Hanko AI›Japanese Law Guide›個人情報保護法第27条

個人情報保護法第27条

Personal Information Protection Act Article 27 (Restrictions on Third-Party Provision)

個人情報保護法第27条(第三者提供の制限)

Plain-language explanation

Note: The retrieved text did not actually contain the text of Article 27 itself. Instead, the system returned related provisions — Article 26 (breach reporting obligations), Article 54 (guidelines by certified personal information protection organizations), and Article 56 (restriction on using the "certified organization" name). Based on general knowledge of the Act's structure, Article 27 typically governs "Restrictions on Provision to Third Parties," setting out the default rule that a business handling personal information may not provide personal data to a third party without the data subject's consent, along with exceptions such as the opt-out procedure. We recommend verifying the exact current text via an official source such as e-Gov before relying on it for legal decisions.

For context, the retrieved Article 26 requires a personal information handling business operator to report to the Personal Information Protection Commission (and, in most cases, notify the affected individuals) when a data breach or similar security incident occurs that poses a significant risk to individual rights and interests — unless the operator was merely a subcontractor and already notified the outsourcing party. This is commonly discussed alongside third-party provision rules because sharing data with subcontractors or joint-use partners raises similar compliance questions about what counts as a "third party" and what safeguards or consents are required.

In practice, businesses often confuse legitimate data sharing (e.g., with subcontractors, or under a joint-use arrangement) with prohibited third-party provision. Misclassifying a data transfer can trigger both a violation of the third-party provision rules and, if a leak results, the breach-reporting duties under Article 26. Given the retrieved text does not confirm Article 27's actual wording, please treat this explanation as directional only and confirm the current statutory text before making compliance decisions.

日本語での解説

この照会では第27条そのものの条文が取得できず、代わりに第26条(漏えい等の報告義務)、第54条(個人情報保護指針の作成)、第56条(認定団体の名称使用制限)の内容が返されました。一般的に個人情報保護法第27条は「第三者提供の制限」を定める条文であり、個人情報取扱事業者が本人の同意を得ずに個人データを第三者に提供することを原則として禁止し、オプトアウト手続などの例外要件を規定しています。正確な条文内容を確認したい場合は、e-Gov法令検索など公的データベースで最新の条文を直接ご確認いただくことを強くお勧めします。

なお、参考として提供された第26条は、個人データの漏えい等が発生した際に、事業者が個人情報保護委員会へ報告し、本人へも通知する義務を定めたものです。第三者提供に関する第27条の理解を深める際には、この報告義務や、認定個人情報保護団体の指針作成義務(第54条)など、関連する周辺規定も併せて確認することが実務上重要です。

ビジネス実務においては、第三者提供に関するルールを誤解すると、委託先への情報共有や共同利用のスキームが違法な「第三者提供」とみなされるリスクがあります。正確な条文確認と専門家への相談を強く推奨します。

Common scenarios

  • ▸業務委託先にユーザーの個人データを渡す際、それが「第三者提供」に該当するか、それとも委託の範囲内かを判断する場面
  • ▸グループ会社間で顧客データを共同利用するスキームを構築する際の適法性チェック
  • ▸マーケティング目的で外部の広告会社に顧客リストを提供しようとする場面
  • ▸オプトアウト方式で個人データを第三者提供する際の届出・通知手続きの整備
  • ▸M&A・事業譲渡に伴い顧客データを譲渡先企業へ移転する際の同意取得の要否確認

Related statutes

  • 個人情報保護法第23条(第三者提供の制限の原則)
  • 個人情報保護法第26条(漏えい等の報告等)
  • 個人情報保護法第28条(外国にある第三者への提供の制限)
  • 個人情報保護法第54条(個人情報保護指針)

Does this affect your contract?

Hanko AI reviews your contracts against 個人情報保護法第27条 and other Japanese statutes in under 60 seconds.

Review your contract free →

Generated by Hanko AI from the official Japanese statute corpus. A general statutory reference for the practising attorney. Confirm the current statute against the facts of your matter.

Personal Information Protection Act Article 27 (Restrictions on Third-Party Provision) | 個人情報保護法第27条 | Hanko AI | Hanko AI 判断