Japan Act on Protection of Personal Information
Japan primary data protection law governing handling of personal information. Updated 2022 with stricter requirements for cross-border transfers and breach notification.
What APPI draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Security Control
Business operators MUST take necessary and appropriate measures to prevent leakage, loss, or damage of personal data.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Breach Notification
Significant data breaches MUST be reported to the PPC and affected individuals without delay.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
Disclosure Request
Business operators MUST disclose retained personal data to individuals upon request.
Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.
Cross-Border Transfer
Transfer of personal data outside Japan REQUIRES consent or equivalent protection confirmation.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
What APPI covers
Art. 2(1); special care-required personal information at Art. 2(3)
Information about a living individual which identifies them, including by an individual identification code.
In scope
- Information identifying a living individual
- Individual identification codes, including My Number and passport numbers
Yō-hairyo kojin jōhō — special care-required personal information (Art. 2(3))
The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.
- Race, creed and social status
- Medical history
- Criminal record
- Facts of having suffered damage from a crime
What falls outside
Anonymously processed information and pseudonymously processed information sit in their own regimes with reduced obligations rather than outside the Act — a three-tier structure other instruments do not have.
Personal Information Protection Commission · as at 2026-08
How APPI is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Personal Information Protection Commission of Japan.
| Published maximum | Charged | As at |
|---|---|---|
| JPY 100 million | against a corporate offender | 2026-08 |
The Commission works through guidance and orders first. The penalty attaches to breaching an order or to providing a false report, rather than to the underlying handling failure, and the corporate ceiling was raised substantially by the 2020 amendments.
The enforcement culture is corrective rather than punitive; orders and published guidance are far more common than fines.
Uncapped exposure that sits outside this instrument
These come from company law rather than from APPI, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for APPI,
not configured for it afterwards
Japan Personal Data Monitoring
Track access to My Number and Japanese personal data
APPI Compliance Report
Security measure documentation for PPC assessment
Japanese PII Patterns
Detect My Number, Japanese names, and address formats
Cross-Border Transfer Detection
Alert when Japanese personal data accessed from outside Japan
Other Data Privacy frameworks
Walk into the APPI audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.