NTT Docomo reports customer-information disclosure
NTT Docomo announced on September 16 that information linked to approximately 340,000 customer accounts had been provided to Amazon Japan without the customers’ consent. According to reports by multiple media outlets published the same day, the information involved 344,213 mobile lines connected to online applications for certain Docomo pricing plans.
The data shared consisted of telephone numbers and the names of the customers’ selected pricing plans. Docomo said Amazon Japan has already deleted the information. Based on the details publicly reported so far, the disclosed data did not include a broader range of personal information such as names, addresses, payment details, or communications content. However, telephone numbers remain personal data and can still create privacy and security concerns when handled without the user’s approval.
What caused the disclosure?
The incident was attributed to a configuration error on the Docomo side. In February, the telecommunications company updated the information displayed during certain online contract procedures. During that update, a setting intended to obtain customers’ consent before sharing information with Amazon Japan was reportedly omitted.
As a result, customers who completed online contracts between April 21 and August 20 were affected. The issue did not arise because customers actively selected an option to share their information; rather, the consent mechanism was not properly configured after the display changes were introduced. This distinction is important because consent is a central principle in the handling of personal information, particularly when data is transferred to another company.
Why the case matters in Japan
Japan has a highly developed digital-services market, with consumers increasingly signing up for mobile plans, payments, shopping services, and government-related procedures online. Large companies such as NTT Docomo frequently work with technology and e-commerce partners to provide connected services. These partnerships can make online applications more convenient, but they also require careful coordination over privacy notices, consent screens, data transfers, and system settings.
For international readers, NTT Docomo is one of Japan’s largest telecommunications operators and a major provider of mobile and digital services. Amazon Japan is the Japanese arm of the global e-commerce company. The involvement of two prominent brands means the incident is likely to draw attention from customers, regulators, and businesses reviewing how consent is managed across partner platforms.
Lessons for customers and companies
The case highlights how a relatively small technical or administrative change can affect hundreds of thousands of online transactions. Consent procedures are not merely wording displayed on a website; they depend on software configuration, internal checks, employee awareness, and ongoing audits. A missing setting can therefore have consequences well beyond the original system update.
Docomo’s disclosure and Amazon Japan’s deletion of the information are important steps toward addressing the matter. Customers affected by the incident may reasonably expect clear explanations about the scope of the disclosure, the period involved, the safeguards applied, and whether any further action is necessary. Companies operating in Japan and serving overseas users can also view the case as a reminder that privacy protection must remain part of every stage of digital-service development.
The incident does not diminish Japan’s broad progress in building reliable digital infrastructure, but it underlines the need for constant verification as online services become more interconnected. Transparent reporting, prompt containment, and stronger consent controls will be essential to maintaining public confidence in Japan’s rapidly evolving digital economy.