Global Privacy Law Japan

Japan APPI Overview: Scope, Duties, and PPC Enforcement

Japan's APPI explained: covered data categories, consent and purpose rules, breach reporting, cross-border transfers, EU mutual adequacy, and PPC enforcement powers.

Regulation

Act on the Protection of Personal Information (APPI), Act No. 57 of 2003, substantially amended in 2015, 2020 (in force April 1, 2022), and under triennial review toward further reform

Max Penalty

Criminal fines up to JPY 100 million for corporations violating PPC orders or unlawfully providing personal-information databases; individuals face imprisonment up to one year or fines

Enforcing Authority

Personal Information Protection Commission (PPC)

Official Source

www.ppc.go.jp

Executive Summary

  • The APPI governs handling of personal information by business operators in Japan and abroad when handling Japanese data subjects' information in connection with supplying goods or services to persons in Japan.
  • The 2020 amendment (effective April 2022) added mandatory breach reporting to the PPC, expanded data subject rights, created 'pseudonymously processed information,' and regulated third-party provision of 'personally referable information.'
  • Purpose specification does most of the lawful-basis work: consent is required mainly for special care-required information, third-party provision, and cross-border transfers, not for ordinary collection.
  • Japan and the EU maintain mutual adequacy (since 2019, reaffirmed in the 2023 review), with PPC supplementary rules applying stricter handling to EU-origin data.
  • The PPC enforces through guidance, recommendations, and orders; violating an order carries criminal penalties up to JPY 100 million for companies, and the triennial-review reform debate includes administrative fines.

The APPI rewards a different instinct than the GDPR: where Europe asks ‘what is your lawful basis,’ Japan asks ‘what did you tell people you would do, and did you stay inside it,’ purpose discipline, category discipline, and flow discipline, policed by a regulator that governs mostly through guidance and escalates to orders backed by criminal law. Its architecture keeps proving quietly influential: the pseudonymization tier, the personally-referable-information solution to adtech flows, and the mutual-adequacy arrangement with the EU each solved problems other regimes still argue about. With the triennial review pushing toward administrative fines, the free-guidance era is closing; operators that already keep the records the current law requires, purposes, categories, transfers, incidents, supervision, will find the coming penalty regime changes their exposure, not their work.

RegimeAPPI (2003), majorly amended 2015 and 2020 (in force April 2022)
RegulatorPersonal Information Protection Commission (PPC)
PenaltiesCriminal fines to JPY 100M (corporate) for order violations and database theft; administrative fines under review
EU relationshipMutual adequacy since 2019, reaffirmed 2023; Supplementary Rules for EU-origin data
Breach reportingTwo-stage PPC reports; 1,000+ individuals or sensitive/wrongful-purpose incidents
Regulator sitePPC English portal

Going deeper

Work the full requirement set. The APPI compliance guide turns the categories and duties into a build list.

Master the transfer rules. APPI cross-border transfers covers the three routes and the ongoing-monitoring duty.

Compare frameworks. APPI vs GDPR maps the purpose-discipline model against lawful bases; the My Number Act adds the stricter national-ID regime.

Your site’s trackers are personally referable information in the making: see what flows where with a free scan.

Frequently Asked Questions

Who must comply with the APPI, and how do its data categories work?

The APPI applies to 'personal information handling business operators,' any person or entity using a personal-information database for business, with no size threshold since the 2015 amendment removed the old 5,000-record exemption, and it reaches foreign operators that handle personal information of persons in Japan in connection with supplying goods or services to them, with the 2020 amendment making PPC reporting, guidance, and orders directly enforceable against such foreign operators. The category architecture is the APPI's distinctive feature, because duties attach per category. Personal information: information about a living individual identifiable by name, birth date, or other descriptions, or containing an individual identification code (biometric data, passport and license numbers). Personal data: personal information constituting a database, where most handling duties attach. Retained personal data: personal data over which the operator has authority to disclose and correct, where individual rights attach (the 2020 amendment removed the old six-month minimum, so short-lived data now counts). Special care-required personal information: race, creed, social status, medical history, criminal record, crime-victim status, and similar, requiring prior consent for acquisition, with no legitimate-interests style alternative. Pseudonymously processed information (2020): internally useful data processed so individuals cannot be identified without cross-referencing, with relaxed duties (no breach reports or disclosure requests) but a ban on third-party provision and re-identification. Anonymously processed information: irreversibly de-identified data usable and shareable under production and publication standards. Getting the category right per dataset is the first compliance act; most APPI findings trace to operators treating regulated categories as if they were unregulated ones.

How do purpose, consent, and third-party provision rules differ from GDPR logic?

The APPI does not use a lawful-basis menu. Instead: specify the purpose of use as concretely as possible, notify or publicly announce it (the ubiquitous Japanese privacy policy), use personal information only within that purpose's scope, and obtain prior consent to exceed it, with purpose changes allowed without consent only within a scope reasonably recognized as relevant to the original. Acquisition must be proper (no deceit or improper means, a provision the PPC has enforced against inappropriate scraping and the Broadview/Rikunabi-style inference services), and special care-required information needs prior consent to acquire at all. The heavily regulated act is third-party provision: providing personal data to a third party requires prior consent, subject to exceptions (legal grounds, joint use with published scope, outsourcing within purpose, business succession) and to the opt-out filing route (provide after PPC filing and public notice with opt-out rights, unavailable for special care-required information and improperly acquired data, and tightened after the Suisho Shimbun name-list scandals). Two record-keeping duties police the flows: providers and recipients must keep transfer and receipt records (who, what, when, on what ground), the traceability rules. The 2020 amendment closed the cookie-era gap with 'personally referable information': data like browsing history that is not personal information for the provider but becomes personal data for the recipient (DMP-to-advertiser flows) now requires confirmation that the recipient obtained the individual's consent, Japan's answer to the third-party-cookie problem, arrived at through provision rules rather than consent banners.

What are the breach-reporting and security duties?

Since April 2022, breach response is mandatory rather than voluntary. Triggering events: leakage, loss, or damage of personal data involving special care-required information; data likely to cause property damage if misused (payment credentials); incidents from possibly wrongful purposes (attacks, including ransomware, which the PPC treats as reportable even where exfiltration is unproven); or more than 1,000 affected individuals. Two-stage reporting to the PPC: a prompt preliminary report (roughly within three to five days of learning of the incident, per PPC guidelines) and a definitive report within 30 days (60 for wrongful-purpose incidents), plus notification to affected individuals as necessary depending on the circumstances (direct notification, or public announcement with easy inquiry where direct notice is difficult). Security duties behind the reporting: take necessary and appropriate measures for security control of personal data, elaborated in PPC guidelines as organizational, personnel, physical, and technical controls scaled to the operator, supervise employees and, critically, trustees, outsourcing data handling requires necessary and appropriate supervision of the contractor (contract terms, monitoring, the duty behind several major PPC actions, including the Benesse line of cases and the 2024 guidance revisions after the NTT West subsidiary leak of some nine million records). Practical notes: the 1,000-person threshold makes many marketing-database incidents reportable that would pass unremarked elsewhere; the wrongful-purpose category converts most cyberattacks into PPC matters; and the two-stage clock demands that incident-response plans pre-assign the preliminary-report decision, because five days disappears quickly in a live incident.

How do cross-border transfers work, including the EU adequacy arrangement?

Transferring personal data to a third party in a foreign country requires one of three routes. Consent: the individual's prior consent to the foreign transfer, with 2022-strengthened information duties, at the time of consent the operator must provide information about the destination country's name, its personal-information protection system, and the recipient's protective measures (making blanket 'we may transfer overseas' clauses non-compliant). Equivalent-standards country: transfers to countries the PPC designates as having equivalent standards, currently the EEA and the UK, proceed as domestic transfers. Recipient safeguards: the recipient maintains standards equivalent to APPI obligations through appropriate and reasonable means (contracts, intra-group rules) or holds APEC CBPR certification, with the transferring operator owing ongoing duties, periodic confirmation of the recipient's implementation and the destination regime's relevant developments, and provision of that information to individuals on request, an ongoing-monitoring duty that resembles a standing, lightweight transfer impact assessment. In the other direction, the EU-Japan mutual adequacy arrangement (January 2019, the first mutual arrangement of its kind, reaffirmed by the Commission's 2023 review) lets EU data flow to Japan freely, conditioned on the PPC's Supplementary Rules, binding on Japanese operators for EU-origin data: stricter retained-data treatment, special care-required expansion to match GDPR special categories, onward-transfer limits, and anonymization standards, so operators receiving EU data run a two-track handling regime, ordinary APPI for domestic data and APPI-plus-Supplementary-Rules for the EU-origin subset, which their data maps must be able to distinguish.

How is the APPI enforced, and what reforms are coming?

The PPC's toolkit escalates: requests for reports and on-site inspections; guidance and advice (the bulk of its output, published in aggregate); recommendations where violations affect individual rights; and orders where recommendations go unheeded or urgency exists, with names published. Criminal penalties attach to order violations (up to one year imprisonment or JPY 1 million for individuals; up to JPY 100 million for corporations under the dual-liability provisions), to unlawful provision of personal-information databases for wrongful gain (the insider-theft offense created after Benesse), and to false reports to the PPC. Notable practice: the PPC's administrative guidance to LINE (2021, data access from China), its orders in the Broadview cases, guidance to NTT West group after the 2023-2024 subsidiary breach, and its 2023-2025 attention to generative-AI scraping (cautioning OpenAI on special care-required acquisition) sketch its priorities: improper acquisition, outsourcing supervision, foreign access, and children's data. What it lacks, administrative fines scaled to turnover, is the center of the reform debate: the statutory triennial review produced a 2024-2025 PPC interim position exploring administrative monetary penalties, collective-action mechanisms, and expanded children's protections, with legislation anticipated but not yet enacted as of early 2026; the direction of travel is unmistakably toward GDPR-style economic sanctions. For operators, the present-tense posture: PPC guidance is functionally binding (orders follow ignoring it), reputational exposure from published actions exceeds the formal penalties, and the traceability records, breach registers, and outsourcing-supervision evidence the current law demands are exactly what any fined future will audit first.

Regulatory Crosswalk

GDPR (mutual adequacy)APEC CBPRMy Number ActISO/IEC 27701

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.