Although this may still change, Councillor Sawaki of the Personal Information Protection Commission explained the current state of deliberations on the outline of proposed amendments to the Act on the Protection of Personal Information. The details are as follows.
Report 2: Status of Deliberations Toward Amending the So-Called 3-Year Review System under the Act on the Protection of Personal Information; Kiyoshi Sawaki, Councillor, Personal Information Protection Commission
I. The Nature of Individuals’ Rights Regarding Personal Data
1. Relaxing the Requirements for Requests to Cease Use, Erase Data, or Cease Third-Party Provision
To strengthen data subjects’ involvement with retained personal data, the requirements for requesting the cessation of use or other handling of retained personal data and for requesting the cessation of third-party provision will be relaxed, thereby broadening the scope of individuals’ rights.
Note: Until now, such requests were limited to cases involving improper use.
2. Promoting the Digitalization of Disclosure
Awareness and proper operation of the current disclosure-request system will be promoted. In addition, to improve convenience for data subjects in using retained personal data obtained through disclosure requests, data subjects will be allowed to specify the method of disclosure, including the provision of electronic records.
Note: Until now, disclosure was premised on paper. This will make it digital.
3. Expanding the Scope of Retained Personal Data Subject to Disclosure and Other Requests
In light of changing risks as the information society advances, retained personal data subject to disclosure and other requests by data subjects will no longer be limited according to retention period. Short-term retained data that is erased within 6 months, which is currently excluded, will be included in retained personal data.
4. Strengthening Opt-Out Regulations
Given the current situation in which circulation of name lists makes it difficult for data subjects to be involved, the scope of personal data that may be provided to third parties under opt-out provisions will be limited. In addition, data subjects will be allowed to request disclosure of records that personal information handling business operators are currently required to keep when providing personal data to, or receiving it from, third parties, thereby making data subjects’ involvement more effective.
II. The Nature of the Obligations Business Operators Must Observe
1. Making Breach Reporting and Notification to Data Subjects Mandatory
From the standpoint of protecting individuals’ rights and interests and ensuring fairness, personal information handling business operators will be required to promptly report to the Personal Information Protection Commission and notify affected data subjects when an incident falls within specified categories, such as a personal data breach affecting at least a certain number of individuals. This will enable the Commission to learn of breaches and similar incidents at an early stage and allow data subjects to take necessary measures.
Note: This is currently addressed through guidelines. It will not stop at notification to an accredited personal information protection organization.
2. Clarifying the Obligation of Proper Use
In light of changing risks as the information society advances, it will be clarified that personal information handling business operators must not use personal information by improper means.
Note: The current law regulates improper acquisition, but does not explicitly regulate improper purposes of use. The legal framework was designed on the premise that individuals’ rights and interests would not be infringed, but outrageous cases keep emerging, so this will now be stated expressly.
It is causing harm to society. Merely having the correct procedural form is not enough.
III. The Nature of Mechanisms Encouraging Voluntary Initiatives by Business Operators
1. Diversifying the Accredited Personal Information Protection Organization System
In light of the diversification of business practices involving personal information among personal information handling business operators and changes in the forms of discipline required, the accredited personal information protection organization system will be expanded. In addition to the current system, under which such organizations receive complaints and provide guidance concerning all handling of personal information by covered business operators, it will become possible to accredit organizations whose activities are limited to specified business activities.
Note: Until now, becoming an accredited personal information protection organization meant having to handle all inquiries concerning personal information. For example, an organization in the retail industry could not limit its work to the online component.
2. Enhancing Matters Publicized Concerning Retained Personal Data
To enable data subjects to understand and engage appropriately, and to encourage proper handling by personal information handling business operators through fuller explanations to data subjects about retained personal data, matters that should be explained to data subjects—such as the personal information handling framework, the details of measures taken, and the methods used to process retained personal data—will be added to the matters required by law to be publicized (matters specified by Cabinet Order).
Note: Matters that cannot be expressed through the existing statement of purpose of use should be included. Cabinet Order?
IV. The Nature of Measures Concerning Data Utilization
1. Establishing “Pseudonymized Information”
To promote innovation, “pseudonymized information” will be introduced as a category of personal information processed so that a specific individual cannot be identified without cross-referencing it with other information. Provided that certain conduct restrictions limit pseudonymized information to internal analysis by business operators that does not involve use to identify data subjects, and that the purposes of using pseudonymized information are specified and publicized, some obligations to respond to requests by individuals (including requests for disclosure, correction, cessation of use, and similar actions) and some restrictions on handling will be relaxed.
Note: It will remain personal information, but will be excluded from the obligation to respond to requests from data subjects.
2. Clarifying the Rules for Information That Becomes Personal Data at the Recipient
As methods of using information concerning individuals diversify, and to maintain a balance between protecting personal information and using it properly and effectively, rules restricting third-party provision of personal data will be applied to information that is not personal data at the provider but is clearly expected to become personal data at the recipient.
3. Clarifying the Operation of Exceptions for Handling Personal Information in the Public Interest
For handling personal information in the public interest that is exempt from restrictions on purposes of use and third-party provision, specific examples will be added to guidelines and Q &A materials, among other steps, to promote data utilization that benefits the public as a whole.
V. The Nature of Penalties
The current statutory penalties will be reviewed as necessary, including the introduction of heavier penalties under provisions punishing corporations.
Deferred
VI. The Nature of the Law’s Extraterritorial Application and Cross-Border Transfers
1. Expanding the Scope of Extraterritorial Application
In light of the globalization of economic and social activity and the diversification of cross-border transfers, foreign business operators handling personal information or anonymously processed information concerning persons in Japan will be subject to requests for reports and orders from the Personal Information Protection Commission. If a business operator fails to comply with an order, the Commission will also be permitted to publicize that fact.
2. Strengthening Restrictions on Providing Personal Data to Third Parties in Foreign Countries
As cross-border transfers of personal information diversify, fuller information will be required to be provided to data subjects concerning the recipient business operator’s handling of personal information, including the name of the destination country and whether that country has a personal information protection system. This requirement will apply to the transferring personal information handling business operator, with the aim of enabling data subjects to understand and engage appropriately and encouraging proper handling of personal information by personal information handling business operators. In addition to providing information when a transfer is based on the data subject’s consent, when personal data is transferred without such consent on the condition that the recipient business operator has established a system ensuring continued proper handling, information must be provided at the data subject’s request.
VII. Handling Personal Information Across the Public and Private Sectors
1. Integrating Legislation for Administrative Organs and Incorporated Administrative Agencies with Legislation for the Private Sector
In response to observations that differences in provisions and jurisdiction have caused difficulties in personal information protection systems for administrative organs, incorporated administrative agencies, and similar bodies, the government will proactively and actively pursue concrete deliberations according to a clear schedule. The aim will be to consolidate and integrate the provisions concerning protection of personal information in the private sector, administrative organs, incorporated administrative agencies, and similar bodies, and to place these systems under the unified jurisdiction of the Personal Information Protection Commission.
Note: A clear schedule is mentioned because if we wait 3 years, the law will change, so it cannot take that long.
2. Personal Information Protection Systems of Local Governments
Discussions will proceed with local governments and other parties on practical issues concerning the appropriate form of rules, including unification under national law, for the handling of personal information held by local governments and currently governed by ordinances, as well as the appropriate division of roles between the national and local governments in local-government personal information protection systems.
Related posts

Summary of Personal Information Protection Commission Meeting No. 281, Document 2, “Review Based on the So-Called 3-Year Review Provision of the Act on the Protection of Personal Information (Approaches to More Substantive Protection of Individuals’ Rights and Interests ③)” (Secretariat of the Personal Information Protection Commission, April 24, Reiwa 6)
The following is an AI-generated summary by Otia.AI of Personal Information Protection Commission Meeting No. 281, Document 2, “Review Based on the So-Called 3-Year Review Provision…

Is the Act on the Protection of Personal Information Really That Full of Loopholes?
I had vaguely suspected as much ever since it was enacted, but the thought that it really could be this riddled with loopholes leaves me feeling…

Nostalgic: Cabinet Secretariat > Numbering System for Social Security and Taxation > Working Group on Personal Information Protection and Working Group on Information-Linkage Infrastructure Technology(2011)
I suddenly came across something incredibly nostalgic. These include minutes and other materials from meetings of the Working Group on Information-Linkage Infrastructure Technology, which had been…
