For any organization doing business in Japan, understanding Japan’s data protection law is critical to maintaining compliance and protecting sensitive data. As privacy regulations continue to evolve, having a thorough understanding of Japan’s data protection law—officially known as the Act on the Protection of Personal Information (APPI)—is more important than ever. This law plays a key role in how companies handle financial records, personal data, and other sensitive information. In this post, we’ll explore what businesses need to know about Japan’s data protection law, how it affects global operations in the country, and what steps you can take to ensure compliance. Read on to equip your business with the insights needed for long-term success in the Japanese market
Overview of Japan’s data protection law (APPI)
The primary legislation governing the collecting and processing of personal data is the Act on the Protection of Personal Information Act No. 57 of 2003 (“APPI”). This law was significantly revised in both 2017 and 2022. The primary purpose of the APPI is to protect individuals’ personal data by regulating how businesses and organizations collect, use, share, and store that data.
Because of the amended legislation, Japan became the first country to receive an adequacy judgement from the European Commission (EC) after the GDPR went into effect on January 23, 2019. These rulings, which govern cross-border data transfers from the EU, represent the level of data protection in a third nation in comparison to EU legislation.
The Act is overseen by the Personal Information Protection Commission (PPC), an independent administrative body founded in 2005
Key Terms Defined by Japan’s Data Protection Law (APPI)
Japanese law defines personal information as any details about a living individual that can identify that person. This includes names, addresses, email addresses, photographs, telephone numbers, and similar data. The APPI further defines “personal data” as information that can identify a specific individual either on its own or when combined with other data.
Under this legislation, a “data controller” is an individual or entity responsible for determining the purposes and means of processing personal data. Data controllers are required to comply with certain obligations under the APPI, such as notifying individuals when their personal data is being collected, obtaining consent from individuals before collecting and using their information, and ensuring that appropriate measures are taken to prevent unauthorized access.
Data processors handle personal data on behalf of data controllers. Under the APPI, they must follow specific obligations. They must take reasonable measures to ensure the security and accuracy of the personal data they process. If any unauthorized access or loss of data occurs, they must promptly notify the data controller. They must also avoid transferring personal data outside Japan unless they have established proper safeguards.
What is the purpose of APPI and who does it apply to
The APPI was enacted to ensure that individuals’ personal data is properly protected and handled with respect. This law applies to any company or organization, both inside and outside of Japan, that collects, processes or stores the personal data of Japanese nationals. It also applies to companies and organizations located in Japan that process the personal data of non-residents of Japan, provided that the processing relates to activities taking place in Japan. Companies and organizations should ensure that their data protection practices are compliant with the APPI to avoid potential penalties or other repercussions.
Previously, the APPI only applied to businesses who had 5,000 identifiable individuals in their database on at least single day in the previous six months however, the 2017 modified APPI eliminated this restriction.
How does APPI protect personal data
The APPI outlines strict requirements for how companies and organizations must handle personal data. Businesses must obtain individuals’ consent before collecting their personal information and must notify them when collecting their data. They must also implement reasonable security measures to protect personal data and ensure they do not transfer it outside Japan without appropriate safeguards.
The APPI grants individuals the right to access their personal data held by companies and request corrections to inaccurate or incomplete information. Authorities may fine companies that violate the APPI. Organizations must also take all reasonable steps to mitigate any harm caused by a breach of the legislation.
Sensitive Information as per APPI
- Criminal records
- Religious Beliefs
- Marital Status
- Medical history
- Race
Requirements for companies under Japan’s data protection law
The APPI requires companies and organizations to take a number of steps in order to ensure that they are compliant with the legislation. These include:
• Obtain consent from individuals before collecting their personal data
• Alert people of the collection of their data and its intended use.
• Take appropriate security measures to protect personal data
• Notify the individual and the Personal Information Protection Commission (PPC) in the event of any unauthorized access or loss of personal data
• Avoid sending any personal information outside of Japan without the appropriate security measures in place.
• Provide individuals with access to their own personal data, and allow them to have inaccurate or incomplete data corrected
• Follow the instructions of the PPC in order to rectify any non-compliance
• Ensure that any third-party data processors comply with the APPI as well.
Companies should ensure that their data protection practices are compliant with the APPI in order to avoid potential penalties or other repercussions. Data controllers and processors are both responsible for ensuring compliance with the APPI. Data controllers have additional responsibilities, such as providing clear instructions to data processors about how the personal data should be handled, ensuring that any third-party data processors comply with the APPI, and notifying the PPC of any unauthorized access or loss of personal data. It is important for companies to be aware of their responsibilities under the APPI, and to take all reasonable steps to ensure compliance.
What are the exemptions to APPI?
The press, professional writing/journalistic activities, academic, and political activities are all exempt from the APPI, therefore this includes broadcasters, newspaper publishers or other press organizations, universities or other academic institutions, religious institutions, and political parties. Government organizations, both federal and local, as well as administrative bodies, are likewise exempt.
What are the penalties for noncompliance with APPI
In 2020, lawmakers increased penalties under the APPI to a maximum of 1 million yen (about €7,000) for individuals and 100 million yen (approximately €700,000) for enterprises. Authorities may adjust fines based on the severity, scope, and other relevant factors of the violation.
Before taking enforcement action, the Personal Information Protection Commission (PPC) typically gives non-compliant organizations a chance to revise their policies. Businesses must notify the PPC when a data breach occurs—unless they encrypted the compromised data using the highest security standards.
Tips on how to comply with APPI effectively
1. Have a clear and comprehensive privacy policy:
Companies must ensure that their internal policies are compliant with the APPI, and be able to provide evidence of this if asked. This includes having a clear and comprehensive privacy policy that outlines how personal data is collected, stored, used and disposed of.
2. Train staff on data protection principles:
Companies must also ensure that their staff members are properly trained in data protection principles. This includes informing them of the APPI and what it requires, as well as any internal policies and procedures they should follow.
3. Utilize industry-standard security measures:
Companies must also implement industry-standard security measures to protect personal data. This includes encryption and other measures to keep personal data safe from unauthorized access or loss.
4. Maintain compliance documents:
Companies must also maintain records of their data protection policies, procedures, and other evidence of compliance with the APPI. This will be useful if there is an audit by the PPC or another enforcement agency.
5. Report any data breaches:
In the event of a data breach, companies must notify the PPC and any affected individuals as soon as possible. This will help to limit any potential damage and ensure that businesses are in compliance with the APPI.
6. Update policies regularly:
Lastly, it is important for companies to regularly review and update their policies to ensure they comply with any changes in the APPI. This will help companies avoid potential penalties or other repercussions from non-compliance.
By following these tips, companies can ensure that they are compliant with the APPI and minimize any risks associated with data protection. Companies should make sure that they have taken all reasonable steps to protect personal data and that they understand their responsibilities under the APPI. Doing so will help them avoid potential penalties for any violations of the APPI.