The use of cookies or other similar technologies is not directly regulated by the current APPI, unless such use allows the identification of an individual by combining the data obtained with other data; However, if personal data is collected through this technology, such personal data is subject to the APPI. Currently, there is no reporting requirement under the IPPA, and the PPC notification only provides that a material handling operator must endeavor to report a breach to the government through the PPC, an accredited data protection agency, or any other regulatory body or body. However, no notification is required in the following cases: In THC judgments of 25. In March 2020, on appeals against the two TDC judgments mentioned above, it was found that the subsidiary could reasonably expect that its controls against data exports to new Android smartphones using MTP would not work, and therefore breached its duty of care by not controlling data exports to new smartphone models. Benesse had breached its duty of care by failing to monitor the subsidiary, so that the subsidiary and Benesse were liable as accomplices to damages in the amount of JPY 3,300 (approximately €27) plus 5% late fees per year and per person concerned. If entrepreneurs become aware of a data breach that may violate the rights and interests of individuals, they are now required to notify the PPC as well as the data subjects. You must first submit an initial report to inform the PPC of the situation as soon as possible, and then submit a secondary report outlining the specific causes and corrective actions taken. If direct notification of affected individuals proves too difficult, the APPI allows entrepreneurs to make a public announcement and set up an office to process applications. As noted above, depending on the circumstances of the case, it may be appropriate for prior informed consent to publicly disclose the relevant facts of the data breach and the steps to be taken to prevent its recurrence; There is no indication of the form that such notification should take and, although it may be sufficient as a communication to the contracting entities concerned, its effectiveness as such should be carefully evaluated. It is important to note that recent political support for stronger data protection measures goes beyond transfers to China. For example, Amari also reportedly called on the PPC to widely limit the permitted transfer of personal data abroad to countries with data protection standards equivalent to the APPI (a restriction that, if implemented, would far exceed the restrictions on transfers under the current APPI and the 2020 amendments).
In addition to pseudonymous information, the 2020 amendments introduce a fourth additional category of information under Article 26(2) – namely «information that may be the subject of a personal reference». This fourth category includes cookies and purchase history (for example) which may not be independently linked to a specific person (and therefore would not constitute PI), but which, if transmitted to an operator with additional related data, could become PI. To account for these qualified transfers, the 2020 amendments introduce a consent requirement (e.g. an opt-in cookie banner). LINE also plays a crucial role for the Japanese government: government agencies at the national and local levels use LINE for official communications, including sensitive personal data such as COVID-19 health data collection. The news of LINE`s transfer of user data to China, including possible access by the Chinese government, has therefore horrified individuals and officials. 6.1 Is there a legal obligation for companies to register or inform the Data Protection Authority (or other government body) in relation to their processing activities? Under the current IPAP, while the obligation to report a data breach to the PPC is only an effort, it would be preferable to file a report unless one of the above exceptions applies (in which case a report is not required). If the pilot-in-command believes that the data breach is not serious enough to warrant formal reporting, but is not exempt from reporting, the pilot-in-command may seek informal advice from the PPC on what action to take. If the data breach is very serious, for example: loss of bank details and passwords, or the PIC is not sure what action to take, the PIC should contact the PPC (and local legal counsel) as soon as possible without waiting for the official report to the PPC. If a data breach is not reported and PPC becomes aware of it later, it may request the submission of a report.
9.7 What are the maximum penalties for sending marketing communications in violation of applicable restrictions? While the privacy policy only states that it is «desirable» for an affected pilot-in-command to take action, including notification of affected parties as well as publication of the incident, and that ICPs should «make efforts» to notify the PPC, the guidelines on the protection of personal data in the financial sector published jointly by the PPC and the FSA, provide that such measures are mandatory in the financial services sector. Similarly, the commentary published by the MIC, which contains information on the Law on Telecommunications Enterprises (Law No. 86 of 25 December 1984), provides that a violation of the secrecy of communications must be reported to the Authority. (ii) significantly strengthen companies` disclosure and due diligence obligations with respect to data transfers abroad; The customer`s prior consent to a transfer of their personal data (including sensitive information) is not required if the transfer: According to the amended APPI, a report to the PPC and notification of data subjects are mandatory in certain cases, and the new regulations clarify the details of this obligation. Any loss of certain personal data must be reported to the PPC, although there is no set deadline for notification; The form of the report is slightly different from that of data breaches. The system of escalation of corrective orders by the PPC is the same as for the loss of other personal data, although failure to comply with an improvement order may result in more severe criminal penalties for both the PIC and one of its officials responsible for the loss. Notification of affected customers is still only «desirable». Russia: New law requires explicit consent to make personal data public and later disclose it Failure to comply with an improvement order would result in a prison sentence of up to six months or a fine of up to 300,000 JPY (about €2,500) for a person who is the PIC. the director or employee of the PIC entity responsible for the infringement and the same criminal fine for PIC as a company. There are no specific restrictions on video surveillance data that differ from restrictions on other personal data under the APPI. In the event that a data recipient does not directly link the information provided to other stored personal data, even if the information provided can easily be linked to the personal data, this does not necessarily fall under the notion of «receiving the information provided as personal data» and, therefore, the data provider is not obliged to confirm that the recipient of the data has obtained his consent.
The PPC FAQ further explains that this exception applies when a contractor is considering outsourcing (i.e. outsourcing) the processing of data to a third party abroad, but the location of the foreign country cannot be specified because the mandated party has not yet been determined. In this case, the data subject will receive information about the inability to indicate the foreign country and provide the required information, as well as the specific reason for the case (including the need to obtain the consent of the person before the designated party has been determined). If it is possible to provide useful information to individuals, such as information on candidate countries abroad, this information should also be provided. Recently, PPC published a report explaining the data protection systems for 31 countries and regions (as shown in the graph below) on its website.