< Back to all clusters
[BUSINESS] · Japan · 2 sources

started · updated

Japan data breaches highlight lack of security investment

Recent waves of data breaches in Japan have highlighted systemic vulnerabilities in corporate information security. Discussions surrounding these incidents, including a notable breach involving Times Car where identification documents were leaked, emphasize the risks associated with companies retaining sensitive personal data for extended periods, even after users have ceased using their services.

Analysis suggests that Japanese companies often lack incentives to invest in robust security. Unlike the European Union’s GDPR, which treats personal data as a potential liability through strict minimization principles and heavy fines—up to 4% of global annual turnover—the Japanese legal framework provides fewer financial deterrents for major leaks. This often results in security being viewed as a cost center rather than a necessity.

Data from the IPA indicates that 62.6% of small and medium-sized enterprises have not invested in security measures over the past three years, citing a lack of perceived necessity or unclear return on investment. Experts suggest that until the legal landscape shifts to make data retention a liability rather than an asset, many firms will continue to prioritize cost-saving over proactive defense.

Entities

European Union · IPA · Times Car