Act 2003
Act on the Protection of Personal Information (APPI)
Kojin Jōhō no Hogo ni kansuru Hōritsu
Issued by Personal Information Protection Commission
Effective: 30 May 2003
Last amended: 17 Jul 2026
Plain-English summary
The Act on the Protection of Personal Information is a very well-balanced piece of legislation that creates a framework for the processing of personal information, providing extraterritorial jurisdiction over any entity operating globally that processes personal information about individuals in Japan. In accordance with the regulation, data controllers are required to disclose the intended purpose of the processing of the data, to take proper security measures in order to prevent any leaks, to keep transactional logs, and to receive explicit consent before transferring personal data to third parties and internationally. The Act contains a reciprocal data adequacy regime with the European Union and the UK, making it an extremely strong privacy standard for the whole world. The major amendments adopted in 2026 move Japan away from its pure consent approach to a risk-based approach for an accountable AI ecosystem. The new amendments include a very strict fines regime for business organizations, the creation of a highly protected category of "Specific Biometric Personal Information" (for example, facial recognition data), very tough rules for obtaining parental consent for minors under 16 years old, and transparency exceptions making it easier to use data for training AI models.
Who it applies to
Banking · Insurance · Telecom & Tech · Healthcare & Pharma
Topics
Data Protection & Privacy
Obligations arising from this instrument
| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| Lawful basis, notice and data subject rights | Ongoing | PPC | source | |
Within the Act on the Protection of Personal Information (APPI), Japan regulates an established framework for the protection of legal basis, privacy notice, and individual rights through the Personal Information Protection Commission (PPC). This regulatory model requires strict definition of the Purpose of Utilization, provides absolute erasure power to individuals on private data such as biometric data, and imposes permanent business compliance after recent changes. |
||||
| Personal data breach notification | Deadline Event-based | PPC | source | |
As per Article 26 of the Act on the Protection of Personal Information (APPI), Japan has implemented a stringent and continuous dual data breach notification requirement through its Personal Information Protection Commission (PPC). The organizations regulated under this policy have to comply with the mandatory dual filing process of reporting, wherein they are required to submit a preliminary report within 3 to 5 days from the discovery of an event if the breach of information involves sensitive care-required data, poses imminent financial risk, comes from cybercrime, or affects 1,000 people. At the same time, business organizations have to inform each of the affected data owners individually or provide public notice in cases where it becomes difficult to contact them. Under the amendments made to the APPI in 2026, the new enforcement model will shift from procedural guidelines to an effective administrative surcharge approach to impose heavy fines on companies not complying with the policy requirements. |
||||
| No obligations match these filters. | ||||
Latest news
No related news yet. We publish updates as regulators act.