Introduction
Data protection law is one of the most rapidly evolving areas of law of the past decade. Beginning with the EU's GDPR (General Data Protection Regulation, effective 2018), powerful personal data protection laws have come into force one after another around the world, and enforcement has grown more active. As for penalties for violations, under the GDPR the fine is the higher of 4% of total worldwide annual turnover or EUR 20 million; under the APPI (Japan's Act on the Protection of Personal Information), a corporate penalty of up to JPY 100 million is expected to be introduced in the 2026 amendment.
The difficulty of data protection law lies in the fact that (1) multiple jurisdictions apply in overlapping fashion; (2) both technical and organizational measures are required; and (3) the reputational impact of a violation is greater than the fine itself. For multinational companies, SaaS providers, and companies operating e-commerce sites, data protection compliance is a management issue that bears directly on business continuity.
Areas of Practice
1. APPI (Act on the Protection of Personal Information) Compliance - Responding to the 2022 and 2026 amendments - Designing the privacy policy, purposes of use, and consent-acquisition flows - Reporting to the Personal Information Protection Commission and notifying data subjects upon a breach - Designing the use of pseudonymized and anonymized information - Building frameworks for third-party provision and management of entrusted parties - Consent for cross-border transfers and surveying the protection laws of the destination country
2. GDPR (EU General Data Protection Regulation) Compliance - Organizing the legal bases (consent, performance of a contract, legitimate interests, etc.) - Preparing records of processing activities (ROPA) and DPIAs (Data Protection Impact Assessments) - Responding to data-subject rights (right of access, right to erasure, right to portability) - Determining whether a DPO (Data Protection Officer) must be appointed, and supporting the role
3. Data Breach and Incident Response - Initial response upon discovery of a breach (including the 72-hour GDPR reporting requirement) - Directing forensic investigation and liaison with investigation firms - Preparing and submitting reports to supervisory authorities - Draft notifications to data subjects and guidance for call-center response - Damages negotiations and response to class actions
How We Approach Typical Matters
The following illustrate the kinds of matters we handle and how we would approach them. They are not descriptions of past engagements or results.
Scenario 1: Bringing a SaaS Provider into GDPR Compliance
A company that is compliant with Japan's Act on the Protection of Personal Information but has not addressed the GDPR may need to achieve compliance quickly once a significant contract with a European counterparty comes into view.
In such a matter we assist with (1) a gap analysis against GDPR requirements; (2) revision of the privacy policy and terms of use (bilingual Japanese/English); (3) preparation of records of processing activities (ROPA); (4) conducting a data protection impact assessment (DPIA); (5) preparing a DPA template for customers; and (6) designing an internal training program.
Scenario 2: Responding to Amendments to the Personal Information Protection Act
Businesses holding multiple categories of data such as point-of-sale records, membership data, security camera footage, and employee data often need to take stock of their internal data flows when the law is amended.
In this situation we provide integrated support: (1) company-wide data mapping; (2) review and restructuring of stated purposes of use; (3) advice on consent collection flows; (4) revision of agreements with service providers such as cloud vendors and marketing agencies; (5) revision of internal rules and manuals; (6) preparation of a breach response manual; and (7) training for directors and front-line staff.
Scenario 3: Responding to a Large-Scale Personal Data Breach
Where unauthorized external access exposes a large volume of customer data, public attention is high and the quality of the initial response largely determines the outcome.
In such a matter we assist with (1) directing the immediate response (evidence preservation and selection of a forensic investigator); (2) the preliminary report to the Personal Information Protection Commission; (3) drafting individual notices, FAQs, and the approach for the inquiry desk; (4) preparing the press release and website notice; (5) supporting the filing of a criminal complaint; (6) reporting to business partners; (7) preparing for damages claims or class actions; and (8) designing measures to prevent recurrence.
How to Engage Us
- Initial Consultation (first 30 minutes free / available online): We hear your current situation and challenges and organize the issues.
- Estimate and Proposal: We present the scope and timeline. We accommodate both project-based and retainer arrangements.
- Commencement and Progress Sharing: We report progress at each milestone and coordinate with your internal approval processes.
- Completion and Aftercare: We can also provide continued support with updates on legal amendments and enforcement trends, and periodic reviews.
Contact
For consultations in the data protection field, please reach out via our contact form. For emergency breach response, please note this and we will prioritize your matter.