Loading…
Japan's framework combines the APPI with rules and guidelines issued by the Personal Information Protection Commission, legislation on national identification numbers, telecommunications and marketing rules, and sector-specific guidance. Depending on its activities, an organisation may need to consider several of these alongside one another.
The requirements applicable to an organisation depend on its activities, sector, the categories of information it handles, and its regulatory status.
The APPI is Japan's principal data protection law. It sets obligations for businesses that handle personal information and is enforced by the Personal Information Protection Commission (PPC).
Depending on applicability, organisations may need to address:
Organisations should assess the APPI's scope, including its extraterritorial application, and the categories of information they handle before determining which obligations apply.
The APPI has been amended several times. The 2015 amendments, which took full effect in May 2017, extended the Act's reach to businesses abroad and followed the establishment of the PPC in 2016. Amendments that took effect in April 2022 introduced mandatory breach reporting, expanded individual rights, new categories of information, and higher corporate penalties.
The Act is subject to periodic review, and further amendments have been under consideration.
Organisations should monitor the outcome of the current review and confirm the provisions in force.
The Cabinet Order, the PPC's Enforcement Rules, and the PPC's guidelines set out how the APPI's requirements should be met in practice, including detailed expectations on security measures, breach reporting, and cross-border transfers.
The guidelines are an important reference for compliance, and sector-specific guidelines add further expectations in certain industries.
The My Number Act regulates the handling of individual numbers used for tax, social security, and disaster response purposes. It imposes stricter rules than the APPI on collecting, using, storing, and providing these numbers.
Organisations that employ staff in Japan typically handle individual numbers and should assess these requirements.
The Telecommunications Business Act includes rules on the external transmission of user information by certain online services, which are relevant to cookies and similar technologies.
The Act on Regulation of Transmission of Specified Electronic Mail and the Act on Specified Commercial Transactions regulate commercial email and generally require prior opt-in consent.
Businesses operating in regulated industries may face additional obligations beyond general data protection law.
Sector considerations:
The APPI and related requirements may apply to:
Organisations that handle personal information for business purposes in Japan, regardless of their size.
Businesses outside Japan that handle the personal information of individuals in Japan in connection with supplying goods or services to them.
Companies entrusted with handling personal data for other businesses, which are subject to supervision by those businesses and to their own security duties.
Online services, which should also consider the rules on external transmission of user information and opt-in consent for commercial email.
Organisations handling employee records and individual numbers under the My Number Act.
Businesses receiving personal data from the EU or UK under the adequacy arrangements, which must follow the PPC's Supplementary Rules.
The precise obligations depend on the organisation's role, processing activities, size, risk profile, and territorial scope.
Businesses must specify the purpose of use as precisely as possible, notify individuals of it or make it public, and not use personal information beyond that purpose without consent. Special care-required personal information generally needs the individual's prior consent to acquire.
Businesses must take necessary and appropriate measures to keep personal data secure, and exercise necessary and appropriate supervision over employees and over contractors entrusted with handling personal data.
Individuals can request disclosure of their retained personal data, its correction, and, in certain circumstances, that its use or provision to third parties be stopped. Businesses should maintain procedures for receiving and responding to these requests.
Certain breaches must be reported to the PPC and notified to affected individuals, including those involving special care-required information, a risk of financial harm, a suspected wrongful purpose, or more than 1,000 individuals. A preliminary report is required promptly, followed by a final report within 30 days, or 60 days where a wrongful purpose is suspected.
Providing personal data to a third party generally requires the individual's prior consent, subject to exceptions such as entrustment to a contractor and joint use. Businesses must keep records of what they provide and confirm certain matters when they receive personal data.
Providing personal data to a third party in a foreign country requires the individual's consent, given after receiving information about that country's data protection system, unless the recipient is in a country recognised by the PPC or has a system that meets the PPC's standards.
The APPI does not generally require a Data Protection Officer or a local representative, although appointing a person responsible for personal information handling is recommended practice.
The APPI gives individuals a number of rights over their retained personal data. Depending on the circumstances, these may include:
Individuals may ask to be told the purpose for which their retained personal data is used.
Individuals may request disclosure of their retained personal data, including in electronic form, and of records of its provision to third parties.
Individuals may request that inaccurate retained personal data be corrected, added to, or deleted.
Individuals may request that use stop or data be erased in certain cases, such as unlawful handling or where their rights or legitimate interests are likely to be harmed.
Individuals may request that the provision of their data to third parties stop in the circumstances set out in the Act.
Businesses are expected to handle complaints about their handling of personal information appropriately and promptly.
Organisations should publish the procedure for making requests and assess the conditions and exceptions that apply to each right.
The APPI has been strengthened through a series of amendments.
The Act on the Protection of Personal Information was enacted, with its obligations on businesses taking full effect in 2005.
The 2015 amendments took full effect, extending the Act to certain businesses outside Japan. The Personal Information Protection Commission had been established in 2016.
The EU and Japan recognised each other's data protection systems as providing an adequate level of protection, easing transfers between them.
Amendments took effect introducing mandatory breach reporting, expanded individual rights, and higher corporate penalties.
Important: the APPI is reviewed periodically and further amendments have been under consideration. Confirm the provisions in force using official sources before changing your compliance programme.
The Personal Information Protection Commission (PPC) is Japan's independent data protection authority. It supervises compliance with the APPI, issues guidelines, and can require reports, carry out on-site inspections, and give guidance, recommendations, and orders, including to businesses outside Japan.
Sector authorities, such as the Financial Services Agency and the Ministry of Internal Affairs and Communications, issue additional guidelines and may exercise delegated powers in the industries they oversee.
Organisations should check whether sector-specific guidelines apply to them in addition to the PPC's general guidelines.
The APPI is enforced mainly through PPC guidance, recommendations, and orders. Failing to comply with a PPC order can lead to imprisonment of up to one year or a fine of up to ¥1 million for individuals, and a fine of up to ¥100 million for corporations.
Providing or misusing a personal information database for wrongful gain is also a criminal offence, with fines of up to ¥100 million for corporations. The PPC may publicise failures to comply with its orders. The APPI does not currently provide for administrative fines, although this has been under consideration in the review of the Act.
RegulatoryBridge helps organisations assess Japan's regulatory requirements and coordinate their compliance activities with wider international programmes.
Review your handling of personal information, purposes of use, notices, policies, governance arrangements, and operational controls to identify potential gaps.
Review how responsibility for personal information handling is organised, including internal rules, the supervision of contractors, and coordination with your global privacy team.
Review consent practices, published information, request-handling processes, and related documentation against the requirements applicable to you.
Evaluate incident procedures, escalation responsibilities, and readiness to make preliminary and final reports to the PPC and notify individuals.
Assess data flows into and out of Japan, transfer mechanisms, vendor relationships, and record-keeping against the APPI's transfer requirements.
Help organise requirements across privacy, telecommunications, financial services, and other regulatory frameworks relevant to your business.
Monitor relevant developments and review compliance plans when legislation, PPC guidelines, or the outcome of the APPI review change.
The scope of support is tailored to the organisation's activities, risk profile, and applicable legal requirements.
Assess your organisation's activities, role in processing personal data, industry, and connections to Japan.
Identify applicable provisions, relevant authorities, effective dates, and sector-specific requirements.
Review existing policies, notices, consent mechanisms, contracts, security controls, and operational processes.
Prioritise remediation activities and establish owners, milestones, documentation requirements, and implementation plans.
Review regulatory developments, reassess relevant obligations, and update compliance processes when required.
We support your privacy governance, PPC interactions, and breach response - so your global product team doesn't have to.