3.1.5 Security Obligations and Data Breach Notifications Concerning
Data Processed by Electronic Means
The APPI requires Business Operators to take appropriate safety control measures,
supervise their employees (Article 21), and supervise contractors (Article 22) when
they handle “personal data”.
The Telecommunications Business Law obligates telecommunications facilities
to comply with the technical standards stipulated in “Section 4 of Telecommunications Facilities”. However, the law aims to ensure the security of the entire telecommunications business in general rather than the protection of personal information
specifically.
There is no provision that requires data breach notifications in the APPI. The
“Policies Concerning the Protection of Personal Information” set forth by the
Japanese Cabinet in 2004 “in accordance with” the APPI state “in the case of
incidents such as data leakage, it is important for business operators handling
personal information to disclose information about the incident to the extent possible
in order to prevent secondary damage or similar cases”. Many business operators
have disclosed information regarding data leaks in accordance with this policy.
Additionally, in 2017, the PPC announced guidelines
11 recommending that operators report immediately to the responsible person and take necessary measures to
prevent expansion of the damage caused by the leakage.
As for the My Numbers, Article 29(4) of the My Number Act obligates relevant
institutions (primarily governmental agencies) to report data breaches to the PPC.
3.2 Data Protection in the Electronic Communications Sector
The Telecommunications Business Law stipulates special protections concerning
“confidential communications handled by telecommunications carriers”.
12
Confidential aspects of communications include information such as their sender,
where and when they were communicated, etc., as well as their contents (Cabinet
Legislation Bureau, Issue No. 24, Dec. 9, 1963). Traffic data held by telecommunications carriers and the source and destination network addresses in the packet
headers on packet communication systems they transmit are also protected as
confidential information associated with communications.
11 The PPC, Guidance for Responding to Cases Such as Personal Data Leaks, etc., (Announcement
No. 1 of 2017 by the Personal Information Protection Committee), https://www.ppc.go.jp/personal/
legal. Accessed 6 Nov 2018.
12 Provisions concerning confidential information protected by secrecy of communications are set
forth in the Constitution of Japan (Article 21(2)), the Telecommunications Business Act (Article
4 and Article 179), the Radio Law (Article 109 and Article 109(2)), and the Cable Telecommunications Act (Articles 9 and 14).
Data Protection in the Internet: Japanese National Report
261
Précédent

- 266/540

Suivant