Japan’s APPI requires control over purpose, recipients and the evidence connecting them.
Japan’s Act on the Protection of Personal Information governs how organizations acquire, use, secure, share and transfer personal information. The framework distinguishes personal information, personal data, retained personal data, personal related information and specially processed datasets — and applies different requirements to each. Captain Compliance helps teams discover digital collection, publish clear notices, manage consent and requests, document recipients and prepare for qualifying leakage events.
The question is not only whether information was collected. It is what happened after collection.
An organization must specify the purpose of using personal information as explicitly as reasonably possible. Using it beyond the reasonably related scope of that purpose generally requires consent unless an exception applies.
The purpose of use generally must be communicated to the individual or publicly announced. When information is obtained directly from a written document, including an electronic form, the purpose generally must be stated beforehand unless an exception applies.
Personal information must not be acquired through deception or other improper means. Acquiring special care-required personal information generally requires advance consent unless a statutory exception applies.
Organizations must implement necessary and appropriate security safeguards and supervise employees and entrusted service providers handling personal data. Entrustment, business succession and qualifying joint use are not treated identically to ordinary third-party provision.
Providing personal data to an independent third party generally requires advance consent unless an exception or valid opt-out arrangement applies. Organizations may also need to create, verify and retain records of personal-data provisions and receipts.
Providing personal data to a third party in a foreign country may rely on informed consent, an equivalent-country designation, or a recipient maintaining qualifying equivalent safeguards. Each path carries different information, documentation and monitoring requirements.
Cookie identifiers, browsing histories, location data and similar information may constitute personal related information when they do not identify an individual for the provider. Additional confirmation and recordkeeping can apply when a recipient is expected to acquire that information as personal data.
Not every incident is reportable. Qualifying events include those involving special care-required personal information, risk of financial or property damage, a potentially wrongful purpose, or personal data concerning more than 1,000 individuals. Report promptly to the PPC, generally within approximately three to five days after discovery, with a final report generally within 30 days — or 60 days where a wrongful purpose may be involved. Individuals also receive rights involving disclosure, correction, addition, deletion, cessation of use, erasure and cessation of third-party provision.
Under the currently effective law, corporate fines of up to ¥100 million may apply to specified offenses, including certain violations of PPC orders and improper provision or misappropriation of personal-information databases. The PPC may also investigate, request reports, conduct inspections, provide guidance, issue recommendations and issue orders. This is not an automatic fine for every compliance mistake.
A transfer may rely on advance consent covering provision to a foreign third party. Before obtaining consent, the organization generally must provide information about the foreign country’s personal-information protection system and the recipient’s protective measures, to the extent required by PPC rules.
A transfer may occur to a third party in a country designated by the PPC as having a personal-information protection system equivalent to Japan’s. The EU and United Kingdom are currently recognized, subject to applicable details and supplementary requirements.
A transfer may rely on the recipient maintaining a qualifying system of safeguards equivalent to APPI requirements, including through an appropriate contractual or organizational arrangement or applicable international certification framework. The transferring organization must periodically confirm the safeguards continue, generally at approximately annual intervals or more frequently, review foreign legal developments affecting them, address problems, and stop transfers if continued safeguards cannot be ensured. Statutory exceptions may also apply; transfer classification should be reviewed with qualified Japanese counsel.
Make purposes, choices and recipients traceable.
Captain Compliance helps privacy, legal, security and engineering teams connect website behavior with notices, consent, request handling, recipients, transfer pathways and incident evidence.
Real-time tracker discovery
Continuously identify cookies, pixels, scripts and third-party technologies that may collect personal information or personal related information.
Consent and preference controls
Configure consent and preference experiences for activities that require or rely on consent, without treating consent as the universal APPI processing basis.
Purpose-of-use notices
Publish and version disclosures describing purposes of use, request procedures, contact information and other required information.
Recipient and transfer mapping
Document domestic recipients, entrusted processors, joint-use arrangements, foreign recipients, destination countries and the selected transfer pathway.
Individual-rights workflows
Centralize requests involving disclosure, correction, addition, deletion, cessation of use, erasure and cessation of third-party provision.
Leakage-response workflow
Organize discovery time, affected information, individual counts, risk categories, preliminary reports, final reports, individual notices and remediation evidence.
Vendor and safeguard monitoring
Record entrusted service providers, security requirements, foreign-recipient safeguards, review dates and remediation decisions.
Information-category governance
Helps distinguish personal information, personal data, retained personal data, personal related information, pseudonymously processed information and anonymously processed information.
Japan has enacted its next APPI update. Implementation comes next.
Japan’s 2026 amendment was enacted 10 July and promulgated 17 July 2026. Except for limited provisions, it will take effect on a date established by Cabinet Order within two years. The PPC is still preparing implementing orders, rules and guidance. Children — express rules involving individuals under 16, including legal-representative involvement for certain consent and notice matters, and a best-interests consideration. Facial-feature data — particular transparency, opt-out and cessation-of-use protections for specified facial-feature data. Statistical and AI-related uses — defined pathways allowing certain data uses or disclosures without consent when limited to producing statistical information or qualifying outputs, including some AI-development contexts, subject to safeguards. Enforcement — future administrative monetary penalties for certain serious violations, and expanded enforcement tools. Service providers and leakage response — revised obligations affecting entrusted processors, and possible relaxation of individual notification in specified low-risk leakage circumstances. These are enacted future changes, not currently effective obligations. The page should be updated when the Cabinet Order, PPC rules and implementation date are finalized.
Build your APPI readiness plan- Day 1 — Scan digital collection — Identify cookies, pixels, scripts, forms and third-party services operating on Japan-facing pages
- Week 1 — Classify information and purposes — Map information categories, purposes of use, special care-required information and retention practices
- Week 2 — Update notices and preferences — Publish purpose-of-use disclosures and configure consent or refusal controls where needed
- Week 3 — Map recipients and transfers — Distinguish entrusted processors, joint use, domestic third parties and foreign recipients
- Week 4 — Prepare rights and leakage workflows — Configure request handling, incident assessment, PPC reporting and individual-notification records
- Ongoing — Monitor vendors and the 2026 amendment — Detect technology changes, periodically review foreign-recipient safeguards, and update the program when the amendment’s effective date and implementing guidance are finalized
From isolated notices to documented APPI operations.
- Purposes of use written too broadly
- Website technologies not reflected in notices
- Every transfer treated as ordinary third-party sharing
- Entrusted processors and joint use not distinguished
- Foreign-recipient safeguards not reviewed
- Cookie identifiers ignored because they are not immediately identifying
- Leakage decisions made without documented thresholds
- Individual requests handled through ordinary inboxes
- Pseudonymized and anonymous information treated as interchangeable
- Future 2026 rules mixed with current obligations
- Purposes connected to actual collection
- Trackers and recipients continuously inventoried
- Recipient types documented separately
- Foreign-transfer pathways and safeguards recorded
- Personal related information included in the review
- Leakage thresholds and reporting dates centralized
- Rights requests routed through documented workflows
- Processed-information categories governed separately
- Current requirements distinguished from enacted future amendments
- Evidence preserved for internal and regulatory review
Japan’s APPI, answered plainly.
What is Japan’s APPI?+
Does APPI apply to companies outside Japan?+
Does APPI require consent for all personal-information processing?+
Does every website cookie require consent under APPI?+
Does every third-party provision require consent?+
How can personal data be transferred outside Japan?+
Must every data leakage be reported?+
What are APPI’s leakage-reporting timelines?+
What is the difference between pseudonymously and anonymously processed information?+
Is Japan’s 2026 APPI amendment already effective?+
APPI Compliance Software – Connect collection, purpose and recipients in one defensible record.
Captain Compliance helps teams monitor website technologies, publish accurate notices, manage choices, handle individual requests and organize APPI transfer and leakage evidence. Learn your companies APPI applicability, transfer requirements and leakage obligations. Start by booking an APPI review demo.
Book an APPI review View pricing