Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Solutions / APPI · JAPAN
JAPAN APPI · PPC · PERSONAL DATA

Japan’s APPI requires control over purpose, recipients and the evidence connecting them.

Japan’s Act on the Protection of Personal Information governs how organizations acquire, use, secure, share and transfer personal information. The framework distinguishes personal information, personal data, retained personal data, personal related information and specially processed datasets — and applies different requirements to each. Captain Compliance helps teams discover digital collection, publish clear notices, manage consent and requests, document recipients and prepare for qualifying leakage events.

Purpose-of-use controlsRecipient and transfer recordsLeakage-response workflows

The question is not only whether information was collected. It is what happened after collection.

Purpose
Purpose of use

An organization must specify the purpose of using personal information as explicitly as reasonably possible. Using it beyond the reasonably related scope of that purpose generally requires consent unless an exception applies.

Notice
Notice and publication

The purpose of use generally must be communicated to the individual or publicly announced. When information is obtained directly from a written document, including an electronic form, the purpose generally must be stated beforehand unless an exception applies.

Acquisition
Proper acquisition and sensitive information

Personal information must not be acquired through deception or other improper means. Acquiring special care-required personal information generally requires advance consent unless a statutory exception applies.

Security
Security and vendor supervision

Organizations must implement necessary and appropriate security safeguards and supervise employees and entrusted service providers handling personal data. Entrustment, business succession and qualifying joint use are not treated identically to ordinary third-party provision.

Provision
Domestic third-party provision

Providing personal data to an independent third party generally requires advance consent unless an exception or valid opt-out arrangement applies. Organizations may also need to create, verify and retain records of personal-data provisions and receipts.

Overseas
Foreign transfers

Providing personal data to a third party in a foreign country may rely on informed consent, an equivalent-country designation, or a recipient maintaining qualifying equivalent safeguards. Each path carries different information, documentation and monitoring requirements.

Related
Personal related information

Cookie identifiers, browsing histories, location data and similar information may constitute personal related information when they do not identify an individual for the provider. Additional confirmation and recordkeeping can apply when a recipient is expected to acquire that information as personal data.

Leakage
Leakage response and individual rights

Not every incident is reportable. Qualifying events include those involving special care-required personal information, risk of financial or property damage, a potentially wrongful purpose, or personal data concerning more than 1,000 individuals. Report promptly to the PPC, generally within approximately three to five days after discovery, with a final report generally within 30 days — or 60 days where a wrongful purpose may be involved. Individuals also receive rights involving disclosure, correction, addition, deletion, cessation of use, erasure and cessation of third-party provision.

¥100M
What penalties look like today

Under the currently effective law, corporate fines of up to ¥100 million may apply to specified offenses, including certain violations of PPC orders and improper provision or misappropriation of personal-information databases. The PPC may also investigate, request reports, conduct inspections, provide guidance, issue recommendations and issue orders. This is not an automatic fine for every compliance mistake.

Consent
Transfer pathway — informed consent

A transfer may rely on advance consent covering provision to a foreign third party. Before obtaining consent, the organization generally must provide information about the foreign country’s personal-information protection system and the recipient’s protective measures, to the extent required by PPC rules.

Country
Transfer pathway — equivalent country

A transfer may occur to a third party in a country designated by the PPC as having a personal-information protection system equivalent to Japan’s. The EU and United Kingdom are currently recognized, subject to applicable details and supplementary requirements.

Safeguards
Transfer pathway — equivalent safeguards

A transfer may rely on the recipient maintaining a qualifying system of safeguards equivalent to APPI requirements, including through an appropriate contractual or organizational arrangement or applicable international certification framework. The transferring organization must periodically confirm the safeguards continue, generally at approximately annual intervals or more frequently, review foreign legal developments affecting them, address problems, and stop transfers if continued safeguards cannot be ensured. Statutory exceptions may also apply; transfer classification should be reviewed with qualified Japanese counsel.

Make purposes, choices and recipients traceable.

Captain Compliance helps privacy, legal, security and engineering teams connect website behavior with notices, consent, request handling, recipients, transfer pathways and incident evidence.

S

Real-time tracker discovery

Continuously identify cookies, pixels, scripts and third-party technologies that may collect personal information or personal related information.

C

Consent and preference controls

Configure consent and preference experiences for activities that require or rely on consent, without treating consent as the universal APPI processing basis.

N

Purpose-of-use notices

Publish and version disclosures describing purposes of use, request procedures, contact information and other required information.

T

Recipient and transfer mapping

Document domestic recipients, entrusted processors, joint-use arrangements, foreign recipients, destination countries and the selected transfer pathway.

R

Individual-rights workflows

Centralize requests involving disclosure, correction, addition, deletion, cessation of use, erasure and cessation of third-party provision.

L

Leakage-response workflow

Organize discovery time, affected information, individual counts, risk categories, preliminary reports, final reports, individual notices and remediation evidence.

V

Vendor and safeguard monitoring

Record entrusted service providers, security requirements, foreign-recipient safeguards, review dates and remediation decisions.

G

Information-category governance

Helps distinguish personal information, personal data, retained personal data, personal related information, pseudonymously processed information and anonymously processed information.

Japan has enacted its next APPI update. Implementation comes next.

Japan’s 2026 amendment was enacted 10 July and promulgated 17 July 2026. Except for limited provisions, it will take effect on a date established by Cabinet Order within two years. The PPC is still preparing implementing orders, rules and guidance. Children — express rules involving individuals under 16, including legal-representative involvement for certain consent and notice matters, and a best-interests consideration. Facial-feature data — particular transparency, opt-out and cessation-of-use protections for specified facial-feature data. Statistical and AI-related uses — defined pathways allowing certain data uses or disclosures without consent when limited to producing statistical information or qualifying outputs, including some AI-development contexts, subject to safeguards. Enforcement — future administrative monetary penalties for certain serious violations, and expanded enforcement tools. Service providers and leakage response — revised obligations affecting entrusted processors, and possible relaxation of individual notification in specified low-risk leakage circumstances. These are enacted future changes, not currently effective obligations. The page should be updated when the Cabinet Order, PPC rules and implementation date are finalized.

Build your APPI readiness plan
A PRACTICAL APPI ROLLOUT
  • Day 1 — Scan digital collection — Identify cookies, pixels, scripts, forms and third-party services operating on Japan-facing pages
  • Week 1 — Classify information and purposes — Map information categories, purposes of use, special care-required information and retention practices
  • Week 2 — Update notices and preferences — Publish purpose-of-use disclosures and configure consent or refusal controls where needed
  • Week 3 — Map recipients and transfers — Distinguish entrusted processors, joint use, domestic third parties and foreign recipients
  • Week 4 — Prepare rights and leakage workflows — Configure request handling, incident assessment, PPC reporting and individual-notification records
  • Ongoing — Monitor vendors and the 2026 amendment — Detect technology changes, periodically review foreign-recipient safeguards, and update the program when the amendment’s effective date and implementing guidance are finalized

From isolated notices to documented APPI operations.

Without an operating program
  • Purposes of use written too broadly
  • Website technologies not reflected in notices
  • Every transfer treated as ordinary third-party sharing
  • Entrusted processors and joint use not distinguished
  • Foreign-recipient safeguards not reviewed
  • Cookie identifiers ignored because they are not immediately identifying
  • Leakage decisions made without documented thresholds
  • Individual requests handled through ordinary inboxes
  • Pseudonymized and anonymous information treated as interchangeable
  • Future 2026 rules mixed with current obligations
With Captain Compliance
  • Purposes connected to actual collection
  • Trackers and recipients continuously inventoried
  • Recipient types documented separately
  • Foreign-transfer pathways and safeguards recorded
  • Personal related information included in the review
  • Leakage thresholds and reporting dates centralized
  • Rights requests routed through documented workflows
  • Processed-information categories governed separately
  • Current requirements distinguished from enacted future amendments
  • Evidence preserved for internal and regulatory review

Japan’s APPI, answered plainly.

What is Japan’s APPI?+
The Act on the Protection of Personal Information is Japan’s comprehensive personal-information law. It regulates acquisition, purposes of use, security, third-party provision, foreign transfers, leakage response and individual rights.
Does APPI apply to companies outside Japan?+
It can. APPI may apply to a foreign business processing personal information concerning individuals in Japan in connection with providing goods or services to them. Covered foreign businesses may be subject to PPC reporting, recommendations and orders.
Does APPI require consent for all personal-information processing?+
No. APPI generally requires organizations to specify and disclose the purpose of use and restrict incompatible use. Consent is specifically important for certain activities, including acquisition of special care-required personal information, some uses outside the disclosed purpose, third-party provision and foreign transfers, subject to exceptions.
Does every website cookie require consent under APPI?+
No. APPI is not a cookie-specific consent law. A cookie identifier may be personal information, personal data or personal related information depending on how it is maintained and combined with other information. Transfers of personal related information can trigger confirmation and recordkeeping when the recipient is expected to acquire it as personal data.
Does every third-party provision require consent?+
Not always. APPI contains statutory exceptions and an opt-out framework. Entrustment, business succession and qualifying joint use are also treated differently from ordinary third-party provision. Each arrangement must be classified correctly.
How can personal data be transferred outside Japan?+
Common pathways include informed consent, transfer to a recipient in a PPC-designated equivalent country, or transfer to a recipient maintaining equivalent safeguards. Statutory exceptions may also apply.
Must every data leakage be reported?+
No. PPC reporting and individual notification apply to specified qualifying events, including certain events involving special care-required data, potential financial harm, potentially wrongful conduct, or more than 1,000 individuals.
What are APPI’s leakage-reporting timelines?+
A qualifying event should be reported promptly, generally through a preliminary report within approximately three to five days after discovery. A final report is generally due within 30 days, or 60 days when the incident may involve a wrongful purpose.
What is the difference between pseudonymously and anonymously processed information?+
Pseudonymously processed information is processed so an individual cannot be identified without additional information, and is generally intended for restricted internal use under special rules. Anonymously processed information is processed so an individual cannot be identified and the information cannot be restored, with separate creation, disclosure and handling requirements.
Is Japan’s 2026 APPI amendment already effective?+
Not generally. It was enacted 10 July and promulgated 17 July 2026. Except for limited provisions, it will take effect on a date established by Cabinet Order within two years. Implementing rules and PPC guidance are still being developed.

APPI Compliance Software – Connect collection, purpose and recipients in one defensible record.

Captain Compliance helps teams monitor website technologies, publish accurate notices, manage choices, handle individual requests and organize APPI transfer and leakage evidence. Learn your companies APPI applicability, transfer requirements and leakage obligations. Start by booking an APPI review demo.

Book an APPI review View pricing