On September 3, RIZAP announced that an employee mistakenly uploaded customer information to an external generative AI service used for personal purposes. The affected data consists of a portion of the records of individuals subject to specific health guidance who were registered in the management system between January 1 and August 19.
The leaked information includes health insurance certificate symbols and numbers, email addresses, names, dates of birth, gender, addresses, and portions of phone numbers. Additionally, some sensitive personal information, such as support formats and disease information, was included.
The company explained that it received confirmation from the AI service operator that the data was likely not viewed by third parties or used for AI training. However, the company stated that it is still confirming whether employees of the service operator were able to view the relevant data.
Reporting to Personal Information Protection Commission has been completed. The company plans to contact the affected individuals sequentially. RIZAP stated that it will re-emphasize the prohibition of using unauthorized AI services within the company and strive to prevent a recurrence.
Source: 従業員が「個人利用のAIサービス」に顧客情報をアップロード RIZAPが謝罪 (ITmedia AI+, 2026-09-04)