APPI Compliance for Foreign Companies: Japan's Data-Protection Law
Japan's Act on the Protection of Personal Information reaches foreign companies that handle the data of people in Japan, whether or not they have an office here. What triggers it, the breach-reporting duty, the cross-border-transfer rules, and how it compares to the GDPR.
Japan’s data-protection law reaches foreign companies that handle the personal data of people in Japan, whether or not they have an office here. There is no licence to obtain and no registration to do business, which is exactly why it is so easy to overlook, and the obligations attach the moment you handle the data, not when you set up a Japanese entity.
For any global digital business, SaaS platform, e-commerce operation, or app with users in Japan, the Act on the Protection of Personal Information, the APPI (個人情報の保護に関する法律), is a live compliance obligation. It is frequently mistaken for a problem that only Japanese companies have, or assumed to be covered by an existing GDPR programme. Both assumptions are wrong, and both are common.
What follows is what triggers the Act, the two obligations foreign companies most often stumble on, breach reporting and cross-border transfer, how it relates to the GDPR, and where data policy becomes a public affairs question. The regulator is the Personal Information Protection Commission (個人情報保護委員会, PPC).
What triggers the APPI: the extraterritorial reach
The APPI applies to any business that handles personal information, and crucially it applies extraterritorially. A foreign company that handles the personal data of individuals in Japan in connection with supplying goods or services to them is subject to the Act, whether or not it has an establishment in Japan.
That is the trigger foreign companies miss. You do not need a Japanese subsidiary, an office, or even Japanese-language marketing to be caught; you need to be handling the data of people in Japan as part of serving them. A US or European company with Japanese users, customers, or app installs is, in the ordinary case, within scope. And because there is no registration step that would force the question, many such companies never consciously ask it, and discover the obligation only when something goes wrong.
It is not the GDPR, though it looks like it
The most efficient way to get the APPI wrong is to assume a GDPR programme discharges it.
The two laws are genuine cousins. Both regulate personal-data handling, grant individuals rights over their data, restrict international transfers, and require breach handling. And the relationship is formally recognized: the EU and Japan have found each other to provide adequate protection, which smooths EU-Japan data flows. A mature GDPR programme is a strong starting point.
But the APPI has its own definitions, its own consent and notice rules, and its own procedures, and they diverge from the GDPR in specifics that matter operationally, how consent is framed, what notice is required, how categories of data are treated, how breaches are reported. Mapping a GDPR programme onto the APPI is real work, not a formality, and assuming equivalence is a shortcut that leaves gaps precisely where enforcement and reputational risk sit.
The two obligations foreign companies stumble on
Two parts of the Act generate most of the operational exposure for a foreign company.
Breach reporting
Since the 2022 amendment, certain data breaches must be reported to the PPC and notified to affected individuals. This is not a paper formality: across a year the PPC receives on the order of 7,000 breach reports, with a comparable volume of individual notifications, which is the measure of how routinely the duty is triggered in practice.
For a foreign company, the requirement is only as good as the incident-response process behind it. You need a process that recognizes when an incident is reportable in Japan specifically, that can assemble what the PPC requires, and that can act inside the required timeframe, which is not generous. A global incident-response playbook that does not have a Japan branch will miss the Japanese obligation while it is busy with the others.
Cross-border data transfer
Moving Japanese personal data out of Japan is restricted. To provide personal data to a third party in a foreign country, you generally need one of: the individual’s consent based on prescribed information; a destination recognized as having an adequate system; or a recipient that has put in place a compliant framework. Where you rely on consent or on the recipient’s framework rather than on adequacy, further information and ongoing-oversight duties attach.
For a global company, this is one of the most consequential parts of the Act, because the ordinary architecture of a modern service, Japanese users’ data flowing to cloud infrastructure, analytics, or group affiliates abroad, is exactly the pattern the transfer rules govern. Getting the transfer basis right, and maintaining the oversight it requires, is not a one-time sign-off but a standing obligation baked into how the data actually moves.
Enforcement is no longer light
A company relying on a memory of the APPI as a low-enforcement regime is working from an outdated picture. The PPC has powers to require reports, conduct on-site inspections, and issue guidance and orders, and it has become steadily more active. Non-compliance with an order, and certain other breaches, can bring penalties, and in a market that takes data handling seriously the reputational exposure can outweigh the formal sanction. The direction of travel, here as in most jurisdictions, is toward more enforcement, not less.
Where this becomes a public affairs question
The compliance build is legal and operational work, and privacy counsel handle it. The public affairs questions are upstream and adjacent.
Data-protection rules are not static, and the areas that matter most to global businesses, cross-border transfer mechanics, the treatment of new data types and technologies, the interaction of the APPI with sector rules and with economic-security measures on data, are under continual development through PPC policy and periodic amendment. A company whose model depends on how data can move, or on how a new category of processing is treated, has a legitimate interest in how those rules evolve, and the PPC and the wider policy process are where that is decided. Beyond the rules, data governance increasingly intersects with Japan’s economic-security and digital-policy agendas, which is squarely public affairs terrain. Engaging on how the framework develops, not only complying with it as it stands, is the strategic dimension for a company for whom data flows are core.
If data policy is material to your Japan business, get in touch.
How to plan it
- Assume you are in scope if you handle data of people in Japan. The reach is extraterritorial and there is no registration step to prompt the question.
- Run an APPI-specific assessment, not a GDPR read-across. They are cousins, not equivalents; the gaps are in the specifics.
- Give your incident response a Japan branch. Breach reporting to the PPC and to individuals is a real, time-bound duty.
- Get the cross-border-transfer basis right and maintain it. For a global service this is the highest-frequency exposure, and it is a standing obligation.
- Engage on the framework where data flows are core. Transfer rules and new-technology treatment are moving, and the policy stage is where to be heard.
Why this matters for public affairs in Japan
Data protection looks like a compliance function, and for a company with a settled model it largely is. But the APPI sits inside Japan’s fast-developing digital and economic-security policy, and the rules that decide how data can be handled and moved, especially across borders, are being written and revised. For a company whose Japanese business depends on those rules, compliance is downstream of policy that can be engaged, and the intersection of data with economic security is becoming a first-order strategic issue rather than a back-office one. Knowing where the compliance obligation ends and the policy question begins is what turns data protection from a cost center into a managed strategic position.
Gemini Group advises global technology and data-driven companies on APPI strategy, PPC engagement, and the intersection of data, digital, and economic-security policy in Japan. Contact us to discuss your data position.
Further reading: our Digital Agency overview covers the body driving Japan’s digital-governance agenda, and the market-entry regulatory checklist maps the wider compliance landscape for a digital entrant.
Frequently asked questions
- What is the APPI and does it apply to foreign companies?
- The APPI is the Act on the Protection of Personal Information (個人情報の保護に関する法律), Japan's data-protection law, enforced by the Personal Information Protection Commission (PPC). It applies to any business that handles personal information, and it reaches extraterritorially: a foreign company that handles the personal data of individuals in Japan in connection with supplying goods or services to them is subject to it, whether or not it has a Japanese establishment. There is no registration to do business, but there are obligations that attach the moment you handle the data.
- Is the APPI the same as the GDPR?
- They are close cousins, not identical. Both regulate the handling of personal data, grant individuals rights over their data, restrict cross-border transfers, and require breach handling, and the EU and Japan recognize each other as providing adequate protection, which eases EU-Japan data flows. But the APPI has its own definitions, its own consent and notice rules, and its own procedures, so a GDPR programme is a strong starting point but not a substitute for an APPI-specific assessment. Assuming GDPR compliance equals APPI compliance is a common and risky shortcut.
- What are the breach-reporting obligations under the APPI?
- Since the 2022 amendment, certain data breaches must be reported to the Personal Information Protection Commission and notified to the affected individuals. Reporting is a real operational duty, not a formality: across a year the PPC receives on the order of 7,000 breach reports, alongside a comparable volume of notifications to individuals. A foreign company handling Japanese personal data needs an incident-response process that knows when a breach is reportable in Japan and can act inside the required timeframe.
- What are the rules on transferring personal data out of Japan?
- Cross-border transfer is restricted. To provide personal data to a third party in a foreign country you generally need the individual's consent based on prescribed information, or the destination must be recognized as having an adequate system, or the recipient must have put in place a compliant framework. Where you rely on consent or the recipient's framework rather than adequacy, additional information and ongoing-oversight duties apply. For a global company routing Japanese data to servers or affiliates abroad, this is one of the most operationally significant parts of the Act.
- Who enforces the APPI and what are the penalties?
- The Personal Information Protection Commission (個人情報保護委員会, PPC) enforces it, with powers to require reports, conduct on-site inspections, and issue guidance and orders. Failing to comply with a PPC order, and certain other breaches, can lead to penalties, and beyond the formal sanction there is real reputational exposure in a market that takes data handling seriously. The PPC has been increasingly active, so treating the APPI as low-risk because enforcement was once light is out of date.
- Does a foreign company need a representative in Japan under the APPI?
- A foreign business subject to the APPI without an establishment in Japan is expected to be reachable and accountable to the PPC and to individuals, and appointing a local representative or contact is the practical way most companies meet that expectation and handle rights requests and regulator contact. The precise requirement should be confirmed for your situation, but operating as if the extraterritorial reach carries no local-accountability expectation is a mistake.