Japan
A close Five Eyes SIGINT partner and Budapest Convention party hosting $500M+ in NSA operations, its 1,700-person signals agency a secret to most of its own government and free of independent oversight
Overview
Japan’s Directorate for Signals Intelligence (DFS) operates ~1,700 personnel across at least six surveillance facilities conducting around-the-clock interception, with no independent oversight body, most Japanese government officials are kept in the dark about its activities. The DFS runs on NSA-provided XKeyscore, and Japan has financed NSA operations on Japanese soil (detailed below). Japan participates in Five Eyes Plus after initially declining SSPAC membership. CIRO is being upgraded to a National Intelligence Bureau by mid-2026, with an external intelligence agency planned by end of FY2027.[1][2]
On the civilian side, the APPI (Act on the Protection of Personal Information, three-year review cycle) earned Japan the first EU mutual adequacy decision (January 2019). The Active Cyber Defense Act (May 2025) authorises pre-emptive cyber operations and government access to telecommunications metadata via agreements with critical infrastructure operators. Japan has no mandatory data retention law.[3]
Japan’s outward data-sharing runs through its alliances and treaties, each detailed below. Anchored by the US-Japan security alliance (the 1960 Treaty of Mutual Cooperation and Security plus GSOMIA), it participates in Five Eyes Plus intelligence sharing (having declined formal SSPAC membership), holds bilateral intelligence-sharing agreements with Australia, the UK, France, and South Korea, and provides mutual legal assistance through bilateral treaties (with the United States, South Korea, China, Hong Kong, Russia, and Vietnam), the EU-Japan MLA agreement, and the Budapest Convention on Cybercrime. These are the channels through which the domestic protections described below are, in practice, bypassed.[2][14][15][24]
International Data Sharing Agreements
Five Eyes Plus
Japan initially declined SSPAC membership, citing disclosure risk. Since January 2020, it participates in “Five Eyes Plus”, joining the Five Eyes (Australia, Canada, New Zealand, the United Kingdom, and the United States) together with France and South Korea, for intelligence on North Korea and China. Discussion of formal “Six Eyes” membership continues but has not materialised.[2]
Mutual Legal Assistance
Japan’s MLAT/MLAA partners: United States (signed August 5, 2003, Japan’s first bilateral MLAT, in force July 21, 2006), South Korea, China, Hong Kong SAR, Russia, and Vietnam. Japan also signed an EU-Japan MLA agreement, the first “self-standing” MLA agreement between the EU and a non-EU country. Japan can also provide assistance without a treaty based on the principle of reciprocity. Its treaties are published in the Ministry of Foreign Affairs’ treaties database.[14]
Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Japan ratified the Council of Europe’s cybercrime convention in 2012, one of the first non-European states to do so; it governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states, Japan among them: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[24]
US-Japan Security Alliance
The 1960 Treaty of Mutual Cooperation and Security, supplemented by the GSOMIA (2007) for classified military information. Drives extensive intelligence sharing on China, Russia, and North Korea. Japan maintains separate intelligence-sharing agreements with Australia (2012), the UK (Hiroshima Accord), and France. A US-Japan-Australia trilateral intelligence arrangement was signed in 2016. Japan-South Korea GSOMIA (2016): first bilateral intelligence-sharing agreement since 1945 liberation, focused on North Korean threats.[15][16]
Multilateral Frameworks
Interpol: NPA serves as National Central Bureau. Egmont Group: JAFIC participates (FATF: compliant/largely compliant on 39/40 Recommendations). APEC CBPR and Global CBPR Forum member; the Forum (established 2022 from the APEC system) certifies cross-border personal-data transfers among its nine members, Australia, Canada, Japan, Mexico, the Philippines, Singapore, South Korea, Chinese Taipei, and the United States, with the United Kingdom as an associate. EU mutual adequacy (January 2019).[17][27] Quad: Japan belongs to the Quadrilateral Security Dialogue alongside the United States, India, and Australia, a strategic security-cooperation grouping with an intelligence dimension.[25]
The Privacy Backdoor Effect
Despite PPC enforcement and EU adequacy, alternative access pathways exist:
- Five Eyes Plus: Intelligence sharing with access to partner nations’ collection capabilities
- NSA on Japanese soil: $500M+ investment, XKeyscore deployed to DFS, at least three NSA bases
- MLAT / Budapest Convention: law enforcement data requests through the US and other bilateral treaties, the EU-Japan MLA agreement, and the 82 parties to the Budapest Convention
- Cable hub: Primary US-Asia telecommunications hub exposing transiting communications to interception
- Active Cyber Defense Act: Government metadata access via operator agreements at cable chokepoints
Surveillance and Intelligence
Japan lacks a comprehensive intelligence authorisation statute. Each agency operates under separate legal authority with no independent oversight body reviewing operations across agencies.[5]
DFS (Directorate for Signals Intelligence)
Japan’s secret SIGINT agency (~1,700 personnel), revealed by The Intercept in 2017–2018 based on Snowden documents. The MALLARD programme (Tachiarai base, northern Kyushu) collected ~200,000 internet sessions per week (stored two months). NSA provided XKeyscore in April 2013. Japan financed $500M+ in NSA facilities including at least three NSA bases. The Misawa Security Operations Center (LADYLOVE) uses ~12 antenna domes for satellite interception across the Asia-Pacific. Operations are “so highly classified that the Japanese government has disclosed little about its work” with “no independent oversight.”[1][6]
Other Intelligence Agencies
CIRO (~170 agents): Principal civilian intelligence body under the Cabinet Secretariat, operating surveillance satellites. Upgrading to National Intelligence Bureau by mid-2026. DIH (Defence Intelligence Headquarters, est. 1997): 19 ground-based SIGINT stations; expanding beyond SIGINT to IMINT, HUMINT, and OSINT. PSIA (Public Security Intelligence Agency, est. 1952): Investigates organisations threatening the democratic system. NPA Security Bureau: Contains classified signals unit “YAMA” with access to intercepts.[7][8]
Muslim Surveillance Program
In 2010, 114 leaked police files revealed systematic religious profiling of at least 72,000 residents from OIC countries, including ~1,600 school students. The Tokyo Metropolitan Police’s “mosque squad” (43 agents) surveilled mosques and compiled databases. The Supreme Court dismissed plaintiffs’ appeal (May 2016), effectively confirming the programme’s legality.[9]
Internet Infrastructure and Cable Surveillance
Japan is the telecommunications hub for nearly all US-Asia bandwidth. At least 20 international cable landing stations serve ~30 cable systems. 99% of international communications depend on subsea cables, with 80%+ of data centres in Tokyo/Osaka. Major IXPs: JPNAP (five networks), JPIX, and BBIX (SoftBank subsidiary). Major transpacific cables include Pacific Crossing-1, FASTER, NCP, JUPITER, and Topaz.[10]
Japan’s position as the primary US-Asia cable hub makes its landing stations strategically significant for intelligence. The DFS operates interception capabilities at cable chokepoints. The Active Cyber Defense Act (2025) enables government agreements with critical infrastructure operators (including NTT Communications, which dominates Japan’s backbone and international cable infrastructure) to receive and analyse telecommunications metadata.[10][11]
Commercial Surveillance
NEC Corporation: 1,000+ active biometric systems in 70+ countries, “Safer Cities” predictive policing suite, US DHS $23.9M contract, and technology underpinning India’s Aadhaar. Cellebrite (majority-owned by Japan’s Sun Corporation): adopted by NPA, Metropolitan Police, prosecutors, and customs. Domestic facial recognition: JR East deployed across 8,350 cameras at 110+ stations (July 2021) targeting ex-prisoners, parolees, and “suspicious” persons. Japan is a founding Wassenaar Arrangement member for dual-use export controls; considering restricting facial recognition exports to China.[12][13]
Recent Developments
Intelligence Reform (2025–2027): CIRO upgrading to National Intelligence Bureau (mid-2026). External intelligence agency planned by end of FY2027. New ministerial intelligence post. Anti-espionage legislation under consideration; HRW warned it “would need to respect rights.”[18]
Active Cyber Defense Act Enacted (May 2025): Authorises pre-emptive cyber operations including neutralising attacker infrastructure abroad. Government metadata access via critical infrastructure operator agreements.[11]
MirrorFace Campaign (January 2025): NPA attributed 200+ cyberattacks (2019–2024) to Chinese APT10 subgroup MirrorFace, targeting MoD, MoFA, JAXA, Japan Airlines, politicians, journalists, and semiconductor firms.[19]
Economic Security Clearance Act (May 2025): Security clearance system for economic security information. Up to 5 years imprisonment for unauthorised disclosure. Enables participation in allied joint development projects.[20]
APPI Amendment Bill (2026): The PPC published its Policy on Institutional Amendments in January 2026, formalising four pillars: (1) introduction of administrative monetary penalties and injunctive relief; (2) a consent exemption for statistical and AI-related processing, easing the strict consent requirement that has been a hurdle for AI training datasets; (3) a risk-based notification framework exempting individual notice for breaches with “low risk of harming the rights and interests of the individual”; and (4) strengthened minors’ protection, including a new Article 40-2 directing consent and notice obligations to the parent or statutory representative when a business handles the data of a child under 16. The Cabinet approved the amendment bill on April 6, 2026, and the Diet passed it on July 10, 2026, with promulgation on July 17, 2026; the new rules enter into force within two years of promulgation, so by mid-2028 at the latest. The surcharges are the first administrative monetary penalties in the APPI’s history. Commentary characterises the package as positioning Japan as one of the most permissive OECD jurisdictions for AI training data.[4][22][26]
The bill also creates a category the earlier four-pillar summary did not capture, and it is the one most relevant to surveillance. Specified Biometric Personal Information is defined as personal information generated by converting a person’s physical characteristics, such as fingerprints or facial features, into numerical data for computer processing, where the data is obtained without special technology or significant cost and is not readily recognisable by the individual as having been collected. That definition is aimed squarely at facial-recognition templates captured from ordinary camera footage, of the kind JR East deployed across 8,350 cameras. Businesses handling such data must publish their identity, the purpose of use, the procedures for rights requests, and the types of physical characteristics converted; the data may not be transferred to third parties under the opt-out mechanism, closing the route by which Japanese data brokers have historically moved personal information without consent; and the thresholds for demanding suspension of use or transfer are relaxed, as they are for children’s data. These biometric provisions became law with the rest of the amendment on its July 10, 2026 Diet passage (promulgated July 17), entering into force within two years of promulgation.[23][26]
Social Media Minors Advisory Group, Ban Rejected (2026): Japan’s government working group on protection of minors online ruled out an Australian-style social media ban at its third meeting in 2026, instead endorsing stricter age verification, parental control tools, content rating systems, and greater platform transparency on risk assessments. Japan’s approach thus diverges from Australia, Denmark, Spain, Greece, Norway, and France in rejecting an outright minimum-age prohibition in favour of platform-side age-assurance obligations within the forthcoming APPI amendment.[21]
Privacy Framework
The PPC (Personal Information Protection Commission) enforces the APPI through a guidance-first approach with escalation to orders and criminal prosecution. Article 13 of the Constitution (right to pursue happiness) is interpreted to include a right to privacy. The APPI’s third mandatory three-year review (initiated November 2023) proposes introducing administrative monetary penalties, injunctive relief, strengthened minors’ protection, and mandatory privacy impact assessments. The Communications Interception Act (1999) requires judicial warrants for wiretapping, limited to specific organised crime offences. The Specially Designated Secrets Act (2013) criminalises disclosure of classified information (up to 10 years imprisonment).[3][4]
Data Retention
Japan has no mandatory data retention law. Operators define their own retention periods, which must be “within the period needed for the purposes of use.” The Active Cyber Defense Act (2025) introduced government access to telecommunications metadata via operator agreements, the most significant expansion of government access since the 1999 Communications Interception Act.[11]
Pending Legislation
- APPI amendment – ENACTED: passed by the Diet on July 10, 2026 and promulgated July 17, 2026 (Cabinet-approved April 6); introduces administrative monetary penalties and injunctive relief, a consent exemption for statistical/AI-training processing, risk-based breach notification, under-16 parental-consent rules (new Article 40-2), and a new category of Specified Biometric Personal Information (facial and fingerprint templates captured without the individual’s awareness) that carries transparency duties, relaxed deletion and suspension thresholds, and a bar on opt-out third-party transfers. In force within two years of promulgation, so by 2028.[4][22][23]
- Intelligence reform and anti-espionage law (surveillance): CIRO’s upgrade to a National Intelligence Bureau (mid-2026) and a planned external intelligence agency (end FY2027) are proceeding; anti-espionage legislation is under consideration, which Human Rights Watch cautioned “would need to respect rights.”[18]
- Minors’ online protection (age verification): rather than an Australian-style ban, the government working group favours age verification, parental controls, and rating systems, to be implemented largely through the APPI amendment and platform obligations.[21]
