The MIC provides guidelines
15 that require telecommunications carriers to make
efforts to restrict the collection of personal information as much as possible to when
it is necessary to provide communication services (Article 6) and to limit the purpose
of use so as not to exceed the necessary range of providing telecommunication
services (Article 4(3)). The guidelines also require telecommunications carriers to
carefully handle some types of information such as communication records, itemized
billing, caller identification, location data, non-payment user information, subscriber
information related to spam mail, and telephone numbers.
3.3 Data Protection and Digital Forensics
Although the APPI calls for an individual’s consent to provide personal data to a
third party, it may also be provided in cases defined as exceptions in the applicable
laws and regulations (Article 23). Therefore, investigation authorities can access
personal data in general based on a search warrant (Article 218 of the Code of
Criminal Procedure) and investigation-related inquiries (Article 197 of the Code of
Criminal Procedure).
To acquire information that includes confidential communications, it is indispensable for investigation authorities to obtain a communications interception warrant (Article 3 of the Act on Wiretapping for Criminal Investigations), a search
warrant (Article 218 of the Code of Criminal Procedure), or to follow other statutory
procedures. Regarding the geographic location data processed by mobile carriers, a
search warrant is required as well (MIC Guideline 35-1).
The Code of Criminal Procedure sets forth procedures for investigating authorities to access records on a cloud server used by a seized computer by copying the
record to the seized computer or other recording medium (Article 218(2)).
A warrant shall contain the scope of the information to be copied from the
electromagnetic records with regard to the recording medium connected via telecommunication lines to the computer that is to be seized.
Interception in the above-referenced act is defined as receiving communications
that are currently being exchanged between parties without notice in order to know
their contents.
Investigation authorities may request in writing that the electronic communications operator refrain from deleting the communications record. In such a case,
investigation authorities must specify the necessary record and period of time, not
to exceed 30 days (Article 197(3) of the Code of Criminal Procedure). The period
may be extended up to 60 days (Article 197(4)).
15 The MIC, “Guidelines for the Protection of Personal Information Handled by Telecommunications Businesses”. (April 18, 2017), http://www.soumu.go.jp/main_sosiki/joho_tsusin/d_syohi/tel
ecom_perinfo_guideline_intro.html. Accessed 6 Nov 2018.
Data Protection in the Internet: Japanese National Report
263
15 that require telecommunications carriers to make
efforts to restrict the collection of personal information as much as possible to when
it is necessary to provide communication services (Article 6) and to limit the purpose
of use so as not to exceed the necessary range of providing telecommunication
services (Article 4(3)). The guidelines also require telecommunications carriers to
carefully handle some types of information such as communication records, itemized
billing, caller identification, location data, non-payment user information, subscriber
information related to spam mail, and telephone numbers.
3.3 Data Protection and Digital Forensics
Although the APPI calls for an individual’s consent to provide personal data to a
third party, it may also be provided in cases defined as exceptions in the applicable
laws and regulations (Article 23). Therefore, investigation authorities can access
personal data in general based on a search warrant (Article 218 of the Code of
Criminal Procedure) and investigation-related inquiries (Article 197 of the Code of
Criminal Procedure).
To acquire information that includes confidential communications, it is indispensable for investigation authorities to obtain a communications interception warrant (Article 3 of the Act on Wiretapping for Criminal Investigations), a search
warrant (Article 218 of the Code of Criminal Procedure), or to follow other statutory
procedures. Regarding the geographic location data processed by mobile carriers, a
search warrant is required as well (MIC Guideline 35-1).
The Code of Criminal Procedure sets forth procedures for investigating authorities to access records on a cloud server used by a seized computer by copying the
record to the seized computer or other recording medium (Article 218(2)).
A warrant shall contain the scope of the information to be copied from the
electromagnetic records with regard to the recording medium connected via telecommunication lines to the computer that is to be seized.
Interception in the above-referenced act is defined as receiving communications
that are currently being exchanged between parties without notice in order to know
their contents.
Investigation authorities may request in writing that the electronic communications operator refrain from deleting the communications record. In such a case,
investigation authorities must specify the necessary record and period of time, not
to exceed 30 days (Article 197(3) of the Code of Criminal Procedure). The period
may be extended up to 60 days (Article 197(4)).
15 The MIC, “Guidelines for the Protection of Personal Information Handled by Telecommunications Businesses”. (April 18, 2017), http://www.soumu.go.jp/main_sosiki/joho_tsusin/d_syohi/tel
ecom_perinfo_guideline_intro.html. Accessed 6 Nov 2018.
Data Protection in the Internet: Japanese National Report
263
