APPI Article 28 — The basic restriction on overseas provision of personal data
Japan's Act on the Protection of Personal Information (APPI) imposes a baseline restriction on the transfer of personal data to third parties in foreign countries under Article 28 (renumbered from Article 24 effective April 1, 2022). A personal information handling business operator (PIHBO) is the core regulated entity — defined in Article 16(2) APPI as a business operator that uses a database of personal information. The Personal Information Protection Commission (PPC) is Japan's data protection supervisory authority, established under Article 152 APPI.
"Foreign country" means "a country or region located outside the territory of Japan" (Art. 28 APPI). The restriction applies when a PIHBO provides personal data to a third party located in a foreign country, except in those cases already exempted from the domestic third-party provision rule under Article 27(1) — for instance, transfers necessary for the protection of life, body, or property when obtaining consent is difficult (Art. 27(1)(ii)), or transfers necessary for cooperation with a public authority where obtaining consent would impede performance of statutory duties (Art. 27(1)(iv)).
The three compliant pathways
Article 28 establishes three lawful mechanisms for cross-border transfers:
1. Transfers to adequate foreign countries (Art. 28 whitelist exception). A PIHBO may transfer personal data to a third party in a "foreign country establishing a personal information protection system recognized to have equivalent standards to that in Japan in regard to the protection of an individual's rights and interests," as "prescribed by rules of the Personal Information Protection Commission" (Art. 28 APPI). Transfers to countries on this PPC-designated whitelist do not require individual consent and carry no additional compliance burden beyond Article 27 (domestic third-party provision). The European Union member states are designated under the EU-Japan mutual adequacy framework (effective January 23, 2019).
2. Transfers to third parties with appropriate data-protection systems (Art. 28(1) carve-out). A PIHBO may transfer personal data to a recipient in a non-adequate foreign country if that recipient is "a person establishing a system conforming to standards prescribed by rules of the Personal Information Protection Commission as necessary for continuously taking action equivalent to the one that a personal information handling business operator shall take concerning the handling of personal data pursuant to the provisions of this Section" (Art. 28(1) APPI). This pathway is designed for transfers to affiliates, processors, or other third parties willing to implement contractual or organizational safeguards equivalent to APPI obligations. The specific system standards are set out in the PPC's Enforcement Rules.
When relying on this pathway, the PIHBO must "take necessary action to ensure that the third party appropriately and continuously takes the said action for the protection of personal information," and must "publicly announce information on the system the said third party has established and the said action the third party takes" (Art. 28(3) APPI). The PIHBO bears ongoing supervisory responsibility and a transparency obligation.
3. Individual consent with mandated information provision (Art. 28(1) principal consent). When neither of the above pathways is available, the PIHBO must "in advance obtain a principal's consent to the effect that he or she approves the provision to a third party in a foreign country" (Art. 28(1) APPI). This is not the simple consent that suffices for domestic third-party provision under Article 27(1). Article 28(2) imposes an additional mandatory information-provision obligation: before obtaining consent, the PIHBO must "in advance provide the principal with information on the personal information protection system of the foreign country, on the action the third party takes for the protection of personal information, and other information that is to serve as a reference to the principal, pursuant to rules of the Personal Information Protection Commission."
The practical effect is that consent must be meaningfully informed — the data subject receives country-level and recipient-level detail enabling her to assess the transfer risk before agreeing. The PPC's rules prescribe the content and form of this information.
Relationship to Article 27 exceptions and recordkeeping
The Article 28 restriction is expressly subject to the exceptions in Article 27(1). When an Article 27(1) exception applies (such as the life-protection or public-authority-cooperation carve-outs), the overseas transfer may proceed without consent under Article 28 as well. However, the PIHBO must still create and maintain records of the transfer under Article 28, except where the transfer falls within an Article 27(1) or (5) exception (Art. 28 cross-reference to recordkeeping provisions).
Practical compliance sequencing
A PIHBO planning an overseas transfer should evaluate the pathways in the following order:
- Check the PPC's whitelist of adequate foreign countries. If the recipient is located in an adequate jurisdiction (such as an EU member state) and the transfer otherwise complies with Article 27, no additional consent or contract is required.
- If the recipient is in a non-adequate country, assess whether the recipient can establish and maintain an appropriate system under PPC rule standards. This pathway is available for intra-group transfers and for transfers to processors or service providers willing to implement contractual commitments that mirror APPI obligations. The PIHBO must supervise ongoing compliance and publicly disclose the recipient's system and practices.
- If neither pathway is available, obtain enhanced consent from the data subject after providing the mandated information about the recipient country's legal framework and the recipient's specific data-protection practices, as prescribed by PPC rules.
The 2020 amendments to APPI (effective April 2022) strengthened the cross-border transfer regime by adding the mandatory information-provision requirement for consent (Art. 28(2)) and the ongoing-supervision and public-disclosure obligations for appropriate-system transfers (Art. 28(3)). These changes reflect Japan's commitment under the EU-Japan adequacy arrangement to maintain a level of protection recognized as substantially equivalent to EU standards for personal data originating in the EU.
Source: Act on the Protection of Personal Information (APPI), Art. 28, June 2020 English translation Source: PPC notice on renumbering of Article 24 to Article 28, effective April 1, 2022
PPC whitelist of adequate foreign countries — EU/EEA and UK only
The Personal Information Protection Commission (PPC) maintains a whitelist of foreign countries designated as having "a personal information protection system recognized to have equivalent standards to that in Japan in regard to the protection of an individual's rights and interests" under Article 28 APPI. Transfers to whitelisted countries do not require the data subject's consent and do not require the data exporter to implement an appropriate-system contract, because the recipient country's legal framework itself is deemed to provide equivalent protection.
As of May 2026, only two jurisdictions are on the PPC whitelist:
- The European Union (all EU Member States in the European Economic Area), designated effective January 23, 2019.
- The United Kingdom, also designated effective January 23, 2019.
The Japan-EU mutual adequacy arrangement
The EU designation was adopted by the PPC at its 85th Personal Information Protection Committee meeting on January 23, 2019, based on Article 24 APPI (renumbered to Article 28 on April 1, 2022). On the same day, the European Commission adopted its reciprocal adequacy decision for Japan under Article 45 GDPR (Decision (EU) 2019/419). This created a mutual adequacy arrangement — the world's largest area of free cross-border personal-data flows based on reciprocal adequacy findings at the time of entry into force.
The arrangement applies to commercial transfers between personal information handling business operators (PIHBOs) in Japan and controllers/processors in the EU. It does not currently cover transfers in the context of public-sector regulatory cooperation or academic research, though both the PPC and the European Commission have indicated interest in expanding the scope to those sectors following the 2021 APPI amendments that extended the law to Japan's public sector.
Personal data transferred from the EU to Japan under the adequacy decision is subject to the Supplementary Rules under the Act on the Protection of Personal Information for the Handling of Personal Data Transferred from the EU and the United Kingdom based on an Adequacy Decision (adopted by the PPC in January 2019, most recently revised March 15, 2023, effective April 1, 2023). The Supplementary Rules impose additional obligations on Japanese PIHBOs handling EU-origin data — for instance, stricter limitations on onward transfers to third countries, enhanced transparency requirements, and a prohibition on using consent as a lawful basis for onward transfers except in narrow circumstances. The European Commission conducted the first periodic review of the adequacy decision in 2021–2023, concluding in March 2023 that the level of protection in Japan remains essentially equivalent to EU standards.
The Japan-UK adequacy arrangement
The UK was added to the PPC whitelist on the same date as the EU (January 23, 2019), initially as part of the EU designation. Following Brexit, the UK maintained its adequacy status with Japan. In October 2023, the PPC and the UK Information Commissioner's Office (ICO) signed a Memorandum of Cooperation to deepen enforcement collaboration. The UK adequacy designation operates in parallel with the EU arrangement, and personal data transferred from the UK to Japan under the adequacy finding is governed by the same Supplementary Rules that apply to EU-origin data.
Countries NOT on the whitelist
No other country or region — including the United States, Canada, Australia, Singapore, South Korea, or China — is currently designated as adequate by the PPC. Transfers to these jurisdictions must rely on one of the other two Article 28 pathways: either the data exporter and recipient must implement an appropriate system of data protection equivalent to APPI standards (typically via a cross-border data transfer agreement or binding corporate rules), or the data exporter must obtain the data subject's enhanced consent after providing mandated information about the recipient country's legal framework and the recipient's specific data-protection measures.
The PPC's Global Strategy for FY2025, published in March 2025, states that the PPC "will continue to work toward expanding the scope or the number of countries and regions covered by the mutual adequacy arrangements" as a top priority, including by concluding consultations with the EU and UK on extending the existing adequacy arrangement to academia and the public sector and by "initiating discussions about a new mutual adequacy arrangement with like-minded countries and regions having shared fundamental values with Japan."
APEC CBPR certification is NOT a whitelist substitute
Certification under the APEC Cross-Border Privacy Rules (CBPR) system (now the Global CBPR System, launched April 2024) is an example of an "international framework" that may satisfy the appropriate-system pathway under Article 28 APPI. However, CBPR certification does not place the recipient on the PPC whitelist and does not eliminate the need for a transfer mechanism. A PIHBO relying on a CBPR-certified recipient must still either implement an appropriate-system contract with the recipient (the CBPR certification helps demonstrate that the recipient has equivalent protections in place) or obtain enhanced consent. CBPR certification is a compliance tool, not an adequacy designation.
Practical compliance sequencing
When planning a cross-border transfer, a PIHBO should first check whether the recipient is located in an EU Member State or the UK. If yes, and if the transfer otherwise complies with Article 27 APPI (domestic third-party provision rules), the transfer may proceed without additional Article 28 compliance steps — no consent, no contract, no public disclosure. For all other destinations, the PIHBO must evaluate the appropriate-system or enhanced-consent pathways and comply with the attendant information-provision, supervision, and transparency obligations described in the base Article 28 section of this guide.
Source: PPC announcement on Japan-EU mutual adequacy framework entry into force, January 23, 2019 Source: PPC Global Strategy for FY2025, March 26, 2025 Source: European Commission Report on first review of Japan adequacy decision, March 2023 Source: Supplementary Rules for EU/UK-origin data, revised March 15, 2023
Appropriate-system pathway — contractual and organizational standards under Art. 28(1) and PPC Rule 11-2
When a personal information handling business operator (PIHBO) transfers personal data to a recipient in a non-adequate foreign country (any country other than EU member states or the UK), the PIHBO may rely on the appropriate-system pathway under Article 28(1) APPI as an alternative to obtaining enhanced consent. This pathway permits the transfer if the foreign recipient "is a person establishing a system conforming to standards prescribed by rules of the Personal Information Protection Commission as necessary for continuously taking action equivalent to the one that a personal information handling business operator shall take concerning the handling of personal data pursuant to the provisions of this Section."
The appropriate-system pathway is the workhorse mechanism for cross-border transfers to the United States, Singapore, China, Canada, Australia, and other major trading partners not on the PPC whitelist. It is designed for intra-corporate transfers within a multinational group, for transfers to service providers and processors under contract, and for transfers to joint controllers or other third parties willing to implement equivalent data-protection safeguards.
PPC Enforcement Rule 11-2 — the required system elements
Article 11-2 of the PPC's Enforcement Rules for the Act on the Protection of Personal Information prescribes the specific standards the foreign recipient's system must meet. The Rule requires the recipient to establish a system that includes:
- A framework equivalent to the PIHBO's obligations under APPI Section 2 (Articles 20–39, covering purpose limitation, accuracy, security, third-party provision restrictions, transparency, and data-subject rights). The recipient must adopt internal rules, policies, or contractual commitments that impose obligations on the recipient mirroring those a PIHBO would bear under APPI if the recipient were operating in Japan.
- Procedures for responding to data-subject requests for disclosure, correction, suspension of use, and erasure under Articles 32–34 APPI, either directly or by assisting the data exporter in responding.
- Organizational and technical safeguards to prevent unauthorized access, loss, destruction, falsification, or leakage of personal data, equivalent to the security management measures required under Article 23 APPI.
- A framework for handling complaints from data subjects regarding the handling of personal data, equivalent to Article 40 APPI.
The recipient's system may be evidenced by:
- A data processing agreement (DPA) or cross-border data transfer agreement between the data exporter and the recipient that contractually binds the recipient to APPI-equivalent obligations;
- Binding corporate rules (BCRs) adopted within a corporate group and binding on all group entities;
- A privacy policy or internal rules adopted by the recipient and enforceable by the data exporter; or
- APEC Cross-Border Privacy Rules (CBPR) certification obtained by the recipient under the Global CBPR System (launched April 2024, successor to the original APEC CBPR framework). CBPR certification is expressly recognized by the PPC as evidence that the recipient has established an appropriate system, though it does not eliminate the data exporter's ongoing supervision obligations.
Ongoing supervision obligations under Article 28(3)
The appropriate-system pathway is not a set-and-forget mechanism. Article 28(3) APPI imposes two continuing obligations on the data exporter:
1. Necessary action to ensure continuous implementation. The PIHBO must "take necessary action to ensure that the third party appropriately and continuously takes the said action for the protection of personal information." This supervision obligation requires the PIHBO to:
- Periodically verify that the recipient remains in compliance with the agreed-upon system (for instance, by requiring annual compliance certifications, conducting audits, or reviewing the recipient's handling practices);
- Investigate and remediate any breach or non-compliance by the recipient;
- Suspend or terminate the transfer relationship if the recipient fails to maintain the required system.
The PPC's guidance indicates that the frequency and intensity of supervision should be proportionate to the volume and sensitivity of the personal data transferred, the recipient's track record, and the risk profile of the destination country.
2. Public disclosure and data-subject information obligations. Article 28(3) APPI requires the PIHBO to "publicly announce information on the system the said third party has established and the said action the third party takes." This transparency obligation is typically satisfied by publishing on the PIHBO's website:
- The name and location of the foreign recipient (or categories of recipients, if the number is large);
- A summary of the contractual or organizational framework the recipient has adopted (e.g., "standard data processing agreement incorporating APPI-equivalent safeguards," "APEC CBPR-certified processor," or "binding corporate rules applicable to all group entities");
- The measures the PIHBO takes to supervise the recipient's ongoing compliance (e.g., annual audits, quarterly compliance certifications).
Additionally, Article 28(3) requires the PIHBO to provide this information "in response to a principal's request" — meaning any data subject whose personal data has been transferred can demand details about the recipient's system and the PIHBO's supervision measures. The PIHBO must respond "without delay" under the general transparency obligations in Article 32 APPI.
Interaction with the enhanced-consent pathway
If the foreign recipient cannot or will not establish an appropriate system meeting PPC Rule 11-2 standards, the PIHBO must instead obtain enhanced consent under Article 28(1) and (2) APPI. That consent pathway requires the PIHBO to provide the data subject, before obtaining consent, with "information on the personal information protection system of the foreign country, on the action the third party takes for the protection of personal information, and other information that is to serve as a reference to the principal, pursuant to rules of the Personal Information Protection Commission."
The appropriate-system pathway eliminates the need for individual consent but imposes contract, supervision, and transparency obligations in its place. The enhanced-consent pathway shifts the burden to the data subject to assess the transfer risk based on mandated disclosures, but it does not require the recipient to implement contractual safeguards or permit the PIHBO to rely on ongoing supervision as a substitute for consent.
Comparison to GDPR Article 46 transfer mechanisms
Practitioners familiar with the EU GDPR will recognize the appropriate-system pathway as functionally similar to GDPR Article 46 standard contractual clauses (SCCs) or binding corporate rules (BCRs). Both frameworks require the data exporter to bind the recipient to equivalent data-protection obligations and to supervise ongoing compliance. However, APPI Article 28 does not prescribe a single template for the appropriate system — unlike the EU Commission's SCCs, which are standardized and must be adopted verbatim. Japanese PIHBOs have flexibility to tailor the contractual or organizational framework to the specific transfer, provided it meets PPC Rule 11-2 standards. The PPC has indicated in enforcement guidance that it will assess the substance of the recipient's commitments, not their form.
Recordkeeping and evidence of compliance
Article 28 APPI incorporates by cross-reference the recordkeeping obligations applicable to domestic third-party provisions under Article 27. When relying on the appropriate-system pathway, the PIHBO must create and maintain records of each transfer, including the date of the transfer, the items of personal data transferred, the identity of the recipient, and the basis for the transfer (i.e., that the recipient has established an appropriate system). These records must be retained for the period prescribed by PPC rules (currently three years from the date of the transfer) and must be available for inspection by the PPC upon request.
The PIHBO should also maintain documentary evidence of the recipient's system (the signed DPA, the BCR document, the CBPR certificate, or the recipient's privacy policy and internal rules) and records of the PIHBO's supervision activities (audit reports, compliance certifications, correspondence regarding remediation of any non-compliance). In enforcement actions, the PPC has required PIHBOs to demonstrate both that the recipient's system met Rule 11-2 standards at the time of the initial transfer and that the PIHBO took "necessary action" to ensure continuous implementation thereafter.
Source: Act on the Protection of Personal Information (APPI), Art. 28, June 2020 English translation Source: PPC overview of 2020 amendments, describing reinforced restrictions on cross-border transfers
Enhanced consent pathway — Article 28(1) and (2) mandatory information-provision requirements
When a personal information handling business operator (PIHBO) transfers personal data to a recipient in a non-adequate foreign country (any country other than EU member states or the UK), and the recipient has not established an appropriate system of data protection under Article 28(1) APPI, the PIHBO must obtain the data subject's enhanced consent before the transfer. This consent pathway is governed by Article 28(1) and (2) APPI and differs materially from the simple consent that suffices for domestic third-party provision under Article 27.
Article 28(1) consent is distinct from Article 27 consent
Under Article 27(1) APPI, a PIHBO may provide personal data to a third party within Japan if the PIHBO "has in advance obtained a principal's consent." The statute does not prescribe the content or form of that consent, and PIHBOs typically obtain it through a short opt-in checkbox or a general privacy-policy acknowledgment. This simple consent is not sufficient for cross-border transfers.
Article 28(1) APPI requires "a principal's consent to the effect that he or she approves the provision to a third party in a foreign country" (emphasis added). The consent must be transfer-specific — it must address the cross-border nature of the provision and identify the foreign recipient or category of recipients. A blanket clause in a privacy policy permitting "sharing with service providers" or "transfers for business purposes" will not satisfy Article 28(1) unless it explicitly flags the overseas transfer and the foreign destination.
Mandatory information provision under Article 28(2) — what the data subject must receive before consenting
Article 28(2) APPI imposes a pre-consent information-provision obligation that has no analog in the domestic third-party provision regime. The PIHBO must, "in advance" of obtaining consent, "provide the principal with information on the personal information protection system of the foreign country, on the action the third party takes for the protection of personal information, and other information that is to serve as a reference to the principal, pursuant to rules of the Personal Information Protection Commission."
The statutory text identifies three categories of mandatory information:
1. Information on the personal information protection system of the foreign country. The PIHBO must describe the legal framework governing personal data in the recipient's jurisdiction. This is a country-level disclosure. The statute does not require a comprehensive treatise on foreign law, but the disclosure must give the data subject a meaningful basis for assessing the transfer risk.
PPC guidance suggests that the country-level information should address:
- Whether the recipient country has comprehensive data-protection legislation (such as GDPR in the EU, PIPL in China, LGPD in Brazil) or sector-specific rules (such as HIPAA in the United States for health data);
- The existence and authority of a data-protection supervisory authority or regulator in the recipient country;
- Whether the recipient country's legal system permits government access to personal data (for instance, under U.S. FISA Section 702 or Chinese national-security laws) and, if so, the scope and procedural safeguards governing that access;
- Whether the recipient country's law provides data subjects with rights equivalent to those under APPI (such as access, correction, and erasure rights).
The PIHBO is not required to provide a legal opinion on the adequacy of the foreign regime — that determination is reserved to the PPC under the whitelist process. However, the disclosure must be factual and current. A PIHBO that tells a data subject "the United States has robust privacy protections" without disclosing the absence of a federal comprehensive privacy law or the breadth of national-security access authorities would fail the Article 28(2) standard.
2. Information on the action the third party takes for the protection of personal information. The PIHBO must describe the recipient-specific data-protection measures the foreign third party has adopted or will adopt. This is a supplement to the country-level disclosure — even if the recipient country's legal framework is weak, the recipient organization may have implemented strong contractual or organizational safeguards.
The recipient-specific disclosure should address:
- The recipient's internal privacy policies and procedures (for instance, whether the recipient has adopted a privacy policy, appointed a data-protection officer or privacy lead, or implemented access controls and encryption);
- Contractual commitments the recipient has made to the PIHBO (for instance, under a data processing agreement that mirrors APPI obligations);
- Certification under a recognized privacy framework, such as the APEC Cross-Border Privacy Rules (CBPR) system or ISO 27001 information-security management standards;
- The recipient's history of data breaches or enforcement actions, if known to the PIHBO and material to the transfer risk.
The statute does not prescribe a minimum level of detail, but the disclosure must give the data subject a reference point for evaluating the recipient's practices. A generic statement that "the recipient will protect your data in accordance with industry standards" is insufficient. The disclosure should identify the specific measures the recipient has implemented or will implement under the transfer agreement.
3. Other information that is to serve as a reference to the principal, pursuant to rules of the Personal Information Protection Commission. This is a catch-all category delegated to PPC rulemaking. The PPC's Enforcement Rules for the Act on the Protection of Personal Information prescribe additional disclosure items, including:
- The name and contact information of the foreign recipient (or, if the number of recipients is large and disclosure of individual names is impracticable, the categories of recipients — e.g., "cloud service providers located in the United States");
- The purpose for which the recipient will use the personal data (which must be consistent with the purpose notified to the data subject at the time of collection under Article 18 APPI);
- The types or items of personal data that will be transferred (e.g., "name, email address, purchase history," rather than a vague "personal information");
- The method by which the data subject can withdraw consent (Article 28 does not create a statutory right to withdraw cross-border transfer consent after the transfer has occurred, but if the PIHBO's internal policy permits withdrawal, that fact must be disclosed).
Form and timing of the information provision
Article 28(2) requires that the information be provided "in advance" of obtaining consent. The PIHBO must give the data subject an opportunity to review the information and make an informed decision before clicking "I agree" or signing a consent form. A disclosure that appears only after the data subject has consented — for instance, in a confirmation email — does not satisfy Article 28(2).
The statute does not prescribe the medium of disclosure. PIHBOs typically provide the Article 28(2) information through:
- A dedicated cross-border transfer notice presented to the data subject in a pop-up or interstitial screen before the consent checkbox, with a link to a detailed disclosure document;
- An integrated privacy notice that combines the Article 18 purpose-of-use notification, the Article 27 third-party provision disclosure, and the Article 28(2) cross-border transfer information in a single layered document, with the Article 28(2) information highlighted or separately flagged;
- A separate consent form for cross-border transfers, distinct from the general terms of service or privacy-policy acknowledgment, that embeds the Article 28(2) information above the signature line.
The PPC has emphasized in guidance that the Article 28(2) information must be easily accessible and understandable. A disclosure buried in a 30-page privacy policy or written in dense legalese will not satisfy the statute's reference-to-the-principal standard, even if all required items are technically present. The PIHBO should use plain language, break the information into digestible sections (country-level framework, recipient-specific measures, data-subject rights), and ensure that the disclosure is presented in a manner that draws the data subject's attention before consent is obtained.
Consequences of non-compliance
Failure to provide the Article 28(2) information, or obtaining consent without "in advance" disclosure, renders the consent invalid. The cross-border transfer proceeds without a lawful basis under Article 28 and constitutes a violation of the restriction on overseas provision of personal data. The Personal Information Protection Commission (PPC) may issue a recommendation or order under Article 145 or 146 APPI directing the PIHBO to suspend the transfer, implement remedial measures, and notify affected data subjects. Violation of a PPC order is subject to criminal penalties under Article 178 APPI (imprisonment of up to one year or a fine of up to ¥1 million for individuals; fines of up to ¥100 million for corporations under Article 179).
The PPC has not yet published a major enforcement action focused solely on Article 28(2) information-provision failures, but the 2020 amendments to APPI (effective April 2022) that introduced the mandatory information-provision requirement reflect the PPC's concern that data subjects were consenting to cross-border transfers without understanding the risks. PIHBOs should treat Article 28(2) compliance as a gating requirement — if the information cannot be provided accurately and comprehensibly, the PIHBO should pursue the appropriate-system pathway under Article 28(1) or limit the transfer to whitelisted jurisdictions (EU/UK).
Comparison to GDPR Article 49(1)(a) derogation for explicit consent
Practitioners familiar with GDPR will note parallels between APPI Article 28(1)/(2) enhanced consent and GDPR Article 49(1)(a), which permits cross-border transfers on the basis of "explicit consent" when no adequacy decision or appropriate safeguard (such as SCCs) is available. Both regimes require informed, transfer-specific consent and impose higher standards than consent for ordinary processing. However, APPI Article 28(2) is more prescriptive than GDPR Article 49(1)(a) in specifying the content of the pre-consent disclosure — GDPR recital 111 states that the data subject must be informed of "the possible risks of such transfers," while APPI Article 28(2) mandates disclosure of the foreign country's legal framework and the recipient's specific measures. The APPI approach reflects Japan's civil-law tradition of detailed statutory specification, whereas GDPR leaves greater room for case-by-case assessment by supervisory authorities.
Source: Act on the Protection of Personal Information (APPI), Art. 28, June 2020 English translation Source: PPC overview of 2020 amendments, describing mandatory information provision for cross-border transfer consent
Onward transfers — Supplementary Rule (4) restrictions on EU/UK-origin data
When a personal information handling business operator (PIHBO) in Japan receives personal data from the European Union or the United Kingdom under the mutual adequacy arrangement (effective January 23, 2019), and then wishes to onward transfer that data to a third country outside Japan, the PIHBO faces stricter restrictions than those imposed by base Article 28 APPI. These enhanced restrictions are imposed by Supplementary Rule (4) of the Supplementary Rules under the Act on the Protection of Personal Information for the Handling of Personal Data Transferred from the EU and the United Kingdom based on an Adequacy Decision, adopted by the PPC in January 2019 and most recently revised March 15, 2023 (effective April 1, 2023).
What is an onward transfer?
An onward transfer occurs when a PIHBO in Japan that has received personal data from the EU or UK (under the adequacy arrangement) subsequently provides that EU/UK-origin data to a third party located in a foreign country (i.e., outside Japan). From the perspective of Japanese law, this is simply an international data transfer governed by Article 28 APPI. However, because the data originated in the EU or UK, the European Commission's adequacy decision requires Japan to apply enhanced safeguards to ensure continuity of protection — meaning the data must remain subject to a level of protection essentially equivalent to the GDPR throughout its lifecycle, even after leaving Japan.
The Supplementary Rules are legally binding on all PIHBOs handling EU/UK-origin data and are enforceable by the PPC in the same manner as the APPI itself. PIHBOs must implement technical or organizational measures (such as data tagging or segregated databases) to identify EU/UK-origin data throughout its lifecycle and apply the Supplementary Rules to any onward transfer of that data.
Supplementary Rule (4) — the onward transfer restriction
Supplementary Rule (4) states that when a PIHBO covered by the Japan-EU adequacy decision intends to onward-transfer EU/UK-origin personal data to a third party in a foreign country, the PIHBO may not rely on all three of the standard Article 28 pathways. Instead, onward transfers of EU/UK-origin data are permitted only under the following mechanisms (without prejudice to the derogations set forth in Article 27(1) APPI, such as the life-protection and public-authority-cooperation exceptions):
1. Onward transfer to another adequate country designated by the PPC under Article 28. If the third-country recipient is located in a jurisdiction on the PPC's whitelist of adequate foreign countries — currently only EU member states and the UK — the onward transfer may proceed without additional safeguards or consent, provided it complies with the domestic third-party provision rules under Article 27 APPI. A PIHBO in Japan may freely onward-transfer EU-origin data to a recipient in Germany or France, or UK-origin data to a recipient in Ireland, without triggering Supplementary Rule (4)'s enhanced requirements.
2. Onward transfer to a recipient that has established "implementing measures providing a level of protection equivalent to the APPI, read together with the Supplementary Rules." This pathway is functionally similar to the Article 28(1) appropriate-system pathway, but the standard is higher: the foreign recipient must implement contractual or organizational safeguards that meet not only the APPI obligations under Articles 20–39 but also the enhanced protections imposed by the Supplementary Rules for EU/UK-origin data. This includes, for example, the Supplementary Rules' stricter limitations on special-category data processing, the expanded definition of sensitive data (which under Supplementary Rule (2) includes medical data, data revealing political opinions, and data concerning an individual's sex life — categories not treated as special-category data under base APPI Article 2(3)), and the enhanced information-provision requirements for onward transfers by consent (Supplementary Rule (4) itself).
The PIHBO must bind the foreign recipient to these APPI-plus-Supplementary-Rules obligations through a data transfer agreement or binding corporate rules applicable within a multinational group. The European Commission's first review of the adequacy decision, published in March 2023, noted that PIHBOs "frame their onward transfers of data originally received from the EU 'by concluding a contract that binds the recipient to measures ensuring the continuity of protection.'" However, the PPC has not published model contractual clauses or detailed guidance specifying the required content of such contracts. The European Commission and the European Data Protection Board (EDPB) have both recommended that the PPC develop model clauses or clearer guidance on the "equivalent measures" standard to assist PIHBOs and their third-country recipients in framing compliant onward-transfer agreements.
APEC CBPR certification is NOT sufficient for onward transfers of EU/UK-origin data. Supplementary Rule (4) expressly excludes reliance on APEC Cross-Border Privacy Rules (CBPR) certification as a standalone basis for onward transfers of EU/UK-origin data. While CBPR certification may satisfy the appropriate-system pathway under base Article 28 APPI for non-EU/UK data, it does not provide a level of protection equivalent to APPI plus Supplementary Rules. A PIHBO onward-transferring EU-origin data to a CBPR-certified recipient in the United States or Singapore must still execute a contract binding the recipient to APPI-plus-Supplementary-Rules obligations; the CBPR certification alone is insufficient. The European Commission's March 2023 review report and the EDPB's Statement 1/2023 on the Japan adequacy review both emphasized this exclusion and called on the PPC to clarify it in the PPC Guidelines on international transfers.
3. Onward transfer with enhanced consent after providing mandated information "on the circumstances surrounding the transfer necessary for the principal to make a decision on his/her consent." If neither of the above pathways is available — for instance, if the foreign recipient is in a non-adequate country and cannot or will not implement APPI-plus-Supplementary-Rules contractual safeguards — the PIHBO must obtain the data subject's consent before the onward transfer. This consent must be informed by the disclosure of "information on the circumstances surrounding the transfer necessary for the principal to make a decision on his/her consent" under Supplementary Rule (4).
This information-provision requirement is more stringent than the base Article 28(2) APPI mandatory disclosure for cross-border transfers. Whereas Article 28(2) requires disclosure of the foreign country's legal framework and the recipient's data-protection measures, Supplementary Rule (4) additionally requires disclosure of the risks arising from the absence of adequate protection in the third country and the absence of appropriate safeguards equivalent to APPI-plus-Supplementary-Rules. The EDPB's Opinion 28/2018 on the draft adequacy decision and the EDPB's Statement 1/2023 on the first review both emphasized that data subjects must be informed not only of the recipient's practices but also of the gaps between the third country's legal framework and the level of protection guaranteed by APPI and the Supplementary Rules.
The practical effect is that onward transfers of EU/UK-origin data on the basis of consent are rare and reserved for narrow, one-off transfers where the data subject has a genuine choice and the risks are transparently disclosed. For routine or bulk onward transfers — such as the use of a U.S. cloud provider to host EU-origin data received by a Japanese subsidiary — consent is not a viable mechanism, and the PIHBO must instead pursue the contractual-safeguards pathway (binding the cloud provider to APPI-plus-Supplementary-Rules obligations).
Relationship to the EU-US Data Privacy Framework
Japan's adequacy arrangement with the EU is independent of the EU-US adequacy regime. The European Commission adopted an adequacy decision for the EU-US Data Privacy Framework (DPF) on July 10, 2023, under Decision (EU) 2023/1795, permitting transfers of EU-origin data to U.S. organizations certified under the DPF without additional safeguards. However, the PPC has not designated the United States as an adequate foreign country under Article 28 APPI. A PIHBO in Japan onward-transferring EU-origin data to a U.S. recipient therefore cannot rely on the U.S. recipient's DPF certification to satisfy Supplementary Rule (4), even though that certification would permit a direct transfer from an EU controller to the same U.S. recipient under GDPR Article 45.
Instead, the PIHBO must treat the U.S. recipient as located in a non-adequate country and either (a) bind the U.S. recipient to APPI-plus-Supplementary-Rules contractual safeguards (the contractual-measures pathway under Supplementary Rule (4)), or (b) obtain enhanced consent from the data subject after disclosing the risks of the U.S. transfer. The European Commission's March 2023 review report acknowledged this asymmetry but did not recommend that Japan designate the United States as adequate — likely because the DPF itself applies only to commercial transfers to DPF-certified organizations, while Article 28 adequacy designations are country-wide.
Recordkeeping and enforcement
PIHBOs must maintain records of all onward transfers of EU/UK-origin data under the general recordkeeping obligations incorporated by cross-reference in Article 28 APPI. These records must identify the date of the onward transfer, the items of personal data transferred, the identity of the third-country recipient, and the basis for the transfer (adequate country, contractual safeguards, or consent). The PIHBO should also retain documentary evidence of the contractual safeguards implemented (the signed data transfer agreement or binding corporate rules) and records of any consent obtained (including the information provided to the data subject before consent).
The PPC has not yet published a major enforcement action focused on Supplementary Rule (4) onward-transfer violations, but the European Commission's March 2023 review report indicated that the PPC and the European Commission are monitoring compliance closely. The EDPB has called on the European Commission to ensure that the PPC develops clearer guidance and model clauses for onward transfers, and future periodic reviews of the adequacy arrangement (scheduled every four years under GDPR Article 45(3)) will assess whether PIHBOs are implementing Supplementary Rule (4) effectively in practice.
Practical compliance sequencing for onward transfers
A PIHBO in Japan that receives EU/UK-origin data and plans an onward transfer to a third country should evaluate the Supplementary Rule (4) pathways in the following order:
- Check whether the third-country recipient is located in an adequate foreign country designated by the PPC (currently only EU member states and the UK). If yes, and if the transfer complies with Article 27 APPI, the onward transfer may proceed without additional safeguards or consent.
- If the recipient is in a non-adequate country, assess whether the recipient can implement contractual or organizational measures providing a level of protection equivalent to APPI plus Supplementary Rules. This pathway requires the PIHBO to execute a data transfer agreement or adopt binding corporate rules binding the recipient to the enhanced protections applicable to EU/UK-origin data. The PIHBO must also monitor the recipient's ongoing compliance (as required by Article 28(3) APPI) and publicly disclose the recipient's system and the PIHBO's supervision measures.
- If the recipient cannot or will not implement equivalent measures, obtain enhanced consent from the data subject after providing mandated information on the risks of the onward transfer, including the absence of adequate protection in the third country and the absence of APPI-plus-Supplementary-Rules safeguards. This pathway is viable only for narrow, one-off transfers where the data subject has genuine choice.
PIHBOs should not rely on APEC CBPR certification as a standalone basis for onward transfers of EU/UK-origin data, even though CBPR certification may satisfy the appropriate-system pathway under base Article 28 for non-EU/UK data.
Source: Supplementary Rules under the Act on the Protection of Personal Information for the Handling of Personal Data Transferred from the EU and the United Kingdom based on an Adequacy Decision, revised March 15, 2023 Source: European Commission Implementing Decision (EU) 2019/419 on the adequate protection of personal data by Japan, January 23, 2019 Source: European Commission Report on the first review of the functioning of the adequacy decision for Japan, COM(2023) 275, March 28, 2023
Supplementary Rules for EU/UK-origin data — onward transfer restrictions and enhanced protections under the adequacy arrangement
The Personal Information Protection Commission (PPC) has adopted Supplementary Rules under the Act on the Protection of Personal Information for the Handling of Personal Data Transferred from the EU and the United Kingdom based on an Adequacy Decision (most recently revised March 15, 2023, effective April 1, 2023). These Supplementary Rules are binding law for Japanese personal information handling business operators (PIHBOs) that receive personal data from the European Union or the United Kingdom under the Japan-EU/UK mutual adequacy framework.
A PIHBO that receives personal data from the EU or UK under the adequacy decision (i.e., without needing enhanced consent or an appropriate-system contract, because the adequacy whitelist eliminates the Article 28 APPI transfer barrier at the EU/UK border) must comply with both base APPI and the Supplementary Rules for that subset of data. The Supplementary Rules impose additional obligations that do not apply to personal data collected in Japan or received from non-adequate third countries. Failure to comply with the Supplementary Rules is enforceable by the PPC under Article 145–146 APPI (recommendation and order powers) and is directly actionable by EU/UK data subjects in Japanese courts under Article 84 APPI (civil liability for damages).
Purpose and legal basis of the Supplementary Rules
The Supplementary Rules were a condition of the European Commission's adequacy decision for Japan adopted on January 23, 2019 under GDPR Article 45 (Commission Implementing Decision (EU) 2019/419). The European Commission found that Japan's base APPI framework provided "essentially equivalent" protection to the GDPR for most processing activities, but identified specific gaps where APPI fell short of GDPR standards—particularly in the areas of onward transfers, sensitive data categories, data retention, and data-subject rights for short-term data. The Supplementary Rules bridge those gaps for the subset of personal data transferred from the EU/UK, ensuring that EU/UK-origin data continues to enjoy GDPR-level protection even after it arrives in Japan.
The Supplementary Rules are adopted as administrative rules under Article 6 of the Act for Establishment of the Personal Information Protection Commission (Act No. 122 of 2014). They are not statutory amendments to APPI but have equivalent binding force on regulated PIHBOs. The PPC enforces the Supplementary Rules through the same investigative, recommendation, and order mechanisms it uses for base APPI violations, and the European Commission's adequacy decision explicitly states that the Supplementary Rules are enforceable "by the independent data protection authority – the Personal Information Protection Commission (PPC) or, directly by EU individuals, in the Japanese courts."
Scope — which data is governed by the Supplementary Rules?
The Supplementary Rules apply to personal data transferred from the European Union or the United Kingdom to a PIHBO in Japan on the basis of the adequacy decision. This includes:
- Personal data of EU/UK residents transferred by an EU/UK controller or processor to a Japanese PIHBO, relying on the adequacy finding as the transfer mechanism under GDPR Article 45 or UK GDPR Article 45;
- Personal data that originated in the EU/UK and was subsequently re-transferred to Japan by a third-country recipient (for instance, personal data transferred from France to the United States and then onward-transferred from the United States to Japan), if the initial transfer out of the EU/UK was made under the Japan adequacy decision (the Supplementary Rules follow the data through subsequent hops if the adequacy bridge was used at any point in the chain).
The Supplementary Rules do not apply to:
- Personal data collected directly in Japan from data subjects who are not EU/UK residents (even if the data subject is a French national temporarily residing in Japan, the Supplementary Rules apply only to data transferred from the EU/UK, not data collected locally);
- Personal data transferred to Japan from the EU/UK using a transfer mechanism other than the adequacy decision—for instance, if an EU controller transfers personal data to a Japanese PIHBO under GDPR Article 46 standard contractual clauses (SCCs) because the controller chooses not to rely on adequacy, the Supplementary Rules do not apply (though the SCC obligations do).
In practice, a Japanese PIHBO that receives personal data from both EU/UK sources (under adequacy) and from other jurisdictions must segregate or tag EU/UK-origin data and apply the Supplementary Rules only to that subset. The PIHBO's compliance burden is higher for EU/UK-origin data than for other personal data in its possession.
Key additional obligations under the Supplementary Rules
The Supplementary Rules impose the following enhanced protections for EU/UK-origin personal data:
1. Onward transfer restrictions — consent and appropriate-system requirements are stricter than base APPI.
When a Japanese PIHBO that received personal data from the EU/UK under the adequacy decision wishes to make an onward transfer of that data to a third country (any country other than Japan, the EU, or the UK), the PIHBO must comply with Article 28 APPI plus Supplementary Rule (4).
Supplementary Rule (4) narrows the onward-transfer pathways as follows:
- Adequacy-based onward transfers are permitted only to PPC-whitelisted countries. The PIHBO may onward-transfer EU/UK-origin data to a third party in another adequate country (currently, only EU member states or the UK) without consent and without an appropriate-system contract, because the PPC whitelist satisfies Article 28 APPI. However, onward transfers to non-adequate countries (including the United States, Canada, Australia, Singapore, China, and all other jurisdictions not on the PPC whitelist) require either an appropriate-system contract or enhanced consent.
- APEC Cross-Border Privacy Rules (CBPR) certification is NOT sufficient for onward transfers of EU/UK-origin data. Under base APPI Article 28, a Japanese PIHBO may rely on the recipient's APEC CBPR certification as evidence that the recipient has established an appropriate system of data protection equivalent to APPI standards. However, Supplementary Rule (4) expressly excludes APEC CBPR certification as a valid appropriate-system mechanism for onward transfers of EU/UK-origin data. The European Commission's adequacy decision (recital 50) explains that the APEC CBPR system "does not result from an arrangement binding the exporter and the importer in the context of their bilateral relationship and is clearly of a lower level than the one guaranteed by the combination of the APPI and the Supplementary Rules." The PIHBO must instead implement a bilateral contract, binding corporate rules (BCRs), or other binding arrangement with the onward-transfer recipient that imposes obligations equivalent to APPI plus the Supplementary Rules—not just base APPI.
- Enhanced consent requirements for onward transfers. If the PIHBO cannot establish an appropriate system with the onward-transfer recipient (because the recipient is unwilling to contractually commit to APPI-plus-Supplementary-Rules standards), the PIHBO must obtain the data subject's enhanced consent under Article 28(1) and (2) APPI. Supplementary Rule (4) requires that the consent be "provided information on the circumstances surrounding the transfer necessary for the principal to make a decision on his/her consent." The PPC and the European Data Protection Board (EDPB) have both emphasized that this consent must be genuinely informed about the risks of the onward transfer, including the absence of adequacy in the destination country and the absence of the Supplementary Rules' protections once the data leaves Japan. The EDPB's Statement 1/2023 on the first Japan adequacy review notes concern that "some clear guideline on this would be helpful to ensure that the level of protection for personal data transferred to Japan from the EEA would not be undermined in case of onward transfers on the basis of consent," particularly for employee data where there may be a power imbalance making consent unreliable.
In summary, for onward transfers of EU/UK-origin data, the PIHBO must:
- Check whether the onward-transfer destination is on the PPC whitelist (EU/UK only). If yes, proceed under Article 28 adequacy exception.
- If no, implement a bilateral contract or BCRs that bind the recipient to APPI-plus-Supplementary-Rules obligations (APEC CBPR is not enough).
- If the recipient will not contractually commit, obtain enhanced consent from the data subject with full disclosure of the onward-transfer risks.
2. Expanded definition of sensitive data (special categories of personal data).
APPI Article 2(3) defines "care-required personal information" (sensitive data) to include data relating to race, creed, social status, medical history, criminal record, and fact of victimization by crime. The Supplementary Rules expand this definition for EU/UK-origin data to align with GDPR Article 9's "special categories of personal data." Supplementary Rule (2) provides that, for personal data transferred from the EU/UK, the PIHBO must also treat as sensitive data:
- Genetic data (within the meaning of GDPR Article 4(13));
- Biometric data processed for the purpose of uniquely identifying a natural person (GDPR Article 4(14));
- Data concerning health (GDPR Article 9(1));
- Data concerning a person's sex life or sexual orientation (GDPR Article 9(1)).
The expanded sensitive-data categories trigger the heightened consent and purpose-limitation obligations under APPI Article 20(2) (requirement to obtain consent for acquisition of care-required personal information, subject to narrow statutory exceptions). In practice, a PIHBO that receives health data or biometric data from the EU/UK must obtain consent for its acquisition and use under the Supplementary Rules, even if base APPI would not classify that data as care-required personal information.
3. No exemption for short-term retention — data-subject rights apply to all EU/UK-origin data.
Under base APPI as it existed before the 2020 amendments, the term "retained personal data" (to which data-subject rights of disclosure, correction, suspension of use, and erasure apply under Articles 32–34 APPI) excluded personal data that the PIHBO holds for six months or less. PIHBOs could avoid disclosure obligations by deleting data within six months. The Supplementary Rules eliminate the six-month exemption for EU/UK-origin data. Supplementary Rule (3) provides that, for personal data transferred from the EU/UK, data-subject rights under Articles 32–34 APPI apply regardless of the retention period. An EU/UK data subject may demand disclosure, correction, or erasure of her personal data even if the PIHBO holds it for only a few weeks.
This restriction was incorporated into base APPI effective April 2022 by the 2020 amendments, which abolished the six-month exemption for all personal data (not just EU/UK-origin data). The Supplementary Rules remain in force to clarify that the six-month exemption never applied to EU/UK-origin data, even before the 2020 APPI amendments.
4. Enhanced transparency and information-provision obligations.
Supplementary Rule (5) requires that, when providing the mandatory information to data subjects under APPI Article 18 (purpose of use) and Article 27 (third-party provision notifications), the PIHBO must ensure that the information is "provided in an intelligible form and in clear and plain language" that enables the data subject to understand the processing. This tracks GDPR Article 12(1)'s transparency standard. The PPC's guidance clarifies that PIHBOs handling EU/UK-origin data should avoid dense legalese, use layered notices where appropriate, and ensure that key disclosures (such as onward-transfer destinations and retention periods) are prominently presented, not buried in a 30-page privacy policy.
5. Recordkeeping and accountability — the PIHBO must be able to demonstrate Supplementary Rules compliance.
The PPC conducts random audits to verify compliance with the Supplementary Rules. In its March 2023 report on the first periodic review of the Japan adequacy decision, the European Commission noted that "the PPC announced that it will carry out random checks to ensure compliance with the Supplementary Rules, rather than continuing with the exclusive use of the non-coercive, soft-law powers of guidance." PIHBOs that receive EU/UK-origin data under the adequacy framework should maintain documentation demonstrating:
- The source and legal basis of the EU/UK data transfer (confirmation from the EU/UK data exporter that the transfer relies on the Japan adequacy decision);
- The systems and procedures the PIHBO has implemented to segregate or tag EU/UK-origin data and apply the Supplementary Rules to that subset;
- Records of any onward transfers of EU/UK-origin data, including the identity of the recipient, the onward-transfer mechanism (adequacy, appropriate-system contract, or enhanced consent), and copies of any bilateral contracts or BCRs;
- Evidence of compliance with the expanded sensitive-data definitions and the no-short-term-exemption rule for data-subject rights requests.
The PPC has enforcement authority under APPI Articles 145–146 to issue recommendations and orders directing a PIHBO to cease non-compliant onward transfers, implement remedial measures, or notify affected data subjects. Violation of a PPC order is subject to criminal penalties under APPI Articles 178–179 (up to one year imprisonment or ¥1 million fine for individuals; up to ¥100 million fine for corporations).
The 2023 revision and ongoing convergence between APPI and the Supplementary Rules
The Supplementary Rules were originally adopted on January 23, 2019, simultaneously with the entry into force of the Japan-EU mutual adequacy arrangement. They were revised on March 15, 2023 (effective April 1, 2023) to reflect the 2020 amendments to APPI. Many protections that were initially unique to the Supplementary Rules have since been incorporated into base APPI, making them applicable to all personal data regardless of origin. For instance:
- The abolition of the six-month exemption for "retained personal data" (originally Supplementary Rule (3), now incorporated into base APPI Article 16(4) effective April 2022);
- The mandatory information-provision requirement for cross-border transfer consent (originally a Supplementary Rules concept, now codified in APPI Article 28(2) effective April 2022).
The European Commission's March 2023 report on the first periodic review of the Japan adequacy decision notes that "some of the additional safeguards provided under the Supplementary Rules for personal data coming from the EU, i.e. as regards data retention and the conditions for informed consent for cross-border transfers, have been incorporated into the APPI, thereby making them generally applicable to all personal data, irrespective of their origin or point of collection." This convergence reduces the compliance gap between EU/UK-origin data and other personal data, but key distinctions remain—most importantly, the onward-transfer restrictions (prohibition on APEC CBPR for onward transfers, requirement for APPI-plus-Supplementary-Rules equivalence in contracts) and the expanded sensitive-data categories continue to apply only to EU/UK-origin data.
Practical compliance sequencing for Japanese PIHBOs
A Japanese PIHBO that receives personal data from the EU or UK under the adequacy framework should:
- Identify and tag EU/UK-origin data in its systems so that it can apply the Supplementary Rules to that subset.
- Review onward-transfer arrangements. If the PIHBO onward-transfers EU/UK-origin data to service providers, affiliates, or other third parties in non-adequate countries (including the United States, China, Singapore, or any country other than EU/UK member states), verify that the onward-transfer mechanism is not based solely on APEC CBPR certification. Implement bilateral contracts or BCRs that impose APPI-plus-Supplementary-Rules obligations on the recipient, or obtain enhanced consent.
- Expand sensitive-data handling procedures to cover genetic data, biometric data, health data, and sex-life/sexual-orientation data received from the EU/UK, even if base APPI would not classify those items as care-required personal information.
- Honor data-subject rights requests from EU/UK data subjects regardless of the retention period—no six-month exemption.
- Maintain audit-ready records of EU/UK data flows, onward-transfer contracts, and Supplementary Rules compliance measures, and be prepared for PPC random audits.
The Supplementary Rules are a reminder that adequacy is not a free pass. While the Japan-EU/UK adequacy arrangement eliminates the need for consent or contracts at the point of initial transfer from the EU/UK to Japan, it does so by imposing additional obligations on the Japanese recipient that travel with the data throughout its lifecycle in Japan and any subsequent onward transfers. A PIHBO that treats EU/UK-origin data identically to domestically collected data will violate the Supplementary Rules and jeopardize the adequacy framework.
Source: Supplementary Rules under the Act on the Protection of Personal Information for the Handling of Personal Data Transferred from the EU and the United Kingdom based on an Adequacy Decision, PPC, revised March 15, 2023, effective April 1, 2023 Source: European Commission Implementing Decision (EU) 2019/419 of 23 January 2019 on the adequate protection of personal data by Japan Source: European Commission Report on the first review of the functioning of the adequacy decision for Japan, March 2023
Recordkeeping and audit requirements for cross-border transfers under Article 28 APPI
Personal Information Handling Business Operators (PIHBOs) in Japan must comply with detailed recordkeeping and transparency requirements for every cross-border transfer of personal data under Article 28 of the Act on the Protection of Personal Information (APPI). These duties are codified in Articles 28 and 29 of APPI, and further specified in the PPC’s Enforcement Rules (notably Rule 11-3, July 2022; see source).
Required transfer records For each provision of personal data to a third party in a foreign country—whether the transfer relies on a PPC-designated adequate country, an appropriate-system contract, or enhanced consent under Article 28(1)—the PIHBO must create and maintain a record of:
- The date of transfer (Art. 29(1)(i), Rule 11-3(1)(i))
- The name and address of the recipient (or, if impracticable, the recipient’s category and location) (Art. 29(1)(ii), Rule 11-3(1)(ii))
- The types or items of personal data provided (Art. 29(1)(iii), Rule 11-3(1)(iii))
- The method of provision (Art. 29(1)(iv), Rule 11-3(1)(iv))
- The legal basis for the transfer (e.g., adequacy decision, appropriate-system pathway, or consent; Rule 11-3(1)(v))
- Where the transfer is based on the appropriate-system or consent pathway: evidence of the relevant procedural safeguard (e.g., a copy of the contract or consent and, where applicable, information provided under Article 28(2))
These records must be retained for a minimum of three years from the date of each transfer (Art. 29(2), Rule 11-3(2)).
PPC inspection and supervision The Personal Information Protection Commission (PPC) is authorized to request submission of these records and inspect a PIHBO’s handling of personal data, under APPI Articles 145–146 (orders and recommendations) and Article 152 (general audit and investigatory power). The statute does not detail specific audit triggers or cycles for cross-border transfers, but these inspection powers cover all records required under Article 29 and Rule 11-3.
Scope and documentation practice The recordkeeping requirements apply to all cross-border transfers, including those to affiliates or group companies. The law does not require a specific format, but records should clearly document each transfer event and the compliance pathway used. The PPC has authority to issue orders or recommendations to any PIHBO found to be in violation of these requirements. As of June 2026, there is no published PPC enforcement decision solely focused on cross-border transfer recordkeeping obligations.
Source: Act on the Protection of Personal Information (APPI), Arts. 28–29, 2020 English translation Source: PPC Enforcement Rules for the APPI, Rule 11-3, July 2022
PPC guidelines on transfer impact assessments (TIAs) for cross-border transfers
The Personal Information Protection Commission (PPC) has issued specific guidance on how Personal Information Handling Business Operators (PIHBOs) must assess the risk of overseas transfers to non-adequate countries, especially when relying on the "appropriate system" pathway under Article 28(1) of the Act on the Protection of Personal Information (APPI). While Japanese law does not use the term “transfer impact assessment” (TIA) as in the EU GDPR, the 2022 amendments to APPI and the updated "Guidelines on Protection of Personal Information" (Foreign Third Parties), as revised by the PPC in April 2022, set out an expectation that PIHBOs will conduct a documented assessment of both recipient-country laws and the recipient's measures before transferring personal data overseas.
Scope and triggers
- The assessment requirement applies when a PIHBO transfers personal data to a third party in a non-adequate country (i.e., not in the EU or UK) and wishes to rely on the "appropriate system" rather than enhanced consent (APPI Art. 28(1); Guidelines (Foreign Third Parties), Part 2).
- The PIHBO must confirm that the recipient’s data protection system is “equivalent” to Japan’s, taking into account both the local legal/regulatory risks and the effect of the recipient’s internal rules and contractual commitments.
Content of the required assessment The PPC’s guideline outlines the following steps for a compliant TIA-equivalent:
- Analyze recipient country law on privacy, security, government access, and data subject rights. The PIHBO must confirm whether there are substantive risks that government authorities in the destination country (including courts, law enforcement, or intelligence agencies) could compel the recipient to disclose personal data, and if so, what safeguards, legal remedies, and restrictions apply.
- Evaluate recipient’s internal measures: Policies, technical and organizational safeguards, contract terms, and past compliance history. The PIHBO must confirm the recipient’s documented rules, the technical measures in place, and the enforceability of obligations (e.g., through a data transfer agreement binding the recipient to APPI-equivalent standards).
- Document supervisory/oversight plan: Article 28(3) requires ongoing supervision by the PIHBO, including periodic verification and remedial action for non-compliance.
This analysis must be documented in a way that the PPC can review (see APPI Art. 29 recordkeeping and the Guidelines, Q9–Q14). There is no mandatory template; however, the PPC strongly recommends a written record containing: a summary of country law analysis, identification of specific risks, description of recipient safeguards, the legal basis for transfer, and ongoing monitoring plan. The PPC may request this documentation during an audit or enforcement action.
The PIHBO must also make summary information about the assessment (including country-specific and recipient-specific risks and safeguards) available to data subjects either in its privacy notice or upon request, in line with the transparency requirements in Article 28(3) and Article 32 APPI.
Enforcement and consequences of failure Failure to perform a documented assessment or to maintain adequate records may result in a recommendation, order, or sanction under APPI Articles 145–146. The PPC emphasizes that “sufficient evidence of appropriate action must be available to prove compliance.” No published enforcement actions to date have focused solely on TIA failures, but the trend toward greater scrutiny continues following the 2022 overhaul of PPC guidance.
Source: PPC Guidelines on Protection of Personal Information (Foreign Third Parties), April 2022
Exceptions to Article 28 restriction — life, body, property, and public-duty carve-outs under Article 27(1) APPI
Article 28 of the Act on the Protection of Personal Information (APPI) restricts personal information handling business operators (PIHBOs) in Japan from transferring personal data to a third party in a foreign country except through one of the statutory mechanisms set out in Article 28. However, Article 28 explicitly states that its restriction does not apply where a transfer falls under certain exceptions listed in Article 27(1) APPI.
Article 27(1) APPI — Statutory exceptions A PIHBO may provide personal data—including to a third party located overseas—without obtaining the data subject’s consent and without relying on the Article 28 transfer mechanisms, if the disclosure falls within any of the following exceptions set out in Article 27(1):
- Required by law (Art. 27(1)(i)): The provision is based on applicable legal obligations (for example, a subpoena or legal mandate).
- Life, body, or property emergencies (Art. 27(1)(ii)): The provision is necessary for the protection of an individual’s life, body, or property, and it is difficult to obtain the principal’s consent. (E.g., a hospital might transfer patient data for emergency treatment abroad; this is an illustrative example and not from the official statute or rules.)
- Public health or children’s development (Art. 27(1)(iii)): The provision is necessary for improving public health or promoting the healthy development of children and it is difficult to obtain consent.
- Cooperation with government/public bodies (Art. 27(1)(iv)): The provision is necessary for cooperation with a national governmental organ, local public body, or their agent in carrying out duties prescribed by law, and obtaining consent would impede those duties (e.g., responding to certain law enforcement requests).
- Other exceptions: Academic, artistic, or journalistic activities with continuous data provision under prescribed requirements (Art. 27(1)(v)), and entrustment to a subcontractor (Art. 27(1)(vi))—note entrustment typically does not count as a “third-party provision” for Article 28 purposes if the subcontractor acts only on documented instructions.
Recordkeeping and compliance If a transfer is based on an Article 27(1) exception, the PIHBO may proceed directly with the foreign transfer and is not required to obtain the data subject’s consent or implement an appropriate-system contract under Article 28. However, recordkeeping obligations in Article 29 and Rule 11-3 of the PPC Enforcement Rules still apply unless the specific transfer falls within a recordkeeping exemption. Required records include the date, recipient, data items, method of transfer, and the legal basis (i.e., the relevant Article 27(1) item).
Limitation The statute provides the list of exceptions but does not specify interpretation standards, detailed procedural requirements for invoking an exception, or PPC enforcement practices on this point. Practitioners should read the statutory language closely to confirm fit. Official PPC guidance or enforcement case law may further develop these requirements.
Source: Act on the Protection of Personal Information (APPI), Arts. 27–28, 2020 English translation Source: PPC Enforcement Rules for the APPI, Rule 11-3, July 2022
Entrustment to processors (subcontractors) — Article 28(5) and when overseas service providers are *not* a third-party transfer under APPI
Under Japan’s Act on the Protection of Personal Information (APPI), not all cross-border data flows are regulated as "third-party provisions" requiring compliance with Article 28.
A crucial distinction recognized by APPI—and clarified in Personal Information Protection Commission (PPC) guidelines—is entrustment (委託, itaku) to a processor or subcontractor acting solely on the instructions of the data exporter (the personal information handling business operator, PIHBO). This is functionally equivalent to the “processor” concept known under GDPR.
APPI Article 28(5) refers to Article 27(1)(vi), which carves out entrustment as not a third-party transfer. When a PIHBO provides personal data to a party acting solely “on behalf of the business in whole or in part, within the scope necessary for achieving the purpose of utilization,” such provision is considered entrustment (not a third-party provision) and is not subject to the cross-border transfer restrictions of Article 28. This applies even if the entrusted recipient is located overseas. Mandatory conditions are that:
- The recipient is acting only on the PIHBO’s documented instructions;
- The data is processed within the scope necessary for the business’s own purposes;
- There is no further use or provision by the recipient for its own purpose or unrelated purposes.
Compliance obligations for overseas entrustment: While Article 28’s cross-border restrictions do not apply, Article 26 APPI requires the PIHBO to exercise necessary and adequate supervision over any entrusted party—including foreign vendors or processors. This includes:
- Due diligence on the foreign subcontractor’s data management and security;
- Contractual obligations to observe APPI-equivalent protection measures;
- Ongoing monitoring of compliance.
PPC’s official guidance (see Guidelines on Protection of Personal Information, revised April 2022: Section 3-1-5, Q14) confirms that a processor or cloud provider receiving data for “business entrustment” is not a third party under Article 28, but makes clear that supervision and documentation obligations remain. The PIHBO should include details about such overseas entrustments in its privacy notice and be able to evidence its supervisory steps if requested by the PPC.
If the entrusted vendor uses the data beyond the PIHBO’s instructions or for its own purposes, the exception does not apply; the transfer will be regulated as a third-party provision.
Comparison to GDPR: Under the EU GDPR, this concept maps to controller-processor relations, where a processor acting solely on instructions does not trigger the international transfer rules for controller-to-processor transfers within an adequate jurisdiction.
Key practical compliance steps:
- Document the entrustment relationship and ensure the contract restricts processing to PIHBO instructions;
- Carry out due diligence and ongoing oversight of the overseas processor’s technical and organizational measures;
- Update public privacy disclosures to cover foreign outsourcing arrangements;
- Treat any non-instructed data use as a “third-party provision” subject to Article 28.
Source: Act on the Protection of Personal Information (APPI), 2020 English translation, Articles 26, 27(1)(vi), and 28(5) Source: PPC Guidelines on Protection of Personal Information (General Rule) (April 2022) Section 3-1-5, Q14
Ongoing supervision obligation for cross-border transfers — Art. 28(3) APPI and PPC guidance
Article 28(3) of the Act on the Protection of Personal Information (APPI) requires a Personal Information Handling Business Operator (PIHBO) that relies on the "appropriate-system" pathway for cross-border transfers to take "necessary action to ensure that the third party appropriately and continuously takes the said action for the protection of personal information." This obligation goes beyond establishing one-time contractual safeguards: it requires active and ongoing supervision of the foreign recipient’s data protection measures.
Scope of the ongoing supervision requirement
- The text of Article 28(3) APPI sets out that a PIHBO must ensure the recipient’s continued compliance with APPI-equivalent protection. The law does not list specific steps, leaving the precise operational requirements to be shaped by PPC rules and official guidance.
- The PPC Guidelines (Foreign Third Parties, April 2022, Q14) clarify that, while no fixed method is dictated, "it is expected that the business operator will check the recipient’s handling status at regular intervals and confirm the continued implementation of the necessary measures," and that this may include contractual arrangements for suspension or termination of the transfer if the recipient ceases to maintain the required protection standard.
- Practically, PPC guidance contemplates: (1) periodic checks or confirmations of compliance (which may be annual at minimum, but timing and modality are not set by the law); (2) contracts specifying that the recipient must report any incident or change affecting data protection, and that the transfer may be suspended or ceased if appropriate protection is no longer provided; and (3) maintaining records of supervision actions and responses to data subject requests for information about these measures.
- The PIHBO also has a duty to publicly announce information about the system the third party has established and the measures taken by the PIHBO to ensure protection, and must provide this information to data subjects upon request (Art. 28(3) APPI).
PPC expectations and distinction from best practices
The statute and guidelines do not prescribe a specific format (such as mandatory audits), nor do they require particular types of investigation protocols or remediation measures. Rather, the PPC highlights the expectation of operational oversight matched to the scale and risk of the transfer. Some practices (such as annual audits, or spot checks) may be prudent but are not strictly required under the letter of Japanese law or guidance as of June 2026.
The law and guidance are silent on the specific frequency or content of checks, leaving implementation to the PIHBO’s discretion based on the facts of the transfer. Similarly, while documentation of these activities is important for PPC inquiries, there is no defined standard for the content or manner of such documentation.
Enforcement context
If a PIHBO fails to carry out appropriate ongoing supervision or the recipient no longer maintains the required protection, the PPC may issue a recommendation or order (Arts. 145–146 APPI) and expect prompt remedial action. Unable to confirm as of 2026-06-16 whether any enforcement decisions have been published solely on this supervision obligation.
Source: Act on the Protection of Personal Information (APPI), Art. 28(3), 2020 English translation Source: PPC Guidelines on Protection of Personal Information (Foreign Third Parties), April 2022, Q14
Article 32 APPI data-subject information and transparency obligations for cross-border transfers
Article 32 of Japan’s Act on the Protection of Personal Information (APPI) establishes a duty for any personal information handling business operator (PIHBO) to inform data subjects, upon request, about how their personal data is managed—including when it is transferred internationally. This transparency obligation is distinct from, and supplemental to, the enhanced pre-consent disclosures required by Article 28(2) APPI for the consent pathway. It also operates independently of the adequacy whitelist, appropriate-system pathway, or entrustment.
Legal text and supervisory expectations
Under Article 32: "A personal information handling business operator shall, when requested by a principal to inform the principal of the purpose of use of retained personal data pertaining to the principal, inform the principal without delay, except in cases falling under any of the items of Article 33, paragraph (1)." If a PIHBO holds personal data that has been or may be transferred overseas, current PPC guidelines clarify that the operator must, upon data subject request:
- Provide the name or category, and the country, of foreign recipient(s) of the data (see Guidelines on Foreign Third Parties, Q7–Q8);
- Specify the legal ground for the transfer (adequacy, contract/appropriate system, consent, entrustment), and outline key safeguards such as whether a contract is in place and who is responsible for ongoing oversight (Q9–Q10);
- State the purpose of use for the foreign transfer, consistent with Article 18 (purpose notification) (Q7).
The guidelines state: "It is desirable that business operators provide clear information about international transfers proactively in their privacy policies, but if not provided, this information must be given without delay in response to individual requests." Privacy notices should describe typical transfer destinations and basis, but the minimum legal requirement is to respond to requests under Article 32.
Practical compliance:
- Regularly review and update privacy policies to describe cross-border transfers and mechanisms for transfer;
- Establish clear procedures for responding to Article 32 requests, ensuring the ability to identify overseas recipients and confirm the legal transfer ground;
- Maintain documentation to evidence the basis and safeguards for each cross-border transfer.
Article 32 does not require publication of complete contract texts or technical details, but requires sufficient detail to enable the data subject to understand the destination, purpose, ground, and general protections for their data. Enforcement is governed by the APPI’s general recommendation and order powers if operators fail to comply. Unable to confirm as of 2026-06-16 whether the PPC has published any enforcement actions focused only on Article 32 cross-border transparency.
Cross-border transfers of care-required (special-category) personal information under APPI Article 28 and 2(3)
Japan’s Act on the Protection of Personal Information (APPI) imposes heightened requirements for the cross-border transfer of “care-required personal information”—the term used for what is known in other regimes as special-category or sensitive data. Article 2(3) APPI defines care-required personal information to include data revealing race, creed, social status, medical history, criminal record, victim-status, and, for data originating in the EU or UK, the expanded Supplementary Rules further cover genetic, biometric, health, and sex-life/sexual-orientation data.
Legal triggers for extra protection
Cross-border transfers of care-required personal information to a third party (not mere entrustment to a processor) are regulated under the same Article 28 mechanisms as other personal data. However, Article 20(2) APPI requires the business operator to obtain explicit consent from the principal before acquiring care-required data (with narrow statutory exceptions under Article 20(3)), and this explicit consent requirement overlays the normal Article 28 cross-border transfer obligations.
International transfers — overlay of Article 28 and Article 20 duties
- When transferring care-required personal information to a recipient in a foreign country, the personal information handling business operator (PIHBO) must:
- Satisfy the general requirements for overseas transfers under Article 28 (adequacy, appropriate system, or enhanced consent—each with information provision under Art. 28(2)).
- In addition, ensure that, if the transfer involves acquisition or provision of care-required personal information, explicit consent is obtained from the data subject prior to acquisition (Art. 20(2)), unless a statutory exception applies. This means that even for recipients in adequate countries (EU/UK), acquisition and transfer of care-required personal information generally requires express consent unless exemption conditions are satisfied.
- Supplementary Rules expand the list of covered sensitive items for EU/UK-origin data, so PIHBOs handling such transfers must map the data they receive, determine whether it meets the broader Supplementary Rules definition, and apply both the explicit consent and Article 28 (or Supplementary Rule) transfer conditions.
Practical compliance
- PIHBOs must design collection and transfer flows to separate care-required from ordinary personal information, ensure documentation and records of express consent, and fulfill enhanced Article 28(2) information duties when using the consent pathway for cross-border transfers.
- If the appropriate-system pathway is used, the contract or organizational measures with the foreign recipient must include APPI-equivalent protections for sensitive data, and ongoing supervision should specifically cover the handling of such categories.
Enforcement and records The APPI imposes additional sanctions for unauthorized acquisition or provision of care-required personal information, and the PPC’s Guidelines (General Rule, April 2022) clarify that stricter handling is expected for cross-border transfers involving these categories. PIHBOs should be able to evidence separate consent and the documented grounds for any statutory exception relied upon, in addition to general Article 28 recordkeeping.
Source: Act on the Protection of Personal Information (APPI), Art. 2(3), 20, 28, April 2022 English translation Source: PPC Supplementary Rules, Mar. 2023, expanded sensitive category definitions Source: PPC Guidelines on Protection of Personal Information (General Rule), April 2022
Cross-border transfers of anonymized and pseudonymized information under APPI Articles 36–37
Japan’s Act on the Protection of Personal Information (APPI) establishes specific transfer regimes for "anonymously processed information" and "pseudonymously processed information" (Articles 36 and 37, as amended effective April 2022). Understanding these categories and their transfer implications is critical for privacy and compliance architects engaged in analytics, R&D, or data sharing.
Anonymously Processed Information (API)—Article 36
Under Article 2(6), "anonymously processed information" is information relating to an individual that has been processed such that (i) the individual cannot be identified and (ii) the information cannot be restored by any means. Article 36(1) makes clear that, as long as data qualifies as API under this standard, it is no longer considered "personal data" for APPI purposes. The core consequence: Overseas transfers of API are not subject to APPI Article 28’s cross-border transfer regime. There is no need for adequacy, contracts, or consent mechanisms. However, Article 36(2)–(5) require that a personal information handling business operator (PIHBO, defined in Art. 16(2) as any business that handles a personal information database) publicly announce — "in a manner easily accessible to the principal" — (a) the categories of information contained, (b) key items regarding the processing method, and (c) the purpose of provision. API providers must also, by law, not attempt to re-identify individuals or collude for re-identification. The required publicity is statutory; the PPC Guidelines (2022) elaborate on compliant formats. Providers should also retain documentation of their anonymization process to substantiate compliance if challenged, though the recordkeeping duty itself arises from the Guidelines not the statute.
Pseudonymously Processed Information (PPI)—Article 37
Article 2(5) defines "pseudonymously processed information" as personal data processed such that it cannot identify a specific individual unless combined with additional information — and where that additional information is managed separately under strict controls. Article 37 relaxes certain data subject rights (notably: no duty to respond to requests for disclosure, correction, etc., unless additional information is combined), but PPI remains personal data under APPI. Cross-border transfers of PPI are subject to the full Article 28 regime. This means that PIHBOs must follow the adequacy, appropriate-system, or enhanced consent transfer pathways; no general exemption applies merely because the data is pseudonymized. PPI can reduce domestic disclosure obligations, but it does not relax international transfer requirements.
Practice point for cross-border compliance
- Fully anonymize data (to the Article 2(6) threshold, irreversibility required) for analytic or research transfers seeking to bypass Article 28; publicize and document as required by Article 36.
- For data pseudonymized by technical means but theoretically reversible, treat as PPI — plan for Article 28 compliance on cross-border transfers.
- The PPC’s 2022 Guidelines (see pp. 33–37) recommend concrete steps for documenting anonymization, formats for API publicity, and practical risk controls; these are especially relevant in disputed or audit scenarios.
Source: Act on the Protection of Personal Information (APPI), Arts. 2(5), 2(6), 36, 37, April 2022 English translation Source: PPC Guidelines on Anonymously Processed Information, April 2022
Country-level system disclosure for cross-border transfers — Art. 28(2) APPI and PPC Guidelines
Article 28(2) of the Act on the Protection of Personal Information (APPI) requires that, before obtaining data subject consent for a cross-border transfer under the "enhanced consent" pathway, the Personal Information Handling Business Operator (PIHBO) must provide the principal with information on both the "personal information protection system of the foreign country" and the technical/organizational measures used by the foreign recipient. This section addresses the country-level system disclosure requirement—distinct from the recipient-specific security and contractual measures—and details what the PIHBO must include to meet PPC expectations as of June 2026.
What is "personal information protection system of the foreign country”? According to the statutory text (APPI Art. 28(2)) and PPC Enforcement Rule 11-2(3), the PIHBO must provide advance information on the privacy-related legal/regulatory regime of the recipient’s country. The PPC’s Guidelines on Protection of Personal Information (Foreign Third Parties, April 2022, Part 2, Q9-Q11) specify that the system disclosure should cover:
- Existence and outline of privacy/data protection laws in the foreign country (is there a comprehensive regime analogous to APPI, or only sector-specific legislation?)
- Supervisory authority and its enforcement powers (whether there is an independent body with authority to investigate, issue orders, impose penalties, accept complaints from data subjects)
- Scope and enforceability of data subject rights available under local law (access, correction, erasure, objection, redress mechanisms)
- Conditions under which government authorities may access personal data (law enforcement, intelligence, and any legal remedies or restrictions around such access)
- Other relevant features such as required breach notifications, restrictions on onward transfers, or typical challenges in cross-border enforcement
A PIHBO is expected to use current, factual, and publicly available information—drawing directly from authoritative sources (foreign government publications, laws in English translation if available, regulator websites, or, in some cases, PPC or Ministry of Justice resources). Unsupported marketing claims or generic assurances (“the country takes privacy seriously”) do not meet the legal standard.
Level of detail and language standard The PPC has emphasized that the system disclosure must be “sufficiently specific to serve as a reference to the principal” (Guidelines, Q9). Boilerplate or copy/paste from an internal compliance matrix is not sufficient unless substantively accurate for the country in question. The PIHBO must update the disclosure if material changes occur in recipient-country law or regulatory climate, and must present the information in plain language, avoiding legalese.
Relationship to the TIA and recipient-specific disclosures The country-level system disclosure is required even if the PIHBO has completed a full TIA or detailed recipient-specific due diligence. The TIA and contract review are inward-facing, while this information is directed to the data subject as part of pre-consent transparency. For high-risk jurisdictions (e.g., those with extensive government access provisions or limited supervisory enforcement), the PIHBO should clearly flag these features for the data subject’s awareness prior to consent.
The PPC notes that if reliable current information cannot be obtained (for instance, due to crisis, lack of transparency, or undetermined legal regime), the PIHBO must disclose that uncertainty and describe what is known or unknown at time of transfer. There is no requirement to provide a binding legal opinion—factual detail and candor are key.
Failure to adequately disclose the foreign country’s personal information protection system renders any consent invalid and may expose the PIHBO to PPC enforcement under Articles 145–146 APPI.
Source: Act on the Protection of Personal Information (APPI), Art. 28(2), 2020 English translation Source: PPC Guidelines on Protection of Personal Information (Foreign Third Parties), April 2022, Q9–Q11