Asia-Pacific Japan

Japan APPI Compliance Guide: Requirements After 2022

Japan's Act on the Protection of Personal Information: scope, purpose limitation, consent rules, breach reporting, pseudonymization, and PPC enforcement.

Regulation

Act on the Protection of Personal Information (Act No. 57 of 2003, amended 2020, effective 1 April 2022)

Max Penalty

JPY 100 million corporate fine for order violations or database theft; individual imprisonment up to 1 year

Enforcing Authority

Personal Information Protection Commission (PPC)

Official Source

www.ppc.go.jp

Executive Summary

  • APPI applies to any business operator handling personal information of individuals in Japan, including foreign operators supplying goods or services to Japan.
  • The 2020 amendment (effective 1 April 2022) made breach reporting to the PPC and affected individuals mandatory, raised corporate fines to JPY 100 million, and expanded data subject rights.
  • APPI is purpose-driven rather than consent-driven: operators must specify a utilization purpose and stay within it, with consent required for sensitive data, third-party provision, and most cross-border transfers.
  • Japan holds mutual adequacy with the EU (since 23 January 2019), so EEA data can flow to APPI-compliant operators under supplementary rules.
  • Two engineered categories reduce friction: pseudonymously processed information (relaxed internal-use duties) and anonymously processed information (freely usable if properly de-identified).

APPI is the oldest comprehensive privacy law in Asia (2003) and works differently from the consent-heavy regimes around it. The core discipline is purpose limitation: declare what you use personal information for, publish it, and stay inside it. Consent is reserved for the dangerous edges, sensitive data, third-party sharing, exports. The 2020 amendment, in force since 1 April 2022, hardened the regime with mandatory breach reporting, extraterritorial enforcement, and a tenfold fine increase.

RegulationAPPI, Act No. 57 of 2003 (amended 2020, effective 1 April 2022)
Max penaltyJPY 100M corporate fine; 1 year imprisonment
Enforcing authorityPPC
Official textJapanese Law Translation, Act No. 57

Core obligations

Purpose specification and limitation. Specify the utilization purpose as concretely as possible, publish or notify it at acquisition, and do not exceed it without consent. Purpose changes are allowed only within a scope reasonably related to the original.

Proper acquisition and accuracy. No acquisition by deceit or improper means; keep data accurate and current within the purpose, and delete without delay when no longer needed.

Security control measures. Organizational, human, physical, and technical safeguards proportionate to the data, plus supervision of employees and entrusted processors. The PPC’s guidelines spell out the expected control set; the LINE Yahoo action shows the PPC treating weak vendor supervision as an APPI violation in itself.

Third-party provision. Consent by default, with a narrow opt-out route (notify individuals and file with the PPC, unavailable for sensitive data) and exceptions for entrustment, mergers, and joint use with published terms. Recordkeeping duties apply on both sides of any transfer.

Rights handling. Individuals can demand disclosure (including of provision records since 2022), correction, cessation of use, and deletion; digital disclosure must be offered. Refusals need reasons, and the 2022 amendment lowered the thresholds for cessation demands.

Breach reporting. Mandatory since 2022 for sensitive-data incidents, financial-harm risk, malicious intrusions, or 1,000+ individuals: prompt preliminary report to the PPC, final report within 30 days (60 for malicious acts), and individual notification.

The engineered categories

APPI created two de-identification tiers with distinct duty sets. Anonymously processed information, properly de-identified per PPC standards, escapes most APPI duties and can be freely provided with publication. Pseudonymously processed information (2022) supports internal analytics with relaxed disclosure and cessation duties, but cannot be given to third parties. Used well, these categories carry analytics and ML workloads that would need consent gymnastics elsewhere.

Where this sits internationally

Japan and the EU maintain mutual adequacy (23 January 2019, reaffirmed on first review in 2023), so EEA personal data flows to Japan under the PPC’s supplementary rules, which tighten APPI for adequacy-transferred data. Compare regimes in APPI vs. GDPR, plan exports with the APPI cross-border guide, and note the separate, stricter My Number regime for Japan’s national ID. Baseline your Japanese-facing web properties with a free scan.

Frequently Asked Questions

Does APPI apply to companies outside Japan?

Yes. Since the 2020 amendment, foreign operators handling personal information of individuals in Japan in connection with supplying goods or services are fully subject to APPI, including PPC reporting orders and on-site inspections, and can be publicly named for non-compliance.

Is consent the main lawful basis under APPI?

No. Unlike GDPR or PIPL, APPI lets operators process personal information without consent if they specify and publish a utilization purpose and stay within it. Consent gates specific acts: acquiring sensitive ('special care-required') information, providing data to third parties, and cross-border transfers without an adequacy or safeguards footing.

What breach reporting does APPI require?

Since April 2022, incidents involving sensitive information, financial harm risk, unlawful intent (hacks, ransomware), or more than 1,000 affected individuals must be reported to the PPC, a preliminary report promptly (practice: within 3-5 days) and a final report within 30 days (60 for malicious acts), plus notification to affected individuals.

What is 'special care-required personal information'?

Japan's sensitive-data category: race, creed, social status, medical history, criminal record, crime-victim status, and similar. Acquiring it requires prior consent, and it cannot be provided to third parties under the opt-out mechanism, only with consent or a statutory exception.

What are the actual penalties under APPI?

Criminal penalties, not administrative turnover fines: violating a PPC rectification order or stealing a personal information database carries corporate fines up to JPY 100 million and individual imprisonment up to 1 year. The PPC's stronger day-to-day levers are guidance, orders, and public naming; a 2024 example is its administrative action against LINE Yahoo after a 440,000-record breach.

Regulatory Crosswalk

GDPRAPPI

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.