JAPAN Trends and Developments Contributed by: Yuki Kuroda, Takahiro Nakayama, Takuya Uehara and Nanoko Sasaki, Oh-Ebashi LPC & Partners
Other issues The Interim Report and Next Steps identify the following additional issues for consideration, although the specific directions and timelines for examining these issues remain largely unclear: • a regulatory framework for personal data processing for academic research purposes in hospitals and similar institutions; • the processing of children’s personal data; • a regulatory framework for information related to individuals but not qualifying as personal data due to the inability to identify specific individuals (eg, HTTP cookies); • a regulatory framework for physical charac - teristic data such as facial feature data; • a regulatory framework for opt-out notifica - tion businesses (ie, those that have notified the PPC and published that they will provide personal data to third parties unless data subjects opt out); • ensuring the effectiveness of PPC recommen - dations and orders; • a criminal penalty framework; and • a framework for PPC reporting and data subject notification regarding the unlawful provision of personal data to third parties.
• allowing periodic batch reporting for cases with minimal need for PPC supervision, such as mistaken document delivery to one patient at a hospital counter; and • exempting data subject notification require - ments in cases posing minimal risk to the protection of rights and interests. Governance framework The APPI currently requires businesses to obtain data subject consent when providing personal data to third parties, as discussed above, but there are some exceptions. Specifically, data subject consent is not required when personal data is provided to a third party for the purpose of entrusting personal data processing (Article 27, Para 5, Item 1). Instead, businesses must exercise necessary and appropriate supervision over such third-party processors (Article 25). For instance, cloud service usage may be cat - egorised as entrusted personal data processing. In such cases, cloud service users must super - vise service providers, such as through requiring periodic reports on the status of personal data processing. However, such supervision may be impractical when small-scale businesses use large-scale cloud services. Therefore, the Next Steps propose reviewing regulations for entities entrusted with personal data processing based on practical realities.
268 CHAMBERS.COM
Powered by FlippingBook