixed intervals. • Integration with the Cyber-Resilience Enhance - ment Act: to reduce the administrative burden on businesses, the PPC will co-ordinate with the “Act on Prevention of Damage caused by Unjust Acts against Important Computers” to unify reporting formats and contact points. Reporting thresholds will also be adjusted to align with the risk-based approach of the new cybersecurity laws. • Postponement of collective redress: the proposal to grant qualified consumer organisations the right to seek injunctions and damages has been post - poned in this amendment cycle due to the need for further co-ordination with existing consumer litigation systems. Impact on business operators The 2026 APPI review is expected to alleviate the administrative burden of incident response while miti - gating the most severe legal risks originally anticipat - ed by the industry. While a surcharge system will be introduced to deter designated malicious violations, the current policy does not list deficiencies in security management measures as a direct target for surcharg - es. This clarifies that breaches resulting solely from security vulnerabilities, without accompanying desig - nated illegal acts, are not currently expected to trigger these substantial financial penalties. As the PPC aims for the early submission of the amendment bill to the Diet in 2026, businesses should view this period as an opportunity to refine their internal governance.
240 CHAMBERS.COM
Powered by FlippingBook