Japan privacy watchdog issues urgent alert to firms over spate of data leaks
In short
Japan’s Personal Information Protection Commission issued an urgent alert on Oct. 7 urging businesses that handle personal data to strengthen safety management, after a series of large-scale leaks caused by unauthorised access. The commission called for encryption of communications containing personal data, prompt deletion of data no longer needed, and measures such as log analysis and stricter access controls. It also said it is considering revising its safety management guidelines.
Read the full story 1 min read
Japan’s Personal Information Protection Commission issued an urgent alert on Oct. 7 to businesses that handle personal data, after a series of large-scale leaks caused by unauthorised access. Asahi Shimbun, Nikkei, Livedoor News and TBS NEWS DIG all reported the alert. [ 1 , 2 , 3 , 4 ]
The commission said it has been encountering cases in which operators handling large volumes of personal information suffered external unauthorised access and saw large amounts of personal data leak. It asked businesses to take the measures needed to manage personal information safely, including encrypting communications that contain personal data, and to promptly delete personal data that is no longer necessary. [ 1 ]
Nikkei reported that the commission pointed to the legal requirement that personal data be deleted without delay once it is no longer needed, and warned that in some cases data kept on hand made the damage from a leak more serious. It urged businesses to check whether the personal data they hold is still necessary. As countermeasures against unauthorised access, the commission cited storing and analysing logs of system use and external access to detect intrusions early, and stopping or isolating compromised systems to prevent damage from spreading. [ 2 ]
Livedoor News reported that the alert also called for access rights to personal data to be kept to a minimum, with access decided on each occasion, and for authentication to be moved to stricter methods such as fingerprints and veins. [ 3 ]
The commission has classified past leak incidents into nine patterns — including cases where vulnerabilities were left unaddressed and cases where group companies or overseas sites were targeted — and presented countermeasures for each, according to its published material. Livedoor News added that the commission is proceeding with deliberations on revising its safety management guidelines, citing increasingly sophisticated cyberattacks and an expanding range of targets. [ 1 , 3 ]
Why it matters
The alert puts operators of personal data across Japan on notice that the regulator expects tighter handling of stored data, including deletion of records that are no longer needed. The commission’s stated plans to review its safety management guidelines signal that the compliance requirements themselves may change. The documents cite no specific penalties or named companies, so the immediate effect is guidance rather than enforcement.
Key facts
- The Personal Information Protection Commission published an urgent alert to businesses on Oct. 7. [ 1 , 2 , 3 , 4 ]
- The commission said it was responding to successive large-scale leaks of personal data caused by unauthorised access. [ 1 , 2 , 3 , 4 ]
- It asked businesses to encrypt communications containing personal data and to take other steps needed to manage personal information safely. [ 1 ]
- It called for personal data that is no longer needed to be deleted promptly. [ 1 , 2 , 3 ]
- The commission cited log storage and analysis to detect unauthorised access early, and stopping or isolating compromised systems. [ 2 ]
- It called for minimising access rights to personal data and for stricter authentication such as fingerprints or veins. [ 3 ]
- The commission classified past leak incidents into nine patterns and presented countermeasures for each. [ 1 ]
- The commission is considering a revision of its safety management guidelines. [ 3 ]
Confirmed by several sources
- The Personal Information Protection Commission issued an urgent alert on Oct. 7 over successive large-scale personal data leaks, and asked businesses to strengthen safety management. [ 1 , 2 , 3 , 4 ]
- The commission called for personal data that is no longer needed to be deleted promptly. [ 1 , 2 , 3 ]
- The commission referred to the legal requirement to endeavour to delete personal data without delay once it is no longer needed. [ 1 , 2 , 3 ]
Still unclear
- Which companies or specific incidents prompted the alert The documents say leaks have occurred one after another but name no companies, sectors or incidents.
- The number and scale of the recent leaks The documents describe the leaks as large-scale and successive but give no figures or dates.
- Whether and when the safety management guidelines will be revised Livedoor News says the commission is proceeding with deliberations on a revision; the other documents do not mention a revision or a timetable.
- The exact time the alert was published on Oct. 7 The documents give only the date, not the hour of publication.
What local media are saying
Timeline, local time
- Asahi Shimbun reports the Personal Information Protection Commission issued an urgent alert to businesses over successive large-scale personal data leaks. [ 1 ]
- Nikkei reports the alert and the commission’s call to delete unneeded personal data and to strengthen unauthorised-access countermeasures. [ 2 ]
- Livedoor News and TBS NEWS DIG report the urgent alert and the measures listed in it. [ 3 , 4 ]