Data Security & Breach Notification
Act on the Protection of Personal Information — reporting of data leakage
Japan · April 1, 2022 (mandatory reporting introduced by the 2020 amendment)
Japan reports in two stages rather than one: a prompt preliminary report to the Personal Information Protection Commission once a leak is recognized (PPC guidance treats 'promptly' as roughly three to five days), then a final report within 30 days — extended to 60 days where the incident is likely to have been committed for an improper purpose, such as a cyberattack. Reporting is not triggered by every incident: the duty attaches where the leak involves sensitive personal information, carries a risk of property damage, is likely to have been intentional/malicious, or affects more than 1,000 data subjects. Affected individuals must also be notified. A business calibrated to a single 72-hour GDPR notification will under-serve the Japanese process, which expects an early flag followed by a substantive investigation write-up.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.