Japan
5 regulators · 6 instruments · 6 obligations · 1 upcoming deadline
| Obligation | Timing | Regulator | Arises from | Source | Detail |
|---|---|---|---|---|---|
| Banking | |||||
| AML compliance programme and officer | Ongoing | JAFIC | Act on Prevention of Transfer of Criminal Proceeds | source | |
In Japan, AML/CFT compliance program requirements and compliance officer responsibilities are statutory under the Act on Prevention of Transfer of Criminal Proceeds [JAFIC 1]. Moreover, this is closely monitored by the Financial Services Agency (FSA). Following the evaluation by FATF, Japan has adopted a stringent, risk-based system that makes regulated institutions responsible for identifying, assessing, and mitigating risks of money laundering and terrorist financing in their organizations. |
|||||
| AML record retention | Retention period 7 years | JAFIC | Act on Prevention of Transfer of Criminal Proceeds | source | |
In Japan, a tight seven-year period of document retention is required by the Act on Prevention of Transfer of Criminal Proceeds [JAFIC 1, JAFIC 2] and Financial Services Agency. Regulated entities are required to keep documents for seven years after ending relationship, completion of the transaction, or filing the suspicious transactions report [JAFIC 1]. |
|||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | JAFIC | Act on Prevention of Transfer of Criminal Proceeds | source | |
Japanese legal framework for Customer Due Diligence and Know Your Customer is provided in the Act on Prevention of Transfer of Criminal Proceeds that is implemented by the Financial Services Agency and National Police Agency. The Act imposes an obligation on business operators to verify their clients' identities, determine beneficial owners with a stake of more than 25% of total corporate voting rights, and screen from antisocial groups. |
|||||
| Suspicious transaction reporting | Deadline Event-based | JAFIC | Act on Prevention of Transfer of Criminal Proceeds | source | |
According to Article 8 of the Act on Prevention of Transfer of Criminal Proceeds, the Japanese STR requirement is stringent and data-driven. Under this Act, all suspicious transactions in Japan are supposed to be reported without necessarily having a minimum amount set [JAFIC 1, JAFIC 2]. The requirement is enforced by the Financial Services Agency (FSA), but the reporting center is the Japan Financial Intelligence Center (JAFIC) under the National Police Agency. Therefore, all specified business operators should report suspicious transactions that involve criminal money laundering or terrorist activities, without necessarily setting a monetary threshold. The workflow should identify the customer's profile precisely and the geographical variations involved to facilitate the actionability of the report. It is illegal to tip off the customer about the report, while a person who fails to undergo the normal Customer Due Diligence is automatically treated as a reporting event. |
|||||
| Telecom & Tech | |||||
| Lawful basis, notice and data subject rights | Ongoing | PPC | Act on the Protection of Personal Information (APPI) | source | |
Within the Act on the Protection of Personal Information (APPI), Japan regulates an established framework for the protection of legal basis, privacy notice, and individual rights through the Personal Information Protection Commission (PPC). This regulatory model requires strict definition of the Purpose of Utilization, provides absolute erasure power to individuals on private data such as biometric data, and imposes permanent business compliance after recent changes. |
|||||
| Personal data breach notification | Deadline Event-based | PPC | Act on the Protection of Personal Information (APPI) | source | |
As per Article 26 of the Act on the Protection of Personal Information (APPI), Japan has implemented a stringent and continuous dual data breach notification requirement through its Personal Information Protection Commission (PPC). The organizations regulated under this policy have to comply with the mandatory dual filing process of reporting, wherein they are required to submit a preliminary report within 3 to 5 days from the discovery of an event if the breach of information involves sensitive care-required data, poses imminent financial risk, comes from cybercrime, or affects 1,000 people. At the same time, business organizations have to inform each of the affected data owners individually or provide public notice in cases where it becomes difficult to contact them. Under the amendments made to the APPI in 2026, the new enforcement model will shift from procedural guidelines to an effective administrative surcharge approach to impose heavy fines on companies not complying with the policy requirements. |
|||||
| No obligations match these filters. | |||||