APPIData PrivacyJapanAll Industries

Japan Act on Protection of Personal Information

Japan primary data protection law governing handling of personal information. Updated 2022 with stricter requirements for cross-border transfers and breach notification.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

APPIArticle 23A record of accessAttribution to an individual

Security Control

Business operators MUST take necessary and appropriate measures to prevent leakage, loss, or damage of personal data.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

APPIArticle 26Detecting it in time to notify

Breach Notification

Significant data breaches MUST be reported to the PPC and affected individuals without delay.

Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.

APPIArticle 33Retention and availability

Disclosure Request

Business operators MUST disclose retained personal data to individuals upon request.

Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.

APPIArticle 28A record of access

Cross-Border Transfer

Transfer of personal data outside Japan REQUIRES consent or equivalent protection confirmation.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

What APPI covers

Art. 2(1); special care-required personal information at Art. 2(3)

Information about a living individual which identifies them, including by an individual identification code.

In scope

  • Information identifying a living individual
  • Individual identification codes, including My Number and passport numbers

Yō-hairyo kojin jōhō — special care-required personal information (Art. 2(3))

The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.

  • Race, creed and social status
  • Medical history
  • Criminal record
  • Facts of having suffered damage from a crime

What falls outside

Anonymously processed information and pseudonymously processed information sit in their own regimes with reduced obligations rather than outside the Act — a three-tier structure other instruments do not have.

Personal Information Protection Commission · as at 2026-08

How APPI is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Personal Information Protection Commission of Japan.

Published maximumChargedAs at
JPY 100 millionagainst a corporate offender2026-08

The Commission works through guidance and orders first. The penalty attaches to breaching an order or to providing a false report, rather than to the underlying handling failure, and the corporate ceiling was raised substantially by the 2020 amendments.

The enforcement culture is corrective rather than punitive; orders and published guidance are far more common than fines.

Uncapped exposure that sits outside this instrument

These come from company law rather than from APPI, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for APPI,
not configured for it afterwards

Policy Template

Japan Personal Data Monitoring

Track access to My Number and Japanese personal data

Report

APPI Compliance Report

Security measure documentation for PPC assessment

Classification

Japanese PII Patterns

Detect My Number, Japanese names, and address formats

Alert

Cross-Border Transfer Detection

Alert when Japanese personal data accessed from outside Japan

Other Data Privacy frameworks

Walk into the APPI audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment