| name | japan-appi |
| title | Japan APPI Compliance (2022 Amendments) |
| description | Guides compliance with Japan's Act on the Protection of Personal Information (APPI, 2022 amendments). Covers individual rights expansion, cross-border transfer restrictions including pre-transfer information requirements, PPC enforcement, and pseudonymised and anonymously processed information. Keywords: APPI, Japan data protection, PPC, cross-border transfer, pseudonymised information, individual rights. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/japan-appi |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | jp |
| practice | data-protection |
| language | en |
Japan APPI Compliance (2022 Amendments)
Overview
The Act on the Protection of Personal Information (APPI, 個人情報の保護に関する法律) was originally enacted in 2003, substantially reformed in 2015 (effective May 2017), and further amended in 2020 (effective 1 April 2022). The 2022 amendments significantly strengthened individual rights, tightened cross-border transfer requirements, expanded the scope of anonymously processed information, and introduced the concept of pseudonymously processed information.
The Personal Information Protection Commission (PPC, 個人情報保護委員会) is the independent supervisory authority with rulemaking, enforcement, and international cooperation functions.
Japan received an EU adequacy decision on 23 January 2019, enabling free flow of personal data between the EU/EEA and Japan under supplementary rules adopted by the PPC.
Key Categories of Information
| Category | APPI Definition | Processing Framework |
|---|
| Personal Information (個人情報) | Information relating to a living individual that can identify the individual (Art. 2(1)) | Full APPI obligations apply |
| Personal Data (個人データ) | Personal information forming part of a personal information database (Art. 16(1)) | Additional obligations: accuracy, security, third-party provision rules |
| Retained Personal Data (保有個人データ) | Personal data that the business operator has authority to disclose, correct, or delete (Art. 16(4)) | Subject to individual rights requests |
| Special Care-Required Personal Information (要配慮個人情報) | Race, creed, social status, medical history, criminal record, crime victimisation, disability, and other categories prescribed by Cabinet Order (Art. 2(3)) | Consent required for collection (Art. 20(2)) |
| Pseudonymously Processed Information (仮名加工情報) | Personal information processed to prevent identification without additional information (Art. 2(5)) — introduced 2022 | Relaxed obligations: internal use only; no individual rights; no third-party provision |
| Anonymously Processed Information (匿名加工情報) | Information derived from personal information that cannot identify individuals and cannot be restored (Art. 2(6)) | May be provided to third parties with proper disclosure; no individual consent required |
Cross-Border Transfer (Art. 28, 2022 Amendments)
Pre-Transfer Information Requirement
The 2022 amendments introduced a significant new requirement: before obtaining consent for cross-border transfer, the business operator must provide the individual with information regarding the personal information protection system of the destination country.