In this column, we are introducing the 2026 amendments to the Act on the Protection of Personal Information over three installments. Following the data utilization taken up in the first installment, this installment outlines those of the amendments strengthening the protection of personal information that have a significant impact on corporate practice, including the rules on children’s personal information and on facial feature data, and the review of the opt-out system (the numbering of the headings continues from the previous installment (1)). 

 

II. Key Points of the Amending Act

2. Rules Responding Appropriately to Risk

(1) Rules on the handling of children’s personal information 

Until now, there have been no special statutory provisions on children’s personal information, and matters such as the involvement of statutory representatives were set out only in guidelines and the like. However, children’s capacity for judgment is still insufficient, and they are in a position where they are readily exposed to the adverse effects of improper handling of personal information. Accordingly, the current amendments require the involvement of a statutory representative in obtaining certain consents from, and in giving various notifications to, children under 16 years of age, and also make it possible to request the cessation of use, etc. irrespective of whether any unlawful act has occurred. In addition, provisions have been established imposing on businesses and statutory representatives a duty to give priority consideration to the best interests of the child. 

For companies, the methods of verifying users’ ages and of obtaining the consent of statutory representatives will pose practical challenges. On this point, the government has explained that it will not mandate a uniform method. Specific methods are expected to be indicated in guidelines and the like in the future. 

(2) Rules on facial feature data 

Facial feature data means feature information extracted from a face for the purpose of facial recognition. Not only may such data be acquired in large volumes without the individual being aware of it, but because it is highly unique and unchanging, it may also lead to invasion of privacy. Under the current act, facial feature data has been handled under the same rules as ordinary personal information. The amending act, taking as its subject facial feature data rather than mere facial photographs, imposes a duty to make the purpose of use, etc. publicly known, expands the right to request the cessation of use, etc., and prohibits third-party provision under the opt-out system. 

Companies that use facial recognition technology for entry and exit management, identity verification and the like may need to review their operations going forward. 

 

3. Prevention of Improper Use, etc.

(1) Rules on “contactable personally referable information” 

“Personally referable information” means information relating to an individual which, by itself, cannot identify a specific individual. Where such information contains information that can be used to contact the individual, such as a telephone number, address, email address or Cookie ID, combining it with other information may lead to fraud or invasion of privacy. The amending act therefore designates such information as meets the statutory definition as “contactable personally referable information” and adds rules prohibiting improper use and unlawful acquisition, in the same manner as those established for personal information. 

For companies, it will be important in practice to confirm whether the data they handle contains such information and to review the propriety of its acquisition and use. 

 

(2) Rules on the opt-out system 

The opt-out system is a system under which personal data may be provided to third parties without consent, on condition that certain matters are notified to or published for the individual and that a mechanism is established for accepting objections from the individual. Previously, businesses using this system were not under any duty to verify the identity of the recipient or the purpose of use. However, against the backdrop of the circulation of “dark lists” (lists compiling candidates to be targeted for crimes), the amending act requires verification of the recipient’s identity, including its name or corporate name, address and the name of its representative, as well as of the purpose of use, and also prohibits false answers by the recipient. Violations are subject to a non-penal fine. 

 

(References) 

Personal Information Protection Commission, 「令和8年改正個人情報保護法について」 (retrieved on August 6, 2026, https://www.ppc.go.jp/personalinfo/legal/r8kaiseihogohou/) 

Personal Information Protection Commission, 「個人情報保護法等の一部を改正する法律について」 (retrieved on August 6, 2026, https://www.ppc.go.jp/files/pdf/260717_kaiseihounitsuite.pdf) 

Professional Team

© Copyright – Stellex Law Firm | designed by Morcept