Key takeaways
- On September 24, 2026, an expert panel convened by Japan's National Police Agency (NPA) proposed a new police power called "remote analysis" (遠隔解析). Police would access phones used by criminal groups remotely and copy messages from encrypted apps such as Signal and Telegram.
- The stated target is Japan's anonymous, loosely organized crime rings (匿流, tokuryū) behind record fraud and a wave of violent robberies. But the proposed legal trigger is broader: crimes believed to involve several conspirators, with no requirement that they form an ongoing group.
- Safeguards include a judge's permit in every case, NPA-designated specialist officers, deletion of data outside the permit, notification of the phone's user afterward, and after-the-fact review by public safety commissions.
- The panel met five times in about six weeks and had an outline of its proposal by its third meeting. For a power this intrusive, that is fast. The NPA now aims to amend the law, and the timing of a bill has not been announced.
What was proposed#
Japan's fraud and robbery rings recruit "disposable" low-level members over social media and direct them through encrypted messaging apps. When police arrest the person who makes the call or breaks into the house, the organizers and the next targets usually remain unknown. The panel's proposal notes that fraud losses hit a record of about ¥325.7 billion in 2025.
End-to-end encryption means that even a cooperating messaging provider cannot hand over message content. The panel's answer is to go to the device itself.
How remote analysis would work, according to the proposal:
- Police identify a phone believed to be used by the offenders, for example through victim reports, undercover operations or information from former members.
- Specialist officers apply to a judge for a permit, specifying the device and the information to be obtained.
- With the permit, officers access the device remotely, check its contents, copy the information needed, and delete anything the permit does not cover.
- Information such as the next target's name and address, the planned time, and the roles and weapons of the offenders goes to the officers responsible for preventing the crime, through patrols, warnings to potential victims and similar measures.
The proposal describes remote analysis as a one-time acquisition of data stored on the device, not continuous interception of communications. It also says the information obtained may later be used in criminal proceedings, through the procedures of the Code of Criminal Procedure.
The safeguards#
| Safeguard | What the proposal says |
|---|---|
| Strict requirements | A high probability of serious crime damage, urgency, and no other way to get the information quickly (補充性). Limited to devices used for communication among offenders or with victims |
| Judicial review | A judge's permit required in every case, before access |
| Who does it | Only officers with specialist skills, designated by the NPA Commissioner General. Separate from the officers who act on the information |
| Data handling | Copy only what the permit allows. Delete everything else |
| Notification | The user of the device is notified afterward, once doing so no longer jeopardizes the operation |
| Oversight | Every case reported to the relevant public safety commission, which can check it and instruct police to correct problems |
During its deliberations, the panel was briefed on the United Kingdom's Investigatory Powers Act and on Germany's Code of Criminal Procedure and the Bavarian police law.
Why the Police Duties Execution Act#
The panel chose to frame remote analysis as a power to prevent crime, not to investigate it. So the proposal would place it in the Police Duties Execution Act (警察官職務執行法), which governs what police may do to prevent harm, rather than in the Code of Criminal Procedure. The reasoning is that police often need to act before a crime has legally been committed, and a prosecution-focused procedure would not prevent enough harm.
This is the same act that, from October 1, gives police the power to access and neutralize computers used in cyberattacks, under the new Article 6-2 that we covered in our Active Cyber Defense explainer. If remote analysis is added, the Police Duties Execution Act would become the legal home of two separate powers for police to enter other people's devices over the network.
Our view#
Aimed at tokuryū, written more broadly#
For people in Japan, the most important question is whether this power will stay limited to the groups it is sold as targeting.
The proposal's own wording suggests it may not. It says the power should cover "damage from crimes believed to be committed through a conspiracy of several people". It also says, explicitly, that the law should not require the offenders to have an ongoing association. That is deliberate: tokuryū are loose, shifting networks, and a requirement tied to organized crime groups would miss them. But it also means the legal trigger is not defined as "tokuryū" at all. Any "serious crime" involving several conspirators could, in principle, qualify.
Two more details point the same way:
- Which crimes count as "serious" is not yet defined. The proposal speaks of "certain serious crimes" without a list.
- The threshold is set at the level of an ordinary search and seizure. The panel says it does not need the stricter standard of "sufficient reason" required for wiretapping. For a power that involves breaking into a phone, that is a notable choice.
None of this means the power will be misused. But once a power exists in law, its scope is decided by its wording, not by the problem that justified it. When a bill appears, the points to watch are:
- Whether the covered crimes are listed exhaustively
- Whether there is a review or sunset clause
- Whether police must publish annual statistics on how often the power is used, and against what
Six weeks to a proposal#
The panel's schedule, from the NPA's own records:
| Date (2026) | Meeting |
|---|---|
| August 10 | 1st meeting: open discussion of issues |
| August 26 | 2nd meeting: briefing on UK and German systems |
| September 2 | 3rd meeting: outline of the proposal presented |
| September 9 | 4th meeting |
| September 24 | 5th meeting: proposal adopted |
An outline was on the table 23 days after the first meeting. For comparison, the 2016 expansion of Japan's wiretapping law came out of a Legislative Council subcommittee that deliberated for about three years.
The urgency is real. Fraud losses are at record levels, and violent robberies directed over encrypted apps have shocked the public. Still, a proposal to let police break into phones, which the panel's own report says may involve exploiting device vulnerabilities or deceiving users, deserves more than six weeks of discussion. The speed leaves the impression that the conclusion was set before the panel began. Whether or not that is fair, it makes a careful, public Diet debate all the more important.
For the security community: vulnerabilities#
The proposal openly anticipates that remote analysis may require exploiting vulnerabilities in devices or deceiving the user, and records the view that police should be allowed to do so. It says the specific techniques must stay highly confidential. It also says the police must be able to show afterward that the data really came from the target device.
What it does not discuss is what happens to the vulnerabilities themselves. There is no mention of whether police would report the flaws they use to vendors, or of any process like the US government's Vulnerabilities Equities Process for deciding when to disclose. A police force that keeps unpatched vulnerabilities in widely used phones leaves everyone else exposed to them. That should be part of the debate when the bill is drafted.
What happens next#
According to press reports, the NPA aims to amend the Police Duties Execution Act at an early date. As of publication, it has not announced when a bill will be submitted to the Diet. We will update this article when the bill text is published.
Japanese terms at a glance#
| Japanese | Reading | Meaning |
|---|---|---|
| 遠隔解析 | enkaku kaiseki | "Remote analysis". Proposed police power to access offenders' devices remotely |
| 匿名・流動型犯罪グループ(匿流/トクリュウ) | tokumei ryūdō-gata hanzai gurūpu (tokuryū) | Anonymous, loosely organized crime groups |
| 警察官職務執行法 | keisatsukan shokumu shikkō-hō | Police Duties Execution Act |
| 許可状 | kyokajō | Permit issued by a judge |
| 公安委員会 | kōan iinkai | Public safety commission (civilian police oversight body) |
| 数人の共謀 | sūnin no kyōbō | Conspiracy of several people |