Last updated · 10 categories · 70
claims · 24 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
70Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Lead Signal
Japan's APPI amendment bill has passed a decisive milestone this cycle. The bill, approved by Cabinet on 7 April 2026, is understood to have passed both houses of the Diet on 10 July 2026 and been promulgated on 17 July 2026. That sequence moves the reform from proposed status to enacted law that is not yet in force, correcting an earlier reading of the bill as still pending before the Diet. Entry into force is expected by cabinet order within two years of promulgation, meaning the changes could take effect as late as 2028. Among the provisions queued for that later effective date, the amendment extends APPI's extraterritorial reach to foreign operators that receive Japan-based data subjects' personal information even indirectly, and gives the PPC new powers to compel reports from and issue orders against overseas companies. The same bill is understood to create a 'Specific Biometric Personal Information' category for facial-recognition data, carrying a notice duty and an unconditional right for individuals to demand that its use be suspended.
Other Developments
Elsewhere in Japan's data-protection architecture, the picture this cycle is one of stability rather than acceleration. The Personal Information Protection Commission continues to rely more on non-coercive guidance and advice than on binding orders, and the APPI still gives it no power to impose administrative fines directly — sanctions for violations remain criminal penalties imposed by courts. The EU-Japan mutual adequacy arrangement, the first two-way adequacy finding of its kind, remains in force, with the European Commission's 2023 review having reconfirmed Japan's adequacy status and extended the review cycle from two years to four. Children's-data protections remain at the proposal stage: Japan's APPI still contains no statutory definition of a child, no parental-consent mechanism and no minor-profiling ban, though a reform under PPC consideration would formally define those under 16 as children and add a best-interests safety standard. Reports also suggest sectoral coverage gaps persist: no dedicated telecoms/ePrivacy-style cookie statute, education-sector statute or insurance-sector statute appears to have been identified, leaving those areas governed only by the general APPI regime.
Cross-Monitor Connections
Two threads this cycle intersect with adjacent monitors rather than sitting solely within data protection. Japan's Act on Promotion of Research and Development, and Utilization of AI-related Technology, in force since September 2025, together with the non-binding AI Business Operator Guidelines, are AI-governance instruments best tracked in depth on the artificial-intelligence monitor; the data-protection angle retained here is the continued absence of comprehensive APPI provisions on automated decision-making and profiling. The My Number Act's stricter handling duties for employees' specific personal information, and the Financial Services Agency's sectoral guidelines for financial-industry operators, carry AML/KYC-adjacent significance for the financial-integrity monitor. METI's dedicated credit-card-industry guidelines and the APPI's consent-or-equivalent-protection gate for cross-border transfers are relevant to payments-specific data flows tracked on the world-payments monitor.
Outlook
The near-term marker to watch is not a compliance deadline but a commencement date: the amended APPI's extraterritorial-scope, PPC-compulsion and biometric-category provisions take effect only once a cabinet order is issued, which the enacted text allows to occur any time up to mid-2028. The European Commission's next periodic review of the Japan adequacy arrangement is expected around 2027, testing whether the mutual finding endures through this period of domestic reform. Several reform elements, including an under-16 statutory child-age threshold, a best-interests safety standard, a collective-redress mechanism, and restrictions on opt-out-scheme abuse, were described in PPC interim materials, but whether they survive unchanged in the Diet-passed text has not yet been independently confirmed.
trust tier: ai_unverified
Regulatory Status
Japan's Personal Information Protection Commission is the independent supervisory authority for the Act on the Protection of Personal Information, holding exclusive oversight of both private-sector operators and public-sector bodies since 1 April 2022. Japan's data-protection architecture is structurally distinct from the GDPR: there is no enumerated Article 6-style lawful basis, no mandatory DPIA, no DPO requirement, and the PPC cannot impose administrative fines directly — sanctions remain criminal penalties imposed by courts. Cross-border transfers rely on a stable foundation: the EU-Japan mutual adequacy arrangement — the world's first two-way adequacy finding — remains in force, reconfirmed by the European Commission's 2023 review, which also extended the review cycle to four years. The amendment bill approved by Cabinet on 7 April 2026 has now passed the Diet (10 July 2026) and been promulgated (17 July 2026), moving to enacted-not-yet-effective status, with entry into force expected by cabinet order within two years of promulgation.
Outlook
Japan's risk trajectory is tightening: the enacted-but-not-yet-effective reform, once in force by cabinet order no later than 2028, will extend extraterritorial reach, add PPC compulsion powers over overseas operators, and create the APPI's first biometric-data category, while children's-data protections and the administrative-fine question remain the two open threads to watch.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
A mature, PPC-enforced omnibus statute is in force with EU/UK mutual adequacy recognition; amber-adjacent risk stems only from the pending 2026 reform bill not yet enacted.
Primary frameworkAct on the Protection of Personal Information (APPI), Act No. 57 of 2003, as amended
Traffic-light rationale — GreenA mature, PPC-enforced omnibus statute is in force with EU/UK mutual adequacy recognition; amber-adjacent risk stems only from the pending 2026 reform bill not yet enacted.
Sub-modules (5)
Regulator And AuthorityGreen
The PPC is Japan's independent data protection authority with exclusive oversight of both private- and public-sector personal information handling since the 2021 amendment.
Claims: CLM-JP-a1b2c301, CLM-JP-a1b2c302
Act And InstrumentsGreen
The APPI is complemented by its Cabinet Enforcement Order, PPC Enforcement Rules, PPC Guidelines/Q&As, and EU/UK-specific Supplementary Rules.
Claims: CLM-JP-a1b2c303
Material ScopeGreen
The APPI applies to 'personal information handling business operators' (PIHBOs) processing personal information databases in the course of business, covering personal information, retained personal data, pseudonymised information and anonymously processed information.
Claims: CLM-JP-a1b2c304
Territorial ScopeAmber
Current law already applies extraterritorially to foreign operators acquiring data of Japan-based individuals in connection with supplying goods/services; the pending amendment would broaden this to indirectly-acquired data and add enforcement powers over overseas entities.
Claims: CLM-JP-a1b2c305, CLM-JP-a1b2c306
Regulator Registration And FilingAmber
There is no general controller registration regime; the principal filing obligation is notification to the PPC when relying on the opt-out mechanism for third-party data provision.
Claims: CLM-JP-a1b2c307
Category narrative106 words
Japan operates a comprehensive omnibus data protection regime centred on the Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, as substantially amended in 2015, 2020 and 2021), overseen exclusively by the Personal Information Protection Commission (PPC), an independent supervisory authority. The 2021 amendment harmonised previously separate public- and private-sector regimes under the PPC's exclusive supervision. The APPI applies extraterritorially to foreign operators supplying goods/services to persons in Japan, and a pending 2026 amendment bill (Cabinet-approved 7 April 2026, before the Diet) would further extend extraterritorial reach and give the PPC new powers to compel reports and issue orders to overseas companies.
No periodic updates recorded against this sub-brief.
Sources and claims (7)
ConfirmedPPC — The Personal Information Protection Commission (PPC) is Japan's independent supervisory authority responsible for oversight and enforcement of the APPI.
ConfirmedEUR-Lex — Following the 2021 APPI amendment, the PPC has exclusive supervisory authority over both private-sector business operators and public-sector Administrative Organs and Incorporated Administrative Agencies.
ConfirmedEUR-Lex — The APPI regime is composed of the Act itself plus a Cabinet Enforcement Order, PPC Enforcement Rules, and PPC Guidelines/Q&As that provide authoritative interpretation of the statute.
ConfirmedOneTrust DataGuidance — The APPI applies to personal information handling business operators (PIHBOs) — persons providing a personal information database for use in business — covering personal information, retained personal data, pseudonymised information and anonymously processed information.
ConfirmedIAPP — The APPI already applies extraterritorially to foreign business operators that acquire personal information directly from data subjects in relation to supplying goods or services to persons in Japan and handle that information abroad.
ProbableIAPP — The pending APPI amendment bill would expand extraterritorial application to foreign operators that handle personal information of Japan-based data subjects even where acquired indirectly, and would empower the PPC to compel reports from and issue orders to overseas companies.
ConfirmedIAPP — There is no general controller registration regime under the APPI; the main filing duty is notifying the PPC when a business relies on the opt-out scheme to provide personal data to third parties without consent.
Core consent/sensitive-data rules are settled and in force, but the absence of a GDPR Art 6-style lawful-basis architecture and the unresolved biometric/AI carve-outs create interpretive gaps pending the 2026 reform.
Primary frameworkAct on the Protection of Personal Information (APPI)
Traffic-light rationale — AmberCore consent/sensitive-data rules are settled and in force, but the absence of a GDPR Art 6-style lawful-basis architecture and the unresolved biometric/AI carve-outs create interpretive gaps pending the 2026 reform.
Sub-modules (4)
Lawful BasesAmber
The APPI does not adopt a GDPR-style enumerated lawful-basis regime; lawfulness instead flows from purpose specification, notice, and targeted consent triggers.
Claims: CLM-JP-b2c3d401
Consent ThresholdsGreen
Consent is required for provision of personal data to third parties (subject to opt-out and joint-use exceptions) and for cross-border transfers absent an equivalent-system safeguard.
Claims: CLM-JP-b2c3d402
Special CategoriesAmber
'Special care-required personal information' requires data-subject consent for collection; biometric data is not yet a defined sensitive category but reform is proposed.
The 2020 amendment created a 'pseudonymised information' category (internal-use only, reduced obligations) alongside the pre-existing 'anonymously processed information' concept.
Claims: CLM-JP-b2c3d406
Category narrative108 words
Unlike the GDPR, the APPI does not require an enumerated lawful basis for all processing; instead it relies on purpose specification/notification duties plus consent requirements triggered at specific junctures (sensitive-data collection, purpose-exceeding use, third-party provision, cross-border transfer). 'Special care-required personal information' (race, medical history, criminal record, etc.) requires consent to collect. Biometric data is not currently a distinct sensitive category, but the ongoing triennial review and pending bill would introduce a new 'Specific Biometric Personal Information' category with notice and suspension rights. The 2020 amendment introduced 'pseudonymised information' as a reduced-obligation category for internal statistical use, and a further amendment proposes a consent exemption for statistical processing/AI development.
No periodic updates recorded against this sub-brief.
Sources and claims (6)
ConfirmedIAPP — Unlike the GDPR, the APPI does not require a legal basis for all processing of personal information, relying instead on purpose specification and consent only at specific junctures.
ConfirmedIAPP — Operators handling personal information are in principle required to obtain data subjects' prior consent before providing personal data to third parties, subject to opt-out and joint-use exceptions.
ConfirmedIAPP — The current APPI generally requires data subjects' consent for the collection of special care-required (sensitive) personal information such as race and medical history.
ConfirmedIAPP — Biometric data is not currently categorised as sensitive personal information under Japanese law, and no dedicated biometric-handling rules yet exist.
ProbableIAPP — The pending APPI amendment bill would introduce a 'Specific Biometric Personal Information' category (facial recognition data) requiring notice to data subjects and granting an unconditional right to demand suspension of use.
ConfirmedIAPP — The 2020 APPI amendment introduced 'pseudonymised information,' a category limited to internal statistical use, exempting operators from certain obligations such as responding to disclosure or cessation-of-use demands for retained personal data.
Core access/rectification/erasure/objection rights are codified and were substantially strengthened by the 2020/2022 amendments; residual amber factor is the absence of a fixed response-time statute and of an explicit portability right.
Primary frameworkAct on the Protection of Personal Information (APPI)
Traffic-light rationale — GreenCore access/rectification/erasure/objection rights are codified and were substantially strengthened by the 2020/2022 amendments; residual amber factor is the absence of a fixed response-time statute and of an explicit portability right.
Sub-modules (5)
Access RightGreen
Data subjects may demand disclosure of retained personal data; businesses must respond without delay, subject to limited harm-based exceptions.
Claims: CLM-JP-c3d4e501, CLM-JP-c3d4e502
Rectification And ErasureGreen
Rights to correction, addition or deletion of retained personal data exist; erasure/cessation-of-use rights were expanded by the 2020/2022 amendment beyond the original narrow trigger conditions.
Claims: CLM-JP-c3d4e503, CLM-JP-c3d4e504
Restriction And ObjectionGreen
Cessation of use/third-party provision functions as the APPI's restriction/objection mechanism, now exercisable wherever rights or legitimate interests are likely to be infringed.
Claims: CLM-JP-c3d4e504
Data PortabilityAmber
No explicit portability right analogous to GDPR Art 20 exists; the amendment's electronic-disclosure entitlement is the closest functional equivalent.
Claims: CLM-JP-c3d4e505, CLM-JP-c3d4e506
Deadlines And Response WindowsAmber
The APPI imposes a 'without delay' response standard for disclosure requests rather than a fixed statutory number of days.
Claims: CLM-JP-c3d4e502
Category narrative83 words
Data subjects hold rights to demand disclosure, correction/addition/deletion, and cessation of use or third-party provision of 'retained personal data.' The 2020/2022 amendments broadened these rights (removing the prior six-month retention carve-out, allowing exercise wherever rights/interests are 'likely to be infringed,' and permitting electronic-format disclosure demands). There is no dedicated GDPR Art 20-style portability right, though electronic disclosure functions similarly. Response timing is governed by a 'without delay' standard rather than a fixed statutory clock (contrast with the fixed breach-reporting deadlines under controller duties).
No periodic updates recorded against this sub-brief.
Sources and claims (6)
ConfirmedPPC — Data subjects have the right to demand disclosure of retained personal data held by a business operator.
ConfirmedPPC — A business operator must disclose retained personal data to a data subject without delay, subject to statutory exceptions such as risk of harm to life or improper interference with business operations.
ConfirmedIAPP — Data subjects may demand correction, addition or deletion of the content of retained personal data.
ConfirmedIAPP — The 2020/2022 amendment expanded data subjects' rights to demand cessation of use, deletion, or cessation of third-party provision of retained personal data to cases where a data subject's rights or legitimate interests are likely to be infringed, beyond the prior narrow grounds of purpose-violation, improper collection, or unlawful third-party provision.
ConfirmedIAPP — The 2020/2022 amendment allows data subjects to require that their retained personal data be disclosed to them electronically, whereas the prior law did not expressly permit electronic-format disclosure demands.
ProbableIAPP — The APPI does not contain a distinct data-portability right equivalent to GDPR Article 20; electronic disclosure of retained personal data is the closest functional analogue.
Breach-notification and security-measure duties are robust and in force, but the absence of DPO, formal DPIA, and general ROPA requirements — core GDPR-analogue accountability tools — represents a structural gap relative to omnibus peers.
Primary frameworkAct on the Protection of Personal Information (APPI)
Traffic-light rationale — AmberBreach-notification and security-measure duties are robust and in force, but the absence of DPO, formal DPIA, and general ROPA requirements — core GDPR-analogue accountability tools — represents a structural gap relative to omnibus peers.
Sub-modules (7)
Accountability And DpiaRed
No mandatory DPIA-equivalent process is codified in the APPI; accountability is achieved via security-control-measures and purpose-limitation duties.
Claims: CLM-JP-d4e5f601
Dpo RequirementsRed
The APPI does not include a requirement to appoint a Data Protection Officer.
Claims: CLM-JP-d4e5f602
Ropa RequirementsAmber
No general Art 30-style records-of-processing duty exists; record-keeping obligations are narrower, attaching to third-party data-provision transactions with 3-year retention.
Claims: CLM-JP-d4e5f603
Joint Controller ArrangementsGreen
The APPI's 'joint use' mechanism functions as its joint-controllership analogue, requiring disclosure of the managing entity's identity and contact details.
Claims: CLM-JP-d4e5f604
Security MeasuresGreen
Operators must implement organisational, personnel, physical and technical security-control measures, including 'understanding of the external environment' when data is processed abroad.
Claims: CLM-JP-d4e5f605
Breach NotificationGreen
Mandatory two-stage breach reporting to the PPC (preliminary + final) and subject notification apply to defined categories of data breach.
Claims: CLM-JP-d4e5f606, CLM-JP-d4e5f607
Retention And DisposalAmber
No general statutory retention-period ceiling exists; operators must delete personal data without delay once the purpose of use no longer requires it.
Claims: CLM-JP-d4e5f608
Category narrative89 words
The APPI does not draw a GDPR-style controller/processor distinction, nor does it mandate a DPO or a formal DPIA process; accountability instead flows through security-control-measures obligations, purpose/deletion duties, and (since 2020/2022) mandatory two-stage breach reporting to the PPC plus subject notification for defined high-risk breaches (sensitive data, property-damage risk, cyberattack, or >1,000 affected individuals). Record-keeping obligations attach specifically to third-party data provision (3-year retention) rather than a general Art 30-style ROPA. 'Joint use' arrangements function as the closest analogue to joint controllership, requiring disclosure of the responsible party's details.
No periodic updates recorded against this sub-brief.
Sources and claims (8)
ConfirmedOneTrust DataGuidance — The APPI does not impose a mandatory Data Protection Impact Assessment process equivalent to GDPR Article 35.
ConfirmedOneTrust DataGuidance — The APPI does not include a requirement to appoint a Data Protection Officer.
ConfirmedIAPP — The amended Cabinet Order and Enforcement Rules impose record-keeping obligations on providers of personal data to third parties, covering confirmation of consent, date of provision, recipient details and data categories, generally retained for three years.
ConfirmedIAPP — Where a business relies on a 'joint use' mechanism to share personal data with others, the APPI requires disclosure of the address of the business managing the jointly used data and the name of its representative.
ConfirmedIAPP — Businesses must implement organisational, personnel, physical and technical security-control measures over personal data, and the amended guidelines additionally require 'understanding of the external environment' when personal data is processed in a foreign country.
ConfirmedIAPP — The amended APPI implements a legal obligation to report to the PPC and notify affected data subjects when a data breach (leakage, loss or damage) occurs or is likely to have occurred, replacing the prior mere 'duty to make an effort.'
ConfirmedIAPP — Breach reporting follows a two-stage process: a preliminary report filed promptly (generally within three to five days for corporations) after recognition of a potential breach, and a final report within 30 days (60 days for cyberattack-related breaches).
ConfirmedOneTrust DataGuidance — Business operators must delete personal data without delay once its utilisation is no longer necessary for the specified purpose, though the APPI does not fix a general maximum retention period.
A functioning, reviewed mutual adequacy arrangement with the EU/UK and codified transfer mechanisms place this module on solid footing; amber-adjacent nuance is the still-evolving TIA/monitoring guidance under the pending 2026 reform.
Primary frameworkAct on the Protection of Personal Information (APPI); EU-Japan Mutual Adequacy Framework
Traffic-light rationale — GreenA functioning, reviewed mutual adequacy arrangement with the EU/UK and codified transfer mechanisms place this module on solid footing; amber-adjacent nuance is the still-evolving TIA/monitoring guidance under the pending 2026 reform.
Sub-modules (6)
Transfer MechanismsGreen
Transfers rely on data-subject consent or an established equivalent protection system at the recipient, each carrying distinct information-provision duties.
Claims: CLM-JP-e5f6a701
Adequacy ReceivedGreen
Japan does not 'receive' adequacy in the GDPR sense as a third country importer of an EU decision toward itself in reverse; rather it operates the mutual EU-Japan adequacy arrangement (see adequacy_granted).
Claims: CLM-JP-e5f6a702
Adequacy GrantedGreen
The European Commission's 2019 Implementing Decision recognises Japan as ensuring an adequate level of protection for EU-origin personal data transferred to APPI-regulated operators; this was reconfirmed in the Commission's 2023 first periodic review.
Claims: CLM-JP-e5f6a703, CLM-JP-e5f6a704
Sccs And BcrsGreen
The APPI's 'established protection system' mechanism functions as its SCC/BCR-equivalent, supplemented by binding PPC Supplementary Rules for EU- and UK-origin data.
Claims: CLM-JP-e5f6a705
Transfer Impact AssessmentAmber
Operators relying on the established-system transfer mechanism must regularly monitor (at least annually) the continued adequacy of the recipient's protections and explain monitoring frequency/method to data subjects on request.
Claims: CLM-JP-e5f6a706
Data LocalisationGreen
No general data-localisation mandate applies to ordinary personal information under the APPI.
Claims: CLM-JP-e5f6a707
Category narrative104 words
Cross-border transfers require either data-subject consent or reliance on an 'established personal information protection system' at the recipient (broadly SCC-equivalent contractual/organisational measures), with annual monitoring of the importer's system. Japan holds the world's first mutual (two-way) adequacy arrangement with the EU (in force since 23 January 2019, extended in scope to the UK), reinforced by binding PPC Supplementary Rules imposing GDPR-aligned safeguards on EU-origin data. The European Commission's first periodic review (2023) reconfirmed adequacy and moved the review cycle from two to four years. No general data-localisation mandate applies to ordinary personal information, though sector-specific instruments (e.g., My Number Act) impose stricter domestic-handling requirements.
No periodic updates recorded against this sub-brief.
Sources and claims (7)
ConfirmedIAPP — A cross-border transfer of personal data from Japan can be permitted based on either the data subject's consent or the establishment of an equivalent personal information protection system at the recipient.
ConfirmedEUR-Lex — The EU-Japan arrangement adopted in January 2019 was the first-ever mutual (two-way) adequacy finding, with the PPC recognising the EU as a jurisdiction with an equivalent data-protection system alongside the Commission's reciprocal finding.
ConfirmedEUR-Lex — The European Commission's Implementing Decision (EU) 2019/419 found that Japan ensures an adequate level of protection for personal data transferred from the EU to APPI-regulated business operators.
ConfirmedEUR-Lex — The European Commission's first periodic review, concluded in 2023, found that Japan continues to ensure an adequate level of protection for EU-origin personal data and moved the review cycle from two to four years.
ConfirmedPPC — The PPC has adopted binding Supplementary Rules under the APPI for the handling of personal data transferred from the EU and the United Kingdom based on an adequacy decision, enforceable by the PPC and directly by individuals in Japanese courts.
ProbableIAPP — Where a cross-border transfer relies on the recipient's established protection system, the operator must regularly monitor that system (guidelines clarify a frequency of at least once a year) and explain the monitoring frequency and method to data subjects upon request.
ProbableOneTrust DataGuidance — No general data-localisation requirement applies to ordinary personal information handled by APPI-regulated business operators.
Financial-sector and My Number overlays are well-documented and in force; telecoms/ePrivacy, education and insurance sector-specific DP overlays are not clearly codified, producing residual coverage gaps.
Primary frameworkAPPI supplemented by FSA/METI sectoral guidelines and the My Number Act
Traffic-light rationale — AmberFinancial-sector and My Number overlays are well-documented and in force; telecoms/ePrivacy, education and insurance sector-specific DP overlays are not clearly codified, producing residual coverage gaps.
Sub-modules (7)
Financial Sector OverlayGreen
The FSA issues sector-specific personal-information-protection guidelines for financial institutions (excluding credit cards, which fall to METI).
Claims: CLM-JP-f6a7b801
Health Sector OverlayAmber
No dedicated health/medical-sector statute analogous to HIPAA was identified beyond the general special-care-required-information consent rule for medical history.
Claims: CLM-JP-f6a7b802
Telecoms And EprivacyRed
No dedicated telecoms/ePrivacy-style instrument governing cookies or electronic communications was identified as currently in force.
Claims: CLM-JP-f6a7b803
Employment DataAmber
Employers handling employees' My Number-linked 'specific personal information' face stricter obligations than under general APPI duties.
Claims: CLM-JP-f6a7b804
Credit And ScoringGreen
METI has issued dedicated guidelines for personal-information protection in the credit-card industry.
Claims: CLM-JP-f6a7b805
EducationRed
No education-sector-specific data-protection statute was identified; the ongoing children's-data reform references the utility of student learning data as a competing policy consideration.
Claims: CLM-JP-f6a7b806
InsuranceRed
No insurance-sector-specific personal-information statute distinct from FSA financial guidance was identified.
Claims: CLM-JP-f6a7b807
Category narrative63 words
Sector-specific overlays supplement the general APPI framework: the Financial Services Agency (FSA) issues financial-industry personal-information guidelines; METI issues credit-card-industry and genetic-information-industry guidelines; and the My Number Act imposes stricter obligations on 'specific personal information' (national ID numbers) used by employers and financial institutions, independently supervised alongside APPI compliance. No dedicated telecoms/ePrivacy-style cookie statute or education-sector-specific data law was identified as currently in force.
No periodic updates recorded against this sub-brief.
Sources and claims (7)
ConfirmedOneTrust DataGuidance — The Financial Services Agency (FSA) has issued guidelines for personal-information protection in the financial industries, supplementing the general APPI regime for financial-sector operators other than credit-card businesses.
UncertainIAPP — No comprehensive health-sector-specific statute analogous to HIPAA was identified; medical history is treated as special care-required personal information under the general APPI consent rule.
UncertainOneTrust DataGuidance — No dedicated telecoms/ePrivacy-style statute governing cookies or electronic-communications metadata distinct from the general APPI regime was identified as currently in force.
ConfirmedOneTrust DataGuidance — The My Number Act and related guidelines require employers to establish appropriate secure-storage and handling systems for employees' 'specific personal information,' which are generally stricter than an employer's other APPI-based obligations.
ConfirmedOneTrust DataGuidance — The Ministry of Economy, Trade and Industry (METI) has issued dedicated guidelines for personal-information protection in the credit-card industry.
UncertainIAPP — No education-sector-specific data-protection statute was identified; the PPC's ongoing children's-data reform explicitly weighs the usefulness of student education/learning data against protective considerations.
UncertainOneTrust DataGuidance — No insurance-sector-specific personal-information statute distinct from the FSA's general financial-industry guidance was identified.
Opt-out and third-party data-provision rules are codified and enforceable, but dark-patterns, standardised opt-out signals, and clean-room-specific rules are absent, and reform of the opt-out scheme itself remains pending.
Primary frameworkAct on the Protection of Personal Information (APPI)
Traffic-light rationale — AmberOpt-out and third-party data-provision rules are codified and enforceable, but dark-patterns, standardised opt-out signals, and clean-room-specific rules are absent, and reform of the opt-out scheme itself remains pending.
Sub-modules (6)
Cookies And TrackersAmber
Cookie-derived individual-related information triggers third-party-provision consent-confirmation duties only when the recipient is likely to render it identifiable.
Claims: CLM-JP-a7b8c901
Dark PatternsRed
No dedicated dark-patterns prohibition was identified under current Japanese data-protection law.
Claims: CLM-JP-a7b8c902
Opt Out SignalsRed
No standardised, legally-recognised opt-out signal mechanism (e.g., GPC/DAA-equivalent) was identified under the APPI.
Claims: CLM-JP-a7b8c903
Clean Rooms And DcrRed
No clean-room / data-collaboration-room-specific rules were identified as distinct from general third-party-provision and joint-use requirements.
Claims: CLM-JP-a7b8c904
Cross Context AdvertisingAmber
Cross-context data sharing for advertising is governed by the general third-party-provision consent/opt-out framework rather than a CPRA-style 'sale'/'share' taxonomy.
Claims: CLM-JP-a7b8c901
Direct MarketingAmber
Direct marketing via shared personal data is governed by the opt-out scheme (PPC filing plus subject notice/accessibility), which functions as the suppression mechanism; reform would restrict abuse of this scheme.
Claims: CLM-JP-a7b8c905, CLM-JP-a7b8c906
Category narrative94 words
Cookie-derived browsing/behavioural data is regulated indirectly through APPI's 'individual related information' provision rule: a provider must confirm the recipient has obtained consent where the recipient is likely to combine such data into identifiable personal data. The opt-out scheme (PPC filing + subject notice) is the principal mechanism enabling third-party data provision, including for marketing purposes, without individual consent; the pending amendment would tighten this scheme by barring provision of improperly-collected data or data received via another party's opt-out filing. No dedicated dark-patterns prohibition or GPC/DAA-style recognised opt-out signal was identified in current Japanese law.
No periodic updates recorded against this sub-brief.
Sources and claims (6)
ConfirmedIAPP — Where a business provides information about a living individual that is not itself personal information (e.g., website browsing history via cookies), and the recipient is likely to receive it in a form that becomes personal data, the provider must confirm the recipient has obtained the data subject's consent.
UncertainIAPP — No dedicated statutory prohibition on dark patterns in consent or data-collection interfaces was identified under current Japanese data-protection law.
UncertainIAPP — No legally-recognised, standardised browser/device opt-out signal mechanism analogous to the Global Privacy Control was identified under the APPI.
UncertainIAPP — No rules specific to data clean rooms or data-collaboration platforms distinct from general third-party-provision and joint-use requirements were identified.
ConfirmedIAPP — Personal data may be provided to third parties for purposes such as marketing without consent if the operator notifies data subjects of opt-out matters (or makes them easily accessible) and files with the PPC.
ProbableIAPP — The pending amendment would bar use of the opt-out scheme to provide personal data collected by deceit or improper means, or data that was itself received via another party's opt-out scheme, in response to observed abuse for fraud-adjacent list trading.
AI-specific promotional legislation and sectoral biometric/genetic guidance exist, but core ADM/profiling and binding biometric protections remain in the proposal stage, and state-surveillance carve-outs limit PPC coercive reach over public bodies.
Primary frameworkAPPI (general); Act on Promotion of Research and Development, and Utilization of AI-related Technology (AI Promotion Act, 2025)
Traffic-light rationale — AmberAI-specific promotional legislation and sectoral biometric/genetic guidance exist, but core ADM/profiling and binding biometric protections remain in the proposal stage, and state-surveillance carve-outs limit PPC coercive reach over public bodies.
Sub-modules (6)
Profiling RestrictionsRed
No comprehensive profiling-restriction framework currently exists under the APPI; reform is under PPC consideration.
Claims: CLM-JP-b8c9d001, CLM-JP-b8c9d002
Automated Decision Making TransparencyRed
Neither the APPI nor PPC Guidelines contain comprehensive legal provisions on automated decision-making and profiling, per the European Parliament's adequacy-review findings; only limited sectoral rules touch the issue.
Claims: CLM-JP-b8c9d003
Ai Risk AssessmentsAmber
Japan's AI Promotion Act establishes a national AI governance framework, supplemented by non-binding AI Business Operator Guidelines rather than mandatory AI-specific risk assessments.
Claims: CLM-JP-b8c9d004, CLM-JP-b8c9d005
Biometric RegimeAmber
No binding biometric-specific data regime currently exists; a proposed 'Specific Biometric Personal Information' category for facial-recognition data is pending in the 2026 reform bill.
Claims: CLM-JP-b8c9d002
Genetic DataAmber
Genetic data is addressed only via non-binding METI sectoral guidance; the PPC's triennial review is separately considering genomic-data regulation.
Claims: CLM-JP-b8c9d006, CLM-JP-b8c9d007
State Surveillance CarveoutsAmber
The PPC's oversight of Administrative Organs (including law-enforcement and national-security data collection) is limited to non-coercive tools; it cannot issue binding orders or impose fines on those public authorities.
Claims: CLM-JP-b8c9d008
Category narrative114 words
The APPI currently contains no comprehensive automated-decision-making or profiling framework equivalent to GDPR Article 22; the European Parliament has explicitly flagged this gap. Reform is under active PPC consideration as part of the ongoing triennial review, alongside a proposed 'Specific Biometric Personal Information' regime for facial-recognition data. Separately, Japan's AI Promotion Act (enacted May 2025, in force September 2025) establishes a light-touch, innovation-oriented national AI framework, complemented by non-binding AI Business Operator Guidelines. Genetic data is addressed only via non-binding METI sectoral guidance, with genomic-data regulation flagged for further PPC review. Government/national-security data access by public authorities is subject to PPC oversight powers that stop short of binding orders or fines against those authorities.
No periodic updates recorded against this sub-brief.
Sources and claims (8)
ProbableIAPP — The PPC's triennial-review Interim Summary flags continued consideration of profiling regulation as an open policy issue for the APPI reform.
ProbableIAPP — The pending APPI amendment bill would create a 'Specific Biometric Personal Information' category for facial-recognition data, requiring notice/accessibility to data subjects and an unconditional right to demand suspension of use.
ConfirmedEUR-Lex — Neither the APPI nor PPC Guidelines contain comprehensive legal provisions on automated decision-making and profiling; only limited sectoral rules address the matter without an overarching protective framework.
ConfirmedIAPP — Japan enacted the Act on Promotion of Research and Development, and Utilization of AI-related Technology (AI Promotion Act) in May 2025, which came into full effect in September 2025.
ConfirmedIAPP — Japan's AI Business Operator Guidelines consolidate AI-governance principles and best practices but constitute non-binding soft guidance rather than a mandatory AI-specific risk-assessment regime.
ConfirmedOneTrust DataGuidance — METI has issued non-binding sectoral guidelines for the protection of personal information in industries using genetic information of individuals.
ProbableIAPP — The PPC's triennial-review Interim Summary lists regulation of genomic data among issues requiring continued consideration.
ConfirmedEUR-Lex — Although the PPC oversees Administrative Organs' collection and processing of personal information, including law-enforcement and national-security data collection, it has not been empowered to issue binding orders to, or impose fines on, these public authorities; its tools are limited to reporting requests, on-site inspections, guidance, advice and recommendations.
No codified statutory age-of-consent, parental-consent mechanism, minor-profiling ban, or dependent-adults regime currently exists; all children's-data protections are at the proposal stage pending the 2026/2027 reform.
Primary frameworkAct on the Protection of Personal Information (APPI) — children's provisions pending
Traffic-light rationale — RedNo codified statutory age-of-consent, parental-consent mechanism, minor-profiling ban, or dependent-adults regime currently exists; all children's-data protections are at the proposal stage pending the 2026/2027 reform.
Sub-modules (5)
Age VerificationRed
No statutory age-verification requirement exists; the APPI does not currently define a child's age, though PPC Q&A informally references ages 12-15 and under, and reform proposes codifying under-16 as the child threshold.
Claims: CLM-JP-c9d0e101, CLM-JP-c9d0e102
Parental ConsentRed
No statutory parental-consent mechanism analogous to COPPA or GDPR Article 8 currently exists under the APPI.
Claims: CLM-JP-c9d0e101
Minor Profiling BansRed
No minor-specific profiling ban currently exists; reform proposes a best-interests-of-the-child standard for safety-control measures applied to children's data.
Claims: CLM-JP-c9d0e103
Education SettingsRed
No education-setting-specific data-protection statute was identified; the reform discussion balances children's-data protection against the utility of student learning data.
Claims: CLM-JP-c9d0e104
Dependent AdultsRed
No dedicated dependent-adults (elderly/incapacitated) data-protection regime was identified; the closest policy analogue is PPC concern over opt-out-scheme misuse enabling elder-targeted financial fraud.
Claims: CLM-JP-c9d0e105
Category narrative85 words
The APPI currently contains no statutory definition of a 'child' and no explicit children's-data provisions; PPC Q&A guidance informally treats individuals aged roughly 12-15 and under as children depending on context. The PPC's ongoing triennial review proposes to codify children as those under 16, strengthen safety-control-measure obligations with a best-interests standard, and permit more flexible ex-post suspension of use for children's retained personal data. No dedicated education-setting or dependent-adults (elderly/incapacitated) data-protection regime was identified, beyond a general policy concern about opt-out-scheme misuse in elder-fraud contexts.
No periodic updates recorded against this sub-brief.
Sources and claims (5)
ConfirmedIAPP — Under current law there are basically no explicit statutory provisions regarding the handling of children's personal information, and the APPI does not define the age of a child; PPC Q&A guidance indicates the applicable age can vary by data type and business nature, generally referencing ages 12-15 and under.
ProbableIAPP — The PPC's triennial-review reform proposes formally defining those under 16 years old as children for APPI purposes.
ProbableIAPP — The reform proposes strengthening safety-control-measure obligations specific to children's personal data, including a requirement that operators prioritise and give special consideration to the best interests of children.
UncertainIAPP — The PPC's reform discussion explicitly weighs the vulnerability and need for protection of children's data against the usefulness of student education and learning data, without proposing a dedicated education-sector statute.
ConfirmedIAPP — No dedicated dependent-adults data-protection regime exists; the PPC has instead flagged demand to regulate malicious personal-information list providers as a countermeasure against criminal groups using elderly individuals' financial information to commit fraud.
Criminal-penalty enforcement architecture and civil tort redress are settled and in force, but the absence of PPC administrative fining power and of a codified collective-redress mechanism — both under active reform — constrain current enforcement intensity.
Primary frameworkAct on the Protection of Personal Information (APPI); Civil Code Article 709 (tort)
Traffic-light rationale — AmberCriminal-penalty enforcement architecture and civil tort redress are settled and in force, but the absence of PPC administrative fining power and of a codified collective-redress mechanism — both under active reform — constrain current enforcement intensity.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
PPC coercive powers include binding orders (Art 148) alongside non-coercive guidance/recommendations; violation of a binding order carries criminal, not administrative, penalties.
Historical PPC enforcement activity (2019-2020 baseline period) shows heavy reliance on non-coercive tools, with only a handful of binding orders and no fines/imprisonment sanctions recorded in that window.
Claims: CLM-JP-d0e1f205
Regulator Funding And CapacityGreen
The 2021 APPI amendment expanded PPC enforcement powers and led to an increase in its resources, per the European Commission's adequacy-review findings.
Claims: CLM-JP-d0e1f206
Collective Redress And Class ActionsRed
No codified collective-redress or class-action mechanism for data-protection claims currently exists; the PPC is actively considering a new injunctive-relief and damages-restoration system operated by qualified organisations.
Claims: CLM-JP-d0e1f207
Private Right Of ActionGreen
Individuals may pursue civil damages for data-protection violations via the general tort provision in Civil Code Article 709.
Claims: CLM-JP-d0e1f208
Recent Developments 180DAmber
Within the last 180 days, the PPC finalised its triennial System Reform Policy (January 2026) and the Cabinet approved an APPI amendment bill (April 2026) now before the Diet, alongside new cross-border cooperation MOUs.
Claims: CLM-JP-d0e1f209, CLM-JP-d0e1f210
Category narrative129 words
PPC enforcement currently relies predominantly on non-coercive tools (guidance, advice, recommendations) with binding orders and criminal sanctions rare; the PPC itself cannot impose administrative monetary fines — sanctions for violating a binding PPC order are criminal (up to one year's imprisonment or a JPY 1,000,000 fine for individuals; up to JPY 100 million for corporate entities), enforced by courts. An administrative fine system and new collective-redress/injunctive-relief mechanisms are under active PPC consideration as part of the ongoing triennial review. Private redress is available generally through Civil Code Article 709 tort claims. Recent 180-day developments include the PPC's January 2026 System Reform Policy decision and the Cabinet's April 2026 approval of an APPI amendment bill now before the Diet, alongside a series of 2025-2026 international cooperation MOUs (Canada, Philippines, Singapore).
No periodic updates recorded against this sub-brief.
Sources and claims (10)
ConfirmedEUR-Lex — The PPC has made greater use of non-coercive powers of guidance and advice than of coercive powers such as binding orders under Article 148 of the APPI.
ConfirmedIAPP — Violating a binding PPC order carries imprisonment with labour of up to one year or a fine of up to JPY 1,000,000 for individuals, and a fine of up to JPY 100 million for corporate entities.
ConfirmedIAPP — Submitting a false report to the PPC carries a fine of up to JPY 500,000.
ConfirmedOneTrust DataGuidance — The PPC does not have the power to impose administrative monetary fines directly, unlike GDPR supervisory authorities; sanctions for APPI violations are criminal and imposed by courts.
ConfirmedEUR-Lex — Between 1 April 2019 and 30 September 2020, the PPC reported issuing five recommendations and two binding orders, with no business operator sanctioned by fine or imprisonment for violating a binding order in that period.
ConfirmedEUR-Lex — The 2021 APPI amendment expanded the PPC's enforcement powers and led to an increase in its resources.
ProbableIAPP — The PPC is considering establishing a new system of injunctive relief and restoration of damages operated by qualified organisations, as part of its four-pronged enforcement-strengthening review.
ConfirmedEUR-Lex — Civil Code Article 709 provides the main general ground for civil litigation for damages arising from privacy or data-protection infringements in Japan.
ConfirmedPPC — On 9 January 2026, the PPC decided its System Reform Policy under the triennial review of the Act on the Protection of Personal Information.
ProbableIAPP — Japan's Cabinet approved a bill to amend the Act on the Protection of Personal Information on 7 April 2026 and submitted it to the Diet, where it was expected to be enacted during that session.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Japan
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 70 claim(s), 24 source(s) in the cumulative register.