Under a special provision of Japan’s revised Personal Information Protection Act, sensitive data such as medical history can now be shared without the individual’s consent, provided the purpose is AI development or statistical research. In response, an online petition calling for operational safeguards has gathered more than 30,000 signatures.
On 5channel, opinions split over whether data is really being handed over complete with names and addresses, and just how thoroughly it’s actually anonymized. Posts citing Diet testimony — in which Chief Cabinet Secretary Kihara and Minister Matsumoto reportedly said that stripping out personally identifiable information is “difficult in practice” — fueled growing unease about what this law change really means on the ground.
“My information, shared without my knowledge…” The woman behind the petition calling for “operational safeguards” on the revised Personal Information Protection Act’s special provision: Tokyo Shimbun Digital
August 18, 2026, 06:00 — Article for paid subscribers only
An online petition calling for operational safeguards on the revised Personal Information Protection Act’s special provision — which allows sensitive information such as medical history to be shared without the individual’s consent for the purposes of AI development or statistical research — has gathered more than 30,000 signatures.
Source: tokyo-np.co.jp / Original article here
If something's free, there's a reason.
Unlike your average, not-too-careful LINE user, the people speaking up this time — folks who go to the hospital a lot — might just be the type who sweats the details.
Is that ambiguity itself the thing people are pushing back against?
No, it's handed over complete with address and name attached.
Akira Nagatsuma raised this in the Diet, and Kihara admitted that removing that info isn't technically feasible.
Big-data analysis might surface side effects that clinical trials never caught — like "people who take this drug tend to get this reaction."
I saw in the news that names get handed over in the data as-is, unredacted.
You really think that rule actually gets followed?
Way too naive.
Even if it's handed over in a state that's just barely non-identifiable, it can still be pieced together like a jigsaw puzzle with data from past leaks to reconstruct the full picture.
And it's the people with the least "value" who are easiest to exploit for crime.
isn't it terrifying that raw personal data of every kind ends up piled up at specific companies?
Nobody's watching what they actually do with it internally lol
Seriously, this.
There are already plenty of sketchy companies as it is.
Isn't it fine as long as it's not illegal?
Is that actually true?
Standard practice is to "sanitize" (strip out personally identifiable info) before turning data into big data.
Also, the information handed over isn't the final "statistical data" itself — at the stage where raw data moves from the source to the recipient, it may still contain names and addresses. Processing it into a non-identifiable form only happens at the final output stage.
And yet vetting of the recipient organizations is lax, basically running on the honor system.
In Diet questioning, Chief Cabinet Secretary Kihara said it's not feasible to strip out personally identifiable info like address and name.
Well, if you're a woman, having a gynecological condition exposed would be pretty embarrassing.
Insurance could shift away from uniform premiums based on the law of large numbers
toward extreme risk-segmentation at the individual level.
AI could also end up taking over the role background-check agencies play in employment and marriage discrimination.
No, I don't think that's really the main purpose — there's no real use value in the names themselves.
The point of big data is analyzing relationships/correlations,
so if names are used at all it's probably just to avoid duplicate entries. They should just swap it for some other identifier so individuals can't be identified.
Real names aren't necessary for big data.
So the fact that they stubbornly refuse to strip real names out means that's exactly where the real purpose lies.
What exactly do you mean by "that"? What kind of personal-data use are you imagining?
Big data's main purpose is trend analysis —
like "taking this drug causes this side effect,"
or whether there's regional variation in disease based on address.
Names are probably just there to avoid double-counting duplicate entries, so a number or code would work just as well.
The standing principle up to now has been "remove real names."
This time it's a special exception making "real names OK."
Do you not get that basic premise?
According to Minister Matsumoto,
removing names isn't feasible because it would place too much burden on the hospitals holding the data.
Wait, it is anonymous… right? Hard to believe, but still.
It's all "without the individual's consent," so it's probably handed over completely raw, everything included.
This law change literally says "you don't have to anonymize it."
>>1
It's right there in the article — it says the data is handed over with real names attached.
*This article is compiled as an excerpt and summary of the 5channel (Breaking News Plus) thread ““Don’t hand over our medical histories to AI developers without asking” — the woman behind the petition calling for “operational safeguards” on the revised Personal Information Protection Act’s special provision.”
Leave a Reply