Act on the Protection of Personal Information (APPI)
The Act on the Protection of Personal Information (APPI) is Japan’s comprehensive data protection legislation. Originally enacted in 2003 and substantially amended in 2020, the APPI regulates the handling of personal information by business operators. The Act establishes principles for the collection, use, and provision of personal information, requires consent for handling of sensitive information, and grants individuals rights of access, correction, and deletion. The 2020 amendments strengthened penalties and introduced data breach notification requirements.
Legal area: Law governing the collection, use, and protection of personal data.
Year enacted: 2003
Full text: https://elaws.e-gov.go.jp/document?lawid=japan-appi
Key Provisions
- Chapter I: General provisions (definitions, scope)
- Chapter II: Principles (purpose limitation, accuracy)
- Chapter III: Rights of individuals (access, correction, deletion)
- Chapter IV: Obligations of business operators (consent, security)
- Chapter V: Cross-border transfer restrictions
- Chapter VI: Personal Information Protection Commission
- Chapter VIII: Penalties (up to ¥100 million for corporations)
Significance
The APPI has been strengthened through significant amendments in 2020 and 2022 to address the evolving data economy. The 2020 amendments introduced the right to request deletion, strengthened data breach notification requirements, and increased penalties. The Act’s cross-border transfer provisions have been updated to require adequacy decisions or consent. Japan received an EU adequacy decision in 2019, facilitating data flows between Japan and the EU. The Personal Information Protection Commission oversees enforcement.