The following is an AI-generated summary by Otia.AI of Personal Information Protection Commission Meeting No. 281, Document 2, “Review Based on the So-Called 3-Year Review Provision of the Act on the Protection of Personal Information (Approaches to More Substantive Protection of Individuals’ Rights and Interests ③).” Please note that it has been posted as-is, without corrections, to demonstrate Otia.ai’s capabilities.
Approach to Rules Governing Businesses That Have Filed Opt-Out Notifications ①
- Rules under the Current Act (Rules at the Time of Provision)
- As a general rule, a business handling personal information must not provide personal data to a third party without obtaining the individual’s consent.
- However, provision without the individual’s consent is permitted if certain conditions are met and a notification has been filed with the Personal Information Protection Commission.
- The provision was established to permit the active circulation of personal information and strike a balance between protection and use.
Approach to Rules Governing Businesses That Have Filed Opt-Out Notifications ②
- Rules under the Current Act (Rules at the Time of Provision)
- A business that has filed an opt-out notification must make its name and address, the method for stopping provision, and other matters readily accessible to the individual.
- “Readily accessible to the individual” means a state in which the information can be continuously and easily accessed.
- Examples include posting it on a website or displaying it at an office counter.
Approach to Rules Governing Businesses That Have Filed Opt-Out Notifications ③
- Rules under the Current Act (Rules at the Time of Provision)
- If there is a risk that the recipient business may facilitate an unlawful or unjust act, this constitutes improper use.
- The recipient’s purpose of use and identity-verification method are not included among the matters subject to record-keeping obligations.
Approach to Rules Governing Businesses That Have Filed Opt-Out Notifications ④
- Rules under the Current Act (Rules at the Time of Acquisition)
- A business handling personal information must not acquire personal information by deception or other wrongful means.
- When receiving personal data from a third party, the business is obligated to confirm how it was acquired.
Approach to Rules Governing Businesses That Have Filed Opt-Out Notifications ⑤
- Background to the Amendments
- Amendment in Heisei 27
- To prevent unlawfully acquired personal information from being resold to list brokers, businesses were required to confirm how the information was acquired.
- Amendment in Reiwa 2
- Providing unlawfully acquired personal data under the opt-out provision was prohibited.
- The use of personal information in a manner that facilitates unlawful or unjust acts was prohibited.
- Amendment in Heisei 27
Approach to Rules Governing Businesses That Have Filed Opt-Out Notifications ⑥
- Emergency Measures Plan
- With the increase in specialized fraud, preventing the leakage of lists through the proper enforcement of the Act on the Protection of Personal Information was called for.
- Enforcement against malicious “list brokers” that provide lists to criminal groups was strengthened.
Approach to Rules Governing Businesses That Have Filed Opt-Out Notifications ⑦
- Fact-Finding Survey ①
- Approximately 2 tenths of businesses gave unclear specific answers about how they make notified matters readily accessible to individuals.
- Approximately 2 tenths of businesses lacked a specific method for confirming that the providing business had acquired the personal information by appropriate means.
Approach to Rules Governing Businesses That Have Filed Opt-Out Notifications ⑧
- Fact-Finding Survey ②
- Approximately 3 tenths of businesses did not confirm that the recipient would not facilitate unlawful or unjust acts.
- Approximately 3 tenths of businesses did not conduct identity-verification procedures for recipients.
Approach to Rules Governing Businesses That Have Filed Opt-Out Notifications ⑨
- Examples of Inappropriate Responses
- Business Planning Ltd.
- Sold a list to a reseller and failed to create records.
- Chuo Business Service Co., Ltd.
- Failed to create records of the recipient’s name and address.
- Free Business Co., Ltd.
- Failed to perform confirmation or create records when receiving the data.
- Business Planning Ltd.
Approach to Rules Governing Businesses That Have Filed Opt-Out Notifications ⑩
- Cases Involving Personal Information Unlawfully Removed
- Case A
- An employee of a second-tier subcontractor unlawfully copied Basic Resident Register data and sold it to a list broker.
- Case B
- Unlawfully acquired customer information and sold it to a list broker.
- Case C
- Unlawfully removed customer information and sold it to a list broker.
- Case D
- Unlawfully removed personal data and sold it to a list broker.
- Case A
Approach to Rules Governing Businesses That Have Filed Opt-Out Notifications ⑪
- Frequently Asked Questions and Consultations
- Is the fact that the sale of lists is permitted itself not a problem?
- There are many cases in which inquiries to list brokers are refused or suspension of provision is not carried out.
Related posts

OECD: Enhancing Access to and Sharing of Data in the Age of AI
This is slightly old news, but the OECD published an interesting document on February 5. Enhancing Access to and Sharing of Data in the Age of…

Data Sustains Lives—MyDataConference 2026 Opening Address
The following is the opening address for the MyData Japan Conference 2026, delivered by Nat Sakimura in his capacity as Chair of the General Incorporated Association…

The MyData Conference 2026 Is This Wednesday. See You at Hitotsubashi Hall!
I have been posting announcements on X every few days, and the MyDataJapan Conference 2026 is this Wednesday. There are many highlights: Naohiro Fujie, Representative Director…
