🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
JP · run data-protection-2026-07-29 v13-gdpri-1.0.0
content: ai_generated 24 sources retrieved model claude-sonnet-5 ·

Japan

JP schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 70 claims · 24 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
70Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Lead Signal

Japan's APPI amendment bill has passed a decisive milestone this cycle. The bill, approved by Cabinet on 7 April 2026, is understood to have passed both houses of the Diet on 10 July 2026 and been promulgated on 17 July 2026. That sequence moves the reform from proposed status to enacted law that is not yet in force, correcting an earlier reading of the bill as still pending before the Diet. Entry into force is expected by cabinet order within two years of promulgation, meaning the changes could take effect as late as 2028. Among the provisions queued for that later effective date, the amendment extends APPI's extraterritorial reach to foreign operators that receive Japan-based data subjects' personal information even indirectly, and gives the PPC new powers to compel reports from and issue orders against overseas companies. The same bill is understood to create a 'Specific Biometric Personal Information' category for facial-recognition data, carrying a notice duty and an unconditional right for individuals to demand that its use be suspended.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A mature, PPC-enforced omnibus statute is in force with EU/UK mutual adequacy recognition; amber-adjacent risk stems only from the pending 2026 reform bill not yet enacted.

Primary frameworkAct on the Protection of Personal Information (APPI), Act No. 57 of 2003, as amended
Traffic-light rationale — GreenA mature, PPC-enforced omnibus statute is in force with EU/UK mutual adequacy recognition; amber-adjacent risk stems only from the pending 2026 reform bill not yet enacted.

Sub-modules (5)

Regulator And AuthorityGreen

The PPC is Japan's independent data protection authority with exclusive oversight of both private- and public-sector personal information handling since the 2021 amendment.

Claims: CLM-JP-a1b2c301, CLM-JP-a1b2c302

Act And InstrumentsGreen

The APPI is complemented by its Cabinet Enforcement Order, PPC Enforcement Rules, PPC Guidelines/Q&As, and EU/UK-specific Supplementary Rules.

Claims: CLM-JP-a1b2c303

Material ScopeGreen

The APPI applies to 'personal information handling business operators' (PIHBOs) processing personal information databases in the course of business, covering personal information, retained personal data, pseudonymised information and anonymously processed information.

Claims: CLM-JP-a1b2c304

Territorial ScopeAmber

Current law already applies extraterritorially to foreign operators acquiring data of Japan-based individuals in connection with supplying goods/services; the pending amendment would broaden this to indirectly-acquired data and add enforcement powers over overseas entities.

Claims: CLM-JP-a1b2c305, CLM-JP-a1b2c306

Regulator Registration And FilingAmber

There is no general controller registration regime; the principal filing obligation is notification to the PPC when relying on the opt-out mechanism for third-party data provision.

Claims: CLM-JP-a1b2c307

Category narrative106 words

Japan operates a comprehensive omnibus data protection regime centred on the Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, as substantially amended in 2015, 2020 and 2021), overseen exclusively by the Personal Information Protection Commission (PPC), an independent supervisory authority. The 2021 amendment harmonised previously separate public- and private-sector regimes under the PPC's exclusive supervision. The APPI applies extraterritorially to foreign operators supplying goods/services to persons in Japan, and a pending 2026 amendment bill (Cabinet-approved 7 April 2026, before the Diet) would further extend extraterritorial reach and give the PPC new powers to compel reports and issue orders to overseas companies.

No periodic updates recorded against this sub-brief.

Sources and claims (7)
  1. ConfirmedPPCThe Personal Information Protection Commission (PPC) is Japan's independent supervisory authority responsible for oversight and enforcement of the APPI.
  2. ConfirmedEUR-LexFollowing the 2021 APPI amendment, the PPC has exclusive supervisory authority over both private-sector business operators and public-sector Administrative Organs and Incorporated Administrative Agencies.
  3. ConfirmedEUR-LexThe APPI regime is composed of the Act itself plus a Cabinet Enforcement Order, PPC Enforcement Rules, and PPC Guidelines/Q&As that provide authoritative interpretation of the statute.
  4. ConfirmedOneTrust DataGuidanceThe APPI applies to personal information handling business operators (PIHBOs) — persons providing a personal information database for use in business — covering personal information, retained personal data, pseudonymised information and anonymously processed information.
  5. ConfirmedIAPPThe APPI already applies extraterritorially to foreign business operators that acquire personal information directly from data subjects in relation to supplying goods or services to persons in Japan and handle that information abroad.
  6. ProbableIAPPThe pending APPI amendment bill would expand extraterritorial application to foreign operators that handle personal information of Japan-based data subjects even where acquired indirectly, and would empower the PPC to compel reports from and issue orders to overseas companies.
  7. ConfirmedIAPPThere is no general controller registration regime under the APPI; the main filing duty is notifying the PPC when a business relies on the opt-out scheme to provide personal data to third parties without consent.

#

Core consent/sensitive-data rules are settled and in force, but the absence of a GDPR Art 6-style lawful-basis architecture and the unresolved biometric/AI carve-outs create interpretive gaps pending the 2026 reform.

Primary frameworkAct on the Protection of Personal Information (APPI)
Traffic-light rationale — AmberCore consent/sensitive-data rules are settled and in force, but the absence of a GDPR Art 6-style lawful-basis architecture and the unresolved biometric/AI carve-outs create interpretive gaps pending the 2026 reform.

Sub-modules (4)

Lawful BasesAmber

The APPI does not adopt a GDPR-style enumerated lawful-basis regime; lawfulness instead flows from purpose specification, notice, and targeted consent triggers.

Claims: CLM-JP-b2c3d401

Special CategoriesAmber

'Special care-required personal information' requires data-subject consent for collection; biometric data is not yet a defined sensitive category but reform is proposed.

Claims: CLM-JP-b2c3d403, CLM-JP-b2c3d404, CLM-JP-b2c3d405

Pseudonymisation And AnonymisationGreen

The 2020 amendment created a 'pseudonymised information' category (internal-use only, reduced obligations) alongside the pre-existing 'anonymously processed information' concept.

Claims: CLM-JP-b2c3d406

Category narrative108 words

Unlike the GDPR, the APPI does not require an enumerated lawful basis for all processing; instead it relies on purpose specification/notification duties plus consent requirements triggered at specific junctures (sensitive-data collection, purpose-exceeding use, third-party provision, cross-border transfer). 'Special care-required personal information' (race, medical history, criminal record, etc.) requires consent to collect. Biometric data is not currently a distinct sensitive category, but the ongoing triennial review and pending bill would introduce a new 'Specific Biometric Personal Information' category with notice and suspension rights. The 2020 amendment introduced 'pseudonymised information' as a reduced-obligation category for internal statistical use, and a further amendment proposes a consent exemption for statistical processing/AI development.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedIAPPUnlike the GDPR, the APPI does not require a legal basis for all processing of personal information, relying instead on purpose specification and consent only at specific junctures.
  2. ConfirmedIAPPOperators handling personal information are in principle required to obtain data subjects' prior consent before providing personal data to third parties, subject to opt-out and joint-use exceptions.
  3. ConfirmedIAPPThe current APPI generally requires data subjects' consent for the collection of special care-required (sensitive) personal information such as race and medical history.
  4. ConfirmedIAPPBiometric data is not currently categorised as sensitive personal information under Japanese law, and no dedicated biometric-handling rules yet exist.
  5. ProbableIAPPThe pending APPI amendment bill would introduce a 'Specific Biometric Personal Information' category (facial recognition data) requiring notice to data subjects and granting an unconditional right to demand suspension of use.
  6. ConfirmedIAPPThe 2020 APPI amendment introduced 'pseudonymised information,' a category limited to internal statistical use, exempting operators from certain obligations such as responding to disclosure or cessation-of-use demands for retained personal data.

#

Core access/rectification/erasure/objection rights are codified and were substantially strengthened by the 2020/2022 amendments; residual amber factor is the absence of a fixed response-time statute and of an explicit portability right.

Primary frameworkAct on the Protection of Personal Information (APPI)
Traffic-light rationale — GreenCore access/rectification/erasure/objection rights are codified and were substantially strengthened by the 2020/2022 amendments; residual amber factor is the absence of a fixed response-time statute and of an explicit portability right.

Sub-modules (5)

Access RightGreen

Data subjects may demand disclosure of retained personal data; businesses must respond without delay, subject to limited harm-based exceptions.

Claims: CLM-JP-c3d4e501, CLM-JP-c3d4e502

Rectification And ErasureGreen

Rights to correction, addition or deletion of retained personal data exist; erasure/cessation-of-use rights were expanded by the 2020/2022 amendment beyond the original narrow trigger conditions.

Claims: CLM-JP-c3d4e503, CLM-JP-c3d4e504

Restriction And ObjectionGreen

Cessation of use/third-party provision functions as the APPI's restriction/objection mechanism, now exercisable wherever rights or legitimate interests are likely to be infringed.

Claims: CLM-JP-c3d4e504

Data PortabilityAmber

No explicit portability right analogous to GDPR Art 20 exists; the amendment's electronic-disclosure entitlement is the closest functional equivalent.

Claims: CLM-JP-c3d4e505, CLM-JP-c3d4e506

Deadlines And Response WindowsAmber

The APPI imposes a 'without delay' response standard for disclosure requests rather than a fixed statutory number of days.

Claims: CLM-JP-c3d4e502

Category narrative83 words

Data subjects hold rights to demand disclosure, correction/addition/deletion, and cessation of use or third-party provision of 'retained personal data.' The 2020/2022 amendments broadened these rights (removing the prior six-month retention carve-out, allowing exercise wherever rights/interests are 'likely to be infringed,' and permitting electronic-format disclosure demands). There is no dedicated GDPR Art 20-style portability right, though electronic disclosure functions similarly. Response timing is governed by a 'without delay' standard rather than a fixed statutory clock (contrast with the fixed breach-reporting deadlines under controller duties).

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedPPCData subjects have the right to demand disclosure of retained personal data held by a business operator.
  2. ConfirmedPPCA business operator must disclose retained personal data to a data subject without delay, subject to statutory exceptions such as risk of harm to life or improper interference with business operations.
  3. ConfirmedIAPPData subjects may demand correction, addition or deletion of the content of retained personal data.
  4. ConfirmedIAPPThe 2020/2022 amendment expanded data subjects' rights to demand cessation of use, deletion, or cessation of third-party provision of retained personal data to cases where a data subject's rights or legitimate interests are likely to be infringed, beyond the prior narrow grounds of purpose-violation, improper collection, or unlawful third-party provision.
  5. ConfirmedIAPPThe 2020/2022 amendment allows data subjects to require that their retained personal data be disclosed to them electronically, whereas the prior law did not expressly permit electronic-format disclosure demands.
  6. ProbableIAPPThe APPI does not contain a distinct data-portability right equivalent to GDPR Article 20; electronic disclosure of retained personal data is the closest functional analogue.

#

Breach-notification and security-measure duties are robust and in force, but the absence of DPO, formal DPIA, and general ROPA requirements — core GDPR-analogue accountability tools — represents a structural gap relative to omnibus peers.

Primary frameworkAct on the Protection of Personal Information (APPI)
Traffic-light rationale — AmberBreach-notification and security-measure duties are robust and in force, but the absence of DPO, formal DPIA, and general ROPA requirements — core GDPR-analogue accountability tools — represents a structural gap relative to omnibus peers.

Sub-modules (7)

Accountability And DpiaRed

No mandatory DPIA-equivalent process is codified in the APPI; accountability is achieved via security-control-measures and purpose-limitation duties.

Claims: CLM-JP-d4e5f601

Dpo RequirementsRed

The APPI does not include a requirement to appoint a Data Protection Officer.

Claims: CLM-JP-d4e5f602

Ropa RequirementsAmber

No general Art 30-style records-of-processing duty exists; record-keeping obligations are narrower, attaching to third-party data-provision transactions with 3-year retention.

Claims: CLM-JP-d4e5f603

Joint Controller ArrangementsGreen

The APPI's 'joint use' mechanism functions as its joint-controllership analogue, requiring disclosure of the managing entity's identity and contact details.

Claims: CLM-JP-d4e5f604

Security MeasuresGreen

Operators must implement organisational, personnel, physical and technical security-control measures, including 'understanding of the external environment' when data is processed abroad.

Claims: CLM-JP-d4e5f605

Breach NotificationGreen

Mandatory two-stage breach reporting to the PPC (preliminary + final) and subject notification apply to defined categories of data breach.

Claims: CLM-JP-d4e5f606, CLM-JP-d4e5f607

Retention And DisposalAmber

No general statutory retention-period ceiling exists; operators must delete personal data without delay once the purpose of use no longer requires it.

Claims: CLM-JP-d4e5f608

Category narrative89 words

The APPI does not draw a GDPR-style controller/processor distinction, nor does it mandate a DPO or a formal DPIA process; accountability instead flows through security-control-measures obligations, purpose/deletion duties, and (since 2020/2022) mandatory two-stage breach reporting to the PPC plus subject notification for defined high-risk breaches (sensitive data, property-damage risk, cyberattack, or >1,000 affected individuals). Record-keeping obligations attach specifically to third-party data provision (3-year retention) rather than a general Art 30-style ROPA. 'Joint use' arrangements function as the closest analogue to joint controllership, requiring disclosure of the responsible party's details.

No periodic updates recorded against this sub-brief.

Sources and claims (8)
  1. ConfirmedOneTrust DataGuidanceThe APPI does not impose a mandatory Data Protection Impact Assessment process equivalent to GDPR Article 35.
  2. ConfirmedOneTrust DataGuidanceThe APPI does not include a requirement to appoint a Data Protection Officer.
  3. ConfirmedIAPPThe amended Cabinet Order and Enforcement Rules impose record-keeping obligations on providers of personal data to third parties, covering confirmation of consent, date of provision, recipient details and data categories, generally retained for three years.
  4. ConfirmedIAPPWhere a business relies on a 'joint use' mechanism to share personal data with others, the APPI requires disclosure of the address of the business managing the jointly used data and the name of its representative.
  5. ConfirmedIAPPBusinesses must implement organisational, personnel, physical and technical security-control measures over personal data, and the amended guidelines additionally require 'understanding of the external environment' when personal data is processed in a foreign country.
  6. ConfirmedIAPPThe amended APPI implements a legal obligation to report to the PPC and notify affected data subjects when a data breach (leakage, loss or damage) occurs or is likely to have occurred, replacing the prior mere 'duty to make an effort.'
  7. ConfirmedIAPPBreach reporting follows a two-stage process: a preliminary report filed promptly (generally within three to five days for corporations) after recognition of a potential breach, and a final report within 30 days (60 days for cyberattack-related breaches).
  8. ConfirmedOneTrust DataGuidanceBusiness operators must delete personal data without delay once its utilisation is no longer necessary for the specified purpose, though the APPI does not fix a general maximum retention period.

#

A functioning, reviewed mutual adequacy arrangement with the EU/UK and codified transfer mechanisms place this module on solid footing; amber-adjacent nuance is the still-evolving TIA/monitoring guidance under the pending 2026 reform.

Primary frameworkAct on the Protection of Personal Information (APPI); EU-Japan Mutual Adequacy Framework
Traffic-light rationale — GreenA functioning, reviewed mutual adequacy arrangement with the EU/UK and codified transfer mechanisms place this module on solid footing; amber-adjacent nuance is the still-evolving TIA/monitoring guidance under the pending 2026 reform.

Sub-modules (6)

Transfer MechanismsGreen

Transfers rely on data-subject consent or an established equivalent protection system at the recipient, each carrying distinct information-provision duties.

Claims: CLM-JP-e5f6a701

Adequacy ReceivedGreen

Japan does not 'receive' adequacy in the GDPR sense as a third country importer of an EU decision toward itself in reverse; rather it operates the mutual EU-Japan adequacy arrangement (see adequacy_granted).

Claims: CLM-JP-e5f6a702

Adequacy GrantedGreen

The European Commission's 2019 Implementing Decision recognises Japan as ensuring an adequate level of protection for EU-origin personal data transferred to APPI-regulated operators; this was reconfirmed in the Commission's 2023 first periodic review.

Claims: CLM-JP-e5f6a703, CLM-JP-e5f6a704

Sccs And BcrsGreen

The APPI's 'established protection system' mechanism functions as its SCC/BCR-equivalent, supplemented by binding PPC Supplementary Rules for EU- and UK-origin data.

Claims: CLM-JP-e5f6a705

Transfer Impact AssessmentAmber

Operators relying on the established-system transfer mechanism must regularly monitor (at least annually) the continued adequacy of the recipient's protections and explain monitoring frequency/method to data subjects on request.

Claims: CLM-JP-e5f6a706

Data LocalisationGreen

No general data-localisation mandate applies to ordinary personal information under the APPI.

Claims: CLM-JP-e5f6a707

Category narrative104 words

Cross-border transfers require either data-subject consent or reliance on an 'established personal information protection system' at the recipient (broadly SCC-equivalent contractual/organisational measures), with annual monitoring of the importer's system. Japan holds the world's first mutual (two-way) adequacy arrangement with the EU (in force since 23 January 2019, extended in scope to the UK), reinforced by binding PPC Supplementary Rules imposing GDPR-aligned safeguards on EU-origin data. The European Commission's first periodic review (2023) reconfirmed adequacy and moved the review cycle from two to four years. No general data-localisation mandate applies to ordinary personal information, though sector-specific instruments (e.g., My Number Act) impose stricter domestic-handling requirements.

No periodic updates recorded against this sub-brief.

Sources and claims (7)
  1. ConfirmedIAPPA cross-border transfer of personal data from Japan can be permitted based on either the data subject's consent or the establishment of an equivalent personal information protection system at the recipient.
  2. ConfirmedEUR-LexThe EU-Japan arrangement adopted in January 2019 was the first-ever mutual (two-way) adequacy finding, with the PPC recognising the EU as a jurisdiction with an equivalent data-protection system alongside the Commission's reciprocal finding.
  3. ConfirmedEUR-LexThe European Commission's Implementing Decision (EU) 2019/419 found that Japan ensures an adequate level of protection for personal data transferred from the EU to APPI-regulated business operators.
  4. ConfirmedEUR-LexThe European Commission's first periodic review, concluded in 2023, found that Japan continues to ensure an adequate level of protection for EU-origin personal data and moved the review cycle from two to four years.
  5. ConfirmedPPCThe PPC has adopted binding Supplementary Rules under the APPI for the handling of personal data transferred from the EU and the United Kingdom based on an adequacy decision, enforceable by the PPC and directly by individuals in Japanese courts.
  6. ProbableIAPPWhere a cross-border transfer relies on the recipient's established protection system, the operator must regularly monitor that system (guidelines clarify a frequency of at least once a year) and explain the monitoring frequency and method to data subjects upon request.
  7. ProbableOneTrust DataGuidanceNo general data-localisation requirement applies to ordinary personal information handled by APPI-regulated business operators.

#

Financial-sector and My Number overlays are well-documented and in force; telecoms/ePrivacy, education and insurance sector-specific DP overlays are not clearly codified, producing residual coverage gaps.

Primary frameworkAPPI supplemented by FSA/METI sectoral guidelines and the My Number Act
Traffic-light rationale — AmberFinancial-sector and My Number overlays are well-documented and in force; telecoms/ePrivacy, education and insurance sector-specific DP overlays are not clearly codified, producing residual coverage gaps.

Sub-modules (7)

Financial Sector OverlayGreen

The FSA issues sector-specific personal-information-protection guidelines for financial institutions (excluding credit cards, which fall to METI).

Claims: CLM-JP-f6a7b801

Health Sector OverlayAmber

No dedicated health/medical-sector statute analogous to HIPAA was identified beyond the general special-care-required-information consent rule for medical history.

Claims: CLM-JP-f6a7b802

Telecoms And EprivacyRed

No dedicated telecoms/ePrivacy-style instrument governing cookies or electronic communications was identified as currently in force.

Claims: CLM-JP-f6a7b803

Employment DataAmber

Employers handling employees' My Number-linked 'specific personal information' face stricter obligations than under general APPI duties.

Claims: CLM-JP-f6a7b804

Credit And ScoringGreen

METI has issued dedicated guidelines for personal-information protection in the credit-card industry.

Claims: CLM-JP-f6a7b805

EducationRed

No education-sector-specific data-protection statute was identified; the ongoing children's-data reform references the utility of student learning data as a competing policy consideration.

Claims: CLM-JP-f6a7b806

InsuranceRed

No insurance-sector-specific personal-information statute distinct from FSA financial guidance was identified.

Claims: CLM-JP-f6a7b807

Category narrative63 words

Sector-specific overlays supplement the general APPI framework: the Financial Services Agency (FSA) issues financial-industry personal-information guidelines; METI issues credit-card-industry and genetic-information-industry guidelines; and the My Number Act imposes stricter obligations on 'specific personal information' (national ID numbers) used by employers and financial institutions, independently supervised alongside APPI compliance. No dedicated telecoms/ePrivacy-style cookie statute or education-sector-specific data law was identified as currently in force.

No periodic updates recorded against this sub-brief.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidanceThe Financial Services Agency (FSA) has issued guidelines for personal-information protection in the financial industries, supplementing the general APPI regime for financial-sector operators other than credit-card businesses.
  2. UncertainIAPPNo comprehensive health-sector-specific statute analogous to HIPAA was identified; medical history is treated as special care-required personal information under the general APPI consent rule.
  3. UncertainOneTrust DataGuidanceNo dedicated telecoms/ePrivacy-style statute governing cookies or electronic-communications metadata distinct from the general APPI regime was identified as currently in force.
  4. ConfirmedOneTrust DataGuidanceThe My Number Act and related guidelines require employers to establish appropriate secure-storage and handling systems for employees' 'specific personal information,' which are generally stricter than an employer's other APPI-based obligations.
  5. ConfirmedOneTrust DataGuidanceThe Ministry of Economy, Trade and Industry (METI) has issued dedicated guidelines for personal-information protection in the credit-card industry.
  6. UncertainIAPPNo education-sector-specific data-protection statute was identified; the PPC's ongoing children's-data reform explicitly weighs the usefulness of student education/learning data against protective considerations.
  7. UncertainOneTrust DataGuidanceNo insurance-sector-specific personal-information statute distinct from the FSA's general financial-industry guidance was identified.

#

Opt-out and third-party data-provision rules are codified and enforceable, but dark-patterns, standardised opt-out signals, and clean-room-specific rules are absent, and reform of the opt-out scheme itself remains pending.

Primary frameworkAct on the Protection of Personal Information (APPI)
Traffic-light rationale — AmberOpt-out and third-party data-provision rules are codified and enforceable, but dark-patterns, standardised opt-out signals, and clean-room-specific rules are absent, and reform of the opt-out scheme itself remains pending.

Sub-modules (6)

Cookies And TrackersAmber

Cookie-derived individual-related information triggers third-party-provision consent-confirmation duties only when the recipient is likely to render it identifiable.

Claims: CLM-JP-a7b8c901

Dark PatternsRed

No dedicated dark-patterns prohibition was identified under current Japanese data-protection law.

Claims: CLM-JP-a7b8c902

Opt Out SignalsRed

No standardised, legally-recognised opt-out signal mechanism (e.g., GPC/DAA-equivalent) was identified under the APPI.

Claims: CLM-JP-a7b8c903

Clean Rooms And DcrRed

No clean-room / data-collaboration-room-specific rules were identified as distinct from general third-party-provision and joint-use requirements.

Claims: CLM-JP-a7b8c904

Cross Context AdvertisingAmber

Cross-context data sharing for advertising is governed by the general third-party-provision consent/opt-out framework rather than a CPRA-style 'sale'/'share' taxonomy.

Claims: CLM-JP-a7b8c901

Direct MarketingAmber

Direct marketing via shared personal data is governed by the opt-out scheme (PPC filing plus subject notice/accessibility), which functions as the suppression mechanism; reform would restrict abuse of this scheme.

Claims: CLM-JP-a7b8c905, CLM-JP-a7b8c906

Category narrative94 words

Cookie-derived browsing/behavioural data is regulated indirectly through APPI's 'individual related information' provision rule: a provider must confirm the recipient has obtained consent where the recipient is likely to combine such data into identifiable personal data. The opt-out scheme (PPC filing + subject notice) is the principal mechanism enabling third-party data provision, including for marketing purposes, without individual consent; the pending amendment would tighten this scheme by barring provision of improperly-collected data or data received via another party's opt-out filing. No dedicated dark-patterns prohibition or GPC/DAA-style recognised opt-out signal was identified in current Japanese law.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedIAPPWhere a business provides information about a living individual that is not itself personal information (e.g., website browsing history via cookies), and the recipient is likely to receive it in a form that becomes personal data, the provider must confirm the recipient has obtained the data subject's consent.
  2. UncertainIAPPNo dedicated statutory prohibition on dark patterns in consent or data-collection interfaces was identified under current Japanese data-protection law.
  3. UncertainIAPPNo legally-recognised, standardised browser/device opt-out signal mechanism analogous to the Global Privacy Control was identified under the APPI.
  4. UncertainIAPPNo rules specific to data clean rooms or data-collaboration platforms distinct from general third-party-provision and joint-use requirements were identified.
  5. ConfirmedIAPPPersonal data may be provided to third parties for purposes such as marketing without consent if the operator notifies data subjects of opt-out matters (or makes them easily accessible) and files with the PPC.
  6. ProbableIAPPThe pending amendment would bar use of the opt-out scheme to provide personal data collected by deceit or improper means, or data that was itself received via another party's opt-out scheme, in response to observed abuse for fraud-adjacent list trading.

#

AI-specific promotional legislation and sectoral biometric/genetic guidance exist, but core ADM/profiling and binding biometric protections remain in the proposal stage, and state-surveillance carve-outs limit PPC coercive reach over public bodies.

Primary frameworkAPPI (general); Act on Promotion of Research and Development, and Utilization of AI-related Technology (AI Promotion Act, 2025)
Traffic-light rationale — AmberAI-specific promotional legislation and sectoral biometric/genetic guidance exist, but core ADM/profiling and binding biometric protections remain in the proposal stage, and state-surveillance carve-outs limit PPC coercive reach over public bodies.

Sub-modules (6)

Profiling RestrictionsRed

No comprehensive profiling-restriction framework currently exists under the APPI; reform is under PPC consideration.

Claims: CLM-JP-b8c9d001, CLM-JP-b8c9d002

Automated Decision Making TransparencyRed

Neither the APPI nor PPC Guidelines contain comprehensive legal provisions on automated decision-making and profiling, per the European Parliament's adequacy-review findings; only limited sectoral rules touch the issue.

Claims: CLM-JP-b8c9d003

Ai Risk AssessmentsAmber

Japan's AI Promotion Act establishes a national AI governance framework, supplemented by non-binding AI Business Operator Guidelines rather than mandatory AI-specific risk assessments.

Claims: CLM-JP-b8c9d004, CLM-JP-b8c9d005

Biometric RegimeAmber

No binding biometric-specific data regime currently exists; a proposed 'Specific Biometric Personal Information' category for facial-recognition data is pending in the 2026 reform bill.

Claims: CLM-JP-b8c9d002

Genetic DataAmber

Genetic data is addressed only via non-binding METI sectoral guidance; the PPC's triennial review is separately considering genomic-data regulation.

Claims: CLM-JP-b8c9d006, CLM-JP-b8c9d007

State Surveillance CarveoutsAmber

The PPC's oversight of Administrative Organs (including law-enforcement and national-security data collection) is limited to non-coercive tools; it cannot issue binding orders or impose fines on those public authorities.

Claims: CLM-JP-b8c9d008

Category narrative114 words

The APPI currently contains no comprehensive automated-decision-making or profiling framework equivalent to GDPR Article 22; the European Parliament has explicitly flagged this gap. Reform is under active PPC consideration as part of the ongoing triennial review, alongside a proposed 'Specific Biometric Personal Information' regime for facial-recognition data. Separately, Japan's AI Promotion Act (enacted May 2025, in force September 2025) establishes a light-touch, innovation-oriented national AI framework, complemented by non-binding AI Business Operator Guidelines. Genetic data is addressed only via non-binding METI sectoral guidance, with genomic-data regulation flagged for further PPC review. Government/national-security data access by public authorities is subject to PPC oversight powers that stop short of binding orders or fines against those authorities.

No periodic updates recorded against this sub-brief.

Sources and claims (8)
  1. ProbableIAPPThe PPC's triennial-review Interim Summary flags continued consideration of profiling regulation as an open policy issue for the APPI reform.
  2. ProbableIAPPThe pending APPI amendment bill would create a 'Specific Biometric Personal Information' category for facial-recognition data, requiring notice/accessibility to data subjects and an unconditional right to demand suspension of use.
  3. ConfirmedEUR-LexNeither the APPI nor PPC Guidelines contain comprehensive legal provisions on automated decision-making and profiling; only limited sectoral rules address the matter without an overarching protective framework.
  4. ConfirmedIAPPJapan enacted the Act on Promotion of Research and Development, and Utilization of AI-related Technology (AI Promotion Act) in May 2025, which came into full effect in September 2025.
  5. ConfirmedIAPPJapan's AI Business Operator Guidelines consolidate AI-governance principles and best practices but constitute non-binding soft guidance rather than a mandatory AI-specific risk-assessment regime.
  6. ConfirmedOneTrust DataGuidanceMETI has issued non-binding sectoral guidelines for the protection of personal information in industries using genetic information of individuals.
  7. ProbableIAPPThe PPC's triennial-review Interim Summary lists regulation of genomic data among issues requiring continued consideration.
  8. ConfirmedEUR-LexAlthough the PPC oversees Administrative Organs' collection and processing of personal information, including law-enforcement and national-security data collection, it has not been empowered to issue binding orders to, or impose fines on, these public authorities; its tools are limited to reporting requests, on-site inspections, guidance, advice and recommendations.

#

No codified statutory age-of-consent, parental-consent mechanism, minor-profiling ban, or dependent-adults regime currently exists; all children's-data protections are at the proposal stage pending the 2026/2027 reform.

Primary frameworkAct on the Protection of Personal Information (APPI) — children's provisions pending
Traffic-light rationale — RedNo codified statutory age-of-consent, parental-consent mechanism, minor-profiling ban, or dependent-adults regime currently exists; all children's-data protections are at the proposal stage pending the 2026/2027 reform.

Sub-modules (5)

Age VerificationRed

No statutory age-verification requirement exists; the APPI does not currently define a child's age, though PPC Q&A informally references ages 12-15 and under, and reform proposes codifying under-16 as the child threshold.

Claims: CLM-JP-c9d0e101, CLM-JP-c9d0e102

Minor Profiling BansRed

No minor-specific profiling ban currently exists; reform proposes a best-interests-of-the-child standard for safety-control measures applied to children's data.

Claims: CLM-JP-c9d0e103

Education SettingsRed

No education-setting-specific data-protection statute was identified; the reform discussion balances children's-data protection against the utility of student learning data.

Claims: CLM-JP-c9d0e104

Dependent AdultsRed

No dedicated dependent-adults (elderly/incapacitated) data-protection regime was identified; the closest policy analogue is PPC concern over opt-out-scheme misuse enabling elder-targeted financial fraud.

Claims: CLM-JP-c9d0e105

Category narrative85 words

The APPI currently contains no statutory definition of a 'child' and no explicit children's-data provisions; PPC Q&A guidance informally treats individuals aged roughly 12-15 and under as children depending on context. The PPC's ongoing triennial review proposes to codify children as those under 16, strengthen safety-control-measure obligations with a best-interests standard, and permit more flexible ex-post suspension of use for children's retained personal data. No dedicated education-setting or dependent-adults (elderly/incapacitated) data-protection regime was identified, beyond a general policy concern about opt-out-scheme misuse in elder-fraud contexts.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedIAPPUnder current law there are basically no explicit statutory provisions regarding the handling of children's personal information, and the APPI does not define the age of a child; PPC Q&A guidance indicates the applicable age can vary by data type and business nature, generally referencing ages 12-15 and under.
  2. ProbableIAPPThe PPC's triennial-review reform proposes formally defining those under 16 years old as children for APPI purposes.
  3. ProbableIAPPThe reform proposes strengthening safety-control-measure obligations specific to children's personal data, including a requirement that operators prioritise and give special consideration to the best interests of children.
  4. UncertainIAPPThe PPC's reform discussion explicitly weighs the vulnerability and need for protection of children's data against the usefulness of student education and learning data, without proposing a dedicated education-sector statute.
  5. ConfirmedIAPPNo dedicated dependent-adults data-protection regime exists; the PPC has instead flagged demand to regulate malicious personal-information list providers as a countermeasure against criminal groups using elderly individuals' financial information to commit fraud.

#

Criminal-penalty enforcement architecture and civil tort redress are settled and in force, but the absence of PPC administrative fining power and of a codified collective-redress mechanism — both under active reform — constrain current enforcement intensity.

Primary frameworkAct on the Protection of Personal Information (APPI); Civil Code Article 709 (tort)
Traffic-light rationale — AmberCriminal-penalty enforcement architecture and civil tort redress are settled and in force, but the absence of PPC administrative fining power and of a codified collective-redress mechanism — both under active reform — constrain current enforcement intensity.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

PPC coercive powers include binding orders (Art 148) alongside non-coercive guidance/recommendations; violation of a binding order carries criminal, not administrative, penalties.

Claims: CLM-JP-d0e1f201, CLM-JP-d0e1f202, CLM-JP-d0e1f203, CLM-JP-d0e1f204

Enforcement Activity IndexAmber

Historical PPC enforcement activity (2019-2020 baseline period) shows heavy reliance on non-coercive tools, with only a handful of binding orders and no fines/imprisonment sanctions recorded in that window.

Claims: CLM-JP-d0e1f205

Regulator Funding And CapacityGreen

The 2021 APPI amendment expanded PPC enforcement powers and led to an increase in its resources, per the European Commission's adequacy-review findings.

Claims: CLM-JP-d0e1f206

Collective Redress And Class ActionsRed

No codified collective-redress or class-action mechanism for data-protection claims currently exists; the PPC is actively considering a new injunctive-relief and damages-restoration system operated by qualified organisations.

Claims: CLM-JP-d0e1f207

Private Right Of ActionGreen

Individuals may pursue civil damages for data-protection violations via the general tort provision in Civil Code Article 709.

Claims: CLM-JP-d0e1f208

Recent Developments 180DAmber

Within the last 180 days, the PPC finalised its triennial System Reform Policy (January 2026) and the Cabinet approved an APPI amendment bill (April 2026) now before the Diet, alongside new cross-border cooperation MOUs.

Claims: CLM-JP-d0e1f209, CLM-JP-d0e1f210

Category narrative129 words

PPC enforcement currently relies predominantly on non-coercive tools (guidance, advice, recommendations) with binding orders and criminal sanctions rare; the PPC itself cannot impose administrative monetary fines — sanctions for violating a binding PPC order are criminal (up to one year's imprisonment or a JPY 1,000,000 fine for individuals; up to JPY 100 million for corporate entities), enforced by courts. An administrative fine system and new collective-redress/injunctive-relief mechanisms are under active PPC consideration as part of the ongoing triennial review. Private redress is available generally through Civil Code Article 709 tort claims. Recent 180-day developments include the PPC's January 2026 System Reform Policy decision and the Cabinet's April 2026 approval of an APPI amendment bill now before the Diet, alongside a series of 2025-2026 international cooperation MOUs (Canada, Philippines, Singapore).

No periodic updates recorded against this sub-brief.

Sources and claims (10)
  1. ConfirmedEUR-LexThe PPC has made greater use of non-coercive powers of guidance and advice than of coercive powers such as binding orders under Article 148 of the APPI.
  2. ConfirmedIAPPViolating a binding PPC order carries imprisonment with labour of up to one year or a fine of up to JPY 1,000,000 for individuals, and a fine of up to JPY 100 million for corporate entities.
  3. ConfirmedIAPPSubmitting a false report to the PPC carries a fine of up to JPY 500,000.
  4. ConfirmedOneTrust DataGuidanceThe PPC does not have the power to impose administrative monetary fines directly, unlike GDPR supervisory authorities; sanctions for APPI violations are criminal and imposed by courts.
  5. ConfirmedEUR-LexBetween 1 April 2019 and 30 September 2020, the PPC reported issuing five recommendations and two binding orders, with no business operator sanctioned by fine or imprisonment for violating a binding order in that period.
  6. ConfirmedEUR-LexThe 2021 APPI amendment expanded the PPC's enforcement powers and led to an increase in its resources.
  7. ProbableIAPPThe PPC is considering establishing a new system of injunctive relief and restoration of damages operated by qualified organisations, as part of its four-pronged enforcement-strengthening review.
  8. ConfirmedEUR-LexCivil Code Article 709 provides the main general ground for civil litigation for damages arising from privacy or data-protection infringements in Japan.
  9. ConfirmedPPCOn 9 January 2026, the PPC decided its System Reform Policy under the triennial review of the Act on the Protection of Personal Information.
  10. ProbableIAPPJapan's Cabinet approved a bill to amend the Act on the Protection of Personal Information on 7 April 2026 and submitted it to the Diet, where it was expected to be enacted during that session.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Japan
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 70 claim(s), 24 source(s) in the cumulative register.