APPI is the oldest comprehensive privacy law in Asia (2003) and works differently from the consent-heavy regimes around it. The core discipline is purpose limitation: declare what you use personal information for, publish it, and stay inside it. Consent is reserved for the dangerous edges, sensitive data, third-party sharing, exports. The 2020 amendment, in force since 1 April 2022, hardened the regime with mandatory breach reporting, extraterritorial enforcement, and a tenfold fine increase.
| Regulation | APPI, Act No. 57 of 2003 (amended 2020, effective 1 April 2022) |
|---|---|
| Max penalty | JPY 100M corporate fine; 1 year imprisonment |
| Enforcing authority | PPC |
| Official text | Japanese Law Translation, Act No. 57 |
Core obligations
Purpose specification and limitation. Specify the utilization purpose as concretely as possible, publish or notify it at acquisition, and do not exceed it without consent. Purpose changes are allowed only within a scope reasonably related to the original.
Proper acquisition and accuracy. No acquisition by deceit or improper means; keep data accurate and current within the purpose, and delete without delay when no longer needed.
Security control measures. Organizational, human, physical, and technical safeguards proportionate to the data, plus supervision of employees and entrusted processors. The PPC’s guidelines spell out the expected control set; the LINE Yahoo action shows the PPC treating weak vendor supervision as an APPI violation in itself.
Third-party provision. Consent by default, with a narrow opt-out route (notify individuals and file with the PPC, unavailable for sensitive data) and exceptions for entrustment, mergers, and joint use with published terms. Recordkeeping duties apply on both sides of any transfer.
Rights handling. Individuals can demand disclosure (including of provision records since 2022), correction, cessation of use, and deletion; digital disclosure must be offered. Refusals need reasons, and the 2022 amendment lowered the thresholds for cessation demands.
Breach reporting. Mandatory since 2022 for sensitive-data incidents, financial-harm risk, malicious intrusions, or 1,000+ individuals: prompt preliminary report to the PPC, final report within 30 days (60 for malicious acts), and individual notification.
The engineered categories
APPI created two de-identification tiers with distinct duty sets. Anonymously processed information, properly de-identified per PPC standards, escapes most APPI duties and can be freely provided with publication. Pseudonymously processed information (2022) supports internal analytics with relaxed disclosure and cessation duties, but cannot be given to third parties. Used well, these categories carry analytics and ML workloads that would need consent gymnastics elsewhere.
Where this sits internationally
Japan and the EU maintain mutual adequacy (23 January 2019, reaffirmed on first review in 2023), so EEA personal data flows to Japan under the PPC’s supplementary rules, which tighten APPI for adequacy-transferred data. Compare regimes in APPI vs. GDPR, plan exports with the APPI cross-border guide, and note the separate, stricter My Number regime for Japan’s national ID. Baseline your Japanese-facing web properties with a free scan.