Japan's Personal Information Protection Commission (PPC) on 7 October cautioned businesses that hold personal data at scale to tighten defences against outside intrusion and to delete data they no longer need. The commission said it has seen cases in which widely used services handling large volumes of personal information were hit by unauthorised access, leaving large amounts of data leaked or at risk of leaking.
Who the caution is aimed at
The PPC singled out several groups. They are businesses with a high industry share in services used by many people, or in services where customers find it hard to choose the provider; holders of highly sensitive data, or data that could lead to financial loss or be used in fraud; and others whose leaks would likely harm individuals' rights.
The commission said it investigates cases reported under Article 26(1) of the Act on the Protection of Personal Information and, where needed, uses guidance and its other powers to push companies toward voluntary improvement of the security measures required by Article 23. The caution names no company and announces no new penalty.
What binds and what is only an example
The PPC's guideline annex on security measures separates "measures that must be taken" from "examples of methods". Failing the first can be judged a violation of the law. The examples are illustrations: a company need not adopt all of them, and other methods can be appropriate, scaled to the harm a leak would do to individuals, the firm's size and the nature and volume of its data.
The draft technical measures
Following a decision at its 369th meeting on 16 September 2026, the PPC plans to revise the examples, including a modernisation. It expects to finalise the revision next April, and released the planned content now because it considers it more useful as a reference in the meantime.
The attached draft for technical security measures is organised under five headings: access control; identifying and authenticating users; preventing unauthorised external access; preventing leaks in the use of information systems; and detecting unauthorised access. Among the examples listed are:
- assessing the source location, time and device security state of each access request before deciding whether to allow it;
- multi-factor authentication, including phishing-resistant forms, for access from outside the network, administrator access and access to important data;
- allowing access to personal data only from devices that meet the organisation's security standards;
- keeping and regularly analysing logs;
- detection tools such as IDS/IPS and EDR, and isolating compromised systems or disabling accounts to limit damage.
The draft also carries a separate column of examples for small and medium-sized businesses. The PPC reminded firms that security measures also cover handling rules, organisational, human and physical measures, and understanding of the external environment.
Deleting what is no longer needed
Article 22 asks businesses to make efforts to delete personal data without delay once it is no longer needed for its purpose, for example when the purpose is met or the underlying business is discontinued. Data that other laws require to be retained for a set period is excepted. The PPC said it has seen cases where failure to delete made a leak more serious, and asked companies to review whether stored data is needed, together with its legal basis. Article 22 is a separate provision from the Article 23 security duty.
The PPC also revised its "WARNING" document on preventing leaks through unauthorised access, first issued on 11 December 2024. It groups reported problems into nine case types, from unpatched vulnerabilities and weak logins to inadequate oversight of group companies, cloud service leaks and abused APIs. Insufficient measures against them may be judged a breach of Articles 23, 24 or 25.
The revised examples remain a draft until the PPC's planned finalisation next April.
