Jurisdiction Guides / Asia-Pacific
Japan Privacy & Data Protection Laws
Every regime below can apply to a business handling Japan residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
APPI applies extraterritorially wherever a personal-information-handling business operator, regardless of location, handles the personal information of a person in Japan 'in relation to' supplying goods or services to that person (Art. 171) — confirmed against the PPC's official English translation. Unlike GDPR, there is no separate statutory 'monitoring behavior' limb. Art. 57 exempts operators from Chapter IV obligations for press reporting, professional writing, academic research, or religious/political activity; no small-business exemption, and government bodies are regulated under a different chapter of the same integrated Act rather than being unregulated. Amendment in progress: a substantial APPI amendment bill passed the Diet on July 10, 2026 and was promulgated July 17, 2026. It adds protections for children's data (parental consent under 16), a new 'specific biometric personal information' category, a statistical-processing exemption, and administrative fines plus broader PPC order-making power. Most of it takes effect on a date to be fixed by cabinet order within two years of promulgation (so by mid-2028), with a subset of penalty provisions commencing January 17, 2027 — the entry below still describes the currently operative law.
Sector-Specific Law · 1
Any business with employees in Japan handles My Numbers, because the number is required for payroll withholding and social insurance filings — which makes this the sectoral law most likely to bind a foreign company that thinks it only has an APPI problem. The Act treats a My Number and the data attached to it as 'specific personal information' and regulates it far more tightly than the APPI regulates ordinary personal data: collection only for the purposes the Act enumerates, notified purposes, identity verification on collection, no use beyond those purposes, no provision to third parties even WITH the individual's consent except as the Act allows, and deletion once the retention period ends. Outsourcing to a payroll or benefits provider is permitted without consent but carries a duty of necessary and appropriate supervision. Breach can attract criminal liability, including imprisonment, for the entity and for individual employees — an exposure the APPI does not create. Marked 'check': the primary text is Japanese-language and the penalty detail was triangulated across independent sources.
Cross-Border Data Transfer · 1
The default under Art. 28(1) is the data subject's prior consent — and since the 2020 amendment took effect, that consent is only valid if it was informed in a specific way: the business must first give the individual reference information about the destination country's data protection regime and the measures the recipient takes. Consent is not needed where the destination is a country the Personal Information Protection Commission has designated as having an equivalent standard (the EU and the UK are designated), or where the recipient has established a system meeting APPI-equivalent standards, in which case the exporter takes on ongoing duties to check the recipient's continued compliance and to make that information available to the data subject on request. APEC CBPR certification is recognised as one route to the equivalent-system test.
Data Security & Breach Notification · 1
Japan reports in two stages rather than one: a prompt preliminary report to the Personal Information Protection Commission once a leak is recognized (PPC guidance treats 'promptly' as roughly three to five days), then a final report within 30 days — extended to 60 days where the incident is likely to have been committed for an improper purpose, such as a cyberattack. Reporting is not triggered by every incident: the duty attaches where the leak involves sensitive personal information, carries a risk of property damage, is likely to have been intentional/malicious, or affects more than 1,000 data subjects. Affected individuals must also be notified. A business calibrated to a single 72-hour GDPR notification will under-serve the Japanese process, which expects an early flag followed by a substantive investigation write-up.
On the Horizon — Proposed, Not Yet Law · 1
Once in force, the amendments require that where the APPI calls for consent and the data subject is under 16, consent comes from the legal representative, and that notices which would otherwise go to the individual go to the representative instead; they also give minors enhanced standing to request cessation of use or of third-party provision, and impose a duty on businesses to make efforts to prioritise the best interests of the minor. Reporting also indicates a parental-approval requirement for collecting biometrics from an under-16, which sits alongside the package's new 'specific biometric personal information' category. For a business serving Japanese users this is a material change from the current position, where children's protection rests on interpretive guidance rather than on a statutory age line — and the lead time is real: the obligations attach on a Cabinet Order date that has not been set, so age-assurance and guardian-consent flows should be designed now rather than scheduled against a known deadline.
Status: Enacted but not yet operative — the status ambiguity noted in earlier passes is now resolved. Japan currently has no statutory children's consent age: the PPC's Q&A guidance treats children aged roughly 12 to 15 or younger as generally lacking decision-making capacity, assessed case by case, which is guidance rather than a rule. The 2026 amendment package puts an under-16 threshold into the Act itself. It cleared the House of Representatives on May 26, 2026, passed the House of Councillors on July 10, 2026, and was promulgated on July 17, 2026 as Act No. 56 of 2026 — confirmed against the PPC's own page for the Reiwa 8 amendment. Commencement is split: a subset of provisions, principally penalty-related, takes effect January 17, 2027 (six months after promulgation), while the main body — including the under-16 provisions — commences on a date to be fixed by Cabinet Order within two years of promulgation, so no later than July 16, 2028. That Cabinet Order had not been made, and much of the operative detail depends on PPC regulations and guidelines still to be issued.
Other Asia-Pacific jurisdictions