No statutory DPO, ROPA, or DPIA requirement under APPI
Japan's Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, as amended) does not impose a mandatory data protection officer (DPO) designation requirement, nor does it require organizations to maintain a formal record of processing activities (ROPA) or conduct data protection impact assessments (DPIAs) in the manner prescribed by the EU General Data Protection Regulation (GDPR). This marks a fundamental structural difference from EU-style data protection law.
No statutory DPO mandate. The APPI contains no provision equivalent to GDPR Article 37 that mandates the appointment of a privacy or data protection officer. A "personal information handling business operator" (the APPI's term for an entity that handles personal information in the course of business, defined in Article 16) is not required by statute to designate a named individual with defined responsibilities for data protection compliance.
The closest the APPI comes to a governance requirement is Article 23, which obligates business operators to "take necessary and proper measures for the prevention of leakage, loss or damage, and for other security control of personal data." Article 23 does not specify what organizational structures satisfy this obligation. The Personal Information Protection Commission (PPC)—Japan's independent supervisory authority established under Article 146—issues non-binding guidelines that recommend, as an organizational security measure, appointing a person responsible for supervising the handling of personal data. However, this is interpretive guidance on how to meet the Article 23 security standard, not a free-standing legal duty. An organization that does not appoint such a supervisor is not in per se violation of the APPI, but may face enforcement exposure under Article 23 if a breach reveals inadequate governance.
No ROPA-style processing inventory. The APPI does not contain an analogue to GDPR Article 30, which requires controllers and processors to maintain comprehensive written records describing their processing activities, including data categories, purposes, recipients, retention periods, and technical safeguards. Japanese business operators are not required to prepare or update a general inventory of personal data processing operations for supervisory review.
The APPI does impose narrower, context-specific recordkeeping obligations. Article 29 requires business operators to create and retain records when providing personal data to a third party. Article 30 requires parallel records when receiving personal data from a third party (with confirmation of the source and the lawfulness of the third party's acquisition). Both record obligations apply when the provision or receipt does not fall within the consent or statutory exceptions listed in Article 23. These records must be maintained "for a period of time prescribed by rules of the Personal Information Protection Commission" (Article 29(2) and Article 30(4)), but they document third-party transactions, not the full lifecycle of processing activity.
The APPI does not mandate a master register of processing purposes, data flows, retention schedules, or security measures in the manner of a GDPR ROPA.
No statutory DPIA trigger. The APPI does not require business operators to conduct a data protection impact assessment before undertaking processing that is "likely to result in a high risk to the rights and freedoms of natural persons," as GDPR Article 35 does. There is no obligation to document or consult the PPC about high-risk processing, even when handling "personal information requiring special care" (sensitive personal information defined in Article 2(3) to include race, creed, social status, medical history, criminal record, and other categories at risk of discriminatory use).
Sectoral regulations outside the APPI may impose analogous requirements. For example, the Telecommunications Business Act requires certain designated telecommunications carriers to appoint an information protection officer and conduct annual compliance reviews, but these obligations derive from sectoral statute, not the APPI itself.
Recordkeeping obligations under Articles 29 and 30. The third-party provision records required by Article 29 must include the date of provision, the categories or items of personal data provided, and the name or designation of the third-party recipient. The receipt records required by Article 30 must include the date of receipt, the third party's name, confirmation that the third party obtained the data lawfully, and the categories or items of data received. These records serve a traceability function—enabling the PPC to audit data flows in the event of a breach or investigation—but they do not replicate the holistic accountability framework of a ROPA.
Supervisory authority. The Personal Information Protection Commission, established by Chapter VII of the APPI, has authority to issue guidelines (Article 145), conduct on-site inspections (Article 147), demand reports (Article 146), issue recommendations and orders to business operators (Article 147), and, following the 2020 amendments, levy administrative fines for serious violations (Article 148). The PPC's enforcement practice emphasizes breach remediation, purpose-of-use compliance, and cross-border transfer safeguards. It does not systematically audit for the presence of a DPO or ROPA in the manner of certain EU supervisory authorities.
Practical note for cross-border operations. Organizations with EU establishments, EU data subjects, or business partners requiring GDPR-level accountability often voluntarily implement DPO designation, ROPA documentation, and DPIA protocols to satisfy GDPR extraterritorial obligations or contractual commitments, even when handling Japanese personal data under the APPI. The EU-Japan mutual adequacy framework (effective January 2019) facilitates these transfers but does not impose GDPR governance requirements on purely domestic Japanese processing.
Article 29 third-party provision records — content, retention, and access rights
Japan's Act on the Protection of Personal Information (APPI) imposes a recordkeeping obligation on business operators when they provide personal data to third parties, serving a traceability and audit function distinct from a comprehensive record of processing activities. Article 29 of the APPI, as amended in 2020 and effective April 1, 2022, requires the creation and retention of records documenting the date, recipient, and content of third-party data transfers that do not fall within the consent or statutory exceptions listed in Articles 23(1) and 23(5).
Article 29(1) triggering events. A "personal information handling business operator" (defined in Article 16 as an entity that handles a personal information database in the course of business) must prepare a record when it provides personal data to a third party. The record obligation applies unless the provision falls under one of the Article 23(1) exceptions (consent obtained, necessary based on laws and regulations, necessary for the protection of life/body/property and consent is difficult, necessary for cooperation with a state or local government organ, or necessary for public health or child development and consent is difficult) or the Article 23(5) exceptions (provision to a joint user with prior notice, provision in connection with business succession, or provision to an entrusted party for the purpose of achieving the purpose of use). When any of these exceptions applies, no Article 29 record is required.
Provision to a third party is defined by exclusion. Under Article 27(5), the following recipients do not constitute a "third party" and therefore do not trigger the Article 29 recordkeeping duty: (i) a party to whom the business operator entrusts the handling of personal data in whole or in part to the extent necessary to achieve the purpose of use; (ii) a party who acquires personal data as a result of business succession due to merger or other reasons; or (iii) a party who will jointly use personal data with the providing business operator, where the business operator has notified the principal in advance of the items of personal data to be jointly used, the scope of joint users, the purpose of use by the joint users, and the name of the party responsible for management of the personal data.
Required record contents. Article 29(1) specifies that the record must include (i) the date of provision, (ii) the name or other information identifying the third-party recipient, and (iii) "other matters prescribed by Order of the Personal Information Protection Commission." The Personal Information Protection Commission's Enforcement Rules (Rules of the Personal Information Protection Commission No. 3, 2016, as amended) expand the required contents at Article 12 to include the items or categories of personal data provided. The record does not need to include the purpose of the provision or the lawful basis, only the transactional facts of what, when, and to whom.
Retention period. Article 29(2) requires the business operator to "maintain a record under the preceding paragraph for a period of time prescribed by rules of the Personal Information Protection Commission from the date when it prepared the record." Article 14 of the PPC Enforcement Rules prescribes a three-year retention period as the general rule, measured from the last date on which personal data relating to the record was provided. Two narrower retention periods apply to specific recordkeeping methods: (i) if the record is kept using the method prescribed in Article 12(3) of the Enforcement Rules (an automated recording method integrated into the data-transfer system that captures provision details in real time), the retention period is one year from the last date of provision relating to the record; (ii) if the record is kept using the simplified method described in the proviso to Article 12(2) (a ledger format in which multiple provisions to the same recipient are aggregated under periodic entries rather than recorded transaction by transaction), the retention period is three years from the last date of provision relating to the record. In practice, the three-year period is the compliance baseline for most business operators not using advanced automated recording systems.
Data subject access rights. Data subjects have a statutory right to request disclosure of the third-party provision records that relate to them. Article 33(1) of the APPI grants the principal (the individual to whom the personal data pertains) the right to demand that a business operator disclose "the fact of provision to a third party" and related records concerning retained personal data. The Article 33(5) cross-reference confirms that the disclosure rights in Articles 33(1)–(3) apply mutatis mutandis to Article 29 records. The business operator must respond to a disclosure demand "without delay" under Article 33(2), and may charge a fee that does not exceed the actual cost of providing the disclosure, as prescribed in Article 33(4) and notified to the principal under Article 32(1)(iii). Refusal is permitted only if disclosure would harm the life, body, property, or other rights and interests of the principal or a third party; would significantly impede the proper execution of the business operator's operations; or would violate other laws and regulations (Article 33(2), items (i)–(iii)).
Supervisory enforcement. The Personal Information Protection Commission, Japan's independent supervisory authority established under Article 145 of the APPI, may demand reports (Article 146), conduct on-site inspections (Article 147), and issue recommendations and orders to business operators (Articles 147–148). The PPC's enforcement practice routinely audits third-party provision records during breach investigations and cross-border transfer assessments to verify compliance with the Article 27 consent requirement and the Article 28 cross-border transfer safeguards. Failure to create or retain Article 29 records constitutes a violation of the APPI's security-control and accountability obligations under Article 23, which can result in a recommendation, an order, or, following the 2020 amendments, an administrative fine of up to 100 million yen for a business operator (Article 178) and criminal penalties for officers who fail to comply with a PPC order (up to one year of detention or a fine of up to 1 million yen, Article 176).
Practical context. The Article 29 recordkeeping obligation is the closest APPI analogue to a controller-processor accountability register. It does not, however, replicate the comprehensive lifecycle documentation required by GDPR Article 30 (record of processing activities). Article 29 records are transaction-specific, capturing outbound data flows to third parties, but do not document the categories of processing, retention schedules, technical safeguards, or international transfers. Article 30 imposes a parallel recordkeeping obligation on the recipient of personal data from a third party, requiring confirmation of the source's identity and the lawfulness of the source's acquisition. Together, Articles 29 and 30 create a bilateral traceability framework, but they do not constitute a general processing register. Organizations with EU establishments or contractual GDPR commitments often maintain a GDPR Article 30 ROPA voluntarily to meet extraterritorial obligations, even when handling purely domestic Japanese personal data under the APPI.
Article 30 third-party receipt records — confirmation, content, and retention obligations
Japan's Act on the Protection of Personal Information (APPI) imposes a complementary recordkeeping obligation on business operators when they receive personal data from a third party, creating the inbound half of a bilateral traceability framework. Article 30 of the APPI, as amended in 2020 and effective April 1, 2022, requires the receiving business operator to confirm the source's identity and the lawfulness of the source's acquisition, and to document these confirmations in a record retained for a prescribed period.
Article 30(1) triggering event and confirmation duty. A "personal information handling business operator" (defined in Article 16 as an entity that handles a personal information database in the course of business) must, when receiving personal data from a third party, confirm the matters specified in Article 30(1), items (i) and (ii): (i) the name and address of the third party (if the third party is a corporation, the name of its representative), and (ii) the background of the acquisition of the personal data by the third party. This confirmation obligation does not apply if the receipt falls within one of the Article 27(1) or Article 27(5) exceptions—the same exceptions that govern third-party provision under Article 23. Specifically, the Article 30 confirmation duty is excused when the receipt is based on the principal's consent, is necessary pursuant to laws and regulations, is necessary for the protection of life/body/property where consent is difficult to obtain, is necessary for cooperation with a state or local government organ, is necessary for public health or child development, or falls within the joint-use, business-succession, or processing-subcontract exceptions that exclude the transferring party from "third party" status.
The "background of acquisition" confirmation in Article 30(1)(ii) requires the receiving operator to verify that the third party obtained the data lawfully—in practice, by confirming that the third party's acquisition satisfied the APPI's purpose-of-use notice requirements (Article 18), lawful-acquisition prohibition (Article 20), and consent requirements for sensitive personal information (Article 20). Article 30(2) reinforces this verification duty by prohibiting the third party from deceiving the receiving operator "on a matter relating to the confirmation." This creates a paired obligation: the third party must truthfully disclose how it acquired the data, and the receiving operator must confirm that disclosure before accepting the data.
Required record contents and retention period. Article 30(3) requires the receiving operator to prepare a record of the confirmation conducted under Article 30(1), documenting the fact and substance of the verification. The statute cross-references "rules of the Personal Information Protection Commission" for the specific record contents and format. Article 13 of the PPC Enforcement Rules (Rules of the Personal Information Protection Commission No. 3, 2016, as amended) implements this mandate, requiring the record to include (i) the date of receipt, (ii) the name and address of the third party (and the representative's name if the third party is a corporation), (iii) the background of the third party's acquisition of the personal data, and (iv) the items or categories of personal data received.
Article 13(2) of the Enforcement Rules permits a simplified ledger format when the business operator receives personal data continuously or repeatedly from the same third party, or when it anticipates such continuous or repeated receipt. Rather than creating a new record for each transaction, the operator may maintain a single aggregated record covering multiple receipts, reducing compliance burden for ongoing data-sharing relationships (e.g., B2B data feeds, affiliate-network arrangements, or recurring vendor deliveries).
Article 13(3) of the Enforcement Rules provides a further accommodation: when the receipt occurs "in connection with supplying the principal with goods or services," and the required Article 13(1) record contents are already stated in a contract or other document produced in connection with that supply, the contract or document may substitute for a separate Article 30 receipt record. This exception streamlines compliance for consumer-facing transactions where the commercial documentation already evidences the source and lawfulness of the data flow.
Article 30(4) requires the business operator to retain the Article 30(3) record "for a period of time prescribed by rules of the Personal Information Protection Commission from the date when it kept the record." Article 14 of the PPC Enforcement Rules, which governs retention periods for both Article 29 provision records and Article 30 receipt records, prescribes a three-year retention period as the general rule, measured from the last date on which personal data relating to the record was received. Two shorter periods apply to specific recordkeeping methods mirroring the Article 29 framework: (i) one year from the last date of receipt if the record is kept using an automated recording method integrated into the data-transfer system (Article 12(3) method applied mutatis mutandis), and (ii) three years if using the simplified aggregated-ledger method under Article 13(2). In practice, three years is the compliance baseline for most operators not using advanced automated systems.
Data subject access rights and supervisory enforcement. Data subjects have a statutory right to request disclosure of third-party receipt records that relate to them. Article 33(5) of the APPI applies the general disclosure framework in Articles 33(1)–(3) mutatis mutandis to Article 30(3) receipt records, granting the principal the right to demand disclosure of "the fact of provision to a third party" and related records. The business operator must respond "without delay" under Article 33(2), may charge a fee capped at actual cost under Article 33(4), and may refuse only if disclosure would harm the life, body, property, or other rights of the principal or a third party; would significantly impede the operator's business; or would violate other laws (Article 33(2), items (i)–(iii)).
The Personal Information Protection Commission, Japan's independent supervisory authority established under Article 145 of the APPI, may demand reports (Article 146), conduct on-site inspections (Article 147), and issue recommendations and orders (Articles 147–148). The PPC's enforcement practice routinely audits Article 30 receipt records in parallel with Article 29 provision records during breach investigations, cross-border transfer assessments, and purpose-of-use compliance reviews. Failure to confirm the source and background of acquisition, or to create and retain the required records, constitutes a violation of the APPI's accountability obligations under Article 23 (security control of personal data). Such violations can result in a PPC recommendation or order and, following the 2020 amendments, an administrative fine of up to 100 million yen for a business operator (Article 178) and criminal penalties for officers who fail to comply with a PPC order (up to one year of detention or a fine of up to 1 million yen, Article 176).
Bilateral traceability framework. Article 30 and Article 29 together create a comprehensive audit trail for third-party data flows. Article 29 captures outbound transfers (who the operator provided data to, when, and what categories), while Article 30 captures inbound receipts (who the operator received data from, when, what categories, and the lawfulness of the source's acquisition). This bilateral recordkeeping regime does not, however, replicate the comprehensive lifecycle documentation required by GDPR Article 30 (record of processing activities). The APPI's Articles 29 and 30 are transaction-specific, documenting third-party data movements rather than the full inventory of processing purposes, retention schedules, technical safeguards, and international transfers. Organizations with EU establishments or contractual GDPR commitments often voluntarily maintain a GDPR Article 30 ROPA to satisfy extraterritorial obligations, even when processing purely domestic Japanese personal data under the APPI.
Practical note for cross-border operations. The Article 30 confirmation-of-lawful-acquisition duty is particularly salient in cross-border data-sharing arrangements. When a Japanese business operator receives personal data from a foreign affiliate, vendor, or data broker, Article 30(1)(ii) requires the operator to verify the "background of acquisition"—in effect, to confirm that the foreign transferor obtained the data lawfully under the applicable foreign law (e.g., GDPR consent, CCPA opt-out respect, or LGPD lawful basis) before transferring it to Japan. This due-diligence obligation is separate from, and in addition to, the Article 28 cross-border transfer safeguards that apply when the Japanese operator subsequently transfers the data out of Japan to a third country. The PPC's enforcement practice emphasizes that Article 30 is not satisfied by a boilerplate contractual representation; the receiving operator must conduct reasonable inquiry into the source's acquisition method and document the substance of that inquiry in the Article 30(3) record.
Article 23 security control obligation — PPC Guidelines on organizational measures and recommended privacy-officer designation
Japan's Act on the Protection of Personal Information (APPI) does not mandate the appointment of a data protection officer (DPO) in the manner of GDPR Article 37, but it imposes a comprehensive security control obligation under Article 23 that the Personal Information Protection Commission (PPC) interprets through detailed Guidelines to include organizational governance measures—among them the recommended designation of a person responsible for supervising personal data handling. This interpretive guidance creates a practical governance expectation that resembles a DPO-lite function, even absent a statutory appointment mandate.
Article 23 security control obligation. Article 23 of the APPI requires every "personal information handling business operator" (defined in Article 16 as an entity that handles a personal information database in the course of business) to "take necessary and proper measures for the prevention of leakage, loss or damage, and for other security control of personal data." The statute itself does not prescribe what organizational structures, technical safeguards, or procedural controls satisfy this obligation. The language is deliberately flexible, permitting the PPC to issue interpretive guidelines that evolve with technology and breach patterns.
The Article 23 obligation is subject-neutral—it applies equally to small operators handling a modest customer database and to large-scale platforms processing millions of records. There is no de minimis exception, no employee-count threshold, and no processing-volume trigger. Any entity that maintains a personal information database "for the purpose of facilitating search for specific personal information" (Article 16) must comply with Article 23's security-control mandate.
PPC Guidelines on security control measures. The Personal Information Protection Commission issues Guidelines for the Act on the Protection of Personal Information (General Rules) (Notice of the Personal Information Protection Commission No. 65, as amended) that elaborate the Article 23 obligation into four categories of required or recommended measures: organizational, human, physical, and technical security control. These Guidelines are not binding law in the sense that a business operator cannot be criminally prosecuted for non-compliance with a Guideline provision that goes beyond the statute, but the PPC treats the Guidelines as authoritative interpretations of Article 23's "necessary and proper measures" standard. In enforcement practice, the PPC issues recommendations and orders under Articles 146–148 of the APPI when an operator's breach reveals inadequate security control, and the PPC's assessment of adequacy is benchmarked against the Guidelines.
Organizational security control measures. The PPC Guidelines on organizational measures recommend that business operators:
- Establish a basic policy on the protection of personal data, setting out the organization's commitment to compliance with the APPI, the scope of personal data handled, and the allocation of responsibility for security control.
- Designate a person responsible for supervising the handling of personal data ("personal data supervisor" or similar title—the Guidelines do not mandate the term "DPO" or "Chief Privacy Officer"). This designated supervisor is responsible for developing internal rules, overseeing security measures, handling breach response, and serving as the point of contact for data-subject requests and PPC inquiries. The Guidelines recommend that the supervisor have authority commensurate with the scale and sensitivity of the operator's data processing, but do not prescribe qualifications, independence guarantees, or resource commitments in the manner of GDPR Article 38.
- Define the scope of personal data and handling personnel. The operator should identify which employees, contractors, and business units handle personal data, and should limit access on a need-to-know basis.
- Adopt internal rules governing the acquisition, use, provision, retention, and disposal of personal data, aligned with the purposes of use disclosed under Article 18 and the consent requirements under Articles 23 and 27.
- Implement supervision and audit mechanisms to monitor compliance with internal rules, including periodic self-assessment, logging of access to sensitive personal data, and incident-response protocols.
The PPC's 2018 survey of business operators (cited in the PPC's Every-Three-Year Review report) found that 68.5% of all operators and 86.0% of large-scale operators reported having established a division or designated personnel responsible for supervising company-wide personal information protection. This voluntary adoption rate reflects industry understanding that the Article 23 security-control obligation, as interpreted through the PPC Guidelines, effectively requires some form of governance structure even when the APPI does not use the word "DPO."
Human security control measures. The Guidelines recommend regular training and education for employees who handle personal data, covering the operator's internal rules, the APPI's requirements, and breach-prevention techniques. Training should be tailored to the employee's role—front-line customer-service staff need different instruction than database administrators or data scientists. The operator should document training completion and conduct refresher sessions when internal rules or statutory requirements change.
The Guidelines also recommend that the operator include confidentiality and security obligations in employment contracts, contractor agreements, and business-succession arrangements, and that the operator enforce disciplinary measures when employees violate internal data-protection rules.
Technical and physical security control measures. The PPC Guidelines recommend that operators implement technical safeguards such as access control (authentication, authorization, least-privilege principles), encryption of personal data in transit and at rest, logging and monitoring of access to personal data, protection against unauthorized external access (firewalls, intrusion detection, vulnerability patching), and backup and disaster-recovery procedures.
Physical safeguards should include secure storage of documents and electronic media containing personal data, access restrictions to server rooms and filing cabinets, and procedures to prevent theft, loss, or inadvertent disclosure during transport or disposal of media. The PPC's Privacy Awareness Week campaigns (2024, 2025) emphasize that a significant share of reported breaches in Japan involve human error—wrong delivery of mail, loss of USB drives, misdirected emails—and that physical and procedural controls are as critical as firewalls and encryption.
No statutory DPIA or ROPA requirement, but Guidelines recommend documentation. The APPI does not require a data protection impact assessment (DPIA) before high-risk processing, nor does it mandate a comprehensive record of processing activities (ROPA) in the manner of GDPR Article 30. However, the PPC Guidelines' recommendation that operators "establish a basic policy" and "adopt internal rules" implicitly calls for documentation of processing purposes, data categories, retention periods, and security measures. Operators with EU establishments or contractual GDPR commitments often maintain a GDPR-compliant ROPA and DPIA framework voluntarily to satisfy extraterritorial obligations, and then apply the same documentation discipline to their Japanese processing as a matter of consistent governance.
Enforcement practice and the Article 23 reasonableness standard. The PPC's enforcement approach emphasizes remediation over punishment. When a breach occurs, the PPC conducts an investigation (Articles 146–147) and assesses whether the operator's security measures were "necessary and proper" under Article 23 given the volume, sensitivity, and nature of the personal data at issue. If the PPC concludes that the operator's measures were inadequate, it issues a recommendation under Article 147 directing the operator to take corrective action—appoint a supervisor, revise internal rules, implement access controls, retrain staff, or adopt technical safeguards. If the operator fails to comply with the recommendation, the PPC may issue a legally binding order under Article 147. Non-compliance with a PPC order can result in an administrative fine of up to 100 million yen for the business operator (Article 178, added by the 2020 amendments and effective April 1, 2022) and criminal penalties for officers who obstruct PPC inspections or fail to comply with orders (up to one year of detention or a fine of up to 1 million yen, Article 176).
The PPC's 2025 Privacy Awareness Week materials report that in the first half of fiscal year 2024 (April 1 to September 30, 2024), 7,735 personal data breach cases were directly reported to the PPC, a sharp increase from 4,938 in the same period of 2023. The leading causes included incorrect delivery and loss of documents by hospitals and pharmacies, phishing scams, and incorrect delivery of credit cards. The PPC's public statements emphasize that "to reduce human error-related leaks, it is essential not only to provide education on personal information protection through training but also to establish an organizational framework that prevents leaks from occurring"—language that echoes the Guidelines' recommendation for a designated supervisor and internal rules.
Contrast with GDPR Article 37 DPO mandate. Under GDPR Article 37(1), a controller or processor must designate a DPO when (a) processing is carried out by a public authority, (b) core activities consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, or (c) core activities consist of large-scale processing of special-category or criminal-offense data. The GDPR prescribes the DPO's tasks (Article 39: monitor compliance, advise on DPIAs, serve as contact point for supervisory authorities and data subjects, report directly to highest management), independence guarantees (Article 38: no instructions regarding exercise of tasks, no dismissal or penalty for performing tasks), and qualifications (Article 37(5): professional qualities and expert knowledge of data protection law).
The APPI imposes none of these requirements. Article 23's security-control obligation is outcome-based, not role-based. The PPC Guidelines recommend appointing a supervisor as an organizational measure to achieve the Article 23 security standard, but they do not mandate that the supervisor possess legal qualifications, report to the board, operate independently of business management, or maintain a public contact registry. An operator that does not appoint a supervisor is not in per se violation of the APPI, but if a breach occurs and the PPC investigation reveals that the operator lacked any governance structure to oversee compliance, the PPC may conclude that the operator failed to take "necessary and proper measures" under Article 23 and issue a recommendation or order to establish such a structure.
Practical guidance for cross-border operations. Organizations operating in both Japan and the EU face overlapping but non-identical governance obligations. A GDPR-mandated DPO can serve double duty as the APPI-recommended personal-data supervisor, provided the organization documents the supervisor's responsibilities under Japanese law (Article 23 compliance oversight, breach reporting to the PPC under APPI breach-notification rules, response to data-subject access requests under Article 33) and ensures the supervisor has working knowledge of the APPI, PPC Guidelines, and PPC enforcement practice. The GDPR DPO's independence and reporting-line protections under Article 38 exceed what the APPI requires, so layering GDPR governance onto Japanese operations raises the compliance floor, which the PPC treats as a positive factor in breach assessments.
Conversely, a Japan-only operator that has not designated a supervisor should assess its Article 23 exposure by reference to the PPC's 2018 survey benchmark (68.5% of operators, 86% of large-scale operators, have done so) and the breach statistics (7,735 reported incidents in six months, with human error as the leading cause). The regulatory signal is clear: the PPC expects organizational governance, and the absence of a designated supervisor is a red flag in any post-breach investigation.
Article 25 supervision of entrusted persons — due diligence, contract clauses, and ongoing audit obligations
Japan's Act on the Protection of Personal Information (APPI) imposes a mandatory supervision obligation on business operators when they entrust the handling of personal data to processors, subcontractors, or service providers. Article 25 of the APPI creates the closest Japanese analogue to GDPR controller-processor accountability, requiring the data controller ("personal information handling business operator") to exercise "necessary and appropriate supervision" over the entrusted party to ensure security control of the outsourced personal data. This obligation applies to any entrustment arrangement—cloud hosting, payroll processing, IT support, marketing agencies, call centers, and data analytics vendors—and operates independently of the third-party provision rules in Article 27.
Article 25 statutory text. Article 25 of the APPI provides: "If a business handling personal information entrusts another person with all or part of the handling of personal data, it must exercise the necessary and adequate supervision over the person it entrusts, pursuant to the provisions of Article 25 of the Act, so as to ensure the secure management of the personal data with whose handling it entrusts that person." The statute does not prescribe specific supervision measures, leaving the Personal Information Protection Commission (PPC) to elaborate the standard through Guidelines and enforcement practice.
What constitutes "entrustment." The PPC's sectoral guidelines (Financial Sector Guidelines, Article 10, published on japaneselawtranslation.go.jp) define "entrustment" broadly as "the entirety of contracts, irrespective of the form or type thereof, under which a business handling personal information has another entity carry out the whole or part of the handling of personal data." Entrustment includes not only formal outsourcing agreements but also cloud service subscriptions, software-as-a-service arrangements, affiliate data-sharing agreements where the affiliate acts on the controller's instructions, and any contractual relationship under which the entrusted party processes personal data on behalf of and at the direction of the business operator. The definition is functional, not formal—the critical element is that the entrusted party handles personal data to achieve the business operator's purpose of use, rather than for its own independent business purpose.
Distinction from third-party provision. Article 25 entrustment and Article 27 third-party provision are mutually exclusive categories. Article 27(5)(i) provides that an "entrusted person" (a party to whom the business operator entrusts the handling of personal data in whole or in part to the extent necessary to achieve the purpose of use) does not constitute a "third party" for purposes of the consent requirement in Article 27(1). When a business operator entrusts data processing to a vendor acting solely on the operator's behalf and under the operator's instructions, the transaction is governed by Article 25's supervision obligation, not Article 27's consent requirement. The operator need not obtain data-subject consent before transferring personal data to the entrusted party, but the operator remains fully liable for the entrusted party's data handling and must exercise active supervision. Conversely, when the business operator provides personal data to a recipient that will use the data for its own purposes (e.g., selling a customer list to a marketing broker, or sharing employee data with a co-venturer for the co-venturer's independent HR purposes), the transaction is a third-party provision under Article 27, requiring consent or an Article 27(1) statutory exception, and triggering the Article 29 recordkeeping obligation.
Required supervision measures — PPC Guidelines framework. The PPC's Financial Sector Guidelines (Article 10) and the general-rules Guidelines elaborate Article 25's "necessary and appropriate supervision" standard into three sequential duties: (1) appropriate selection of the entrusted party (due diligence), (2) contractual specification of security measures, and (3) ongoing monitoring and audit of the entrusted party's compliance. The Guidelines emphasize that the level of supervision must correspond to the risk arising from the scale and nature of the entrusted business, the sensitivity of the personal data, and the volume of records, in light of the potential harm to data subjects if the data is leaked, lost, or damaged.
1. Due diligence and appropriate selection. Before entrusting personal data processing to a third party, the business operator must assess whether the prospective entrusted party has the organizational capacity, technical infrastructure, and track record to handle personal data securely. The Financial Sector Guidelines recommend that operators establish written selection criteria covering the entrusted party's organizational structure, basic security policies, internal handling rules, employee training programs, incident-response protocols, and compliance history. The operator should review the prospective vendor's information-security certifications (e.g., ISO/IEC 27001, Privacy Mark), conduct on-site inspections or questionnaire assessments, and confirm that the vendor's security measures align with the operator's own Article 23 security-control obligations. This due-diligence obligation applies at the outset of the entrustment relationship and when the contract is renewed or the scope of processing is expanded.
2. Contractual security requirements. The business operator must incorporate into the entrustment contract binding clauses that obligate the entrusted party to implement security measures equivalent to those the operator itself must maintain under Article 23. The Financial Sector Guidelines recommend that the contract specify: (i) the purpose and scope of the entrusted processing (what categories of personal data, for what business function, under what retention schedule); (ii) a prohibition on the entrusted party using the personal data for any purpose other than the entrusted task; (iii) a prohibition on the entrusted party providing the personal data to a third party without the operator's prior written consent; (iv) organizational, human, physical, and technical security measures the entrusted party must implement (access controls, encryption, logging, employee confidentiality agreements, secure disposal protocols); (v) an obligation to report any personal data breach, unauthorized access, or security incident to the operator immediately; (vi) a right for the operator to audit the entrusted party's security practices, either directly or through a third-party auditor; (vii) cooperation with the operator in responding to data-subject access requests, correction demands, or PPC investigations; and (viii) secure return or destruction of personal data upon termination of the contract.
The PPC's enforcement practice treats the absence of these contractual clauses as evidence that the operator failed to exercise "necessary and appropriate supervision" under Article 25. A contractual boilerplate is not sufficient—the clauses must be tailored to the nature of the entrusted processing and actually enforced through audit and remediation.
3. Ongoing monitoring and audit. The business operator's Article 25 duty does not end when the contract is signed. The operator must conduct periodic monitoring to verify that the entrusted party is complying with the contractual security requirements and applicable APPI obligations. The Financial Sector Guidelines recommend that operators: (i) require the entrusted party to submit periodic compliance reports documenting security incidents, access logs, employee training completion, and any changes to security infrastructure; (ii) conduct periodic on-site inspections or third-party audits of the entrusted party's facilities, information systems, and handling procedures; (iii) review the entrusted party's breach-notification records and incident-response timelines; and (iv) update the entrustment contract and security requirements when the operator's risk assessment changes (e.g., when the entrusted party begins processing sensitive personal information under Article 20, or when the volume of records increases by an order of magnitude).
The frequency and depth of monitoring should be proportionate to the risk. For a vendor processing low-volume, non-sensitive customer-contact data (e.g., a call center handling product inquiries), annual self-certification questionnaires and breach-notification reporting may suffice. For a cloud infrastructure provider hosting millions of medical records, health insurance claims, or financial account data, the operator should conduct quarterly compliance reviews, annual penetration testing, and real-time breach alerts.
Sub-outsourcing (re-entrustment) supervision. When the entrusted party intends to sub-outsource (re-entrust) the handling of personal data to a further entrusted party (e.g., a cloud provider hiring a data-center operator, or a payroll processor engaging a backup-tape storage vendor), the Financial Sector Guidelines state that it is "desirable" that the original business operator confirm that (i) the entrusted party will appropriately supervise the sub-entrusted party in accordance with Article 25, and (ii) the sub-entrusted party will implement the same Article 23 security measures that the first-tier entrusted party must maintain. The Guidelines recommend that the original operator require the entrusted party to obtain the operator's prior written approval before sub-outsourcing, provide advance notice of the sub-entrusted party's identity and the scope of re-entrusted processing, and conduct its own audits of the sub-entrusted party (or permit the operator to audit the sub-entrusted party directly). The same supervision framework applies recursively to further layers of sub-outsourcing.
The PPC's enforcement posture is that the original business operator remains liable under Article 23 for any breach or security failure by the sub-entrusted party, even when the sub-entrustment occurred without the operator's knowledge. The operator's Article 25 supervision duty includes verifying that the entrusted party has a robust sub-vendor management program and contractually prohibiting unauthorized re-entrustment.
Risk-based supervision standard. The Financial Sector Guidelines expressly state that "the supervision is to correspond to risks arising from the scale and nature of the entrusted business, the handling status of personal data and other factors, in consideration of the significance of infringement of rights and interests that may be suffered by the identifiable person in the event of the leaking, etc. of personal data." This risk-based framework permits (and requires) operators to calibrate their supervision intensity to the sensitivity and volume of the outsourced data. Processing sensitive personal information under Article 20 (race, creed, social status, medical history, criminal record) or large-scale databases of financial or health data triggers heightened supervision obligations—more frequent audits, stricter contractual controls, mandatory breach-notification escalation, and technical measures such as encryption-at-rest and role-based access controls. Low-risk entrustment (e.g., outsourcing bulk-mail printing of marketing postcards that contain only name and mailing address) permits lighter-touch supervision, but the operator must document the risk assessment that justifies the reduced oversight.
Enforcement consequences and operator liability. The Personal Information Protection Commission may demand reports (Article 146), conduct on-site inspections (Article 147), and issue recommendations and orders to business operators (Article 147) when a breach investigation reveals that the operator failed to exercise "necessary and appropriate supervision" over an entrusted party under Article 25. The PPC's enforcement practice holds the business operator (not the entrusted party) primarily accountable for breaches caused by the entrusted party's security failures. This vicarious-liability principle reflects the statutory design: Article 25 does not impose direct APPI obligations on the entrusted party (who may not even be a "personal information handling business operator" under Article 16 if it processes data solely on behalf of the principal operator), but instead obligates the principal operator to ensure that the entrusted party adheres to the same security standards the operator itself must meet under Article 23.
Following the 2020 amendments (effective April 1, 2022), the PPC may levy administrative fines of up to 100 million yen on a business operator that fails to comply with a PPC order (Article 178). Criminal penalties (up to one year of detention or a fine of up to 1 million yen, Article 176) apply to officers who obstruct PPC inspections or fail to comply with a PPC order. In practice, the PPC's enforcement approach emphasizes remediation—when a breach occurs due to an entrusted party's security lapse, the PPC issues a recommendation directing the operator to revise its vendor-selection criteria, strengthen contractual security clauses, terminate the non-compliant vendor, enhance audit procedures, and report back to the PPC on corrective measures. Operators that demonstrate robust Article 25 supervision programs—documented due diligence, contractual security requirements, periodic audits, and prompt breach response—typically receive lighter sanctions than operators that had no vendor-oversight process in place.
Practical guidance for cross-border operations and GDPR alignment. Organizations subject to both the APPI and the GDPR face overlapping processor-supervision obligations. GDPR Article 28 requires controllers to use only processors that provide "sufficient guarantees" of GDPR compliance, to execute a written contract specifying the processor's data-protection obligations (Article 28(3)), and to ensure the processor implements "appropriate technical and organisational measures" (Article 32). APPI Article 25 imposes a parallel supervision duty, though the APPI does not mandate the specific contract clauses enumerated in GDPR Article 28(3) (subject-matter, duration, nature and purpose of processing, type of personal data, data-subject rights assistance, deletion or return of data, audit rights). A GDPR-compliant data processing agreement (DPA) that includes the Article 28(3) mandatory clauses will typically satisfy the APPI Article 25 contractual-supervision requirement, provided the DPA also addresses the APPI-specific obligations: purpose-of-use limitation (Article 18), security control (Article 23), breach notification to the operator (so the operator can assess whether Article 26 breach reporting to the PPC is required), and prohibition on unauthorized third-party provision (Article 27).
Controllers operating in both jurisdictions should template their processor contracts to the higher of the two standards (GDPR Article 28(3) is generally more prescriptive), conduct unified vendor due-diligence assessments covering both GDPR Article 32 and APPI Article 23 security measures, and maintain a single vendor-audit schedule that satisfies the ongoing-supervision requirement under both regimes. The PPC has signaled in enforcement guidance that it views GDPR-compliant processor-management programs favorably as evidence of "necessary and appropriate supervision" under Article 25, particularly when the operator can demonstrate documented vendor risk assessments, annual audit reports, and prompt breach-escalation procedures.
No data protection impact assessment (DPIA) mandate under APPI—even for sensitive or high-risk processing
The Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, as amended) imposes no statutory requirement for a data protection impact assessment (DPIA) before undertaking high-risk processing, including the processing of "personal information requiring special care" (sensitive data) or the use of novel technology such as AI or biometric identification. This is a structural divergence from the GDPR model, which requires controllers to conduct DPIAs when processing is likely to result in a high risk to the rights and freedoms of individuals (Art. 35 GDPR).
APPI statutory silence on DPIAs. There is no section of the APPI that defines, triggers, or mandates a pre-processing risk assessment or consultation with the Personal Information Protection Commission (PPC) analogous to GDPR Art. 35–36. The APPI’s accountability structure relies instead on its general requirement to take “necessary and proper measures” for the security control of personal data (Art. 23), and on recordkeeping for third-party data transfers (Art. 29–30), but none of these provisions reference, require, or describe risk assessment, privacy impact evaluation, or prior consultation for high-risk operations.
Sensitive data and new technologies. The APPI defines “personal information requiring special care” in Art. 2(3), covering data types vulnerable to discriminatory misuse. However, even for such data, the statutory protections cover lawful acquisition, consent for provision to third parties, and additional notification duties (see Art. 20), but never require the operator to document a risk assessment or seek PPC input prior to commencing processing. This applies irrespective of operational scale or technology; there are no DPIA duties for biometric, AI-based, or automated processing projects under base APPI. Sectoral laws or soft-law PPC guidance may recommend internal controls, but these do not crystallize as a procedural DPIA requirement under APPI.
Practical context for cross-border compliance. Japanese organizations subject to the GDPR (eg, with an EU establishment or contracts with EU partners) often implement DPIAs covering their Japanese processing to satisfy extraterritorial GDPR Art. 35 duties. However, a DPIA is not required when handling Japanese personal data only under APPI. The PPC has not issued interpretive guidance or enforcement orders establishing a DPIA-like expectation for any industry or processing context as of June 2026.
Cross-border practitioners: If your processing triggers GDPR DPIA rules, see /guides/european-union/dpo-and-records#data-protection-impact-assessment-art-35-gdpr for the EU approach. For Japanese oversight, the PPC expects risk-based security control (Art. 23) and documentation of third-party transfers (Arts. 29–30), but no formal DPIA.
PPC Guidelines on internal rules and documentation — what must a Japanese privacy program include?
Japan's Act on the Protection of Personal Information (APPI) does not mandate a record of processing activities (ROPA) or a formal Data Protection Impact Assessment (DPIA), but the Personal Information Protection Commission (PPC) Guidelines explicitly require every business operator to establish and document "internal rules" and a basic policy for personal data handling as part of their compliance program. These documentation duties are central to organizational accountability under Article 23 APPI, which requires "necessary and proper measures for security control of personal data."
PPC Guideline requirements for documentation and internal rules. The PPC's "Guidelines on the Act on the Protection of Personal Information (General Rules)" (latest amendment 2022, English summary available) interpret Article 23's security control obligation to require the following for every "personal information handling business operator" (APPI Art.16):
- Establishment of a basic policy. Every organization should document a basic policy on personal information protection that states its compliance stance, a contact point for inquiries/complaints, and basic security objectives. This policy must be maintained and disclosed (typically via website) to facilitate transparency (Guidelines, I.1). There is no required template, but typical elements include the scope of data handled, commitment to compliance, rights of data subjects, and direction for employees.
- Documented internal rules for personal data handling. Operators must develop detailed internal regulations covering all stages of personal data processing: acquisition, use, storage, provision, retention, and disposal. The Guidelines specify that these rules should reflect the actual flows and risks of the operator’s business and explicitly assign responsibilities for implementation and oversight (Guidelines, I.2). This typically includes rules on:
- Security measures (organizational, physical, technical, human)
- Roles and responsibilities, including designation of those overseeing compliance
- Procedures for handling incidents or breaches
- Data subject rights handling
- Training requirements for staff
- Maintenance and review of documentation. Both the basic policy and internal rules must be regularly reviewed and updated to reflect changes in law, guidance, or the nature of processing activities. Operators should document updates and keep records of amendments for accountability. The PPC evaluates the adequacy of documentation and review in investigations and breach response.
Distinction from ROPA/DPIA requirements. Unlike GDPR, there is no list of minimum content elements or prescribed format for documentation under APPI/PPC Guidelines. The required documentation is practical—aimed at governing real data flows and risks—not just a compliance exercise. Nevertheless, organizations with international operations often adapt their GDPR Article 30 (ROPA) and Article 35 (DPIA) templates to meet these APPI internal rules requirements for efficiency and harmonization.
Supervisory expectations and enforcement. The PPC’s enforcement actions treat failure to document internal rules or maintain a basic policy as evidence of inadequate security control under Article 23. While non-compliance does not, by itself, trigger a fine, it increases enforcement risk if a breach or complaint occurs. The PPC’s own survey (2023) reports that nearly 70% of operators maintain written internal policies, and the rate is higher for large-scale firms—the absence of such documentation is a red flag in breach investigations.
Source: Act on the Protection of Personal Information (APPI), Act No. 57 of 2003, as amended, Article 23
PPC Guidelines — requirements for the basic privacy policy under APPI (content, public disclosure, and review)
Japan’s Act on the Protection of Personal Information (APPI) requires all personal information handling business operators to establish a “basic policy” on the protection of personal information as part of their Article 23 obligation to implement “necessary and proper measures” for the security control of personal data. This requirement is specifically detailed in the Personal Information Protection Commission (PPC) Guidelines on the Act (General Rules), most recently amended in 2022 and updated through June 2026.
Content requirements (Guidelines Section I.1): The PPC Guidelines specify that every business operator must document a basic policy that includes at minimum: (1) the operator’s stance on protecting personal information, (2) a point of contact for inquiries and complaints, and (3) principal points of personal data security control measures. The content is adaptable based on the size, nature, and risks of the business but must provide clear notice to data subjects (the "principal"). There is no mandatory template, but the policy must reflect actual governance practices and allow data subjects to easily identify how their rights are safeguarded.
Public disclosure and format (Guidelines Section I.1(3)-(4)): The PPC Guidelines require that the basic policy be made available to the public “in a manner that is easily accessible to the principal.” The most common method is publication on the operator’s website if one exists, but other means (such as physical posting at business premises or providing the policy directly upon request) are permitted. The Guidelines do not require English or multilingual policies, but Japanese language must be provided; provision of other languages is considered good practice for cross-border business but is not required by statute or Guidelines.
Maintenance and review (Guidelines Section I.2; I.1(4)): The operator’s basic policy must be kept up to date with changes in laws, guidance, or business operations, and reviewed "as necessary." The Guidelines do not prescribe a fixed review cycle (such as annual review), but do require updating the policy promptly if operations or requirements change. The PPC expects operators to document updates and be able to show historic policy versions if reviewed in a supervisory context.
Enforcement context: The PPC considers the existence, accessibility, and maintenance of the basic policy a practical threshold when evaluating compliance with Article 23’s security-control obligations. The lack of a policy, or failure to disclose or maintain it, is cited in PPC recommendations or orders following complaints, inspections or incidents, but the Guidelines themselves do not set a statutory fine for non-compliance. PPC may first issue guidance, then a recommendation, and may issue an order if deficiencies are not cured.
Multinational organizations can align their Japanese basic policy with EU GDPR privacy notices or Article 30 records, but must ensure that the minimum APPI-specific content and public access are addressed in Japanese.
Source: Act on the Protection of Personal Information (APPI), Act No. 57 of 2003, as amended, Article 23
Governance requirements for "special care-required personal information" (sensitive data) under APPI — statutory rules and PPC Guidelines expectations (updated for 2026 amendment bill)
Japan’s Act on the Protection of Personal Information (APPI) governs "special care-required personal information" (sensitive data: tokutei minashi kojin joho, Article 2(3)), requiring heightened protection against discriminatory or prejudicial use. Traditionally, the APPI has set a high bar: acquisition of such data is prohibited without the principal’s explicit prior consent (Article 20), subject to narrow statutory exceptions (e.g. legal obligation, risk to life/property). Purpose-of-use must be specified at or before collection (Article 18), and all APPI general security and supervision duties (Articles 23, 25) apply, with supervision standards expected to be commensurate to the heightened risk.
2026 Amendment—Statutory change (pending effect): On April 7, 2026, the Cabinet approved and submitted to the Diet a bill to amend the APPI, responding to the triennial review and seeking to address statistical and AI-related use cases. The Lower House passed the bill on May 26, 2026. The bill establishes that consent will not be required for acquisition and provision of publicly available special care–required personal information if (a) the information is genuinely made public by the individual, government, or prescribed sources, and (b) the purpose of handling is limited to statistical aggregation (including AI training) or other cabinet-order–specified cases. The scope and safeguards for this exception will be set by subordinate regulation and Cabinet orders. Until these Cabinet orders are promulgated and the bill takes full effect (to be within two years of promulgation), prior rules remain in force.
Current rules (in force until amendment effective date):
- Explicit consent required: Article 20 mandates prior consent for acquisition of special care–required personal information, unless a statutory exception applies.
- Purpose-of-use notification: Article 18 applies as usual, requiring specific disclosure.
- Security control and processor supervision: Articles 23 and 25 require proportionately stronger control and diligence for sensitive information, with enforcement focused on sufficiency of measures under PPC Guidelines.
PPC Guidelines — best practices: The PPC’s "General Rules" Guidelines (latest 2022, updated 2026) reinforce that organizations handling special care–required information should:
- Designate responsible supervisors (not strictly mandatory, but lacking oversight may invite PPC orders after incidents)
- Document and limit staff access, with clear records and logs
- Routinely train staff on sensitive information risks and protocols
- Maintain written incident response plans for sensitive information leaks
- Keep records of access, consents, notifications, trainings, and incidents involving sensitive data (ROPA not mandatory, but documentation expected in practice)
The PPC treats deviation from these guidelines as evidence of insufficient privacy governance under Article 23, especially in incident investigations.
Practical impact and next steps: Until the 2026 amendment takes effect (timeline TBA by Cabinet order), organizations must follow existing strict-consent rules for sensitive data. For planned AI/statistical projects seeking to benefit from the new exemption, closely track subordinate regulations and Cabinet orders for operational details and safeguards. Anticipate that new uses may require a review and update of internal rules and risk assessments when the amended law enters into force.
Cross-jurisdictional note: If subject to both APPI and GDPR, remember that GDPR Article 9 maintains its own higher standard for special category data regardless of APPI changes.
Source: APPI (Act No. 57 of 2003, as amended through 2020 and 2026 bill), Article 2(3), Article 18, Article 20, Article 23, Article 25 Source: Cabinet-Approved 2026 APPI Amendment Bill, overview English summary (PPC) (Official English summary currently unlocatable as of 2024-06-12) Source: PPC Guidelines on the Act on the Protection of Personal Information (General Rules), updated June 2026, Sections I, II
Recordkeeping obligations for anonymously processed information (API) and pseudonymously processed information under APPI
Japan’s Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, as amended) establishes specific documentation and governance obligations for "anonymously processed information" (API) and, since the 2022 amendments, "pseudonymously processed information." These regimes serve to enable data utilization (for analytics, research, or sharing) while reducing risks of re-identification and misuse. The statutory requirements for API differ significantly from those for ordinary personal data, and from the looser framework for pseudonymized data under the GDPR. This section traces the exact APPI statutory mandates and the context provided by the Personal Information Protection Commission (PPC) Guidelines, as of mid-2026.
Statutory requirements for API (Articles 2(9–10), 36–39, APPI):
- Definition (Art. 2(9)): API is data relating to an individual that has been processed so that identification and restoration of the original data is impossible. This standard is stricter than GDPR pseudonymization: API must not be capable of re-identification by any reasonably available means. The 2022 amendments further set out a definition for "pseudonymously processed information," which is less strictly de-identified and subject to lighter obligations.
- Creation and records (Arts. 36–38): When a business operator creates API, it must (a) create and retain a record specifying (i) the method of anonymization, (ii) the data items included, (iii) the source of the original data, and (iv) the date of processing; (b) make a public announcement of the categories of data comprised within the API; (c) retain these records for at least three years from a provision or last date of utilization (Art. 38); and (d) clearly label API as such when providing it to any third party (Art. 36(3), 39).
- Disclosure duties (Art. 36(4)): Upon request, the operator must disclose to a data subject the method of anonymization used, unless disclosure would endanger security or significantly impede operations.
- Record of provision (Art. 38): A business operator that provides API to a third party must create and retain a record of the date, categories of data provided, method of provision, and recipient. There is no requirement for a legal basis or consent for API provision, but proper API labelling and recordkeeping are mandatory.
PPC Guidelines (latest, 2022) — recommended practices: While the statute prescribes specific documentation and labeling duties, the PPC Guidelines recommend that operators:
- Implement internal rules documenting risk assessment of anonymization methods prior to API creation;
- Maintain audit trails and control access to any linkage tables or retention of transformation keys that could risk re-identification;
- Clearly distinguish API from other data types in all privacy program documentation;
- Regularly review anonymization methods for evolving re-identification risks.
These are not strict statutory duties but are enforced in PPC audits as practical expectations, and cited as factors in post-incident investigations.
2022 amendments—impact of pseudonymized information: The 2022 amendments introduced the category of "pseudonymously processed information" with lighter recordkeeping and disclosure obligations, but it remains regulated as personal data. Organizations using pseudonymized information must distinguish these records from true API and retain documentation of their processing rationale and measures, as advised in the PPC Guidelines.
Practical enforcement context: Failure to meet API recordkeeping, labeling, and public disclosure requirements has resulted in PPC recommendations and orders, especially for large-scale research and analytics projects. The PPC’s enforcement emphasizes that only data meeting the full API standard is exempt from consent and other personal data rules; any re-identifiable data defaults to mainline APPI obligations.
Source: APPI (Act No. 57 of 2003, as amended), Articles 2(9–10), 36–39 Source: PPC Guidelines on Anonymously and Pseudonymously Processed Information, latest official publication (2022 update)
PPC Guidelines on internal privacy program self-audit — frequency, content, and enforcement context under Article 23 APPI
The Personal Information Protection Commission (PPC) Guidelines for the Act on the Protection of Personal Information (“General Rules”, latest amendment 2022) go beyond requiring documented internal rules and a basic policy—they expressly recommend that every personal information handling business operator conduct periodic internal audits (self-assessments) of its privacy management program. While this audit/self-check regime does not have the force of a statutory mandate (APPI Article 23), it is treated by the PPC as a near-essential governance expectation and carries weight in enforcement outcomes.
What does the PPC expect? Guidelines Section I.2(7) ("Regular Checks, Reviews, and Improvements") states that operators should “periodically check and review the operational status of internal rules, and improve them as necessary.” Operators are to “verify whether the measures for the security control of personal data established in accordance with the internal rules are being effectively implemented and whether there are any operational issues requiring correction.” This expectation is not limited to technical controls, but explicitly includes organizational and procedural controls, personnel training, and actual recordkeeping practices.
Self-audit frequency and format: The Guidelines do not prescribe a fixed audit cycle (for example, annual or quarterly), instead instructing operators to set a schedule “commensurate to the scale, nature, and risk” of their data processing. Large-scale or high-risk data processors are expected to conduct audits at least annually; operators in regulated industries or with recent incidents may require even more frequent checks. The self-audit should be documented: the Guidelines specify recording the audit process, findings, and resulting improvements. There is no mandatory external audit, but larger organizations frequently incorporate PPC-expected self-assessment into internal compliance, risk, or legal audit routines.
Audit content and procedures: An effective self-audit under PPC expectations typically:
- Reviews the implementation and actual practices under all documented internal rules and policies (see /guides/japan/dpo-and-records#ppc-internal-rules-and-documentation, /guides/japan/dpo-and-records#basic-policy-requirement-content-disclosure)
- Assesses whether organizational measures (e.g., designation of responsible supervisor), training, and access controls are being followed
- Reviews records of data transfers, incident responses, and data subject requests
- Identifies gaps, logs remedial actions and deadlines, and documents communication to responsible personnel
PPC enforcement context: Although failure to self-audit is not itself an automatic APPI violation, it is a red flag in PPC breach investigations or complaints. The PPC expects operators to produce audit/self-assessment records as evidence that the Article 23 “necessary and proper measures” standard is being maintained, and often references the presence or absence of regular audits in its recommendations and orders. Organizations lacking any documented review process are seen as lacking operationalized privacy governance, increasing sanction risk if an incident occurs.
Currency context: As of mid-2026, the PPC’s published enforcement guidance and materials from Privacy Awareness Week (2025) repeatedly emphasize the importance of regular self-check/self-assessments as the linchpin of ongoing compliance. While not a formal “ROPA” or “DPIA” alternative, the self-audit is the PPC’s practical proxy for organizational accountability.
Source: PPC Guidelines on the Act on the Protection of Personal Information (General Rules), latest amendment 2022, Section I.2(7) Source: PPC Privacy Awareness Week 2025 — Compliance emphasis on regular privacy self-assessment checks, risk-based review
PPC Guidelines — contact point for complaints and inquiries: content, accessibility, and maintenance under APPI
The Personal Information Protection Commission (PPC) Guidelines for the Act on the Protection of Personal Information (APPI, General Rules, latest amendment 2022) require every personal information handling business operator in Japan to designate and publicly disclose a contact point for complaints and inquiries about personal information handling. This duty on operator transparency is separate from, and less formalized than, the GDPR’s data protection officer (DPO) contact requirement. Under Japanese law, the specific publication obligation arises from the PPC Guidelines rather than from the text of APPI itself.
Designation and publication of a contact point. PPC Guidelines Section I.1(2) states that the basic policy (which every operator must establish and maintain) must include “a point of contact for complaints and inquiries regarding the handling of personal information.” The guideline does not require the name of an individual; a department, role, or established service channel (e.g., privacy office, helpdesk, data protection team) is sufficient. Operators must provide at least one means of contact—commonly a telephone number, email address, or web form. The policy must be made “easily accessible” to data subjects (the “principal”), which for most businesses means web publication.
Content and language. The PPC Guidelines set out minimum requirements: the contact point must be specified in the basic policy, and the method for data subjects to submit requests or complaints must be clear. While there is no statutory obligation to disclose the contact point in languages other than Japanese, the Guidelines recommend (but do not mandate) multilingual access where the operator serves a multinational user base. The contact point must be operational and able to receive and respond to requests without unreasonable delay or hindrance—listing a dormant mailbox or nonfunctional web form would not meet the standard.
Ongoing accuracy and updates. The Guidelines (Section I.1(4)) expect operators to keep the published contact point current and to update the information promptly if personnel, roles, or communication infrastructure change. There is no prescribed review frequency, but updates are required “as necessary.” The PPC expects that an operator can demonstrate historic versions of the basic policy, including contact details, as part of compliance checks.
Supervisory and compliance context. Failure to establish and operate a working contact point is cited as a governance deficiency in PPC recommendations and orders, typically after a complaint about an unresponsive or undisclosed contact mechanism. Although there is no APPI fine solely for lack of a contact point, the absence or inaccessibility of a published contact is a red flag in PPC investigations under Article 23’s general security-control and accountability posture.
Global businesses and cross-border tip. Operators subject to both APPI and GDPR/UK GDPR may, for operational efficiency, use the same contact address (e.g., a DPO or designated privacy team), but the PPC Guidelines require that contact point information be presented in Japanese and actually be able to process APPI-related requests from individuals in Japan.
Source: Act on the Protection of Personal Information (APPI), Act No. 57 of 2003, as amended, Article 23
Management and documentation duties for cross-border transfers under APPI — privacy program and recordkeeping expectations (Article 28, PPC Guidelines)
Japan’s Act on the Protection of Personal Information (APPI) imposes distinct governance and documentation duties on business operators that transfer personal data overseas, but these requirements do not amount to a formal record of processing or data transfer impact assessment akin to the EU GDPR. Instead, operators must embed international transfer controls in their privacy program and retain targeted records sufficient to demonstrate compliance with Article 28 and related PPC Guidelines.
APPI Article 28 — statutory transfer requirements. When a business operator transfers personal data to a third party abroad, Article 28 requires it to ensure that the foreign recipient (i) obtains data-subject consent to the overseas transfer, or (ii) provides an "adequate" level of personal data protection, as specified in rules of the Personal Information Protection Commission (PPC). This is a procedural, not documentation-focused, mandate—operators must verify protections or obtain informed consent, but the statute does not spell out the content of transfer records.
PPC Guidelines — recommended privacy program measures. The PPC Guidelines on the Act (General Rules, 2022) instruct all business operators to document internal procedures and maintain records showing that (1) the need for an overseas transfer was assessed, (2) the protection level at the destination was evaluated, (3) data subjects were notified or consent obtained, and (4) security measures required by APPI (esp. Article 23) are extended contractually to the overseas recipient where appropriate (Guidelines I.2(2), II.5(2)). Operators must also keep evidence of risk assessment and contractual or organizational safeguards implemented in transfer arrangements.
Required records and privacy program expectations:
- Evidence that transfer destinations were evaluated for adequacy, or consent obtained for non-adequate jurisdictions.
- Documentation of the relevant PPC rules used (e.g., adequacy lists, standard contractual clauses).
- Transfer notices or consent records where applicable.
- Security control clauses in contracts with overseas recipients.
- Internal rule updates reflecting cross-border data flows and corresponding risk assessments.
- Audit logs or compliance checks that demonstrate ongoing monitoring of transfer arrangements.
While APPI does not require comprehensive transfer registers, GDPR-style TIA (Transfer Impact Assessment), or a formal prior consultation mechanism, PPC enforcement practice expects operators to be able to produce tangible records of the above points in a supervisory inquiry or after an incident.
Recent enforcement and supervisory practice (2025–2026): PPC has issued recommendations to operators that failed to document overseas transfer risk evaluations, or did not update internal rules/policies to reflect cross-border data flows. The absence of such documentation is increasingly treated as evidence of inadequate governance under Article 23, even though the only hard statutory requirement is under Article 28 (consent or adequacy). Multinational organizations often rely on their GDPR Article 30 and Article 46 transfer documentation templates as a practical means to satisfy Japanese expectations, so long as Japanese-specific notification and contract elements are captured.
For the full legal conditions for transfer, see /guides/japan/international-data-transfers#general-rule-for-cross-border-transfers-under-appi.
Source: Act on the Protection of Personal Information (APPI), Act No. 57 of 2003, as amended, Article 28 Source: PPC Guidelines on the Act on the Protection of Personal Information (General Rules), latest amendment 2022, Sections I.2(2), II.5(2)
Pseudonymously processed information under APPI — definition, recordkeeping, and internal use-only controls (2022 amendments)
Japan’s Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, as amended) established the regime of “pseudonymously processed information” (仮名加工情報, PPI) in its 2020 reform, effective April 1, 2022. Pseudonymously processed information is a distinct category, falling between ordinary personal data and anonymously processed information (API), and is regulated by a targeted set of obligations and carve-outs designed to promote internal analytics and data utility while reducing privacy risk.
Definition and scope (Article 2(10), Article 35-2): PPI means information relating to an individual that has been processed (by deletion, replacement, or other means) so that the individual cannot be identified unless the information is cross-referenced with other information held by the same business operator. PPI must be processed by the same operator and is intended solely for internal use—provision to a third party in principle is prohibited (see below). PPI is not “anonymously processed information” (API), which requires irreversible de-identification even against all external parties.
Processing and internal recordkeeping (Article 35-3): A business operator creating PPI must create and retain records of:
- the method of processing (i.e., what identifiers or data items were deleted or replaced),
- the items of information subject to processing,
- date of processing,
- and a description enabling identification of the processing batch.
There is, however, no duty to make these records public or to provide access to data subjects (contrasting with API where public announcement and access rights apply). Records must be kept for as long as the operator retains the data as PPI. The PPC Guidelines recommend that the operator maintain an updated register of PPI-processing activities as part of its internal rules and privacy-management audit cycle, but this is guidance, not a statutory requirement.
Restrictions on use and provision (Article 35-4): PPI may be used only for the business operator’s own internal purposes and cannot be provided to third parties (including group affiliates acting for their own purposes), subject to narrow statutory exceptions (e.g., legal obligation). PPI is treated as personal data except for selected APPI rules: it is exempted from data subject access (Article 33), correction (Article 34), suspension of use (Article 35), and rules on purpose change (Article 18(2)). Requirements for consent and notification for use/provision do not apply. However, it is still subject to the general APPI obligations of security control (Article 23), breach notification (Article 26), and supervision of processors (Article 25). PPI must be segregated from other personal data, and identifiers/key codes used for pseudonymization must be tightly controlled and not used to re-identify individuals without independent justification.
Enforcement and practical compliance: The Personal Information Protection Commission’s (PPC) enforcement FAQs clarify the boundaries of lawful PPI use: (i) once data is pseudonymized, it cannot be reconverted to ordinary personal data or used to re-identify individuals except under exception, and (ii) use for internal analytics, testing, or product development is permitted, so long as third-party transfer is excluded. When a breach implicates PPI, the incident is still reportable under APPI Article 26. Failure to follow PPI recordkeeping or provision rules is treated as a breach of general APPI security-control duties (Article 23) and may result in PPC recommendations or orders. For organizations handling both PPI and API, PPC expects clear documentation and segregation of categories to avoid regulatory confusion or unauthorized use.
Contrast with GDPR pseudonymization: GDPR defines “pseudonymisation” as a security measure applicable to personal data generally, without creating a special category with statutory carve-outs. By contrast, APPI’s PPI is a regulated data type with precise internal-use exemptions and targeted relief from ordinary data subject rights. Operators managing global compliance should not assume APPI PPI and GDPR pseudonymized data are interchangeable—each triggers a different compliance logic and enforcement expectation.
Currency note: This summary is current as of June 2026. PPC enforcement FAQs and guideline updates are periodically issued and should be checked for interpretive shifts.
Source: Act on the Protection of Personal Information (APPI), Act No. 57 of 2003, as amended through 2022, Articles 2(10), 35-2 to 35-7, 23, 25, 26 Source: APPI Q&A (PPC), pseudonymously processed information, internal-use only and third-party provision prohibition (Japanese)
Breach recordkeeping and incident documentation obligations under APPI — Article 26 reforms and PPC Guidelines (2022, 2025, 2026 amendment bill)
Japan’s Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, as amended) imposes mandatory documentation and internal investigation duties on business operators following personal data breaches. Article 26 requires all operators to act without delay to prevent further damage, investigate the facts and causes, and implement recurrence prevention. The Personal Information Protection Commission (PPC) Guidelines (“General Rules,” latest comprehensive amendment 2022, with ongoing practice notes through Privacy Awareness Weeks 2025 and 2026) operationalize this as requiring detailed records and post-incident reporting documentation, both for statutory notifiable breaches and internal “near miss” incidents.
Statutory and guidance framework up to mid-2026:
- Article 26(1) requires operators, when a leakage, loss, or damage occurs, to "promptly investigate the facts and causes" and "take necessary measures to prevent the occurrence or expansion of damage" as well as recurrence. Article 26(2) imposes report/notification obligations for certain categories of breach, defined and expanded by PPC rules.
- The PPC Guidelines (2022, Section III.3) specify that operators must document—in every breach or incident—(a) the date/time; (b) the type and scope of compromised data; (c) detection method; (d) root cause findings; (e) damage mitigation steps; (f) notification and communication process, including reasoning if external notification was deemed unnecessary; (g) steps for recurrence prevention and internal rules updates; and (h) the decision process over whether notification thresholds were met. The PPC's Privacy Awareness Weeks 2025 and 2026 reinforced this regime, and PPC case reports for FY2025 emphasized that inspection/audit routinely requests these records during investigations.
- No statutory or guideline-specified minimum retention period applies, but practical guidance (and PPC audit practice) recommend at least three years as a baseline (by analogy to third-party provision records under APPI Articles 29/30).
2026 amendment bill — new flexibilities and pending regulatory detail:
- In May 2026, the National Diet passed a bill amending the APPI, introducing two potentially material changes—(a) a relaxation of immediate notification obligations for certain categories of data processors (to be defined by subsequent PPC regulation/Cabinet order), and (b) a new regulatory regime under which notification to data subjects may be replaced with alternate measures (such as web publication, call-center hotlines, or phased notification) if the PPC agrees material risk of harm is low (PPC approval process and operational rules still pending).
- As of June 2026, the amendment bill is not yet effective: Cabinet orders and detailed PPC implementation rules are TBA and are expected no later than 2027. Until promulgation, the 2022 rules and full notification/documentation regime remain in force.
- Practitioners and privacy officers should closely monitor PPC and Cabinet announcements, as the 2026 reforms will affect both the documentary and process expectations for breach handlings and may shift audit/investigation practice, particularly for multinational processors or high-volume data handlers.
Practical enforcement signals:
- PPC enforcement reports in 2025–2026 highlight inadequate documentation—especially lack of rationale for not notifying data subjects or failure to record post-incident remedial steps—as one of the most frequent bases for recommendations or formal orders.
- Failure to document “near miss” or minor incidents, even if not notifiable, is interpreted as a sign of insufficient privacy governance and will weigh against the operator in PPC investigations.
- For cross-border businesses, Japanese documentation must remain APPI-specific (decision logic, root cause, and recurrence prevention unique to Japan context), even when integrated with global GDPR/CCPA-style breach procedures.
Currency notice: This section is current as of June 2026, and will require prompt update once Cabinet orders and PPC rules implementing the 2026 bill are promulgated and effective.
Source: Act on the Protection of Personal Information (APPI), Act No. 57 of 2003, as amended, Article 26 Source: PPC Guidelines on the Act on the Protection of Personal Information (General Rules), latest amendment 2022, Section III.3; PPC Privacy Awareness Week 2025/2026 materials Source: 2026 APPI Amendment Bill overview (Cabinet, PPC)