The secretariat of Japan's Personal Information Protection Commission on October 1, 2026 set out how it intends to write the rules for a new statutory route that lets companies hand personal data to one another, and collect sensitive information already published online, for statistics and AI development without asking the people concerned. The same draft paper proposes a narrower regime for outsourced data processors and lighter paperwork after small data leaks.
In Short
Japan has already passed a law that lets companies use people's information to make statistics and train AI without asking them first, and on October 1 its privacy regulator sketched the detailed rules that will decide how that works. It matters to anyone whose details sit in a company database or on a public web page in Japan, and to the firms that build AI models or handle data for other businesses. If the proposals stick, companies using the shortcut would have to post the details on a public page that search engines can read, contractors handling data would be barred from using it for their own purposes, and many small leaks could be reported to the regulator in batches.
The second instalment of draft rules
The 53-page paper, dated October 1, 2026, was prepared by the secretariat of the Personal Information Protection Commission and carries the label "draft". It is the second in a series setting out the basic approach to the Cabinet Orders and commission rules needed to implement the Act Partially Amending the Act on the Protection of Personal Information, enacted as Act No. 56 of 2026. Much of what the law does is already fixed in statute. What the paper addresses is the detail that the Diet delegated to the regulator: which activities qualify, what must be published, what contracts must contain and which leaks still require a fast report to the commission.
Three topics are covered. The first is the statistics creation exception, the provision that has drawn most attention because it expressly reaches AI development. The second concerns contractors that handle personal data on another business's behalf, which Japanese law calls entrustees. The third deals with breach reporting and the duty to notify affected individuals. According to the paper, the remaining parts of the amended law, including rules against improper use and provisions to make compliance enforceable, will be taken up at later commission meetings, along with guidelines. An overview table attached to the paper also lists delegated provisions on children under 16 and on facial feature data that this instalment does not discuss.
No date for the rules to take effect appears anywhere in the document. Each proposal is put to the commission as a question rather than a settled position, and several invite suggestions for items the secretariat has not listed.
The change is substantial for a statute that, when OpenAI's advertising plans for Japan surfaced in May, had last been amended in 2022.
What the statistics exception allows
Under the current act, acquiring special care-required personal information - the Japanese category for data such as creed, medical history and criminal record that can lead to discrimination - requires the individual's consent under Article 20(2). So does handing personal data to a third party under Article 27(1), unless a listed exception applies. The secretariat points to growing demand among businesses to pool data held by several companies and analyse it across sources, and argues that statistics stripped of any link to particular individuals pose little risk to their rights.
The amended law responds with two routes. Article 30-2(1) allows a business to acquire, without consent, sensitive information that is currently public, provided it is used only for statistics creation. A diagram in the paper labels the source of that information as acquisition through web scraping and similar methods. Article 30-2(5) and Article 31-3(1) allow a business to provide data to a third party without consent on the same condition, notwithstanding the purpose limits in Article 18 and the consent requirement in Article 27(1). A footnote states that the third-party route covers personal data, personal information that is not personal data, and personally referable information, the category Japan created for identifiers such as cookie IDs and browsing histories that do not identify anyone by themselves.
The reach goes further than a first reading suggests. According to the paper, a transfer under the exception may exceed the purposes originally specified under Article 17, and the recipient may thereby obtain sensitive information without consent. Administrative bodies get a parallel extension of their existing statistics exception.
Statute sets the outer fence. Article 2(13) defines statistics creation as producing information on the tendencies or properties of a large body of information, excluding information about individuals, by extracting the elements that make it up and classifying, comparing or otherwise analysing them - but only those activities that commission rules specify as unlikely to harm individuals' rights and interests. A footnote states that the definition includes AI development that can be organised as statistics creation. Both sides of a transfer must publish certain details, provider and recipient must agree in writing that the transfer serves statistics creation only, and acquirers and recipients are barred from other uses and from passing the data on, although an acquirer may itself provide data under the exception. Security management, supervision of staff and subcontractors, the ban on improper use in Article 19, complaint handling under Article 40 and the right to demand suspension or deletion under Article 35 all continue to apply.
Three safeguards the rules would demand
The definition hands the commission the decisive question: which statistics-making activities are low-risk enough to qualify? According to the secretariat, using data only to build statistics or AI models from which the link to specific individuals has been removed has no direct effect on those individuals. That conclusion holds, the paper argues, only if the guarantee is adequate; without one, consent would still be needed.
The proposal therefore confines the exception to activities carried out with three sets of measures in place. The first must prevent use or onward provision beyond what statistics creation requires. The second must prevent leaks and secure the data more generally, and the paper specifies that leaks include restoration, the recovery of source data from the statistics or model. The third must ensure that data no longer needed is deleted without delay. A footnote gives examples of qualifying measures - organisational arrangements and the use of privacy-enhancing technologies, or PETs - applied on the basis of a risk assessment and recorded.
That restoration clause matches what Kiyoshi Sawaki, appearing as a government witness, told a House of Representatives special committee on May 21, 2026. The rules, he said, would require necessary and appropriate measures "to prevent output or restoration from AI models", according to the extract of the Diet record attached to the paper (translation by PPC Land). The risk is measurable. A University of Tübingen study cited in a comparative review of 19 regulatory guidelines on AI training found that large language models memorise between 0.1 and 10 percent of their training data verbatim, and the same review found PETs widely mentioned by regulators but rarely specified in operational terms.
Kuniko Ogawa, also a government witness, told the House of Councillors health, labour and welfare committee on June 9 that the rules were expected to require deletion of unnecessary data items alongside the other safeguards. The regime as a whole, she said, would provide "a level of protection equivalent to the GDPR".
Contacting people to collect their reactions would be excluded
A second question concerns what falls outside the definition altogether. The secretariat's suggested answer targets a specific practice: a company that, to enlarge its training data, uses descriptions contained in data obtained under the exception to approach the individuals concerned and capture their reactions. Methods that act directly on individuals while statistics are being built would be restricted, according to the paper, because the whole justification for the exception rests on the absence of direct effects. The commission is asked whether anything else belongs on the excluded list.
The boundary is narrow but pointed. Prompts sent to people to see how they respond, or experiments designed to generate fresh behavioural data from individuals found in a dataset, would on the paper's description fall outside the exception and back under the act's ordinary consent rules.
What a provider cannot hand over
Diagrams in the paper set limits on the supply side. A provider may rely on the exception only where the recipient needs the data for statistics creation. Data carrying a high risk of harm, and data the statistical purpose does not need, cannot be provided where removing it is not technically difficult. Parties are encouraged, though not required, to confirm and record the statistics to be produced, the data items required and the safeguards in place.
It is a form of data minimisation written into the transfer itself. Sawaki made the same point to the House of Councillors special committee on digital society and AI on June 24: explaining that data is provided only as far as necessary meant publishing in a way that showed, for instance, that "addresses are not needed, names are not needed".
One page, open to crawlers
Publication is the exception's main transparency device. The law fixes two items: the names of the businesses involved and the content of the statistics creation they intend to carry out. Method and further items fall to the commission. According to the paper, the aim is to let individuals and society judge the practice, push businesses towards proper handling and give the regulator a starting point for supervision, which requires a method with high transparency and searchability.
The secretariat suggests publication on the company's own website, subject to four conditions:
- every item on a single web page;
- no measures taken to prevent crawling;
- specific keywords included so the page can be found through search;
- the page kept available long enough for an unspecified number of people to notice it.
The second condition reverses a common habit. Corporate compliance pages are often kept out of search indexes; under this proposal the page would have to stay open to automated collection, which would appear to rule out a robots.txtdisallow rule or similar blocks. Sawaki described the intent to the upper house committee on June 24 as posting on a single page without anti-crawling measures, "making mechanical search possible". The paper also asks whether publication on a website designated by the commission could serve, an arrangement closer to a central register.
Five groups of items
Beyond the two statutory items, the paper proposes grouping further publication items under five headings, each with examples. The first covers the acquiring, providing and receiving businesses, including addresses and representatives' names. The second describes the information itself: an outline, its nature and its data items. A third records the acquisition or provision, such as its timing. The recipient's handling forms the fourth, including the planned statistics creation and how long the data will be held. Finally come the details individuals need to exercise their rights: a complaints contact, the URL of the recipient's publication page and how the provider originally obtained the data.
The structure resembles the eight items Japan already requires businesses to publish for opt-out transfers under Article 27(2), which the secretariat attached as a reference alongside the joint-use and retained-data disclosure rules.
Changes need both parties
Amending published items follows a two-tier structure set in Article 30-2(7). Substantive items, such as the content of the statistics creation, can change only if provider and recipient both publish the change in advance, which the paper treats as equivalent to providing the data afresh. A note spells out the consequence: unless the provider agrees to publish, the recipient cannot change those items. Formal items, starting with the recipient's own name, can be changed by the recipient alone provided it publishes promptly. The secretariat proposes extending this simple route to the provider's name, the parties' addresses and representatives' names, the complaints contact and minor handling details such as the planned retention period.
Records, and data leaving Japan
Businesses already keep records of third-party transfers under Articles 29 and 30, and individuals can obtain them through disclosure requests under Article 33. The paper proposes the familiar entries - date of provision, names and addresses of the parties and their representatives, details sufficient to identify the individuals, the data items and, for recipients, how the provider obtained the data. To these it adds entries specific to the exception: the planned statistics creation, an outline of the recipient's safeguards, confirmation that the written agreement and publication exist, the recipient's complaints contact and its planned retention period.
Cross-border transfers keep the existing restrictions of Article 28, but the paper argues their coverage must widen. Under the exception, the rules have to reach all information about individuals before it becomes statistics, not only personal data, so the standard-compliant system a foreign recipient must maintain is extended to match. Current rules define the standard in Rule 16 as contractual or similar measures consistent with the act, or certification under an international framework. Rule 18(1) requires periodic checks and a halt to transfers when equivalent protection can no longer be ensured, and Rule 18(3) lists information to be provided, including how the system was established, an outline of the measures and the name of the foreign country. The secretariat proposes extending all three to personal information in its broader sense.
The question carries commercial weight. Japan has held a reciprocal data adequacy arrangement with the European Union since January 2019, which lets personal data move from Europe to Japan without additional transfer tools.
Contractors: a new duty, and a way out
The second topic concerns businesses entrusted with personal data. Under Article 25 the entrusting business must supervise its contractor by choosing an appropriate one, signing a contract and keeping track of how data is handled. Where the contractor is itself a business handling personal information, every obligation in Chapter 4 of the act applies to it as well. According to the paper, cases in which businesses in effect depend on third parties to handle personal data have multiplied, supervision has not always worked, and some contractors have used entrusted data on their own account beyond the scope of their contract.
The amended act moves in two directions at once. It imposes an express statutory duty on contractors not to handle entrusted data beyond what the entrusted work requires, with exceptions envisaged where laws require otherwise or for urgent needs such as saving lives or disaster relief. Administrative bodies acting as contractors fall under the same rule. At the same time, Article 58-2 exempts contractors, in principle, from the Chapter 4 obligations where the contract fixes the method of handling and the contractor keeps within it. The overview slide describes the intended beneficiaries as contractors that do not decide the method themselves, citing data entry performed mechanically on the client's instructions. The contract must also oblige the contractor to report promptly to the client any leak, any handling beyond scope and any breach of the contract terms. The scope duty and the security obligations survive the exemption.
What the contract would have to say
Four items would make up the method of handling fixed in the contract, according to the secretariat's proposal: the data concerned, including its data items; the processing operations - acquisition, storage, evaluation, processing, provision and deletion - with sources and recipients named where data is acquired or provided, and criteria stated where it is evaluated or processed; the start and end of handling; and the countries or regions where handling takes place, including whether it occurs abroad and, if so, where. Contracts would be in writing, electronic records included, and the client could specify some items in writing later under the contract.
Six further contract terms are suggested: the content of the entrusted work; keeping handling records and supplying them to the client; supplying information on security measures; reporting what the client needs to respond to a leak, including what it needs for its own report to the commission under Article 26(1); stopping handling at the client's request; and returning or deleting data when the contract ends. The paper accepts that contractors will inevitably decide minor details that do not affect individuals' rights, and asks how specific each item needs to be.
The attachments show where the model comes from. The secretariat reproduced GDPR Articles 4(7), 4(8) and 28(3), together with the European Data Protection Board's Guidelines 07/2020. Those guidelines reserve "essential means" - which data, for how long, who has access and whose data - to the controller, leaving non-essential means such as hardware choices or detailed security measures to the processor. Japan's proposed list follows those essential means closely.
For marketing technology vendors, the scope duty is the provision with teeth. France's CNIL fined Optimove 1 million euros on December 11, 2025 after finding that the company had copied a client's non-anonymised user data into a non-production environment in April 2019 and processed it for internal purposes without instructions. Kenya's regulator, in a draft guidance note dated July 2026, gave processors 48 hours to notify a controller of a breach. Japan's text requires the contractor to report promptly but sets no hourly deadline.
Breach reports: 84% involve one person
The third topic starts from numbers. Under Rule 7 of the current enforcement rules, a business must report to the commission when a leak involves sensitive information not protected by strong encryption or similar measures, data whose misuse could cause financial loss, a suspected act with a wrongful purpose against the business, or more than 1,000 people. Rule 8 requires a preliminary report promptly after the business learns of the incident and a final report within 30 days, or 60 days for wrongful-purpose cases such as cyberattacks. Affected individuals must be notified in every reportable case unless that is difficult.
Figures from the commission's interim review of the act, reproduced in the paper, show where the volume lies. Incidents affecting 1,000 people or fewer made up 96.0% of reports, or 11,635 cases. Single-person incidents alone accounted for 84.0%, or 10,184 cases. Incidents affecting two to 10 people represented 7.6% (918), those affecting 11 to 100 people 2.8% (341) and those affecting 101 to 1,000 people 1.6% (192). The percentages imply roughly 12,100 reports in total and about 485 involving more than 1,000 people, according to PPC Land's calculation; the paper does not state the period covered. Most single-person cases, according to the interim review, involved hospitals or pharmacies handing over or losing documents containing sensitive information, or credit cards sent to the wrong address.
For comparison, Bavaria's data protection authority, which supervises private companies in a single German state, received 3,603 breach notifications in 2025, 524 of them involving ransomware.
Four changes under consideration
The first concerns notification. Amended Article 26(2) permits a substitute measure in place of notifying individuals where failing to notify them poses little risk to their rights. The paper's candidate is a leak consisting only of information meaningless on its own, such as internal user IDs not shared with any outside business or organisation. Both chambers of the Diet asked that the rules state the specific scope and criteria, so that businesses' "arbitrary judgment, abuse and expansive interpretation" do not harm individuals.
Reporting itself is the second. Businesses whose systems and procedures have been checked by a third party could be exempted from preliminary reports within a certain range. For incidents affecting a single person, starting with mistaken handovers and misdeliveries, they could file final reports bundled by period. The checks would cover matters such as appointing a responsible person and having procedures to establish facts promptly, prevent recurrence and notify individuals. The proposed checkers are accredited personal information protection organisations, bodies certified by the commission under the act, and the paper asks whether others could play that role. A blanket exemption is ruled out: some incidents require the commission to issue warnings quickly or decide whether to investigate, so not every case could skip the preliminary report.
Cyber incidents form the third. Japan's Act No. 42 of 2025 on preventing damage from unauthorised acts against important computers, referred to in the paper as the cyber response capability enhancement act, brings its own incident reporting duty. According to the paper, reports submitted on a common format for ransomware and similar incidents would go through a single contact point, with the necessary coordination under the National Cybersecurity Office (NCO), and the thresholds for reporting breaches caused by cyberattacks would be aligned between the two regimes. The paper quotes discussion of the cyber law stressing that incident reports reach the government quickly, through a mechanism that gathers information efficiently without burdening businesses and feeds results back.
The fourth covers illegal transfers. A business's unlawful provision of personal data to a third party is not currently a reportable event, and the act imposes no notification duty for it. The paper argues that deliberate transfers affect individuals no less than accidental leaks and, as a class, carry a greater risk of secondary harm. It proposes making them reportable regardless of the type of data or the number of people affected - in other words, without the 1,000-person threshold that governs ordinary leaks.
Europe is moving the other way on thresholds. The Council presidency compromise of September 3, 2026 on the Digital Omnibus would confine GDPR breach notification to incidents likely to cause high risk and extend the deadline from 72 to 96 hours. Elsewhere, Egypt's regulator expects notification within 72 hours, while India requires six hours for significant data fiduciaries.
What the Diet asked for
The paper attaches the supplementary resolutions both chambers passed with the bill, and they pull in slightly different directions. The House of Representatives special committee on regional revitalisation, children's policy and digital society, in its resolution of May 21, 2026, asked the government to keep the rules consistent with the GDPR and other foreign systems while ensuring that research, development and business activity including AI development is not excessively chilled. It asked for reliable measures preventing identification of individuals through matching with other information, and warned against the statistics concept being interpreted restrictively so that its practical scope is narrowed. It also asked that the commission itself track published notices and release information, and that handling of sensitive information for statistics come with thorough security measures and supervision of contractors.
The House of Councillors special committee on digital society and AI, resolving on July 8, 2026, covered the same ground with additions. It asked that the risk of identification of specific individuals, or inference of sensitive information, by AI models be fully taken into account. Monitoring was to extend to published notices by businesses "including foreign companies", with the commission publishing information and collecting reports where appropriate. Handling of sensitive data for statistics was to be a focus of the commission's supervision. For medical data, it asked for revised guidelines clarifying the relationship with doctors' confidentiality duties and with the ethical guidelines on life science and medical research involving human subjects.
How Japan's approach compares
Japan's statute treats as a lawful target what European proposals mostly treat as residual. The European Commission's Digital Omnibus draft of November 2025 proposed an Article 9(2)(k) allowing sensitive data in AI development only where controllers avoid collecting it to the greatest possible extent and remove it when identified. The European Data Protection Board's Guidelines 03/2026 on web scraping, adopted on July 7, 2026, recommend excluding categories of websites that structurally contain sensitive personal data and treat only incidental collection of special category data under a search engine analogy. Japan's Article 30-2(1), by contrast, names currently public sensitive information as something a business may set out to acquire, provided the purpose is statistics creation.
The legal technique differs too. Europe's draft routes AI development through legitimate interest, with its balancing test against the rights of the people concerned; the Council's text renumbers the clause Article 88 bis. Japan uses a definitional carve-out backed by publication, written agreements and purpose locks, with no balancing test written into the statute, while leaving suspension and deletion rights intact. On transparency the two systems converge in an unexpected place: the EDPB guidelines describe a public privacy policy listing data categories and sources as a measure a scraper relying on the disproportionate-effort exemption must always take, and Japan's single searchable page performs a similar function.
The secretariat plainly has the GDPR in view. It attached Articles 5(1)(b), 9 and 89(1), which treat statistical purposes as compatible with original collection and require safeguards such as data minimisation and pseudonymisation, along with the information duties in Articles 13 and 14. Ogawa's equivalence claim invites comparison with that text.
Within Asia, the closest neighbour moved earlier. South Korea's Personal Information Protection Commission published draft guidelines on processing publicly available data for generative AI in August 2025, and on March 31, 2026 cut the forms required for pseudonymous data processing from 24 to 10 under a three-tier risk system. Japan's own AI framework rests on the AI Promotion Act promulgated on June 4, 2025, which set up an AI Strategy Headquarters within the Cabinet.
Why this matters for the marketing community
Japan is a live market for the platforms building advertising businesses on AI. ChatGPT advertising went live in Japan on June 22, 2026. The rules drafted on October 1 bear on that activity in at least four ways.
First, the exception covers personally referable information, the category that includes the identifiers on which much of ad tech runs. Data of that kind could move between companies for statistics and model building without consent, but the paper's proposed exclusion of methods that act on individuals draws a line at using the same data to approach people and harvest their responses. Where model building ends and targeting begins is precisely the boundary the commission is being asked to draw.
Second, every data partnership relying on the exception would leave a public trace. A single page, open to crawlers, keyword-tagged and listing provider, recipient, data items, purpose and retention period, would give competitors, journalists, researchers and privacy groups a machine-readable map of who supplies data to whom. The proposed requirement that substantive changes be co-published by both parties ties the recipient to the provider for as long as the arrangement lasts.
Third, vendors acting as contractors - measurement firms, customer data platforms, agencies running campaigns on client data - would face a statutory ban on using entrusted data beyond the contract, alongside an exemption whose price is a written contract listing processing operations, durations and the countries involved. Pooling clients' data for a vendor's own model training is the kind of use the duty targets: the paper cites contractors that used entrusted data on their own account as one reason for the change.
Fourth, the reporting changes affect retailers and service businesses whose most common incident is a single misdirected message or parcel. Batch filing for such cases would depend on vetting by an accredited organisation, making accredited vetting the price of lighter paperwork.
What remains open
Seven numbered questions on the statistics exception, three on contracts and six on breach reporting remain with the commission, several of them explicitly inviting additions. The overview table indicates that guidelines and Q&A material will follow, including the commission's thinking on when handling is necessary for statistics creation. The remaining topics of the amended law, from improper use to enforcement, are due at later meetings, and the paper offers no date for the rules to apply.
Timeline
- June 4, 2025 - Japan promulgates the AI Promotion Act, setting up an AI Strategy Headquarters within the Cabinet
- August 2025 - South Korea's PIPC publishes draft guidelines on processing publicly available data for generative AI
- November 2025 - The European Commission's Digital Omnibus draft proposes a legitimate interest basis for AI training and Article 9(2)(k) on sensitive data
- December 11, 2025 - France's CNIL fines Optimove 1 million euros for processor violations
- March 31, 2026 - South Korea's PIPC cuts required pseudonymous data forms from 24 to 10
- May 21, 2026 - The House of Representatives special committee adopts its supplementary resolution on the amendment bill; Kiyoshi Sawaki describes the planned safeguards against output or restoration from AI models
- June 9, 2026 - Kuniko Ogawa tells the House of Councillors health, labour and welfare committee the regime would match GDPR protection levels
- June 22, 2026 - ChatGPT advertising goes live in Japan
- June 24, 2026 - Sawaki tells the House of Councillors special committee that published notices will sit on a single page without anti-crawling measures
- July 7, 2026 - The EDPB adopts Guidelines 03/2026 on web scraping for generative AI
- July 8, 2026 - The House of Councillors special committee adopts its supplementary resolution, including monitoring of foreign companies' notices
- July 2026 - Kenya's data protection regulator dates draft AI guidance giving processors 48 hours to report breaches
- September 3, 2026 - The EU Council presidency compromise proposes a 96-hour, high-risk-only GDPR breach notification rule
- October 1, 2026 - The Personal Information Protection Commission secretariat issues its second draft paper on rules implementing Act No. 56 of 2026
- October 30, 2026 - The EDPB's consultation on Guidelines 03/2026 is due to close
Related PPC Land coverage
- EDPB blocks AI firms from using consent as an excuse to scrape - The European board's July 2026 guidelines on scraping, sensitive data and the legitimate interest test for AI training.
- EU Council draft drops unconditional opt-out from GDPR AI clause - The September 2026 presidency compromise on Article 88 bis, breach thresholds and sensitive data in AI development.
- European Commission proposes major GDPR changes for AI and data processing - The original Digital Omnibus amendments on AI training, sensitive data and breach notification.
- GDPR's AI training legal battle: regulators converge but still clash - A study of 19 regulatory guidelines finding agreement on principles and divergence on operational safeguards such as PETs.
- South Korea establishes AI privacy framework with new guidelines - Korea's August 2025 draft rules for publicly available data in generative AI.
- South Korea rewrites the rulebook on pseudonymous data for AI - The March 2026 overhaul introducing three risk tiers and cutting paperwork for AI training data.
- Asia's AI laws are finally here - and they couldn't be more different - How Japan's AI Promotion Act compares with South Korea's and Taiwan's frameworks.
- French regulator fines Israeli marketing platform 1M euros for processor violations - The CNIL case against a marketing vendor that used client data beyond its instructions.
- Kenya forces impact assessments on recommendation engines and 7 other AI uses - Draft guidance setting a 72-hour regulator clock and a 48-hour processor clock for AI-related breaches.
- Email marketers in Egypt face 3-year consent proof rule, PDPC checklist shows - Egypt's compliance checklist and a comparison of national breach notification deadlines.
- Bavaria's data watchdog hit a record 9,746 complaints in 2025 - and AI is partly to blame - Breach and ransomware notification volumes at one German regulator.
- OpenAI gains 7 Asian markets for ChatGPT ads, passing 60 countries - ChatGPT's advertising roll-out across Asia, including the June 2026 Japan launch and differing privacy rules by market.
- ChatGPT Ads finally leave the US: UK, Japan, Korea, Brazil and Mexico next - The May 2026 expansion plan and the privacy frameworks in each new market.
Summary
Who: The secretariat of Japan's Personal Information Protection Commission, which drafted the paper; businesses handling personal information in Japan, including AI developers, data providers and contractors; administrative bodies covered by parallel provisions; and the two Diet committees whose supplementary resolutions frame the rules.
What: A draft basic approach to the commission rules implementing three parts of the amended Act on the Protection of Personal Information: the statistics creation exception allowing consent-free provision of data and acquisition of public sensitive information for statistics and AI development, subject to safeguards, written agreements and publication on a single crawlable web page; a statutory scope duty for contractors with an exemption for those whose contracts fix the method of handling; and changes to breach reporting, including substitute notification for low-risk leaks, batch filing for single-person incidents, alignment with cyber incident reporting and coverage of illegal transfers.
When: The paper is dated October 1, 2026. The Diet committees adopted their resolutions on May 21 and July 8, 2026. No effective date for the rules is given.
Where: Japan, with cross-border provisions extending standard-compliant system requirements to foreign recipients of data shared under the statistics exception.
Why: The amended law delegates the decisive details to the commission. The secretariat argues that statistics and AI models stripped of links to individuals pose little risk only if their use is guaranteed, that contractors bound by detailed contracts need not carry every obligation, and that single-person leaks, 84% of reports, rarely require urgent regulatory attention when individuals are properly notified.
Discussion