Japan FSA updates financial-sector privacy Q&A to cover reporting of other cyberattack incidents

Japan
Sep 28, 20261 sources
  • 01The FSA’s revised privacy Q&A for financial institutions will apply from October 1, 2026.
  • 02The change follows a September 15, 2026 amendment to an inter-agency cyberattack reporting arrangement.
  • 03A new common form is available for reporting personal-data breaches linked to cyberattacks other than DDoS attacks or ransomware.
  • 04Financial institutions should incorporate the new reporting option into their cyber-incident and data-breach response processes.

Japan’s Financial Services Agency (FSA) has revised its “Q&A on the Protection of Personal Information in Financial Institutions.” The change takes effect on October 1, 2026.

The revision aligns the financial-sector guidance with an inter-agency agreement on cyberattack incident reporting that was amended on September 15, 2026. That agreement adds a new common reporting form for “other cyberattack and similar incidents,” alongside the existing common forms for distributed denial-of-service (DDoS) attacks and ransomware incidents.

The revised Q&A clarifies that, when a financial institution reports a personal-data breach or similar incident to its supervisory authority in connection with another type of cyberattack, it may submit the new “Other Cyberattack and Similar Incident Common Form.”

Banks and other financial institutions should update their incident-response and regulatory-reporting procedures before October 1, 2026. In particular, they should ensure that staff can identify when the new form is available for use and coordinate cyber-incident reporting with personal-data breach reporting obligations.

Sources (1)

fsa.go.jp — Sep 28, 2026

Japan FSA updates financial-sector privacy Q&A to cover reporting of other cyberattack incidents