Your Medical History, Social Media, and Personal Data—Taken Without Your Consent? Inside the Worst Legal Reform

Medical histories and social media data. The horror of no consent required
Medical records, prescription histories, online shopping purchase histories, social media posts. Information related to an individual’s privacy may be provided to companies without the person even being aware of it.
The revised Act on the Protection of Personal Information was passed by the House of Councillors on July 10, enacted, and promulgated on July 17. The revision includes a “Special Exception for Statistical Creation, etc. (Statistical Exception),” which allows personal information to be provided to third parties without the individual’s consent, limited to uses such as creating statistics and developing AI. Information security experts, medical professionals, consumer organizations, and others have criticized the provision, saying it threatens individuals’ rights and interests.
Professor Ichiro Sato of the National Institute of Informatics, who has been involved in developing the Act on the Protection of Personal Information as a member of an expert panel since 2015, describes the Statistical Exception as a provision that promotes the expanded use of personal information, and points out:
“Under the Act on the Protection of Personal Information, as a general rule, an individual’s consent was required when providing personal data to a third party or using it for purposes other than those for which it was originally collected. Under the Statistical Exception, however, as long as the company receiving the personal information intends to use it to create statistics or train AI models, the individual’s consent is no longer required. Nor is the company providing the data required to process it through anonymization or pseudonymization.
Medical histories, criminal records, political or ideological beliefs, religious beliefs, and other sensitive personal information requiring special care can lead to discrimination and disadvantage, so an individual’s consent is mandatory when such information is provided to a third party. However, because the provision of unprocessed original data, including names and addresses, has also become possible without consent under this revision, the possibility that such sensitive personal information will not be adequately protected has increased.”
Moreover, the hurdles for companies receiving personal information are extremely low. There is no government licensing, authorization, or prior screening, nor are there any restrictions based on the size or nationality of the business. Individual proprietors, overseas companies, and even investigative authorities could potentially become recipients of personal information.
“Normally, with such a major change, the details of the proposed revision should have been thoroughly discussed by an expert review panel, or the public should have been invited to submit comments, so that the contents of the amendment would be made transparent. Yet the Statistical Exception suddenly emerged as though it had appeared out of nowhere, and it was enacted without the overall picture being presented to the public. That is the impression I have.”
(The following comments are by Professor Sato.)
Is the aim data matching? Individual laid completely bare
The government’s stated aim in creating this exception is to ease restrictions on the use of personal information and promote the development of domestically produced AI. But is that really the objective? If the data is to be used for AI training or purely for creating statistics, information used to identify individuals, such as their names, should not be necessary.
“The government’s objective is to deregulate the use of personal information, but perhaps the aim of companies that want to make use of the data is data matching.
Companies receiving personal information will be able to perform data matching, linking multiple datasets using names and other identifiers as keys. For example, they could collect medical records from hospitals, academic records from schools, purchase histories from e-commerce sites, and posting histories with names attached from social media companies. By matching these datasets, they could create an enormous amount of profiling data for a single individual—in other words, an extremely detailed portrait of that person.”
Data matching can also make it possible to identify individuals.
“Generally speaking, data matching can be carried out with just three pieces of information: date of birth, sex, and postal code. Within the same postal-code area, there are extremely few people who share the same date of birth and sex.
Suppose a local shop whose main customer base is within a particular postal-code area conducts an anonymous survey asking only for date of birth and sex. If the shop already possesses data on local residents that includes their names and dates of birth, it could easily identify individuals simply by matching the datasets.”
Why, despite being a law intended to protect personal information, was the obligation to delete names or anonymize the data abandoned?
“Because there were that many companies seeking exemption from the obligation to anonymize data. This revision is deregulation intended for that purpose, and economic organizations presumably lobbied politicians strongly for regulatory relaxation. As a result, we have to say that the law was revised by essentially accepting the business community’s demands wholesale.”
If a company receiving personal information were to use data matching to compile detailed private data on an individual, what kinds of disadvantages could result?
“For example, a company could purchase the social media posting histories of third- and fourth-year university students, analyze their content, and exclude them from the hiring process. Or, based on purchase histories of books about illnesses, it could estimate the possibility of a disease associated with a high risk of recurrence or becoming severe and refuse to provide insurance coverage. Depending on how companies use personal information, some people could suffer disadvantages.
There is also the risk that the data could be misused. It could leak to malicious businesses or criminal groups.
Sensitive personal information requiring special care includes not only past criminal records but also information about victims of crimes. If people who are particularly susceptible to fraud were identified through data matching and that information ended up in the hands of special-fraud groups such as the Tokuryū, it could lead to an increase in scams such as the ‘It’s me’ scam.”

with such lenient penalties, the public will be left to suffer in silence
The revised law states that the exception applies to cases where there is little risk of harming an individual’s rights and interests. However, as Professor Sato points out, there are numerous concerns surrounding the exception.
“The Personal Information Protection Commission, which oversees the Act on the Protection of Personal Information, is responsible for monitoring and supervising whether the use of data by companies receiving personal information harms individuals’ rights and interests. Its commissioners include academics and former corporate executives, while its secretariat consists mainly of government officials from various ministries and agencies. But it is questionable whether this organization has the ability to properly monitor and supervise such activities.
In most cases where the Personal Information Protection Commission has issued administrative guidance, it only began taking action after the matter had been reported in the media or after an internal whistleblower came forward. Can an organization that is unable to identify problems on its own really fulfill the role of monitoring?”
The Personal Information Protection Commission will now be responsible for establishing specific rules and guidelines.
“Rules and guidelines cannot go beyond the framework established by laws enacted by the Diet. For example, given the structure of the revised law, it would be difficult to include provisions in the guidelines such as requiring businesses receiving personal information to obtain government authorization or allowing individuals to opt out.
Furthermore, during Diet deliberations on the revised law, the government stated that the Statistical Exception allows the data held by the provider to be handed over as is. This makes it difficult to establish rules or guidelines that require the data to be processed beforehand. In effect, the government’s statements before the Diet have made it harder to implement safeguards.”
The penalties for companies providing and receiving personal information are also lenient. Although a surcharge system was introduced as a financial penalty, following strong opposition from the business community, the scope was limited to cases involving highly malicious conduct, actual harm, and more than 1,000 victims, according to Professor Sato.
“The amount of the surcharge was also limited to an amount equivalent to the profits gained through the malicious conduct. I doubt it will have much of an economic deterrent effect.”
The introduction of a class-action system, under which consumer organizations certified by the government could seek injunctions and other remedies on behalf of individuals, was also abandoned.
“Class actions are a necessary system for providing relief to individuals who have suffered harm, but the business community opposed this as well. As a result, a situation has effectively been established in which individuals who suffer harm will be forced to simply accept their losses without recourse.
Going forward, there is a possibility that more businesses will engage in data use that infringes on people’s rights and interests, assuming that individuals will simply be left to suffer in silence.”
Zero right to refuse! The dark shadow of an approaching surveillance society
There are no legal safeguards, and people are not even given the minimum right to refuse—an opt-out mechanism that would allow individuals to stop or reject the provision of their personal information to third parties. It would be fair to say that the means for people to protect their own personal information have been virtually eliminated.
“Not only will individuals be unable to refuse the provision of their information, but it is also conceivable that companies asked to provide information will find it difficult to refuse.
For example, if a social media company were asked by an investigative authority to provide the posting histories, names, and email addresses of all its users on the grounds that they were needed for statistical purposes, the company would have no legal basis for refusing. Therefore, people should assume that social media posts, as well as footage captured by surveillance cameras and smart glasses in public spaces, could potentially be provided to investigative authorities.”
Professor Sato is also deeply concerned that the spread of smart glasses could usher in a society in which citizens monitor one another.
“Because smart glasses can record images and sound around the wearer simply by turning their head, I believe people will emerge who expose others online out of curiosity or resentment. If that happens, some people may become increasingly suspicious that someone might be recording me, causing them to feel intimidated and voluntarily restrict their own behavior. I believe the impact of the Statistical Exception on society will be far from insignificant.”

Will overseas IT companies ultimately be the only winners?
The intentions of the ruling party and the business community are strongly reflected in the revised law. But if the government prioritized the immediate use of data without examining the risks on the opposite end of the spectrum, then Professor Sato warns that, as a result, the companies themselves could end up undermining their own foundations.
“When users decide whether to consent when using a service, the decisive factor is trust in the company.
However, by uniformly loosening the rules through this legal revision, the government may actually fuel distrust among users and even undermine the trust that reputable companies have built. For companies that have carefully cultivated that trust over the years, this is certainly an unwelcome development.”
For the business community, this could be a serious problem. But the miscalculation may not stop at the loss of trust in domestic companies. As distrust of domestic businesses grows, people may ironically choose to shift to overseas companies to protect themselves.
“Overseas companies, which are outside the scope of the Statistical Exception, may actually be safer because they are more likely to require legitimate consent when providing information to third parties. Ultimately, the biggest beneficiaries may be major overseas IT companies that can easily obtain Japanese data.
This exception was pushed through based on the intentions of the political and business worlds, but it is simply far too misguided.”
▼Ichiro Sato — Professor at the National Institute of Informatics, Research Department of Information and Society, Doctor of Engineering. Completed the doctoral program at Keio University Graduate School in 1996. After serving as a research associate and associate professor at Ochanomizu University Graduate School, and as an associate professor in the Software Research Division of the National Institute of Informatics, he has held his current position since 2006. He has also served as chair of the Digital Agency’s Council of Experts on Policy Evaluation, among other positions.
Reporting and Text: Sayuri Saito PHOTO: Afro