From our other sites
The story
Times Car, the car-sharing service run by Park24, has leaked roughly 1.6 million pieces of personal data belonging to members, including images of their driver’s licenses. One contributing factor: the company kept license photos and other data on file for up to seven years even after a member canceled. Park24 says the retention is required under Japan’s Corporate Tax Act, but some rival rental car companies reportedly delete such images as soon as identity verification is complete. On 5ch, former members shared stories of asking the company to delete their photos after canceling only to be refused, while others questioned why a scanned ID image needs to be kept for so long in the first place.
Park24’s car-sharing service Times Car kept driver’s license images on file for more than seven years, a practice that led to the leak. Rival companies reportedly delete such images immediately after identity verification. This lax data management resulted in a leak of roughly 1.6 million records.
License data retained for 7 years under company policy
According to Park24, personal information such as names, addresses, and dates of birth was kept not only while customers were active members but for seven years after they canceled, in line with the Corporate Tax Act. Regarding this…(continues in the paid edition, 1,140 characters remaining)
Source: nikkei.com / Original article here
What people said
Gotta be internet-accessible for remote work, right.
Times: "We have not confirmed that your information was leaked" (note: they didn't say it WASN'T leaked).
"To check whether you were affected by the leak, please enter your ID, password, address, name, email address, credit card number, and security code at the URL below."
It's a digital-record thing. Some documents are legally required to be kept for 7 years. That rule used to assume paper, but now digital data is allowed too. So the normal move is to digitize the paper and shred it — but painfully slow-moving companies just keep hoarding the paper instead.
I don't remember clearly, but I feel like I wrote my My Number when I signed up. The email I got said everything except my My Number leaked. It is weird that only the My Number would come out unscathed.
New My Number card: currently in the works.
It literally says right there it's based on the Corporate Tax Act.
Management tells them to always keep it on file because personal info is worth money.
They probably think it'd be a waste to delete it — the "might come in handy someday" mindset.
Police often trace suspects' movements through rental car records — if companies really deleted it immediately, that wouldn't even be possible.
They probably keep a paper copy on file separately.
If your license photo gets used for ID verification to buy a phone online, that's genuinely dangerous — you could end up arrested as the front man for a scam ring.
"Your license photo has been leaked" — and that just becomes the setup for the next scam, lol.
Whoever misuses it is the one at fault — you can't really pin that much liability on the company's negligence.
AI has torn down the Japanese-language barrier (that used to shield Japanese firms from foreign attackers).
Is that really something individuals should have to watch out for? If registering is mandatory, the company should be the one managing it properly. With Japan courting all these inbound tourists, a rental car company leaking personal info like this is a failure the government bears some responsibility for too.
Think whatever you want, but you're the one who ends up the victim.
What about someone taking out a loan shark loan in your name? Where's the compensation for that fear?
Criminals combine it with other personal data already circulating in the underground market, which makes the fraud more precise.
Background and key points of this discussion
Identity documents like driver’s license copies can be subject to a retention requirement of up to seven years under the Corporate Tax Act, since they count as accounting records. This rule originally assumed paper documents, but amendments to the Electronic Books Preservation Act later made it acceptable to keep scanned data instead. The real issue isn’t that a retention period exists, but whether it’s necessary to keep license image data for that same length of time even for members who have already canceled — a question of how the policy is applied in practice. That’s exactly where opinions split in the thread: some saw retention for legal-compliance reasons as unavoidable, while others argued that holding onto the image itself is a risk, and it should be destroyed promptly once identity verification is complete. Some posts also tied this and other recent leaks at Japanese companies to a coordinated attack by a specific nation-state, but that is speculation from the 5ch thread, and no supporting facts about this particular case have been reported.
*This article is excerpted and summarized from the 5ch (Breaking News Plus) thread “Times Car license photo leak: kept for 7 years even after cancellation — rivals delete immediately.”
Leave a Reply