Start with Identity
🇯🇵 Japan · Data privacy

APPI

Act on the Protection of Personal Information (APPI)

The APPI is Japan's principal data protection law, originally enacted in 2003 and significantly amended over time, with the most recent major amendment effective 1 April 2022. It is enforced by the Personal Information Protection Commission and governs how businesses handle personal information, including sensitive data and cross-border transfers.

Jurisdiction:🇯🇵 Japan
Type:Data privacy
In effect:2003
Authority:Personal Information Protection Commission (PPC)

Who it applies to

Personal information handling business operators that handle personal information in the course of business, including foreign operators handling the personal information of individuals in Japan in connection with supplying goods or services.

Identity requirements

How it impacts identity systems

Identity areaImpact
Customer identity & consent (CIAM)Purpose specification and consent rules shape how identity and personal data are collected and used in customer systems.
Data residency & cross-border transferTransfers of personal data abroad require consent or equivalent safeguards and added transparency to data subjects.
Breach notificationLeaks of personal data must be reported to the PPC and affected individuals where prescribed thresholds are met.
Audit, logging & accountabilityOperators must implement security control measures and remain accountable for personal data handling.

Penalties

The PPC can issue guidance, recommendations and corrective orders; violating an order can lead to criminal penalties, including imprisonment or fines, with higher fines for corporations.

APPI: frequently asked questions

Who enforces the APPI?
The Personal Information Protection Commission (PPC), an independent central authority, supervises and enforces the APPI, including inspections, recommendations and corrective orders.
Does the APPI apply to companies outside Japan?
Yes. Foreign business operators that handle the personal information of individuals in Japan in connection with supplying goods or services are subject to the APPI.
Is breach reporting required under the APPI?
Yes. Since the amendments effective April 2022, operators must report qualifying leaks of personal data to the PPC and notify affected individuals.
Educational summary, not legal advice. Confirm current requirements with the relevant authority or counsel. See all Japan regulations or the full country index.