Who must comply with the APPI, and how do its data categories work?
The APPI applies to 'personal information handling business operators,' any person or entity using a personal-information database for business, with no size threshold since the 2015 amendment removed the old 5,000-record exemption, and it reaches foreign operators that handle personal information of persons in Japan in connection with supplying goods or services to them, with the 2020 amendment making PPC reporting, guidance, and orders directly enforceable against such foreign operators. The category architecture is the APPI's distinctive feature, because duties attach per category. Personal information: information about a living individual identifiable by name, birth date, or other descriptions, or containing an individual identification code (biometric data, passport and license numbers). Personal data: personal information constituting a database, where most handling duties attach. Retained personal data: personal data over which the operator has authority to disclose and correct, where individual rights attach (the 2020 amendment removed the old six-month minimum, so short-lived data now counts). Special care-required personal information: race, creed, social status, medical history, criminal record, crime-victim status, and similar, requiring prior consent for acquisition, with no legitimate-interests style alternative. Pseudonymously processed information (2020): internally useful data processed so individuals cannot be identified without cross-referencing, with relaxed duties (no breach reports or disclosure requests) but a ban on third-party provision and re-identification. Anonymously processed information: irreversibly de-identified data usable and shareable under production and publication standards. Getting the category right per dataset is the first compliance act; most APPI findings trace to operators treating regulated categories as if they were unregulated ones.
How do purpose, consent, and third-party provision rules differ from GDPR logic?
The APPI does not use a lawful-basis menu. Instead: specify the purpose of use as concretely as possible, notify or publicly announce it (the ubiquitous Japanese privacy policy), use personal information only within that purpose's scope, and obtain prior consent to exceed it, with purpose changes allowed without consent only within a scope reasonably recognized as relevant to the original. Acquisition must be proper (no deceit or improper means, a provision the PPC has enforced against inappropriate scraping and the Broadview/Rikunabi-style inference services), and special care-required information needs prior consent to acquire at all. The heavily regulated act is third-party provision: providing personal data to a third party requires prior consent, subject to exceptions (legal grounds, joint use with published scope, outsourcing within purpose, business succession) and to the opt-out filing route (provide after PPC filing and public notice with opt-out rights, unavailable for special care-required information and improperly acquired data, and tightened after the Suisho Shimbun name-list scandals). Two record-keeping duties police the flows: providers and recipients must keep transfer and receipt records (who, what, when, on what ground), the traceability rules. The 2020 amendment closed the cookie-era gap with 'personally referable information': data like browsing history that is not personal information for the provider but becomes personal data for the recipient (DMP-to-advertiser flows) now requires confirmation that the recipient obtained the individual's consent, Japan's answer to the third-party-cookie problem, arrived at through provision rules rather than consent banners.
What are the breach-reporting and security duties?
Since April 2022, breach response is mandatory rather than voluntary. Triggering events: leakage, loss, or damage of personal data involving special care-required information; data likely to cause property damage if misused (payment credentials); incidents from possibly wrongful purposes (attacks, including ransomware, which the PPC treats as reportable even where exfiltration is unproven); or more than 1,000 affected individuals. Two-stage reporting to the PPC: a prompt preliminary report (roughly within three to five days of learning of the incident, per PPC guidelines) and a definitive report within 30 days (60 for wrongful-purpose incidents), plus notification to affected individuals as necessary depending on the circumstances (direct notification, or public announcement with easy inquiry where direct notice is difficult). Security duties behind the reporting: take necessary and appropriate measures for security control of personal data, elaborated in PPC guidelines as organizational, personnel, physical, and technical controls scaled to the operator, supervise employees and, critically, trustees, outsourcing data handling requires necessary and appropriate supervision of the contractor (contract terms, monitoring, the duty behind several major PPC actions, including the Benesse line of cases and the 2024 guidance revisions after the NTT West subsidiary leak of some nine million records). Practical notes: the 1,000-person threshold makes many marketing-database incidents reportable that would pass unremarked elsewhere; the wrongful-purpose category converts most cyberattacks into PPC matters; and the two-stage clock demands that incident-response plans pre-assign the preliminary-report decision, because five days disappears quickly in a live incident.
How do cross-border transfers work, including the EU adequacy arrangement?
Transferring personal data to a third party in a foreign country requires one of three routes. Consent: the individual's prior consent to the foreign transfer, with 2022-strengthened information duties, at the time of consent the operator must provide information about the destination country's name, its personal-information protection system, and the recipient's protective measures (making blanket 'we may transfer overseas' clauses non-compliant). Equivalent-standards country: transfers to countries the PPC designates as having equivalent standards, currently the EEA and the UK, proceed as domestic transfers. Recipient safeguards: the recipient maintains standards equivalent to APPI obligations through appropriate and reasonable means (contracts, intra-group rules) or holds APEC CBPR certification, with the transferring operator owing ongoing duties, periodic confirmation of the recipient's implementation and the destination regime's relevant developments, and provision of that information to individuals on request, an ongoing-monitoring duty that resembles a standing, lightweight transfer impact assessment. In the other direction, the EU-Japan mutual adequacy arrangement (January 2019, the first mutual arrangement of its kind, reaffirmed by the Commission's 2023 review) lets EU data flow to Japan freely, conditioned on the PPC's Supplementary Rules, binding on Japanese operators for EU-origin data: stricter retained-data treatment, special care-required expansion to match GDPR special categories, onward-transfer limits, and anonymization standards, so operators receiving EU data run a two-track handling regime, ordinary APPI for domestic data and APPI-plus-Supplementary-Rules for the EU-origin subset, which their data maps must be able to distinguish.
How is the APPI enforced, and what reforms are coming?
The PPC's toolkit escalates: requests for reports and on-site inspections; guidance and advice (the bulk of its output, published in aggregate); recommendations where violations affect individual rights; and orders where recommendations go unheeded or urgency exists, with names published. Criminal penalties attach to order violations (up to one year imprisonment or JPY 1 million for individuals; up to JPY 100 million for corporations under the dual-liability provisions), to unlawful provision of personal-information databases for wrongful gain (the insider-theft offense created after Benesse), and to false reports to the PPC. Notable practice: the PPC's administrative guidance to LINE (2021, data access from China), its orders in the Broadview cases, guidance to NTT West group after the 2023-2024 subsidiary breach, and its 2023-2025 attention to generative-AI scraping (cautioning OpenAI on special care-required acquisition) sketch its priorities: improper acquisition, outsourcing supervision, foreign access, and children's data. What it lacks, administrative fines scaled to turnover, is the center of the reform debate: the statutory triennial review produced a 2024-2025 PPC interim position exploring administrative monetary penalties, collective-action mechanisms, and expanded children's protections, with legislation anticipated but not yet enacted as of early 2026; the direction of travel is unmistakably toward GDPR-style economic sanctions. For operators, the present-tense posture: PPC guidance is functionally binding (orders follow ignoring it), reputational exposure from published actions exceeds the formal penalties, and the traceability records, breach registers, and outsourcing-supervision evidence the current law demands are exactly what any fined future will audit first.