Revision of Financial Sector Privacy Q&A Announced
Overview
The Financial Services Agency revised the “Q&A on the Protection of Personal Information at Financial Institutions” in light of the September 15, 2026 revision to the interagency agreement. It clarified, among other things, that reports of leaks, etc. involving personal data in other cyberattack incidents may also be submitted using the newly established common form. The revised Q&A applies from October 1, 2026.
Key points
- The revised financial sector Q&A applies from October 1, 2026.
- It clarified that reports of leaks, etc. in other cyberattack incidents may be submitted using the newly established common form.
- The Financial Services Agency revised the financial sector Q&A in light of the revision to the interagency agreement.
Overview
The “Agreement on Reporting Procedures, etc. in the Event of Damage Caused by a Cyberattack” (interagency agreement dated May 28, 2025) was revised on September 15, 2026. In addition to the existing “DDoS Incident Common Form” (Form 1 in the attachment) and “Ransomware Incident Common Form” (Form 2 in the attachment), an “Other Cyberattack Incident Common Form” (Form 3 in the attachment) was established for use in other incidents.
Details
The financial sector Q&A specifies the forms financial institutions use to report to supervisory authorities when leaks, etc. involving personal data occur. The revision clarified, among other things, that for other cyberattack incidents, reports may also be submitted using the common form in Form 3 of the interagency agreement’s attachment.
From October 1, 2026 onward, the revised text can be accessed on the “Personal Information Protection in the Financial Sector” page.