JAPAN Law and Practice Contributed by: Yoshifumi Onodera, Hiroyuki Tanaka, Naoto Shimamura and Rio Ichii, Mori Hamada & Matsumoto
Filing of Notification of Opt-Out Consent Under Article 27.2 of the APPI, handling oper - ators may provide personal data (excluding special-care-required personal information and personal data acquired by improper means or provided by another handling operator pursu - ant to the opt-out mechanism) to third parties without the opt-in consent of data subjects if the following conditions are satisfied: • they agree to stop providing personal data to the third party upon the data subject’s demand; • they notify the data subjects in advance of certain events outlined in Article 27.2 or make such notification of events readily accessible to the data subjects; and • they submit a notification of certain matters to the PPC. Please note that, in practice, the PPC does not readily accept the foregoing opt-out notification unless it is not practical to seek the data sub - jects’ consent, and it is difficult to use the other exceptions. Data Protection Officers The APPI has no provision mandating the appointment of privacy or data protection offic - ers; however, handling operators must take necessary and proper measures to prevent the leakage, loss or damage of personal data and to implement other security controls. Under the PPC Guidelines, those measures should include the following: • organisational security measures, such as establishing rules for handling personal data and clarifying who is responsible for supervis - ing such handling; • HR security measures, including educating/ training employees;
• physical security measures, including control - ling the area where personal data is handled, such as servers and offices; • technical security measures, including con - trolling access to personal data; and • understanding of the external environment – this security measure was introduced in the amendments to the guidelines and requires handling operators that process personal data in foreign countries to understand the foreign country’s legal system for personal information protection and, taking that legal system into consideration, to take neces - sary and appropriate measures to ensure the security of personal data. Effective since 1 April 2024, the PPC Guidelines also require handling operators to take security control over personal information that will be col - lected and expected to be treated as personal data so that cyber-attackers cannot intercept such information on behalf of the operator. The PPC Guidelines indicate the appointment of a person to be in charge of the handling of personal data as an example of a proper and necessary measure. However, although handling operators are expected to adopt the measures described in the PPC Guidelines, any failure to adopt such measures is not a direct breach of the APPI. Under the TBA, large TSPs are required to appoint a chief manager responsible for han - dling user information. Privacy By Design/Default and Privacy Impact Analyses The APPI does not mandate obligations regard - ing PIAs. However, the PPC has issued a report titled “Promoting the implementation of PIAs – Significance of PIAs and points to keep in mind
254 CHAMBERS.COM
Powered by FlippingBook