Security of HR information systems.
Security of HR Information Systems — Japanese Labour & Data-Protection Law
In Japan, security of HR information systems is not governed by one single “HR cybersecurity law.” It is principally controlled through the Act on the Protection of Personal Information (APPI), employment-law confidentiality obligations, the My Number Act for Individual Number information, contractual duties of confidentiality, and general civil-law principles concerning privacy and employee information.
For an HR information system, the relevant information can include:
- employee names and addresses;
- dates of birth;
- salary and bonus information;
- bank-account information;
- tax information;
- pension and social-insurance information;
- My Number/Individual Number information;
- attendance and working-hour records;
- performance evaluations;
- disciplinary records;
- recruitment records;
- health and medical information;
- stress-check information;
- family information;
- leave records;
- employee complaints and investigations;
- biometric or access-control information.
The security obligation therefore extends beyond merely installing antivirus software. It concerns collection, access, storage, use, transfer, outsourcing, deletion, monitoring and incident response.
1. Legal foundation
A. Act on the Protection of Personal Information
The APPI requires businesses handling personal information to take necessary and appropriate security-control measures for preventing leakage, loss or damage and for otherwise ensuring appropriate management of personal information.
For HR departments, this means that the employer should establish technical and organisational controls appropriate to the sensitivity and volume of employee information.
Typical measures include:
- access controls;
- authentication;
- password controls;
- encryption;
- logging;
- employee training;
- physical security;
- incident-response procedures;
- vendor supervision;
- data minimisation;
- secure deletion.
2. HR systems should use role-based access
One of the most important controls is need-to-know access.
For example:
| HR information | Appropriate access |
|---|---|
| Payroll | Payroll/authorised HR |
| Performance reviews | Relevant HR/management |
| Disciplinary records | Restricted HR/legal personnel |
| Medical information | Highly restricted |
| My Number | Specifically authorised personnel |
| Recruitment records | Recruitment team |
| Attendance data | HR/management according to need |
| Employee bank details | Payroll/authorised finance personnel |
A system where every HR employee can access every employee record creates unnecessary exposure.
3. My Number information requires heightened protection
My Number information is particularly sensitive.
The Japanese Supreme Court's 2023 My Number judgment considered the constitutionality of statutory collection, retention, use and provision of Individual Number information. The Court recognised the highly confidential nature of Specific Personal Information and noted the extensive statutory safeguards, including restrictions on use, encryption, decentralised management, access controls, recordkeeping and supervision.
For an employer, this means that a payroll/HR system containing My Number information should be designed so that:
- access is limited;
- the information is used only for legally permitted purposes;
- unnecessary copies are not created;
- transmission is protected;
- access is logged;
- outsourcing is supervised;
- retention is controlled.
4. Security is both a technical and organisational obligation
A common mistake is to interpret HR information security as purely an IT responsibility.
Japanese compliance requires a broader approach.
Technical controls
- encryption at rest;
- encryption in transit;
- multi-factor authentication;
- endpoint protection;
- network segmentation;
- vulnerability management;
- secure backups;
- audit logs;
- intrusion detection;
- access revocation.
Organisational controls
- information-security policies;
- employee training;
- confidentiality obligations;
- access approval procedures;
- incident-response plans;
- vendor due diligence;
- periodic security audits;
- disciplinary procedures for unauthorised disclosure.
Physical controls
- restricted server rooms;
- locked HR files;
- controlled office access;
- secure disposal;
- protection of backup media.
5. Employee access must be removed promptly
A major HR-security risk arises when an employee:
- resigns;
- is terminated;
- transfers departments;
- changes responsibilities;
- loses authority over sensitive information.
The organisation should therefore operate a joiner-mover-leaver process.
For example:
Termination → HR notification → IT account suspension → VPN termination → cloud access removal → device recovery → token/key revocation → audit-log preservation.
Delayed access termination can create significant exposure.
6. Outsourcing HR systems
Many Japanese employers use:
- cloud HR platforms;
- payroll providers;
- recruitment platforms;
- benefits administrators;
- occupational-health providers;
- background-check companies;
- external HR consultants.
Outsourcing does not eliminate the employer's responsibility.
The employer should conduct appropriate supervision of contractors handling employee information.
Contracts should address:
- permitted purposes;
- security standards;
- confidentiality;
- subcontracting;
- access restrictions;
- breach notification;
- audit rights;
- deletion/return of data;
- international transfers;
- incident cooperation.
7. Cross-border HR databases
Multinational companies frequently centralise HR data in:
- Singapore;
- the United States;
- Europe;
- Australia;
- regional cloud platforms.
This creates additional APPI considerations.
Before transferring Japanese employee information overseas, the employer should determine:
- what information is being transferred;
- why it is being transferred;
- where it will be stored;
- who can access it;
- what safeguards apply;
- whether the legal requirements for overseas provision are satisfied.
8. Employee monitoring systems
Modern HR systems may monitor:
- attendance;
- computer activity;
- email;
- location;
- access cards;
- productivity;
- communications;
- use of corporate devices.
Security and privacy must be considered together.
The employer should avoid collecting substantially more information than is necessary for the legitimate HR purpose.
A good governance principle is:
Collect only what is needed, give access only to those who need it, retain it only as long as necessary, and document why it is being processed.
9. Health and stress-check information
Health information requires particularly careful handling.
Examples include:
- medical examination results;
- sickness information;
- disability-related information;
- occupational-health records;
- stress-check results;
- workplace accommodation information.
HR systems should ideally separate highly sensitive health information from ordinary personnel files.
Access should be strictly limited, with strong audit controls.
10. Data retention and deletion
Security is not achieved merely by protecting information indefinitely.
Keeping unnecessary data creates additional risk.
An employer should establish retention schedules for:
- recruitment records;
- payroll records;
- attendance records;
- disciplinary records;
- health information;
- tax information;
- former-employee records;
- investigation files.
When the legitimate retention period ends, information should be securely deleted or anonymised where appropriate.
11. Incident response
A Japanese employer should have a documented procedure for an HR-data breach.
Recommended sequence
1. Detect
Identify the suspected incident.
2. Contain
Disable compromised accounts and isolate affected systems.
3. Preserve evidence
Protect logs, devices and relevant communications.
4. Determine scope
Identify:
- affected employees;
- information involved;
- time period;
- access method;
- whether information was actually exfiltrated.
5. Regulatory assessment
Determine whether notification/reporting obligations are triggered.
6. Employee communication
Where appropriate, notify affected employees.
7. Remediation
Reset credentials, patch vulnerabilities and improve controls.
8. Post-incident review
Identify the root cause and prevent recurrence.
Case Laws
1. Waseda University Case — Supreme Court, 12 September 2003
This is one of the most important Japanese privacy cases for understanding organisational control of personal information.
Facts
Waseda University collected students' identifying information in connection with participation in a lecture involving a foreign state guest. The university later provided participant information to the police without obtaining prior consent.
Decision
The Supreme Court held that the information was legally protected as information concerning privacy and that the university's disclosure, in the circumstances, constituted a tort because the university could have obtained consent and there were no special circumstances making that impracticable.
HR-system significance
An employer collecting employee information should not assume:
“We already have the information, therefore we can give it to anyone internally or externally.”
Collection and subsequent disclosure are separate issues.
The case supports:
- purpose limitation;
- controlled disclosure;
- employee-information governance;
- careful third-party access.
2. Juki-Net Case — Supreme Court, 6 March 2008
Case
2007 (O) No. 403
The Supreme Court examined the Basic Resident Register Network and constitutional privacy concerns surrounding government collection and use of identification information.
The Court held that the system did not, on the facts and safeguards before it, create the specific risk of unlawful disclosure necessary to establish the claimed constitutional violation.
Importance for HR systems
The judgment is particularly useful for understanding system architecture as a legal safeguard.
The Court considered factors including:
- restricted purposes;
- decentralised information management;
- restrictions on data matching;
- confidentiality duties;
- criminal penalties;
- oversight mechanisms.
HR lesson
A secure HR system should not depend solely on employee promises of confidentiality.
Architecture itself should reduce the possibility of misuse.
3. My Number Case — Supreme Court, 9 March 2023
Case
2022 (O) No. 39
This case concerned the collection, retention, use and provision of Specific Personal Information containing Individual Numbers.
The Supreme Court upheld the statutory system and examined the extensive safeguards surrounding My Number information.
The Court noted measures including:
- decentralised management;
- encrypted communications;
- encryption of transmitted Specific Personal Information;
- restrictions on use;
- logging;
- supervision;
- security assessments;
- employee cybersecurity training.
HR significance
This is particularly important for:
- payroll systems;
- tax systems;
- pension systems;
- employee onboarding;
- social-insurance administration.
It demonstrates that security-by-design is legally significant.
4. Benesse Personal Information Leakage Case — Tokyo District Court, 27 December 2018
Facts
Personal information held by a company was leaked externally by an employee of a subcontractor involved in system development and operation.
The affected individuals brought claims concerning the leakage and resulting distress. The Tokyo District Court awarded damages in part.
HR-system significance
This case is highly relevant to modern cloud HR systems.
A company cannot assume:
“The information was leaked by a contractor, so the company has no responsibility.”
Instead, organisations need:
- vendor due diligence;
- contractual security obligations;
- access restrictions;
- monitoring;
- employee confidentiality;
- subcontractor controls.
5. Furukawa Mining Case — Tokyo High Court, 18 February 1980
Facts
Employees reproduced and distributed a document containing important company secrets, including the basic policy of the company's long-term management plan.
Decision
The court recognised that employees have a duty, arising from the employment relationship and good faith, to protect business secrets. The disciplinary dismissal was upheld because of the serious nature of the disclosure and the employer's efforts to protect the information.
HR-security significance
The principle applies strongly to HR information.
Employees who have privileged access to:
- salary databases;
- disciplinary files;
- executive compensation;
- investigation reports;
- employee complaints;
may have confidentiality obligations extending beyond merely following IT passwords.
6. Merrill Lynch Investment Managers Case — Tokyo District Court, 17 September 2003
Facts
An employee disclosed documents containing HR and customer information to a lawyer while consulting about alleged workplace mistreatment.
The employer treated the disclosure as a breach of confidentiality and dismissed the employee.
Decision
The court recognised the confidential character of the documents but held, in the circumstances, that the disclosure to a lawyer for the legitimate purpose of seeking assistance did not constitute the kind of confidentiality breach necessary to justify the dismissal. The dismissal was therefore invalid.
HR-security significance
This case provides an important qualification:
Confidentiality cannot be applied mechanically.
An HR-security policy should distinguish between:
- malicious disclosure;
- unauthorised commercial disclosure;
- legitimate legal consultation;
- whistleblowing;
- reporting unlawful conduct;
- protected complaints.
Security policies should therefore contain appropriate exceptions and escalation procedures.
7. Photo/Privacy Case — Supreme Court, 10 November 2005
Case
2003 (Ju) No. 281
The Supreme Court considered whether photographing a person's face or appearance without consent could constitute a tort.
The Court held that a person has a legally protected personal interest against having their face or appearance photographed without good reason, assessed in light of circumstances including purpose, location, manner and necessity.
HR-system significance
This is relevant to:
- facial-recognition attendance;
- employee photographs;
- biometric access systems;
- video surveillance;
- AI-based employee monitoring.
An employer should therefore assess the necessity and proportionality of biometric or photographic monitoring rather than assuming that workplace presence eliminates privacy interests.
8. Information-security governance derived from the cases
The cases collectively support several important HR-system principles.
Principle 1 — Personal information remains protected after collection
The Waseda case demonstrates that obtaining information for one purpose does not automatically authorise unrestricted disclosure.
Principle 2 — Security must be designed into the system
The Juki-Net and My Number judgments demonstrate the importance of:
- decentralisation;
- encryption;
- restricted access;
- logging;
- purpose limitation.
Principle 3 — Contractors create security risk
The Benesse litigation demonstrates the significance of controlling third-party access.
Principle 4 — Employees have confidentiality duties
Furukawa Mining demonstrates that serious disclosure of confidential business information can justify disciplinary action.
Principle 5 — Confidentiality is not absolute
Merrill Lynch shows why legitimate legal consultation and other justified disclosures require careful analysis.
Principle 6 — Monitoring requires justification
The photography/privacy judgment demonstrates that employee monitoring can implicate legally protected personal interests.
9. Recommended HR Information-System Security Framework
A Japanese company can structure its HR security programme around the following model:
A. Data classification
Classify HR information as:
Level 1 — Ordinary
- name;
- department;
- work contact details.
Level 2 — Confidential
- salary;
- performance;
- attendance;
- disciplinary information.
Level 3 — Highly confidential
- health information;
- investigation files;
- whistleblowing information;
- executive compensation.
Level 4 — Special statutory controls
- My Number/Specific Personal Information.
B. Access controls
Use:
- role-based access;
- least privilege;
- MFA;
- privileged-access management;
- periodic access reviews;
- automatic termination of inactive accounts.
C. Technical security
Implement:
- encryption;
- secure APIs;
- endpoint protection;
- vulnerability scanning;
- penetration testing;
- immutable backups;
- network segmentation;
- security monitoring;
- audit trails.
D. HR governance
Adopt:
- HR information-security policy;
- confidentiality agreements;
- employee training;
- incident-response policy;
- data-retention policy;
- vendor-security policy;
- disciplinary rules for intentional leakage.
E. Vendor management
Before granting a payroll or HR-cloud provider access:
- identify the information involved;
- conduct security due diligence;
- assess subcontractors;
- define contractual safeguards;
- restrict access;
- require incident notification;
- establish deletion/return procedures;
- periodically audit compliance.
10. Practical HR Security Checklist
| Control | Recommended approach |
|---|---|
| Employee database | Role-based access |
| Payroll | Restricted access + encryption |
| My Number | Special statutory controls |
| Health data | Highly restricted access |
| HR cloud | Vendor due diligence |
| Remote access | MFA + encrypted connection |
| Former employees | Immediate account termination |
| Data transfer | Approved secure channels |
| USB/storage | Restrict or control |
| DLP/encryption where appropriate | |
| Logs | Maintain and review |
| Backups | Encrypted and access-controlled |
| Incident response | Written procedure |
| Employee training | Regular |
| Retention | Defined schedules |
| Disposal | Secure deletion |
| Auditing | Periodic review |
Conclusion
Security of HR information systems in Japan is a combination of privacy protection, information-security controls, employment confidentiality and statutory restrictions on sensitive information.
The central lesson from the Japanese case law is that HR information should not be treated merely as ordinary corporate data. Employee information can constitute legally protected privacy information, and the employer must control who collects it, why it is collected, who can access it, how it is transferred, how long it is retained and what happens when something goes wrong.
For modern Japanese HR departments, the strongest compliance model is therefore:
Data minimisation → purpose limitation → least-privilege access → encryption → logging → vendor controls → employee confidentiality → incident response → secure deletion.
The My Number judgment, Waseda case, Juki-Net case, Benesse personal-information litigation, Furukawa Mining case and Merrill Lynch case together provide particularly useful authorities for constructing an HR information-security framework.

comments