Japan's National Police Agency has opened public comment on a rule that decides how, and how much, police tell you after they have acted on your servers.
The draft, published July 24, 2026, sets out the notice police must send once they use new authority to act against a computer identified as the source of an attack on what the underlying law calls a "critical computer". That authority itself is not new. It came from a 2025 law, Law No. 43, which added Article 6-2 to the Police Duties Execution Act and created "cyber harm prevention officers" empowered to carry out "cyber harm prevention measures" against attacking machines. What has been missing until now is the mechanics of telling the administrator of that machine what just happened to it.
Under the draft, officers must notify the administrator by email, or by an unspecified alternative method, with four required items.
| Required item | What it covers |
|---|---|
| Date of action | The date the cyber harm prevention measure was taken |
| Computer identifier | The IP address or other information identifying the computer used in the attack |
| Action summary | An outline of the cyber harm prevention measure carried out |
| Responsible unit | The police unit to which the officer who took the measure belongs |
Notice arrives after the intervention, not before it. The rule contains no requirement to warn an administrator in advance or to seek consent.
The draft also creates an internal reporting duty. Under its Article 3, the director of the Kanto Regional Police Bureau must promptly report to the National Police Agency's Commissioner-General whenever the bureau judges a cyber harm prevention measure is needed. The definitions section separately references a "request for approval" and a "recommendation" tied to other paragraphs of Article 6-2, which suggests the notification duty sits inside a wider approval and advisory structure that this excerpt does not fully spell out.
For companies running servers, cloud instances, or connected devices in Japan, the practical point is straightforward: a machine hijacked for use in an attack, even unknowingly, can be acted on by police first and explained by email second. The rule does not touch liability for running a compromised system. It only fixes what police must disclose once they have already stepped in.
Comments are open through August 22, 2026, submitted via the e-Gov comment form, by email to [email protected] with "パブリックコメント" in the subject line, or by post to the National Police Agency's Cyber Police Bureau, Cyber Planning Division, in Chiyoda-ku, Tokyo. The draft carries the signature of National Public Safety Commission Chairman Jiro Akama.
