Act on the Protection of Personal Information
Japan's Act on the Protection of Personal Information (APPI) is the country's principal personal data protection law. It regulates how businesses collect, use, store, disclose, secure, and otherwise process personal information.
APPI places strong emphasis on specifying purposes of use, transparency, appropriate handling, security measures, individual rights, and restrictions on third-party disclosure. It also contains specific requirements for sensitive personal information and international transfers.
The law can apply to certain businesses outside Japan when they handle personal information of individuals in Japan in connection with providing goods or services in Japan.
APPI requires organizations to clearly identify the purposes for which personal information is used and handle information within the applicable legal framework.
Consent is not required for every processing activity. However, consent is generally required before providing personal data to a third party, subject to statutory exceptions and limited opt-out mechanisms. Additional consent requirements apply to certain categories of sensitive personal information and certain international transfers.
Japan
In force; major provisions amended in 2022, with further amendments enacted in 2026 and coming into force in stages
Asia & Africa
APPI applies primarily to Personal Information Handling Business Operators that handle personal information databases or similar personal information in the course of business.
The law can also apply to organizations outside Japan where they handle personal information of individuals in Japan in connection with providing goods or services to people in Japan.
Foreign businesses subject to APPI may therefore need to comply with requirements relating to security, data breaches, individual rights, and other applicable obligations.
APPI provides administrative and criminal enforcement mechanisms.
For certain serious violations involving unlawful provision or use of personal information databases and violations of orders issued by the PPC, corporate fines can reach JPY 100 million. Individuals can also face imprisonment or fines for specified offenses.
The PPC can also exercise supervisory powers, including reporting and inspection-related powers and orders under the circumstances established by the Act.
Organizations should therefore maintain documented privacy and security controls rather than treating APPI compliance as a one-time consent exercise.
Organizations subject to APPI should establish controls covering:
APPI's purpose requirements are particularly important: the purpose of use should be sufficiently specific for the individual to understand how their personal information will be used. Generic descriptions such as simply "improving services" may not be sufficiently specific.
One of APPI's core requirements is that businesses must specify the purpose of use of personal information as much as possible.
The purpose should be sufficiently concrete that:
Organizations should therefore avoid vague purpose statements and maintain clear records of the purposes associated with each category of personal information.
Instead of:
"To improve our services."
A more specific purpose could explain that customer information is used to:
The appropriate wording depends on the actual processing activities.
APPI does not require consent for every type of personal information processing.
However, consent plays an important role in several situations, including:
Where consent is required, organizations should ensure that the individual can make an informed decision based on appropriate information about the processing.
APPI recognizes Special Care-Required Personal Information, commonly referred to as sensitive personal information.
This category includes information relating to matters such as:
As a general rule, an organization must obtain the individual's prior consent before acquiring Special Care-Required Personal Information, subject to statutory exceptions.
Organizations handling such information should therefore maintain separate controls for identification, collection, access, disclosure, and consent.
APPI generally restricts the provision of personal data to third parties without the individual's prior consent, subject to exceptions established by law.
Exceptions can include circumstances such as:
The PPC confirms that a third party can include a family member or another person outside the relevant business operator.
APPI provides a limited framework under which certain third-party disclosures may be made through an opt-out procedure rather than individual consent, provided the applicable statutory requirements are satisfied.
This is not a general substitute for consent and requires appropriate notification and regulatory procedures.
These requirements should not be treated as the same APPI obligation.
Prior consent is generally required before acquiring Special Care-Required Personal Information, subject to exceptions.
Prior consent is generally required before providing personal data to a third party, subject to statutory exceptions and the limited opt-out framework.
Additional requirements apply when personal data is provided to a third party in a foreign country.
Separating these consent scenarios helps organizations build more accurate APPI compliance workflows.
APPI provides individuals with rights relating to retained personal data.
Depending on the circumstances, individuals can request actions including:
Organizations should establish a documented process for receiving, authenticating, evaluating, and responding to individual requests.
Organizations should provide individuals with appropriate information about how their personal information is handled.
Privacy information should address relevant matters such as:
APPI's transparency requirements make the privacy notice an important part of the organization's compliance framework.
APPI requires organizations to take necessary and appropriate security control measures to prevent leakage, loss, or damage to personal information.
Security measures can include:
The PPC identifies organizational, human, physical, and technical security measures as relevant components of APPI security controls.
APPI establishes obligations concerning certain leakage, loss, or damage incidents involving personal data.
Where a qualifying breach occurs, the business operator must take the required remedial and reporting measures, including notification to the PPC and affected individuals where applicable.
Foreign businesses subject to APPI can also fall within these breach-related requirements when the incident involves personal information covered by APPI's extraterritorial application.
Organizations should maintain:
APPI contains specific requirements when personal data is provided to a third party located outside Japan.
As a general rule, a business operator must obtain the individual's consent before providing personal data to a foreign third party unless an applicable statutory mechanism or exception applies.
The organization may also rely on prescribed alternatives, including situations where:
The PPC's current international-transfer guidance also requires appropriate information to be provided to individuals where consent is used as the transfer mechanism.
Where consent is obtained for providing personal data to a foreign third party, the individual must receive required information concerning the overseas transfer.
This can include:
The PPC specifically emphasizes that organizations should evaluate the risks associated with international transfers and provide understandable information to individuals.
APPI does not function as a standalone cookie-consent law.
However, cookies, advertising identifiers, device identifiers, analytics technologies, and other online identifiers may fall within APPI's rules depending on how the information is collected, combined, provided, and used.
Organizations should assess:
For websites, organizations should therefore map their cookies and trackers rather than assuming that every cookie requires an APPI consent banner.
APPI also contains rules concerning Personal-Related Information, which can include information about an individual that does not itself constitute personal information but may become personal data when obtained by a recipient.
For example, certain online identifiers or browsing-related information may require additional consideration when provided to another business that is expected to obtain it as personal data.
The PPC clarifies that the relevant third-party rule applies where the recipient is expected to acquire the personal-related information as personal data.
This is particularly relevant to advertising, analytics, audience measurement, and data-sharing ecosystems.
APPI provides specific frameworks for:
These frameworks can allow organizations to use transformed information for specified purposes while applying different obligations from ordinary personal information.
However, simply masking or anonymizing information does not automatically make it legally classified as pseudonymously or anonymously processed information. The applicable statutory processing standards must be followed.
Organizations should establish appropriate policies for retaining and deleting personal information.
Retention practices should consider:
Information that is no longer required should be securely deleted or otherwise handled in accordance with applicable APPI requirements.
Organizations frequently rely on service providers, cloud platforms, analytics providers, marketing platforms, and other vendors to process personal information.
Businesses should therefore maintain appropriate controls over outsourced processing, including:
Where an overseas service provider receives personal data, organizations should separately assess the applicable APPI international-transfer requirements.
Japan enacted another amendment to APPI in July 2026 following approval by the Diet.
The amendment was promulgated on 17 July 2026. According to the PPC, most provisions will enter into force on a date to be specified by Cabinet Order within two years of promulgation. Related Cabinet Orders, PPC rules, and guidelines are still being developed.
This means organizations should distinguish between:
Current APPI requirements
Rules already in force and applicable to present processing activities.
Forthcoming APPI changes
Requirements introduced by the 2026 amendment that will apply after their respective effective dates.
ConsentX's APPI content should be reviewed as the implementing regulations and guidance are finalized.
The Personal Information Protection Commission (PPC) is Japan's principal privacy regulator and plays a central role in supervising APPI compliance.
The PPC provides guidance, FAQs, rules, enforcement information, and international-transfer guidance for organizations subject to APPI.
ConsentX can help organizations operationalize website-level privacy and consent controls relevant to APPI.
Present clear information about relevant website data-processing purposes through configurable consent and privacy interfaces.
Create consent experiences for processing activities where APPI consent is required.
Document user choices and provide evidence for applicable third-party data-sharing consent workflows.
Create separate consent experiences where special-care personal information requires additional authorization.
Help document consent and information presented to users where international data transfers require an APPI-specific consent workflow.
Prevent configured non-essential website trackers from activating before the applicable consent decision.
Maintain consent records containing relevant information such as the user's choice, timestamp, policy version, and consent context.
Support workflows for receiving and managing applicable data-subject requests.
Build a structured consent and privacy workflow for websites serving individuals in Japan.
Scan your website, identify trackers and third-party technologies, configure APPI-specific consent rules, and maintain auditable records of user choices.
Run a website scan to identify cookies, trackers, scripts, pixels, and third-party technologies operating on your website.
Identify what information is collected, why it is collected, where it is sent, and which third parties receive it.
Ensure website processing activities are mapped to clear and specific purposes of use.
Create appropriate consent workflows for sensitive personal information, third-party disclosures, international transfers, and other activities where consent is required.
Use prior-script blocking to prevent configured non-essential trackers from firing before the applicable consent decision.
Store consent receipts documenting the user's choice, timestamp, consent context, and applicable policy version.
Use the DSAR workflow to manage applicable access, correction, deletion, suspension, and other individual requests.
Identify third-party vendors and technologies that transfer personal data outside Japan and assess the appropriate APPI transfer mechanism.
This page provides a plain-English overview of Japan's Act on the Protection of Personal Information for general informational purposes. It is not legal advice.
APPI obligations can vary depending on the organization's activities, categories of personal information, third-party disclosures, international transfers, industry, and other applicable Japanese laws and regulations.
The 2026 APPI amendment also introduces changes that will come into force in stages. Organizations should verify applicable requirements against the current Japanese law, PPC rules, guidelines, and effective dates and obtain qualified local legal advice where necessary.