World Watch/Japan/Cybersecurity

Cybersecurity · Japan

Cybersecurity regulation in Japan (2026)

Comprehensive lawBasic Act on Cybersecurity (Act No. 104 of 2014), supplemented by the Active Cyber Defense Act (enacted May 2025); coordinated by the National Cybersecurity Office (NCO) under the National Cyber Director. Personal-data breach duties sit in the Act on the Protection of Personal Information (APPI), enforced by the Personal Information Protection Commission (PPC).Country index 88 · A

Japan shaded by its cybersecurity status

Japan operates a comprehensive cybersecurity regime anchored by the 2014 Basic Act on Cybersecurity, which sets national policy, defines government roles, and mandates a periodic Cybersecurity Strategy (latest issued December 2025). In May 2025 Japan enacted the Active Cyber Defense Act, a major shift from passive to active defense that adds public-private collaboration, government monitoring of certain communications data, and incident-reporting/notification duties for designated critical-infrastructure operators (phasing in by late 2026/2027). Mandatory personal-data breach reporting to the PPC has applied since the 2022 APPI amendments, alongside sector-specific rules from regulators such as the FSA.

Key points

Foundational law

The Basic Act on Cybersecurity (2014) establishes Japan's basic cybersecurity policy, clarifies the responsibilities of national/local government and operators, and requires formulation of a national Cybersecurity Strategy.

Active Cyber Defense Act (2025)

Enacted 16 May 2025, the ACDA moves Japan from passive to active defense via four pillars: public-private collaboration, monitoring of communications data, counter-access to attack sources, and neutralization by authorities; provisions phase in through 2027.

National authority (NCO)

Following the May 2025 legislation, NISC was reorganized into the National Cybersecurity Office (NCO), headed by a National Cyber Director, established in July 2025 as the central coordinating body.

Personal-data breach reporting (APPI)

Since the April 2022 APPI amendments, operators must report qualifying breaches (sensitive data, risk of property harm, malicious/cyberattack cause, or >1,000 affected individuals) to the PPC and notify affected individuals — a prompt preliminary report (typically 3-5 days) plus a final report within 30 days (60 for malicious cases).

Critical-infrastructure incident reporting

The ACDA introduces an incident-reporting obligation for designated essential-infrastructure providers and advance notification when deploying specified critical computers; this regime is set to take effect on or before November 2026.

Sector-specific rules (finance)

The Financial Services Agency's Comprehensive Guidelines for Supervision of Major Banks require banks to report cybersecurity incidents immediately upon becoming aware, including damage summary, remediation, user/public notification, and preventive measures; METI/IPA issue cross-sector management guidelines.

Timeline - major decisions & events

Dec 23, 2025guidance
New five-year National Cybersecurity Strategy adopted

Japan's Cabinet adopted a new five-year cybersecurity strategy framing cyberattacks as a 'serious security threat' and committing to a state-led model coordinating police, the SDF, and the private sector to detect and respond to threats.

The Japan Times
Jul 1, 2025decisionofficial
National Cybersecurity Office (NCO) replaces NISC

Japan reorganized NISC into the National Cybersecurity Office, headed by a National Cyber Director, with enhanced staffing and elevated reporting to the prime minister—centralizing cross-government cyber policy ahead of active-defense implementation.

National Cybersecurity Office (NCO)
May 16, 2025law
Active Cyber Defense Law enacted

The Diet passed landmark legislation authorizing the government to monitor foreign-origin internet traffic and pre-emptively neutralize hostile cyber infrastructure abroad—a decisive shift from passive to active cyber defense, phasing in through 2026–2027.

Nippon.com
Jun 8, 2024incident
Kadokawa and Niconico ransomware attack

The BlackSuit ransomware group breached media giant Kadokawa, leaking roughly 254,000 individuals' data and crippling the Niconico platform; Kadokawa reportedly paid ~$3M yet data was still leaked, underscoring Japan's private-sector exposure.

Kadokawa Corporation
Jul 4, 2023incident
Port of Nagoya paralyzed by LockBit ransomware

A LockBit 3.0 ransomware attack disabled the Nagoya Port Unified Terminal System, halting Japan's busiest cargo port (≈10% of national trade) for over two days and exposing critical-infrastructure OT vulnerabilities.

The Register
May 11, 2022lawofficial
Economic Security Promotion Act enacted

This law introduced prior government screening of critical equipment and outsourcing by designated essential-infrastructure operators (electricity, finance, telecoms, etc.), embedding supply-chain cybersecurity review into national economic security.

Japanese Law Translation (Govt of Japan)
Apr 1, 2022lawofficial
Amended APPI mandatory breach notification takes effect

The amended Act on the Protection of Personal Information made reporting to the Personal Information Protection Commission and notifying affected individuals mandatory for breaches involving cyberattacks, sensitive data, or 1,000+ records.

Japanese Law Translation (Govt of Japan)
Sep 28, 2021guidanceofficial
Cybersecurity Strategy 2021 adopted

The Cabinet approved Japan's third national strategy under the Basic Act, prioritizing a 'free, fair and secure cyberspace' and explicitly citing rising state-sponsored threats from China, Russia, and North Korea.

NISC / Govt of Japan
Dec 12, 2018law
Basic Act on Cybersecurity amended

Amendments expanded coordination mechanisms, creating a Cybersecurity Council to facilitate public-private information sharing among government, critical-infrastructure operators, and experts.

U.S. Library of Congress
Jan 9, 2015lawofficial
Basic Act on Cybersecurity enters into force; NISC empowered

The Act took effect, establishing the Cybersecurity Strategic Headquarters and giving the renamed National center of Incident readiness and Strategy for Cybersecurity (NISC) statutory authority over national policy and government-wide defense.

Japanese Law Translation (Govt of Japan)
Nov 6, 2014law
Basic Act on Cybersecurity enacted

Japan passed its first dedicated cybersecurity law—the first among G7 nations—setting national principles, defining responsibilities of government and infrastructure operators, and mandating a national cybersecurity strategy.

U.S. Library of Congress
Aug 13, 1999lawofficial
Act on Prohibition of Unauthorized Computer Access enacted

Act No. 128 of 1999 criminalized unauthorized access, obtaining/supplying others' login credentials, and related conduct—the foundational statute underpinning Japan's anti-hacking enforcement and access-control obligations.

Japanese Law Translation (Govt of Japan)

Japan - other topics

Last verified 5/23/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →