APPI
Act on the Protection of Personal Information (Japan)
Japan's privacy law, recognized by the EU as adequate.
The law in brief
Japan's Act on the Protection of Personal Information (APPI) applies to every business that handles personal information in Japan, with no size threshold. It is enforced by the Personal Information Protection Commission (PPC), and it is recognized by the EU as providing adequate protection, with supplementary rules for data received from the EU.
Amendments in force since April 2022 made breach reporting mandatory, extended the law to foreign businesses serving people in Japan, and tightened rules on cross-border transfers and on providing data to third parties.
Who it applies to
- Business operators handling personal information, meaning any business using a personal information database for its business, regardless of size.
- Foreign businesses that handle personal information of people in Japan in connection with supplying goods or services to them.
- It covers personal information, special care-required personal information, pseudonymously processed information, anonymously processed information, and person-related information such as cookie data that becomes personal in the recipient's hands.
What it requires
Purpose of use
Specify the purpose of use as far as possible, notify or publish it, and do not use personal information beyond it without consent.
Security and supervision
Take necessary and appropriate security control measures, and supervise employees and entrusted persons handling personal data.
Breach reporting
Report leaks and similar incidents that risk harming individuals' rights to the PPC and notify the affected individuals.
Consent for third-party provision
Obtain prior consent before providing personal data to a third party, except under listed exceptions or the opt-out procedure notified to the PPC, and keep records.
Cross-border transfer
Obtain consent before providing personal data to a third party in a foreign country, with information about that country's system, unless the recipient maintains an equivalent system or the country is recognized.
People's rights
Individuals can request disclosure of retained personal data and records of third-party provision, correction, and cessation of use or of provision to third parties in specified cases, including when the data is no longer needed or a breach has occurred.
Enforcement and penalties
The PPC can require reports, give guidance and issue orders. Violating a PPC order can lead to imprisonment or fines for individuals and fines of up to ¥100 million for corporations.
What's changing
Periodic review. The PPC reviews the law every three years, and further amendments have been under consideration, including administrative fines. Regulatory Watch reports any bill.
What to do first
- Specify and publish purposes of use, and use data only within them.
- Get consent for special care-required information and for provision to third parties, unless an exception or the notified opt-out applies.
- Before transferring abroad, get consent with information about the destination country's system, or rely on an equivalent system or the EU and UK adequacy routes.
- Keep records of third-party provision and receipt.
- Set up breach reporting: a prompt preliminary report to the PPC, a full report within 30 days (60 for malicious incidents), and notice to individuals.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.
Sources
- Act on the Protection of Personal Information (English translation) Personal Information Protection Commission · Official text or regulator