🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
JP v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing24 sources retrieved model claude-sonnet-5 · 2026-07-29

Japan

JP schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 70 claims · 32 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
70Claimsbaseline..claims[]
6Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 21 September 2026

Lead Signal

Japan's Personal Information Protection Commission (PPC) is set to gain a landmark new enforcement tool once its amended data protection law takes effect. The APPI Amendment Act was approved by Japan's Cabinet on 7 April 2026, passed the Diet on 10 July 2026, and was promulgated on 17 July 2026; commencement will follow by Cabinet order no later than July 2028. The Act introduces the PPC's first direct administrative-fine power, alongside a newly defined "Specific Biometric Personal Information" category subject to heightened transparency, expanded deletion rights, and a prohibition on third-party provision via opt-out.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A mature, PPC-enforced omnibus statute is in force with EU/UK mutual adequacy recognition; amber-adjacent risk stems only from the pending 2026 reform bill not yet enacted.

Primary frameworkAct on the Protection of Personal Information (APPI), Act No. 57 of 2003, as amended
Traffic-light rationale — GreenA mature, PPC-enforced omnibus statute is in force with EU/UK mutual adequacy recognition; amber-adjacent risk stems only from the pending 2026 reform bill not yet enacted.

Sub-modules (5)

Regulator And AuthorityGreen

The PPC is Japan's independent data protection authority with exclusive oversight of both private- and public-sector personal information handling since the 2021 amendment.

Claims (2):

  • The Personal Information Protection Commission (PPC) is Japan's independent supervisory authority responsible for oversight and enforcement of the APPI.
  • Following the 2021 APPI amendment, the PPC has exclusive supervisory authority over both private-sector business operators and public-sector Administrative Organs and Incorporated Administrative Agencies.

Act And InstrumentsGreen

The APPI is complemented by its Cabinet Enforcement Order, PPC Enforcement Rules, PPC Guidelines/Q&As, and EU/UK-specific Supplementary Rules.

Claims (1):

  • The APPI regime is composed of the Act itself plus a Cabinet Enforcement Order, PPC Enforcement Rules, and PPC Guidelines/Q&As that provide authoritative interpretation of the statute.

Material ScopeGreen

The APPI applies to 'personal information handling business operators' (PIHBOs) processing personal information databases in the course of business, covering personal information, retained personal data, pseudonymised information and anonymously processed information.

Claims (1):

  • The APPI applies to personal information handling business operators (PIHBOs) — persons providing a personal information database for use in business — covering personal information, retained personal data, pseudonymised information and anonymously processed information.

Territorial ScopeAmber

Current law already applies extraterritorially to foreign operators acquiring data of Japan-based individuals in connection with supplying goods/services; the pending amendment would broaden this to indirectly-acquired data and add enforcement powers over overseas entities.

Claims (2):

  • The APPI already applies extraterritorially to foreign business operators that acquire personal information directly from data subjects in relation to supplying goods or services to persons in Japan and handle that information abroad.
  • The pending APPI amendment bill would expand extraterritorial application to foreign operators that handle personal information of Japan-based data subjects even where acquired indirectly, and would empower the PPC to compel reports from and issue orders to overseas companies.

Regulator Registration And FilingAmber

There is no general controller registration regime; the principal filing obligation is notification to the PPC when relying on the opt-out mechanism for third-party data provision.

Claims (1):

  • There is no general controller registration regime under the APPI; the main filing duty is notifying the PPC when a business relies on the opt-out scheme to provide personal data to third parties without consent.
Category narrative106 words

Japan operates a comprehensive omnibus data protection regime centred on the Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, as substantially amended in 2015, 2020 and 2021), overseen exclusively by the Personal Information Protection Commission (PPC), an independent supervisory authority. The 2021 amendment harmonised previously separate public- and private-sector regimes under the PPC's exclusive supervision. The APPI applies extraterritorially to foreign operators supplying goods/services to persons in Japan, and a pending 2026 amendment bill (Cabinet-approved 7 April 2026, before the Diet) would further extend extraterritorial reach and give the PPC new powers to compel reports and issue orders to overseas companies.

Periodic update · new data 2026-09-21

Regulator & Framework

The Personal Information Protection Commission (PPC) is Japan's independent data-protection authority enforcing the Act on the Protection of Personal Information (APPI). The APPI Amendment Act was Cabinet-approved on 7 April 2026, passed the Diet on 10 July 2026, and promulgated on 17 July 2026, with commencement by Cabinet order due no later than July 2028; until then, the current APPI framework continues to govern day-to-day compliance obligations. The APPI applies to any Personal Information Handling Business Operator processing the data of individuals in Japan, with no size threshold and extraterritorial reach to foreign operators.

Outlook

The defining variable for this module over the next two years is the timing of the Cabinet order that will actually commence the amendment. No exact date has been fixed within the July 2028 outer limit, and the PPC's institutional role as enforcer is set to expand materially once that order takes effect.

Sources and claims (7)
  1. ConfirmedPPC — The Personal Information Protection Commission (PPC) is Japan's independent supervisory authority responsible for oversight and enforcement of the APPI.observed
  2. ConfirmedEUR-Lex — Following the 2021 APPI amendment, the PPC has exclusive supervisory authority over both private-sector business operators and public-sector Administrative Organs and Incorporated Administrative Agencies.observed
  3. ConfirmedEUR-Lex — The APPI regime is composed of the Act itself plus a Cabinet Enforcement Order, PPC Enforcement Rules, and PPC Guidelines/Q&As that provide authoritative interpretation of the statute.observed
  4. ConfirmedOneTrust DataGuidance — The APPI applies to personal information handling business operators (PIHBOs) — persons providing a personal information database for use in business — covering personal information, retained personal data, pseudonymised information and anonymously processed information.observed
  5. ConfirmedIAPP — The APPI already applies extraterritorially to foreign business operators that acquire personal information directly from data subjects in relation to supplying goods or services to persons in Japan and handle that information abroad.observed
  6. ProbableIAPP — The pending APPI amendment bill would expand extraterritorial application to foreign operators that handle personal information of Japan-based data subjects even where acquired indirectly, and would empower the PPC to compel reports from and issue orders to overseas companies.observed
  7. ConfirmedIAPP — There is no general controller registration regime under the APPI; the main filing duty is notifying the PPC when a business relies on the opt-out scheme to provide personal data to third parties without consent.observed

#

Core consent/sensitive-data rules are settled and in force, but the absence of a GDPR Art 6-style lawful-basis architecture and the unresolved biometric/AI carve-outs create interpretive gaps pending the 2026 reform.

Primary frameworkAct on the Protection of Personal Information (APPI)
Traffic-light rationale — AmberCore consent/sensitive-data rules are settled and in force, but the absence of a GDPR Art 6-style lawful-basis architecture and the unresolved biometric/AI carve-outs create interpretive gaps pending the 2026 reform.

Sub-modules (4)

Lawful BasesAmber

The APPI does not adopt a GDPR-style enumerated lawful-basis regime; lawfulness instead flows from purpose specification, notice, and targeted consent triggers.

Claims (1):

  • Unlike the GDPR, the APPI does not require a legal basis for all processing of personal information, relying instead on purpose specification and consent only at specific junctures.

Special CategoriesAmber

'Special care-required personal information' requires data-subject consent for collection; biometric data is not yet a defined sensitive category but reform is proposed.

Claims (3):

  • The current APPI generally requires data subjects' consent for the collection of special care-required (sensitive) personal information such as race and medical history.
  • Biometric data is not currently categorised as sensitive personal information under Japanese law, and no dedicated biometric-handling rules yet exist.
  • The pending APPI amendment bill would introduce a 'Specific Biometric Personal Information' category (facial recognition data) requiring notice to data subjects and granting an unconditional right to demand suspension of use.

Pseudonymisation And AnonymisationGreen

The 2020 amendment created a 'pseudonymised information' category (internal-use only, reduced obligations) alongside the pre-existing 'anonymously processed information' concept.

Claims (1):

  • The 2020 APPI amendment introduced 'pseudonymised information,' a category limited to internal statistical use, exempting operators from certain obligations such as responding to disclosure or cessation-of-use demands for retained personal data.
Category narrative108 words

Unlike the GDPR, the APPI does not require an enumerated lawful basis for all processing; instead it relies on purpose specification/notification duties plus consent requirements triggered at specific junctures (sensitive-data collection, purpose-exceeding use, third-party provision, cross-border transfer). 'Special care-required personal information' (race, medical history, criminal record, etc.) requires consent to collect. Biometric data is not currently a distinct sensitive category, but the ongoing triennial review and pending bill would introduce a new 'Specific Biometric Personal Information' category with notice and suspension rights. The 2020 amendment introduced 'pseudonymised information' as a reduced-obligation category for internal statistical use, and a further amendment proposes a consent exemption for statistical processing/AI development.

Periodic update · new data 2026-09-21

Lawful Processing & Special Data

The APPI Amendment Act materially widens lawful-processing grounds ahead of its eventual entry into force. A new consent exemption permits collection of publicly available sensitive data and third-party sharing of such data for statistical processing, including AI model development, subject to transparency requirements and contractual safeguards. Separately, the amendment adds a distinct consent exception for processing that "clearly does not prejudice" individuals' rights and interests, and lowers the threshold for invoking existing public-interest exceptions.

Outlook

Because both provisions are enacted but not yet in force, their practical effect awaits Cabinet-order commencement, due no later than July 2028. The AI-training consent exemption in particular positions Japan's regime to diverge somewhat from stricter consent-first approaches elsewhere, a divergence that will become concrete only once implementing guidance and commencement dates are set.

Sources and claims (6)
  1. ConfirmedIAPP — Unlike the GDPR, the APPI does not require a legal basis for all processing of personal information, relying instead on purpose specification and consent only at specific junctures.observed
  2. ConfirmedIAPP — Operators handling personal information are in principle required to obtain data subjects' prior consent before providing personal data to third parties, subject to opt-out and joint-use exceptions.observed
  3. ConfirmedIAPP — The current APPI generally requires data subjects' consent for the collection of special care-required (sensitive) personal information such as race and medical history.observed
  4. ConfirmedIAPP — Biometric data is not currently categorised as sensitive personal information under Japanese law, and no dedicated biometric-handling rules yet exist.observed
  5. ProbableIAPP — The pending APPI amendment bill would introduce a 'Specific Biometric Personal Information' category (facial recognition data) requiring notice to data subjects and granting an unconditional right to demand suspension of use.observed
  6. ConfirmedIAPP — The 2020 APPI amendment introduced 'pseudonymised information,' a category limited to internal statistical use, exempting operators from certain obligations such as responding to disclosure or cessation-of-use demands for retained personal data.observed

#

Core access/rectification/erasure/objection rights are codified and were substantially strengthened by the 2020/2022 amendments; residual amber factor is the absence of a fixed response-time statute and of an explicit portability right.

Primary frameworkAct on the Protection of Personal Information (APPI)
Traffic-light rationale — GreenCore access/rectification/erasure/objection rights are codified and were substantially strengthened by the 2020/2022 amendments; residual amber factor is the absence of a fixed response-time statute and of an explicit portability right.

Sub-modules (5)

Access RightGreen

Data subjects may demand disclosure of retained personal data; businesses must respond without delay, subject to limited harm-based exceptions.

Claims (2):

  • Data subjects have the right to demand disclosure of retained personal data held by a business operator.
  • A business operator must disclose retained personal data to a data subject without delay, subject to statutory exceptions such as risk of harm to life or improper interference with business operations.

Rectification And ErasureGreen

Rights to correction, addition or deletion of retained personal data exist; erasure/cessation-of-use rights were expanded by the 2020/2022 amendment beyond the original narrow trigger conditions.

Claims (2):

  • Data subjects may demand correction, addition or deletion of the content of retained personal data.
  • The 2020/2022 amendment expanded data subjects' rights to demand cessation of use, deletion, or cessation of third-party provision of retained personal data to cases where a data subject's rights or legitimate interests are likely to be infringed, beyond the prior narrow grounds of purpose-violation, improper collection, or unlawful third-party provision.

Restriction And ObjectionGreen

Cessation of use/third-party provision functions as the APPI's restriction/objection mechanism, now exercisable wherever rights or legitimate interests are likely to be infringed.

Claims (1):

  • The 2020/2022 amendment expanded data subjects' rights to demand cessation of use, deletion, or cessation of third-party provision of retained personal data to cases where a data subject's rights or legitimate interests are likely to be infringed, beyond the prior narrow grounds of purpose-violation, improper collection, or unlawful third-party provision.

Data PortabilityAmber

No explicit portability right analogous to GDPR Art 20 exists; the amendment's electronic-disclosure entitlement is the closest functional equivalent.

Claims (2):

  • The 2020/2022 amendment allows data subjects to require that their retained personal data be disclosed to them electronically, whereas the prior law did not expressly permit electronic-format disclosure demands.
  • The APPI does not contain a distinct data-portability right equivalent to GDPR Article 20; electronic disclosure of retained personal data is the closest functional analogue.

Deadlines And Response WindowsAmber

The APPI imposes a 'without delay' response standard for disclosure requests rather than a fixed statutory number of days.

Claims (1):

  • A business operator must disclose retained personal data to a data subject without delay, subject to statutory exceptions such as risk of harm to life or improper interference with business operations.
Category narrative83 words

Data subjects hold rights to demand disclosure, correction/addition/deletion, and cessation of use or third-party provision of 'retained personal data.' The 2020/2022 amendments broadened these rights (removing the prior six-month retention carve-out, allowing exercise wherever rights/interests are 'likely to be infringed,' and permitting electronic-format disclosure demands). There is no dedicated GDPR Art 20-style portability right, though electronic disclosure functions similarly. Response timing is governed by a 'without delay' standard rather than a fixed statutory clock (contrast with the fixed breach-reporting deadlines under controller duties).

Periodic update · new data 2026-09-21

Data Subject Rights

The amendment package produces a mixed picture for data-subject rights. It grants children enhanced deletion and suspension rights alongside a new parental-consent requirement for processing the data of individuals under 16. It also relaxes breach-notification obligations owed to affected individuals: where risk is assessed as low, notification to the individual can be replaced with alternative measures, moving away from the current threshold-based mandatory-notification model.

Outlook

Neither change is yet operative. Once commenced, the relaxed breach-notification default will need to be read alongside the PPC's separate, currently in-force Article 26 reporting-to-PPC obligations, which are unaffected by this particular provision and continue under existing thresholds and online-submission procedures.

Sources and claims (6)
  1. ConfirmedPPC — Data subjects have the right to demand disclosure of retained personal data held by a business operator.observed
  2. ConfirmedPPC — A business operator must disclose retained personal data to a data subject without delay, subject to statutory exceptions such as risk of harm to life or improper interference with business operations.observed
  3. ConfirmedIAPP — Data subjects may demand correction, addition or deletion of the content of retained personal data.observed
  4. ConfirmedIAPP — The 2020/2022 amendment expanded data subjects' rights to demand cessation of use, deletion, or cessation of third-party provision of retained personal data to cases where a data subject's rights or legitimate interests are likely to be infringed, beyond the prior narrow grounds of purpose-violation, improper collection, or unlawful third-party provision.observed
  5. ConfirmedIAPP — The 2020/2022 amendment allows data subjects to require that their retained personal data be disclosed to them electronically, whereas the prior law did not expressly permit electronic-format disclosure demands.observed
  6. ProbableIAPP — The APPI does not contain a distinct data-portability right equivalent to GDPR Article 20; electronic disclosure of retained personal data is the closest functional analogue.observed

#

Breach-notification and security-measure duties are robust and in force, but the absence of DPO, formal DPIA, and general ROPA requirements — core GDPR-analogue accountability tools — represents a structural gap relative to omnibus peers.

Primary frameworkAct on the Protection of Personal Information (APPI)
Traffic-light rationale — AmberBreach-notification and security-measure duties are robust and in force, but the absence of DPO, formal DPIA, and general ROPA requirements — core GDPR-analogue accountability tools — represents a structural gap relative to omnibus peers.

Sub-modules (7)

Accountability And DpiaRed

No mandatory DPIA-equivalent process is codified in the APPI; accountability is achieved via security-control-measures and purpose-limitation duties.

Claims (1):

  • The APPI does not impose a mandatory Data Protection Impact Assessment process equivalent to GDPR Article 35.

Dpo RequirementsRed

The APPI does not include a requirement to appoint a Data Protection Officer.

Claims (1):

  • The APPI does not include a requirement to appoint a Data Protection Officer.

Ropa RequirementsAmber

No general Art 30-style records-of-processing duty exists; record-keeping obligations are narrower, attaching to third-party data-provision transactions with 3-year retention.

Claims (1):

  • The amended Cabinet Order and Enforcement Rules impose record-keeping obligations on providers of personal data to third parties, covering confirmation of consent, date of provision, recipient details and data categories, generally retained for three years.

Joint Controller ArrangementsGreen

The APPI's 'joint use' mechanism functions as its joint-controllership analogue, requiring disclosure of the managing entity's identity and contact details.

Claims (1):

  • Where a business relies on a 'joint use' mechanism to share personal data with others, the APPI requires disclosure of the address of the business managing the jointly used data and the name of its representative.

Security MeasuresGreen

Operators must implement organisational, personnel, physical and technical security-control measures, including 'understanding of the external environment' when data is processed abroad.

Claims (1):

  • Businesses must implement organisational, personnel, physical and technical security-control measures over personal data, and the amended guidelines additionally require 'understanding of the external environment' when personal data is processed in a foreign country.

Breach NotificationGreen

Mandatory two-stage breach reporting to the PPC (preliminary + final) and subject notification apply to defined categories of data breach.

Claims (2):

  • The amended APPI implements a legal obligation to report to the PPC and notify affected data subjects when a data breach (leakage, loss or damage) occurs or is likely to have occurred, replacing the prior mere 'duty to make an effort.'
  • Breach reporting follows a two-stage process: a preliminary report filed promptly (generally within three to five days for corporations) after recognition of a potential breach, and a final report within 30 days (60 days for cyberattack-related breaches).

Retention And DisposalAmber

No general statutory retention-period ceiling exists; operators must delete personal data without delay once the purpose of use no longer requires it.

Claims (1):

  • Business operators must delete personal data without delay once its utilisation is no longer necessary for the specified purpose, though the APPI does not fix a general maximum retention period.
Category narrative89 words

The APPI does not draw a GDPR-style controller/processor distinction, nor does it mandate a DPO or a formal DPIA process; accountability instead flows through security-control-measures obligations, purpose/deletion duties, and (since 2020/2022) mandatory two-stage breach reporting to the PPC plus subject notification for defined high-risk breaches (sensitive data, property-damage risk, cyberattack, or >1,000 affected individuals). Record-keeping obligations attach specifically to third-party data provision (3-year retention) rather than a general Art 30-style ROPA. 'Joint use' arrangements function as the closest analogue to joint controllership, requiring disclosure of the responsible party's details.

Periodic update · new data 2026-09-21

Controller/Processor Duties

The amendment exempts entrusted data processors from most of the APPI's general Chapter 4 obligations, provided the underlying processing agreement specifies prescribed matters, including breach-notification scope and use limitations. Under the current, already-in-force regime, APPI Article 26 requires business operators to report qualifying breaches to the PPC and notify affected individuals, and 2026 policy updates clarified reporting thresholds and introduced online-submission procedures for breach reports to the Commission.

Outlook

The processor exemption will not take effect until Cabinet-order commencement, due no later than July 2028, meaning entrusted-processor arrangements remain fully subject to Chapter 4 obligations in the interim. The Article 26 procedural clarifications, by contrast, are already operative.

Sources and claims (8)
  1. ConfirmedOneTrust DataGuidance — The APPI does not impose a mandatory Data Protection Impact Assessment process equivalent to GDPR Article 35.observed
  2. ConfirmedOneTrust DataGuidance — The APPI does not include a requirement to appoint a Data Protection Officer.observed
  3. ConfirmedIAPP — The amended Cabinet Order and Enforcement Rules impose record-keeping obligations on providers of personal data to third parties, covering confirmation of consent, date of provision, recipient details and data categories, generally retained for three years.observed
  4. ConfirmedIAPP — Where a business relies on a 'joint use' mechanism to share personal data with others, the APPI requires disclosure of the address of the business managing the jointly used data and the name of its representative.observed
  5. ConfirmedIAPP — Businesses must implement organisational, personnel, physical and technical security-control measures over personal data, and the amended guidelines additionally require 'understanding of the external environment' when personal data is processed in a foreign country.observed
  6. ConfirmedIAPP — The amended APPI implements a legal obligation to report to the PPC and notify affected data subjects when a data breach (leakage, loss or damage) occurs or is likely to have occurred, replacing the prior mere 'duty to make an effort.'observed
  7. ConfirmedIAPP — Breach reporting follows a two-stage process: a preliminary report filed promptly (generally within three to five days for corporations) after recognition of a potential breach, and a final report within 30 days (60 days for cyberattack-related breaches).observed
  8. ConfirmedOneTrust DataGuidance — Business operators must delete personal data without delay once its utilisation is no longer necessary for the specified purpose, though the APPI does not fix a general maximum retention period.observed

#

A functioning, reviewed mutual adequacy arrangement with the EU/UK and codified transfer mechanisms place this module on solid footing; amber-adjacent nuance is the still-evolving TIA/monitoring guidance under the pending 2026 reform.

Primary frameworkAct on the Protection of Personal Information (APPI); EU-Japan Mutual Adequacy Framework
Traffic-light rationale — GreenA functioning, reviewed mutual adequacy arrangement with the EU/UK and codified transfer mechanisms place this module on solid footing; amber-adjacent nuance is the still-evolving TIA/monitoring guidance under the pending 2026 reform.

Sub-modules (6)

Transfer MechanismsGreen

Transfers rely on data-subject consent or an established equivalent protection system at the recipient, each carrying distinct information-provision duties.

Claims (1):

  • A cross-border transfer of personal data from Japan can be permitted based on either the data subject's consent or the establishment of an equivalent personal information protection system at the recipient.

Adequacy ReceivedGreen

Japan does not 'receive' adequacy in the GDPR sense as a third country importer of an EU decision toward itself in reverse; rather it operates the mutual EU-Japan adequacy arrangement (see adequacy_granted).

Claims (1):

  • The EU-Japan arrangement adopted in January 2019 was the first-ever mutual (two-way) adequacy finding, with the PPC recognising the EU as a jurisdiction with an equivalent data-protection system alongside the Commission's reciprocal finding.

Adequacy GrantedGreen

The European Commission's 2019 Implementing Decision recognises Japan as ensuring an adequate level of protection for EU-origin personal data transferred to APPI-regulated operators; this was reconfirmed in the Commission's 2023 first periodic review.

Claims (2):

  • The European Commission's Implementing Decision (EU) 2019/419 found that Japan ensures an adequate level of protection for personal data transferred from the EU to APPI-regulated business operators.
  • The European Commission's first periodic review, concluded in 2023, found that Japan continues to ensure an adequate level of protection for EU-origin personal data and moved the review cycle from two to four years.

Sccs And BcrsGreen

The APPI's 'established protection system' mechanism functions as its SCC/BCR-equivalent, supplemented by binding PPC Supplementary Rules for EU- and UK-origin data.

Claims (1):

  • The PPC has adopted binding Supplementary Rules under the APPI for the handling of personal data transferred from the EU and the United Kingdom based on an adequacy decision, enforceable by the PPC and directly by individuals in Japanese courts.

Transfer Impact AssessmentAmber

Operators relying on the established-system transfer mechanism must regularly monitor (at least annually) the continued adequacy of the recipient's protections and explain monitoring frequency/method to data subjects on request.

Claims (1):

  • Where a cross-border transfer relies on the recipient's established protection system, the operator must regularly monitor that system (guidelines clarify a frequency of at least once a year) and explain the monitoring frequency and method to data subjects upon request.

Data LocalisationGreen

No general data-localisation mandate applies to ordinary personal information under the APPI.

Claims (1):

  • No general data-localisation requirement applies to ordinary personal information handled by APPI-regulated business operators.
Category narrative104 words

Cross-border transfers require either data-subject consent or reliance on an 'established personal information protection system' at the recipient (broadly SCC-equivalent contractual/organisational measures), with annual monitoring of the importer's system. Japan holds the world's first mutual (two-way) adequacy arrangement with the EU (in force since 23 January 2019, extended in scope to the UK), reinforced by binding PPC Supplementary Rules imposing GDPR-aligned safeguards on EU-origin data. The European Commission's first periodic review (2023) reconfirmed adequacy and moved the review cycle from two to four years. No general data-localisation mandate applies to ordinary personal information, though sector-specific instruments (e.g., My Number Act) impose stricter domestic-handling requirements.

Periodic update · new data 2026-09-21

Cross-Border & Adequacy

The EU-Japan mutual adequacy decision remains stable this cycle, with the next scheduled Commission review set for 2027, timed to coincide with the expected implementation window of the 2026 APPI amendments.

Outlook

Whether the 2027 review proceeds smoothly will depend on the state of APPI Amendment Act commencement at that point, which is due no later than July 2028.

Sources and claims (7)
  1. ConfirmedIAPP — A cross-border transfer of personal data from Japan can be permitted based on either the data subject's consent or the establishment of an equivalent personal information protection system at the recipient.observed
  2. ConfirmedEUR-Lex — The EU-Japan arrangement adopted in January 2019 was the first-ever mutual (two-way) adequacy finding, with the PPC recognising the EU as a jurisdiction with an equivalent data-protection system alongside the Commission's reciprocal finding.observed
  3. ConfirmedEUR-Lex — The European Commission's Implementing Decision (EU) 2019/419 found that Japan ensures an adequate level of protection for personal data transferred from the EU to APPI-regulated business operators.observed
  4. ConfirmedEUR-Lex — The European Commission's first periodic review, concluded in 2023, found that Japan continues to ensure an adequate level of protection for EU-origin personal data and moved the review cycle from two to four years.observed
  5. ConfirmedPPC — The PPC has adopted binding Supplementary Rules under the APPI for the handling of personal data transferred from the EU and the United Kingdom based on an adequacy decision, enforceable by the PPC and directly by individuals in Japanese courts.observed
  6. ProbableIAPP — Where a cross-border transfer relies on the recipient's established protection system, the operator must regularly monitor that system (guidelines clarify a frequency of at least once a year) and explain the monitoring frequency and method to data subjects upon request.observed
  7. ProbableOneTrust DataGuidance — No general data-localisation requirement applies to ordinary personal information handled by APPI-regulated business operators.observed

#

Financial-sector and My Number overlays are well-documented and in force; telecoms/ePrivacy, education and insurance sector-specific DP overlays are not clearly codified, producing residual coverage gaps.

Primary frameworkAPPI supplemented by FSA/METI sectoral guidelines and the My Number Act
Traffic-light rationale — AmberFinancial-sector and My Number overlays are well-documented and in force; telecoms/ePrivacy, education and insurance sector-specific DP overlays are not clearly codified, producing residual coverage gaps.

Sub-modules (7)

Financial Sector OverlayGreen

The FSA issues sector-specific personal-information-protection guidelines for financial institutions (excluding credit cards, which fall to METI).

Claims (1):

  • The Financial Services Agency (FSA) has issued guidelines for personal-information protection in the financial industries, supplementing the general APPI regime for financial-sector operators other than credit-card businesses.

Health Sector OverlayAmber

No dedicated health/medical-sector statute analogous to HIPAA was identified beyond the general special-care-required-information consent rule for medical history.

Claims (1):

  • No comprehensive health-sector-specific statute analogous to HIPAA was identified; medical history is treated as special care-required personal information under the general APPI consent rule.

Telecoms And EprivacyRed

No dedicated telecoms/ePrivacy-style instrument governing cookies or electronic communications was identified as currently in force.

Claims (1):

  • No dedicated telecoms/ePrivacy-style statute governing cookies or electronic-communications metadata distinct from the general APPI regime was identified as currently in force.

Employment DataAmber

Employers handling employees' My Number-linked 'specific personal information' face stricter obligations than under general APPI duties.

Claims (1):

  • The My Number Act and related guidelines require employers to establish appropriate secure-storage and handling systems for employees' 'specific personal information,' which are generally stricter than an employer's other APPI-based obligations.

Credit And ScoringGreen

METI has issued dedicated guidelines for personal-information protection in the credit-card industry.

Claims (1):

  • The Ministry of Economy, Trade and Industry (METI) has issued dedicated guidelines for personal-information protection in the credit-card industry.

EducationRed

No education-sector-specific data-protection statute was identified; the ongoing children's-data reform references the utility of student learning data as a competing policy consideration.

Claims (1):

  • No education-sector-specific data-protection statute was identified; the PPC's ongoing children's-data reform explicitly weighs the usefulness of student education/learning data against protective considerations.

InsuranceRed

No insurance-sector-specific personal-information statute distinct from FSA financial guidance was identified.

Claims (1):

  • No insurance-sector-specific personal-information statute distinct from the FSA's general financial-industry guidance was identified.
Category narrative63 words

Sector-specific overlays supplement the general APPI framework: the Financial Services Agency (FSA) issues financial-industry personal-information guidelines; METI issues credit-card-industry and genetic-information-industry guidelines; and the My Number Act imposes stricter obligations on 'specific personal information' (national ID numbers) used by employers and financial institutions, independently supervised alongside APPI compliance. No dedicated telecoms/ePrivacy-style cookie statute or education-sector-specific data law was identified as currently in force.

Periodic update · new data 2026-09-21

Sectoral Watch

Sectoral coverage this cycle is thin and confined to insurance. Per the PPC's monitoring report covering October 2024 to September 2025, a non-life insurance company received policyholder data from other insurers via inappropriate methods, resulting in a PPC administrative order or recommendation. No other sectoral overlays — financial, health, telecoms, employment, credit-scoring, or education — were evidenced with material developments this cycle.

Outlook

This module carries a limited-signal flag this cycle: the insurance case is the only sectoral-specific finding, and broader sector-by-sector APPI compliance trends were not independently evidenced.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidance — The Financial Services Agency (FSA) has issued guidelines for personal-information protection in the financial industries, supplementing the general APPI regime for financial-sector operators other than credit-card businesses.observed
  2. UncertainIAPP — No comprehensive health-sector-specific statute analogous to HIPAA was identified; medical history is treated as special care-required personal information under the general APPI consent rule.observed
  3. UncertainOneTrust DataGuidance — No dedicated telecoms/ePrivacy-style statute governing cookies or electronic-communications metadata distinct from the general APPI regime was identified as currently in force.observed
  4. ConfirmedOneTrust DataGuidance — The My Number Act and related guidelines require employers to establish appropriate secure-storage and handling systems for employees' 'specific personal information,' which are generally stricter than an employer's other APPI-based obligations.observed
  5. ConfirmedOneTrust DataGuidance — The Ministry of Economy, Trade and Industry (METI) has issued dedicated guidelines for personal-information protection in the credit-card industry.observed
  6. UncertainIAPP — No education-sector-specific data-protection statute was identified; the PPC's ongoing children's-data reform explicitly weighs the usefulness of student education/learning data against protective considerations.observed
  7. UncertainOneTrust DataGuidance — No insurance-sector-specific personal-information statute distinct from the FSA's general financial-industry guidance was identified.observed

#

Opt-out and third-party data-provision rules are codified and enforceable, but dark-patterns, standardised opt-out signals, and clean-room-specific rules are absent, and reform of the opt-out scheme itself remains pending.

Primary frameworkAct on the Protection of Personal Information (APPI)
Traffic-light rationale — AmberOpt-out and third-party data-provision rules are codified and enforceable, but dark-patterns, standardised opt-out signals, and clean-room-specific rules are absent, and reform of the opt-out scheme itself remains pending.

Sub-modules (6)

Cookies And TrackersAmber

Cookie-derived individual-related information triggers third-party-provision consent-confirmation duties only when the recipient is likely to render it identifiable.

Claims (1):

  • Where a business provides information about a living individual that is not itself personal information (e.g., website browsing history via cookies), and the recipient is likely to receive it in a form that becomes personal data, the provider must confirm the recipient has obtained the data subject's consent.

Dark PatternsRed

No dedicated dark-patterns prohibition was identified under current Japanese data-protection law.

Claims (1):

  • No dedicated statutory prohibition on dark patterns in consent or data-collection interfaces was identified under current Japanese data-protection law.

Opt Out SignalsRed

No standardised, legally-recognised opt-out signal mechanism (e.g., GPC/DAA-equivalent) was identified under the APPI.

Claims (1):

  • No legally-recognised, standardised browser/device opt-out signal mechanism analogous to the Global Privacy Control was identified under the APPI.

Clean Rooms And DcrRed

No clean-room / data-collaboration-room-specific rules were identified as distinct from general third-party-provision and joint-use requirements.

Claims (1):

  • No rules specific to data clean rooms or data-collaboration platforms distinct from general third-party-provision and joint-use requirements were identified.

Cross Context AdvertisingAmber

Cross-context data sharing for advertising is governed by the general third-party-provision consent/opt-out framework rather than a CPRA-style 'sale'/'share' taxonomy.

Claims (1):

  • Where a business provides information about a living individual that is not itself personal information (e.g., website browsing history via cookies), and the recipient is likely to receive it in a form that becomes personal data, the provider must confirm the recipient has obtained the data subject's consent.

Direct MarketingAmber

Direct marketing via shared personal data is governed by the opt-out scheme (PPC filing plus subject notice/accessibility), which functions as the suppression mechanism; reform would restrict abuse of this scheme.

Claims (2):

  • Personal data may be provided to third parties for purposes such as marketing without consent if the operator notifies data subjects of opt-out matters (or makes them easily accessible) and files with the PPC.
  • The pending amendment would bar use of the opt-out scheme to provide personal data collected by deceit or improper means, or data that was itself received via another party's opt-out scheme, in response to observed abuse for fraud-adjacent list trading.
Category narrative94 words

Cookie-derived browsing/behavioural data is regulated indirectly through APPI's 'individual related information' provision rule: a provider must confirm the recipient has obtained consent where the recipient is likely to combine such data into identifiable personal data. The opt-out scheme (PPC filing + subject notice) is the principal mechanism enabling third-party data provision, including for marketing purposes, without individual consent; the pending amendment would tighten this scheme by barring provision of improperly-collected data or data received via another party's opt-out filing. No dedicated dark-patterns prohibition or GPC/DAA-style recognised opt-out signal was identified in current Japanese law.

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ConfirmedIAPP — Where a business provides information about a living individual that is not itself personal information (e.g., website browsing history via cookies), and the recipient is likely to receive it in a form that becomes personal data, the provider must confirm the recipient has obtained the data subject's consent.observed
  2. UncertainIAPP — No dedicated statutory prohibition on dark patterns in consent or data-collection interfaces was identified under current Japanese data-protection law.observed
  3. UncertainIAPP — No legally-recognised, standardised browser/device opt-out signal mechanism analogous to the Global Privacy Control was identified under the APPI.observed
  4. UncertainIAPP — No rules specific to data clean rooms or data-collaboration platforms distinct from general third-party-provision and joint-use requirements were identified.observed
  5. ConfirmedIAPP — Personal data may be provided to third parties for purposes such as marketing without consent if the operator notifies data subjects of opt-out matters (or makes them easily accessible) and files with the PPC.observed
  6. ProbableIAPP — The pending amendment would bar use of the opt-out scheme to provide personal data collected by deceit or improper means, or data that was itself received via another party's opt-out scheme, in response to observed abuse for fraud-adjacent list trading.observed

#

AI-specific promotional legislation and sectoral biometric/genetic guidance exist, but core ADM/profiling and binding biometric protections remain in the proposal stage, and state-surveillance carve-outs limit PPC coercive reach over public bodies.

Primary frameworkAPPI (general); Act on Promotion of Research and Development, and Utilization of AI-related Technology (AI Promotion Act, 2025)
Traffic-light rationale — AmberAI-specific promotional legislation and sectoral biometric/genetic guidance exist, but core ADM/profiling and binding biometric protections remain in the proposal stage, and state-surveillance carve-outs limit PPC coercive reach over public bodies.

Sub-modules (6)

Profiling RestrictionsRed

No comprehensive profiling-restriction framework currently exists under the APPI; reform is under PPC consideration.

Claims (2):

  • The PPC's triennial-review Interim Summary flags continued consideration of profiling regulation as an open policy issue for the APPI reform.
  • The pending APPI amendment bill would create a 'Specific Biometric Personal Information' category for facial-recognition data, requiring notice/accessibility to data subjects and an unconditional right to demand suspension of use.

Automated Decision Making TransparencyRed

Neither the APPI nor PPC Guidelines contain comprehensive legal provisions on automated decision-making and profiling, per the European Parliament's adequacy-review findings; only limited sectoral rules touch the issue.

Claims (1):

  • Neither the APPI nor PPC Guidelines contain comprehensive legal provisions on automated decision-making and profiling; only limited sectoral rules address the matter without an overarching protective framework.

Ai Risk AssessmentsAmber

Japan's AI Promotion Act establishes a national AI governance framework, supplemented by non-binding AI Business Operator Guidelines rather than mandatory AI-specific risk assessments.

Claims (2):

  • Japan enacted the Act on Promotion of Research and Development, and Utilization of AI-related Technology (AI Promotion Act) in May 2025, which came into full effect in September 2025.
  • Japan's AI Business Operator Guidelines consolidate AI-governance principles and best practices but constitute non-binding soft guidance rather than a mandatory AI-specific risk-assessment regime.

Biometric RegimeAmber

No binding biometric-specific data regime currently exists; a proposed 'Specific Biometric Personal Information' category for facial-recognition data is pending in the 2026 reform bill.

Claims (1):

  • The pending APPI amendment bill would create a 'Specific Biometric Personal Information' category for facial-recognition data, requiring notice/accessibility to data subjects and an unconditional right to demand suspension of use.

Genetic DataAmber

Genetic data is addressed only via non-binding METI sectoral guidance; the PPC's triennial review is separately considering genomic-data regulation.

Claims (2):

  • METI has issued non-binding sectoral guidelines for the protection of personal information in industries using genetic information of individuals.
  • The PPC's triennial-review Interim Summary lists regulation of genomic data among issues requiring continued consideration.

State Surveillance CarveoutsAmber

The PPC's oversight of Administrative Organs (including law-enforcement and national-security data collection) is limited to non-coercive tools; it cannot issue binding orders or impose fines on those public authorities.

Claims (1):

  • Although the PPC oversees Administrative Organs' collection and processing of personal information, including law-enforcement and national-security data collection, it has not been empowered to issue binding orders to, or impose fines on, these public authorities; its tools are limited to reporting requests, on-site inspections, guidance, advice and recommendations.
Category narrative114 words

The APPI currently contains no comprehensive automated-decision-making or profiling framework equivalent to GDPR Article 22; the European Parliament has explicitly flagged this gap. Reform is under active PPC consideration as part of the ongoing triennial review, alongside a proposed 'Specific Biometric Personal Information' regime for facial-recognition data. Separately, Japan's AI Promotion Act (enacted May 2025, in force September 2025) establishes a light-touch, innovation-oriented national AI framework, complemented by non-binding AI Business Operator Guidelines. Genetic data is addressed only via non-binding METI sectoral guidance, with genomic-data regulation flagged for further PPC review. Government/national-security data access by public authorities is subject to PPC oversight powers that stop short of binding orders or fines against those authorities.

Periodic update · new data 2026-09-21

Algorithmic, Biometric & Surveillance Governance

The APPI Amendment Act establishes "Specific Biometric Personal Information" as a distinct regulated category for the first time, subject to heightened transparency obligations, expanded deletion rights, and a prohibition on third-party provision via opt-out. This marks a structural addition to Japan's special-category data architecture, bringing biometric data under materially tighter handling rules once the provision takes effect.

Outlook

The biometric category will not apply until Cabinet-order commencement, due no later than July 2028. Organisations handling biometric identifiers in Japan face a defined but not-yet-active compliance shift; the opt-out prohibition in particular removes a sharing pathway that exists for other categories of personal data under the current regime.

Sources and claims (8)
  1. ProbableIAPP — The PPC's triennial-review Interim Summary flags continued consideration of profiling regulation as an open policy issue for the APPI reform.observed
  2. ProbableIAPP — The pending APPI amendment bill would create a 'Specific Biometric Personal Information' category for facial-recognition data, requiring notice/accessibility to data subjects and an unconditional right to demand suspension of use.observed
  3. ConfirmedEUR-Lex — Neither the APPI nor PPC Guidelines contain comprehensive legal provisions on automated decision-making and profiling; only limited sectoral rules address the matter without an overarching protective framework.observed
  4. ConfirmedIAPP — Japan enacted the Act on Promotion of Research and Development, and Utilization of AI-related Technology (AI Promotion Act) in May 2025, which came into full effect in September 2025.observed
  5. ConfirmedIAPP — Japan's AI Business Operator Guidelines consolidate AI-governance principles and best practices but constitute non-binding soft guidance rather than a mandatory AI-specific risk-assessment regime.observed
  6. ConfirmedOneTrust DataGuidance — METI has issued non-binding sectoral guidelines for the protection of personal information in industries using genetic information of individuals.observed
  7. ProbableIAPP — The PPC's triennial-review Interim Summary lists regulation of genomic data among issues requiring continued consideration.observed
  8. ConfirmedEUR-Lex — Although the PPC oversees Administrative Organs' collection and processing of personal information, including law-enforcement and national-security data collection, it has not been empowered to issue binding orders to, or impose fines on, these public authorities; its tools are limited to reporting requests, on-site inspections, guidance, advice and recommendations.observed

#

No codified statutory age-of-consent, parental-consent mechanism, minor-profiling ban, or dependent-adults regime currently exists; all children's-data protections are at the proposal stage pending the 2026/2027 reform.

Primary frameworkAct on the Protection of Personal Information (APPI) — children's provisions pending
Traffic-light rationale — RedNo codified statutory age-of-consent, parental-consent mechanism, minor-profiling ban, or dependent-adults regime currently exists; all children's-data protections are at the proposal stage pending the 2026/2027 reform.

Sub-modules (5)

Age VerificationRed

No statutory age-verification requirement exists; the APPI does not currently define a child's age, though PPC Q&A informally references ages 12-15 and under, and reform proposes codifying under-16 as the child threshold.

Claims (2):

  • Under current law there are basically no explicit statutory provisions regarding the handling of children's personal information, and the APPI does not define the age of a child; PPC Q&A guidance indicates the applicable age can vary by data type and business nature, generally referencing ages 12-15 and under.
  • The PPC's triennial-review reform proposes formally defining those under 16 years old as children for APPI purposes.

Minor Profiling BansRed

No minor-specific profiling ban currently exists; reform proposes a best-interests-of-the-child standard for safety-control measures applied to children's data.

Claims (1):

  • The reform proposes strengthening safety-control-measure obligations specific to children's personal data, including a requirement that operators prioritise and give special consideration to the best interests of children.

Education SettingsRed

No education-setting-specific data-protection statute was identified; the reform discussion balances children's-data protection against the utility of student learning data.

Claims (1):

  • The PPC's reform discussion explicitly weighs the vulnerability and need for protection of children's data against the usefulness of student education and learning data, without proposing a dedicated education-sector statute.

Dependent AdultsRed

No dedicated dependent-adults (elderly/incapacitated) data-protection regime was identified; the closest policy analogue is PPC concern over opt-out-scheme misuse enabling elder-targeted financial fraud.

Claims (1):

  • No dedicated dependent-adults data-protection regime exists; the PPC has instead flagged demand to regulate malicious personal-information list providers as a countermeasure against criminal groups using elderly individuals' financial information to commit fraud.
Category narrative85 words

The APPI currently contains no statutory definition of a 'child' and no explicit children's-data provisions; PPC Q&A guidance informally treats individuals aged roughly 12-15 and under as children depending on context. The PPC's ongoing triennial review proposes to codify children as those under 16, strengthen safety-control-measure obligations with a best-interests standard, and permit more flexible ex-post suspension of use for children's retained personal data. No dedicated education-setting or dependent-adults (elderly/incapacitated) data-protection regime was identified, beyond a general policy concern about opt-out-scheme misuse in elder-fraud contexts.

Periodic update · new data 2026-09-21

Children & Vulnerable Groups

The 2026 amendment introduces Japan's first dedicated statutory provisions for minors within the APPI: a parental-consent requirement for processing the personal data of individuals under 16, coupled with enhanced deletion and suspension rights specifically for children.

Outlook

These minors' protections await Cabinet-order commencement, due no later than July 2028. Once active, they will require operators serving Japanese users under 16 to establish parental-consent mechanisms where none were previously mandated under the APPI.

Sources and claims (5)
  1. ConfirmedIAPP — Under current law there are basically no explicit statutory provisions regarding the handling of children's personal information, and the APPI does not define the age of a child; PPC Q&A guidance indicates the applicable age can vary by data type and business nature, generally referencing ages 12-15 and under.observed
  2. ProbableIAPP — The PPC's triennial-review reform proposes formally defining those under 16 years old as children for APPI purposes.observed
  3. ProbableIAPP — The reform proposes strengthening safety-control-measure obligations specific to children's personal data, including a requirement that operators prioritise and give special consideration to the best interests of children.observed
  4. UncertainIAPP — The PPC's reform discussion explicitly weighs the vulnerability and need for protection of children's data against the usefulness of student education and learning data, without proposing a dedicated education-sector statute.observed
  5. ConfirmedIAPP — No dedicated dependent-adults data-protection regime exists; the PPC has instead flagged demand to regulate malicious personal-information list providers as a countermeasure against criminal groups using elderly individuals' financial information to commit fraud.observed

#

Criminal-penalty enforcement architecture and civil tort redress are settled and in force, but the absence of PPC administrative fining power and of a codified collective-redress mechanism — both under active reform — constrain current enforcement intensity.

Primary frameworkAct on the Protection of Personal Information (APPI); Civil Code Article 709 (tort)
Traffic-light rationale — AmberCriminal-penalty enforcement architecture and civil tort redress are settled and in force, but the absence of PPC administrative fining power and of a codified collective-redress mechanism — both under active reform — constrain current enforcement intensity.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

PPC coercive powers include binding orders (Art 148) alongside non-coercive guidance/recommendations; violation of a binding order carries criminal, not administrative, penalties.

Claims (4):

  • The PPC has made greater use of non-coercive powers of guidance and advice than of coercive powers such as binding orders under Article 148 of the APPI.
  • Violating a binding PPC order carries imprisonment with labour of up to one year or a fine of up to JPY 1,000,000 for individuals, and a fine of up to JPY 100 million for corporate entities.
  • Submitting a false report to the PPC carries a fine of up to JPY 500,000.
  • The PPC does not have the power to impose administrative monetary fines directly, unlike GDPR supervisory authorities; sanctions for APPI violations are criminal and imposed by courts.

Enforcement Activity IndexAmber

Historical PPC enforcement activity (2019-2020 baseline period) shows heavy reliance on non-coercive tools, with only a handful of binding orders and no fines/imprisonment sanctions recorded in that window.

Claims (1):

  • Between 1 April 2019 and 30 September 2020, the PPC reported issuing five recommendations and two binding orders, with no business operator sanctioned by fine or imprisonment for violating a binding order in that period.

Regulator Funding And CapacityGreen

The 2021 APPI amendment expanded PPC enforcement powers and led to an increase in its resources, per the European Commission's adequacy-review findings.

Claims (1):

  • The 2021 APPI amendment expanded the PPC's enforcement powers and led to an increase in its resources.

Collective Redress And Class ActionsRed

No codified collective-redress or class-action mechanism for data-protection claims currently exists; the PPC is actively considering a new injunctive-relief and damages-restoration system operated by qualified organisations.

Claims (1):

  • The PPC is considering establishing a new system of injunctive relief and restoration of damages operated by qualified organisations, as part of its four-pronged enforcement-strengthening review.

Private Right Of ActionGreen

Individuals may pursue civil damages for data-protection violations via the general tort provision in Civil Code Article 709.

Claims (1):

  • Civil Code Article 709 provides the main general ground for civil litigation for damages arising from privacy or data-protection infringements in Japan.

Recent Developments 180DAmber

Within the last 180 days, the PPC finalised its triennial System Reform Policy (January 2026) and the Cabinet approved an APPI amendment bill (April 2026) now before the Diet, alongside new cross-border cooperation MOUs.

Claims (2):

  • On 9 January 2026, the PPC decided its System Reform Policy under the triennial review of the Act on the Protection of Personal Information.
  • Japan's Cabinet approved a bill to amend the Act on the Protection of Personal Information on 7 April 2026 and submitted it to the Diet, where it was expected to be enacted during that session.
Category narrative129 words

PPC enforcement currently relies predominantly on non-coercive tools (guidance, advice, recommendations) with binding orders and criminal sanctions rare; the PPC itself cannot impose administrative monetary fines — sanctions for violating a binding PPC order are criminal (up to one year's imprisonment or a JPY 1,000,000 fine for individuals; up to JPY 100 million for corporate entities), enforced by courts. An administrative fine system and new collective-redress/injunctive-relief mechanisms are under active PPC consideration as part of the ongoing triennial review. Private redress is available generally through Civil Code Article 709 tort claims. Recent 180-day developments include the PPC's January 2026 System Reform Policy decision and the Cabinet's April 2026 approval of an APPI amendment bill now before the Diet, alongside a series of 2025-2026 international cooperation MOUs (Canada, Philippines, Singapore).

Periodic update · new data 2026-09-21

Enforcement & Redress

The APPI Amendment Act, enacted by the Diet on 10 July 2026 and promulgated on 17 July 2026, introduces the PPC's first-ever direct administrative monetary-penalty power; the provision is enacted but not yet in force, with commencement due no later than July 2028. Separately, under the current regime, the PPC's own monitoring report published five enforcement cases for the period October 2024 to September 2025, including a list broker suspected of selling personal-data lists to an organised-crime fraud group.

Outlook

Until Cabinet-order commencement, the PPC's enforcement toolkit remains limited to administrative orders, recommendations, and reputational or publication measures rather than direct fines. The activation of direct fining power, whenever it occurs within the window to July 2028, would represent a significant shift in Japan's enforcement posture.

Sources and claims (10)
  1. ConfirmedEUR-Lex — The PPC has made greater use of non-coercive powers of guidance and advice than of coercive powers such as binding orders under Article 148 of the APPI.observed
  2. ConfirmedIAPP — Violating a binding PPC order carries imprisonment with labour of up to one year or a fine of up to JPY 1,000,000 for individuals, and a fine of up to JPY 100 million for corporate entities.observed
  3. ConfirmedIAPP — Submitting a false report to the PPC carries a fine of up to JPY 500,000.observed
  4. ConfirmedOneTrust DataGuidance — The PPC does not have the power to impose administrative monetary fines directly, unlike GDPR supervisory authorities; sanctions for APPI violations are criminal and imposed by courts.observed
  5. ConfirmedEUR-Lex — Between 1 April 2019 and 30 September 2020, the PPC reported issuing five recommendations and two binding orders, with no business operator sanctioned by fine or imprisonment for violating a binding order in that period.observed
  6. ConfirmedEUR-Lex — The 2021 APPI amendment expanded the PPC's enforcement powers and led to an increase in its resources.observed
  7. ProbableIAPP — The PPC is considering establishing a new system of injunctive relief and restoration of damages operated by qualified organisations, as part of its four-pronged enforcement-strengthening review.observed
  8. ConfirmedEUR-Lex — Civil Code Article 709 provides the main general ground for civil litigation for damages arising from privacy or data-protection infringements in Japan.observed
  9. ConfirmedPPC — On 9 January 2026, the PPC decided its System Reform Policy under the triennial review of the Act on the Protection of Personal Information.observed
  10. ProbableIAPP — Japan's Cabinet approved a bill to amend the Act on the Protection of Personal Information on 7 April 2026 and submitted it to the Diet, where it was expected to be enacted during that session.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct46.88
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Japan
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 70 claim(s) (70 category placement(s)), 32 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated with T1 (PPC primary legal texts, PPC overview/triennial-review PDFs, EU Implementing Decision 2019/419) and T2 (European Commission adequacy-review SWD/COM documents, EDPB Statement 1/2023, European Parliament Resolution) anchors for regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, and cross_border_and_adequacy. sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress rely more heavily on T3 secondary commentary (IAPP, DataGuidance) supplementing T1 PPC primary sources, reflecting genuine gaps in codified Japanese sectoral/adtech/biometric/children's/collective-redress law rather than research shortfall. Several claims across lawful_processing_and_special_data, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress are marked regulatory_stage=proposed because they derive from the PPC's ongoing triennial review and the April 2026 Cabinet-approved amendment bill, which had not been enacted as of the 29 July 2026 run date.

Unresolved questions (6):

  • Will the APPI amendment bill approved by Cabinet on 7 April 2026 be enacted during the current Diet session, and what will its final effective date(s) be?
  • Will the PPC introduce an administrative fine system, and if so, what will the calculation methodology and minimum/maximum thresholds be?
  • Will the proposed under-16 statutory child-age threshold and associated parental-consent/best-interests obligations be adopted as drafted?
  • Will 'Specific Biometric Personal Information' rules for facial-recognition data be finalized, and will biometric data be elevated to a special-category status?
  • Is there a Japan-specific ePrivacy/cookie-consent or dark-patterns statute distinct from general APPI third-party-provision rules that was not surfaced in this research pass?
  • What is the precise scope and timeline of the proposed injunctive-relief/collective-redress framework referenced in the PPC's Interim Summary?

Escalate to primary-source review: yes