Will our medical history and diagnoses be used for AI development without our consent? [Special Edition: Mental Health News of Interest]
Good evening.
Have you ever felt that you didn't want anyone to know your diagnosis or medical history?
I have.
On the last Saturday of every month, I deliver TALES analysis, but this month, something caught my attention, so I would like to take up the amendment of the Personal Information Protection Act under the framework of "Mental Health News of Personal Interest".
The fact that I had a period of leave from work, the fact that I am seeing a psychiatrist. These might one day become the reason I lose my current job or place to belong. Regardless of whether it actually happens, just imagining it is scary.
Even if there were no disadvantages, it is offensive to me that my sensitive information is being exchanged without my knowledge.
Isn't it up to each of us to decide whether or not to provide that?
Our most sensitive information is being transferred from one company to another without the individual's consent, with names and addresses left intact.
Such a system was enacted as law on July 10, 2026.
It is the "Act on the Partial Revision of the Act on the Protection of Personal Information," commonly known as the "Amended Personal Information Protection Act."
https://www.ppc.go.jp/news/press/2026/260717/
In this article, I will organize the system called the "Statistical Exception (AI Exception)," which has been particularly controversial, so that even those who are not familiar with the law can understand it.
Let's think together about what will change, why it happened, and what we should keep an eye on from now on.
What has changed
This amended law was passed and enacted at the plenary session of the House of Councillors on July 10, 2026, and promulgated on the 17th of the same month.
It seems that the law was enacted "to further protect personal information while considering its usefulness in line with the development of current AI technology." It is expected to be fully enforced by around July 2028.
This amendment consists of four main pillars.
・Promotion (relaxation) of data utilization for purposes such as statistics creation (including AI development).
・Partial expansion (relaxation) of exceptions where consent is not required.
・Strengthening of regulations (strengthening) against new risks. Establishment of facial feature data, protection of those under 16, etc.
・Strengthening of enforcement effectiveness (strengthening). Establishment of a surcharge system, increase in penalties, etc.
Among them, this article deals with the first one, the so-called "Statistical Exception."
This statistical exception is a system that allows "special care-required personal information" such as medical history, criminal records, and personal beliefs to be provided between businesses without the individual's consent and without processing names or addresses.

https://www.ppc.go.jp/files/pdf/260717_kaiseihounitsuite.pdf
Although it is phrased as "statistical creation," looking at parliamentary replies and the like, the objective of "primarily enabling companies to flexibly develop AI" is clearly visible.
There are two routes depending on how the data is acquired.
・Route 1
Special care-required personal information that is already publicly available on the internet can be acquired without the individual's consent if the purpose is for statistical creation, etc.
This assumes cases where information such as criminal records, beliefs, or political party affiliations published online is automatically collected to analyze social trends.
・Route 2
Personal information held by a business operator (including special care-required personal information) can be provided to a third party for the purpose of statistical creation, etc., without the individual's consent.
This assumes a case where a hospital provides patient diagnosis results to an AI development company.
In other words, Route 2 means that our personal information, including names, addresses, medical history, and everything else, will be handed over as-is for someone's statistical creation (AI development company) without our permission. Moreover, if it can be categorized as "creation of statistics, etc.," the individual's consent is not required.
The missing "rules to protect us"
Even so, here is a fact that shatters our hope that they would proceed with sufficient caution...
Under the current framework, no injunction system, victim recovery system, or sufficient administrative penalty system has been incorporated.
What does this mean?
An injunction system is a right that allows consumer organizations and others to demand that illegal handling of personal information be "stopped."
A victim recovery system is a collective system that allows people who have suffered damage due to violations of the Personal Information Protection Act to collectively seek victim recovery (compensation, etc.).
Although the administrative penalty system itself has been newly established, the scope of application is limited (only 4 types, excluding information leaks), and there is criticism that "the amounts are low and the scope is narrow."
In other words, you cannot stop the handling of personal information once it has leaked, you cannot file a class-action lawsuit even if you suffer damage, and even if an information leak occurs, the business side will not suffer significant damage (administrative penalties).
Furthermore, there are no financial sanctions for accidental mistakes or information leaks caused by hacking.
The Tokyo Bar Association issued a statement by its chairperson on July 3, 2026, stating the following:
Establishing special provisions (Article 30-2, Paragraph 1 of the amendment) that waive the need for individual consent for statistical creation, etc., including AI development, permits the provision of personal identification information such as names and addresses, as well as special care-required personal information such as race, beliefs, and medical history, without any processing, which increases the risk of infringing on individual rights and interests.
Why was "raw data" deemed necessary?
Even if one could be convinced by the argument that "named medical history data is absolutely necessary to create domestic AI that handles advanced medical information," "anonymous" data has been circulating until now anyway.
Even so, why was a new, "looser" law necessary?
In fact, if the data can be cross-referenced by the party providing it, it is treated as "personal data" even if the recipient cannot identify the individual.
Even if names and addresses are removed before transfer, there are many cases where the original data can be cross-referenced using combinations of IDs and dates/times, so the issue of "third-party provision of personal data" remains legally. And if it is personal data, it could not be transferred between businesses for utilization.
The statistical special exception was designed to fill these gaps.
As an example, the only way for a business to provide personal data to use a generative AI service was through "outsourcing." This created the problem that the outsourcing partner could not use the data for their own model training.
But isn't it natural that personal information cannot be used for purposes other than those intended?
If the logic of the proponents is that "we should loosen the rules because AI development companies are having trouble using the data for training if they follow these rules," then I think that is going too far.
"Wouldn't it have been better to at least remove names when providing the data?"
If you protect personal information too strictly, data organization for AI training becomes cumbersome, and development is delayed.
I understand that logic.
But wouldn't it have been better to at least make it mandatory to remove names? Even if it wasn't perfect, it would be better than nothing, right?
The logic of the proponents is,
"But even if names and addresses are deleted, if combinations of patient IDs, medical examination dates/times, and dates of birth remain, the providing hospital can still cross-reference 'whose data this is.' So, it can't be made perfect. It's meaningless."
That is what they say.
This point was also discussed during the deliberation of the bill.
On May 21, 2026, in a question-and-answer session at the House of Representatives, Committee Member Eiji Obana (Liberal Democratic Party) questioned the Secretary-General of the Personal Information Protection Commission to the effect of "Why is it not even mandatory to pseudonymize or delete names?".
The answer, in summary, is "Because it is difficult to organize items in AI development, and it is not easy for the provider to determine which items are unnecessary.".
As a saving grace, there is a requirement of "when necessary" even when providing personal information, and if names, etc., are clearly unnecessary and can be easily deleted but are provided mindlessly, this requirement is not met and it could be illegal.
In the future, PETs (Privacy Enhancing Technologies) and pseudonymization processing will be specified in commission rules and guidelines.
The government has repeatedly expressed this intention.
In the House of Councillors, an amendment was submitted to exclude sensitive personal information from the scope of statistical exceptions.It was submitted by three factions—the Constitutional Democratic Party, Komeito, and Okinawa no Kaze—but it was rejected by a minority.
But since it is a fact that identification becomes difficult without names and addresses, they should have at least left that as a final line of defense. Am I the only one who thinks that if they had done so, it wouldn't have been viewed as such a problem?
Another major point of contention is the definition of 'statistical creation, etc.'—how far does that actually go? It's ambiguous, isn't it?
In an extreme case, if I said I wanted data to create statistics for use in an article, would that be allowed?
The definition of 'statistical creation, etc.' is set to be 'determined by the Personal Information Protection Commission rules,' and the specific scope of application will be decided based on future rules and guidelines. It is ambiguous for now.
Even though there were opposing opinions
At the House of Councillors witness hearing (June 19, 2026), Professor Tomohiro Kuroda of Kyoto University Hospital stated thatthere is no benefit to introducing statistical exceptions, and since there is no obligation for safety management against information leaks, the security of the system will decreaseHe said that as a hospital, providing patient data is 'too scary to do.'
The Japan Federation of Bar Associations also pointed out in a written opinion on April 16, 2026, that statistical information, etc., could be used for profiling,leading to potential infringement of individual rights and interests, and that the scope of statistical creation, etc., should be strictly defined by lawthey stated.
For example, during some kind of screening. Employment. I worry that data like medical history might be used for profiling behind the scenes at times like that.
And I worry that it might end up holding us back when we are trying hard to make a 'fresh start'.
I am truly afraid of that.
Does the promotion of AI development justify a loophole in human rights?
The purpose of the Act on the Protection of Personal Information is to 'protect the rights and interests of individuals while considering the utility of personal information,' and a balance between utilization and protection is a prerequisite.
Since the emergence of ChatGPT at the end of 2022, international competition in AI development has accelerated, and the utilization of data necessary for statistical creation and AI development has become a policy issue.
'Delays in response will create major obstacles to AI development.'
That is why they say that relaxing personal information protection is necessary.
On the other hand, at the House of Councillors witness hearing, Diet member Mikishi Daimon asked why penalties, injunctions, and victim recovery are not being realized.
In other words, it sounds like a criticism that the protection of personal information and consideration for human rights are being put on the back burner in order to prioritize the economy.
What are other countries doing?
So, what about other countries?
EU
The EU has always been strict about personal information management and has implemented the GDPR (General Data Protection Regulation).
In principle, the processing of data in 'special categories,' which corresponds to sensitive personal information, is prohibited.
In 2025, the EU submitted AI-related regulations divided into two bills: the 'AI Omnibus' and the 'Data Omnibus,' and the AI Omnibus was officially adopted by the Council of the EU on June 29, 2026.
However, the clause that would have explicitly allowed AI operators to use AI training based on 'legitimate interests' was ultimately removed from the main text, leaving only a mention in the non-legally binding preamble.
Legal experts have described this as a 'failure to ensure legal certainty.' The Data Omnibus (an amendment to the GDPR itself), which includes exceptions for sensitive data, is stalled in negotiations, and final adoption is not expected until the end of 2026 or later.
On July 7, 2026, the European Data Protection Board (EDPB) published a draft guideline on web scraping for generative AI purposes. While it calls for data minimization measures, it is still in the public comment stage and is not the final version.
In other words, while the EU is moving toward relaxing personal information protection for AI development, it is facing difficulties.
South Korea
The PIPA (Personal Information Protection Act of South Korea), which was passed by the National Assembly in February 2026 and promulgated on March 10, will come into effect on September 11, 2026.
The provision allowing pseudonymized data to be processed without the individual's consent for the purposes of statistics, scientific research, and public interest archiving is actually an existing system that predates this amendment, and the interpretation that AI training can also gain a legal basis through the 'scientific research' route has become established.
What was newly established this time is primarily the strengthening of corporate governance responsibilities.
The cap on administrative fines is generally 3 percent of total revenue, but it can be raised to 10 percent if aggravating factors apply, such as repeated violations within three years or serious violations affecting more than 10 million people.
Note that a special exception for using personal data in its original form (without pseudonymization) for AI training is not included in the amended PIPA and is currently under deliberation in the National Assembly as a separate bill (not yet enacted). This point is a decisive difference from Japan's statistical exception.
As described, both the EU and South Korea are trying to make more data available for AI development.
However, both countries have stopped short of going too far regarding particularly sensitive information such as medical history or personal beliefs.
It can be said that Japan's statistical exception is a fairly bold choice from an international perspective, given that it did not include those additional protective measures.
However, it is not unlimited.
However, this exception cannot be used without limits.
Usage is strictly limited to the scope of 'statistical creation, etc.,' use for other purposes is prohibited, re-provision to third parties is prohibited in principle, and violations are subject to administrative fines in some cases.
Determining the presence or absence of illness in specific individuals, using data for hiring or personnel evaluations, or creating analysis results in a form that can identify individuals is not permitted.
Well, I don't know how well it will actually be protected.
On the other hand, the scope defined by the Personal Information Protection Commission's rules has not yet been decided.
Therefore, the extent to which it is actually properly regulated will depend on how these 'rules' are formulated.
Enforcement is in 2028. We must protect our own information.
Some of you may have felt anxious after reading this far.
However, enforcement is still a long way off.
The specific scope of 'statistical creation, etc.' will be determined by the Personal Information Protection Commission's rules and guidelines from here on out.
Medical history, criminal records, and personal beliefs.
These pieces of information have the power to hold people back later in life when they are trying to recover from setbacks or failures and move forward.
Just when you think, 'I'm okay now,' your past information could be passed on to a third party, potentially causing you to lose your current job or relationships.
It feels like we are heading toward a 'society that does not forgive failure or setbacks,' and as someone affected, I find that frightening.
Of course, it is possible that once it is actually enforced, we might find that it was 'nothing to worry about after all.'
But even just the increased possibility of a leak is scary, and I also question whether the benefits of promoting AI development are worth the fear, the loss of our human rights, and the potential harm we could suffer.
Will really being able to hand over data without protecting personal information provide such a significant boost? And is the wealth it brings worth the same weight as what this law has discarded?
It is deeply regrettable that a law that punches a hole in the Personal Information Protection Act was passed without sufficient explanation or verification.
And as someone on the side of building systems, I know how difficult it is to track where data goes once it has been sent externally. I cannot think of this as someone else's problem.
That is precisely why knowing about this issue is the first step toward protecting yourself.
What will be decided before enforcement, and what kind of discussions will take place?
Watching the movements of the Personal Information Protection Commission and having the option to speak up if necessary—I believe that is the path to protecting our rights ourselves.
There are many parts that have not been decided yet.
We must protect our own personal information.
I would be happy if we could share that sentiment together.
Thank you for reading to the end.
Related Articles
#YeKu
#PersonalInformationProtectionAct
#MentalHealthNews
#Privacy
#AIDevelopment
#SensitivePersonalInformation
#ILikeSociety
#RecentLearning
いいなと思ったら応援しよう!
最後までお読みいただき、ありがとうございます!
「役に立った」「読んでよかったな」と思っていただけたら、無理がない範囲で応援いただけると嬉しいです。
いつも、皆様のあたたかいお気持ちで活動できています😊