Privacy, security and AI governance across 50+ jurisdictionsTalk to us
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Japan · APPI · PPC

Japan’s APPI, built for accountable data use.

The Act on the Protection of Personal Information governs any business handling personal information connected to individuals in Japan and is enforced by the Personal Information Protection Commission. The regime is built on a specified utilisation purpose, tight rules for third-party provision, category-driven breach reporting and three defined routes for sending data overseas.

Applicability

Scope and the four data classes that drive every duty

The APPI applies to a “personal information handling business operator”, a concept with no turnover or headcount threshold, and reaches overseas operators that handle the personal information of people in Japan when supplying goods or services to them. Before designing controls, classify the data, because obligations attach to the class rather than to the system.

Personal information

Information about a living individual that identifies them, including by easy reference to other information, and individual identification codes such as a My Number or biometric template. Transparency and purpose rules attach here.

Personal data

Personal information organised into a systematically searchable database. Accuracy, security, employee and vendor supervision, and third-party provision record-keeping attach at this level.

Retained personal data

Personal data the operator can itself disclose, correct, add to, delete, suspend use of or stop providing. Individual rights and the public-information duty attach here.

Sensitive personal information

Race, creed, social status, medical history, criminal record, victim-of-crime status and similar. Acquisition generally requires prior consent and the opt-out route for third-party provision is unavailable.

Pseudonymously processed information

Processed so an individual cannot be identified without additional information. Usable for internal analysis with relaxed rights and breach duties, but it cannot be provided to third parties except by outsourcing, merger or joint use.

Anonymously processed information

Irreversibly de-identified to the prescribed standard so the original cannot be restored. Can be shared for data collaboration if you publish the categories involved and never attempt re-identification.

Practitioner note. The most common Japanese scoping error is treating every record as “personal information” and over-applying rights processes. Map which systems create a searchable database, because that is where personal data duties and most of your audit evidence begin.

Operating model

What the business must actually do

Specify the utilisation purpose

Identify the purpose as specifically as practicable before use, and notify or publicly announce it promptly after acquisition. Changing purpose is only permitted within a scope reasonably related to the original; otherwise you need fresh consent.

Acquire properly

Do not acquire personal information by deception or other improper means, and obtain prior consent for sensitive personal information unless a statutory exception applies, such as legal requirement or public-health necessity.

Keep data accurate and delete it

Maintain data accurate and up to date within the scope of the purpose, and endeavour to erase personal data without delay once the utilisation purpose has been achieved.

Implement necessary and appropriate security

Apply organisational, human, physical and technical measures matched to the PPC guidelines, including access control, device management, encryption in transit and at rest where appropriate, and logging.

Supervise employees and entrusted parties

Where you entrust handling to a vendor, exercise necessary and appropriate supervision: due diligence before appointment, a written contract, and ongoing monitoring. Entrustment itself is not a third-party provision requiring consent.

Control third-party provision

Provision to a third party generally requires prior consent. The opt-out route requires advance PPC notification and public disclosure and cannot be used for sensitive information, improperly acquired data or data already received via opt-out. Keep the prescribed provision and receipt records.

Publish retained-data information

Make accessible the operator name, purposes of use, procedures for rights requests and complaint contact, and the security measures taken, so individuals can exercise their rights.

Handle complaints

Endeavour to process complaints appropriately and establish the internal system needed to do so, including a designated contact point.

Confirm and record receipts

When receiving personal data from a third party, confirm how the provider acquired it and record the transaction, retaining the record for the prescribed period.

Individuals

Rights over retained personal data

Individual rights under the APPI and how to operationalise them
RightWhat it coversOperational design
DisclosureDisclosure of retained personal data and, on request, of third-party provision records. The individual may specify an electromagnetic record format.Support electronic delivery, not just paper. Track the format requested and record why any alternative was used.
Correction, addition, deletionWhere the content is not factually correct, the operator must investigate and correct without delay.Distinguish factual inaccuracy from disagreement with an opinion or assessment; only the former is in scope.
Suspension of use or erasureAvailable where data was handled beyond the specified purpose, improperly acquired, or where there is no longer a need to use it, a breach has occurred, or the individual’s rights or legitimate interests may be harmed.Build a decision record: which statutory ground, what investigation, and whether an alternative measure was substituted because suspension is disproportionately costly.
Stop third-party provisionThe individual can require provision to third parties, including overseas transfers, to cease on the statutory grounds.Propagate the stop downstream to recipients and suppress in marketing and data-sharing pipelines, not only in the source system.
Information on overseas transfersOn request, information about the safeguards taken by an overseas recipient relied on under the safeguards route.Maintain a per-destination safeguards dossier so this can be answered without a fresh vendor exercise.

Responses must be made without delay, and a refusal or partial refusal must be explained to the individual with reasons. Statutory exceptions include risk to life or property, material hindrance to the business, and conflict with other laws.

Incident response

Category-triggered reporting, not a general harm test

Japan is unusual in defining reportable breaches by category rather than leaving it to a single harm assessment. Encode the four triggers directly into your incident severity matrix so the on-call decision is mechanical.

1. Sensitive information involved

Any leak, loss or damage involving sensitive personal information is reportable, regardless of volume.

2. Risk of financial damage

Breaches of data such as payment card numbers that could cause property damage through improper use are reportable.

3. Improper purpose

Breaches committed with an improper purpose, including ransomware, intrusion and insider theft, are reportable regardless of volume.

4. More than 1,000 individuals

Volume alone triggers the duty once the number of affected data subjects exceeds 1,000.

1

Detect and contain

Trigger the plan on suspicion, not confirmation. Preserve logs and forensic images immediately, since the PPC expects a described cause.

2

Preliminary report

File the prompt report with the PPC, generally within three to five days of awareness, with facts known so far. Do not wait for the full investigation.

3

Notify individuals

Notify affected individuals promptly where a trigger is met. Where individual notice is difficult, substitute measures such as public announcement plus an enquiry desk may be used.

4

Final report

Submit within approximately 30 days, or 60 days for improper-purpose incidents, covering cause, scope, measures taken and recurrence prevention.

Cross-border data

Three routes out of Japan

Overseas transfer routes and their evidence burden
RouteWhat it requiresStanding obligation
Informed consentPrior consent to the overseas provision, after giving prescribed information: the name of the destination country, information on that country’s data protection system, and the protective measures taken by the recipient.Refresh the country information periodically; it must be accurate at the time consent is obtained.
Equivalent-standard countryThe destination is recognised as having a data protection system of a standard equivalent to Japan’s. The EEA and the United Kingdom are the recognised jurisdictions.Confirm the recipient is actually established in the recognised jurisdiction rather than merely contracted through it.
Recipient with equivalent safeguardsThe recipient maintains a system conforming to APPI standards, established by contract, group-wide rules or an approved international framework such as CBPR certification.Take necessary steps to ensure continued implementation, review at a defined interval, and answer individual requests about the safeguards. If safeguards fail, take corrective action or stop the transfer.

Design tip. The safeguards route carries an ongoing monitoring duty that the consent route does not, but consent is fragile and withdrawable. Most multinationals use the safeguards route for intra-group and vendor flows, reserving consent for one-off or exceptional transfers.

Implementation

A sequenced plan for the first 90 days

1

Classify and map

Inventory Japanese data, mark which stores are searchable databases, and tag sensitive, pseudonymised and anonymised sets.

2

Fix the purpose layer

Rewrite utilisation purpose statements to be specific, publish them, and check every new use against the reasonably-related test.

3

Rebuild transfers

Pick a route per destination, paper the safeguards, capture the prescribed pre-consent information, and set the monitoring cadence.

4

Rehearse the PPC clock

Run a tabletop against all four breach triggers and time the preliminary report to prove three-to-five-day readiness.

Questions

Frequently asked questions

Does the APPI apply to a company with no office in Japan?

It can. The APPI reaches businesses outside Japan that handle the personal information of individuals in Japan in connection with supplying goods or services to them. Extraterritorial businesses are subject to PPC reporting and can be named publicly for non-compliance, so treat Japanese customer data as in scope even where the entity is foreign and document the applicability decision.

What is the difference between personal information, personal data and retained personal data?

Personal information is any information identifying a living individual. Personal data is personal information organised into a searchable database. Retained personal data is personal data the business has authority to disclose, correct or delete. Duties escalate across the three: transparency attaches to personal information, third-party provision and accuracy rules attach to personal data, and individual rights attach to retained personal data.

When must a breach be reported to the PPC?

Reporting is triggered by defined categories rather than a general harm test: breaches involving sensitive personal information, breaches likely to cause financial damage through improper use, breaches carried out with improper purpose such as a cyber-attack, and breaches affecting more than 1,000 data subjects. A preliminary report is due promptly, generally within three to five days of awareness, with a final report in around 30 days, extended to 60 days for improper-purpose incidents.

Is consent always required to send personal data outside Japan?

No. Consent is one of three routes. Transfers can also rely on the recipient country being recognised as having an equivalent protection standard, or on the recipient maintaining a system that meets APPI-equivalent standards through contract or intra-group rules. Where you rely on consent you must give prescribed information about the destination country in advance; where you rely on recipient safeguards you must take ongoing steps to ensure they continue and respond to individual requests about them.

What is anonymously processed information used for?

Anonymously processed information is data irreversibly processed so an individual cannot be identified and the original cannot be restored. It can be used and shared more freely for analytics and data collaboration, but only if you follow the prescribed processing standards, publish the categories of information involved, and never attempt re-identification. Pseudonymously processed information is a separate, lighter-touch class usable for internal analysis only.

Verify

Primary sources

General information, not legal advice. The APPI is reviewed on a rolling basis and PPC guidelines are updated frequently. Confirm the current text, guideline version, breach thresholds and recognised transfer destinations for the processing concerned before relying on this page. Researched 21 September 2026.

Planning APPI compliance?

We run gap assessments, transfer design and PPC breach-readiness exercises for organisations handling Japanese personal information.

Talk to Vedhacon