← All guides
Privacy13 min read23 July 2026

Japan APPI 2022 Amendments: Breach Notification, Pseudonymous Processing & Cross-Border Transfers (2026)

Complete guide to Japan's APPI 2022 amendments in force from April 2022. Covers PPC enforcement, mandatory breach notification (5-day speed report), pseudonymously processed information rules, strengthened data subject rights, cross-border transfer consent with country disclosure, third-party provision records, and opt-out restrictions. For Japanese companies and foreign platforms serving Japanese users.

Japan's Act on the Protection of Personal Information (APPI — 個人情報の保護に関する法律) has undergone three major rounds of reform since its 2003 enactment. The most recent amendments — effective April 1, 2022 — represent the most comprehensive changes in the law's history, introducing mandatory breach notification, a new category of pseudonymously processed information (仮名加工情報), strengthened data subject rights with new suspension grounds, and significantly enhanced cross-border transfer consent requirements.

Background: APPI Amendment History

  • 2003: APPI originally enacted — applied only to business operators handling more than 5,000 individual records
  • 2015 amendments (effective May 2017): Removed 5,000-person threshold (all business operators in scope); established the Personal Information Protection Commission (PPC); introduced opt-out third-party provision rules; created anonymously processed information (匿名加工情報) category
  • 2020 amendments (effective April 2022): Mandatory breach notification; pseudonymously processed information; strengthened data subject rights; cross-border transfer consent disclosure; personal related information; opt-out provision restrictions

Key Definitions Under APPI 2022

  • Personal information (個人情報): Information about a living individual that can identify that specific individual by name, date of birth, or other description; includes information containing an individual identification code (個人識別符号)
  • Sensitive personal information (要配慮個人情報): Nine categories requiring explicit consent for acquisition: race; creed; social status; medical history; criminal history; history as a crime victim; physical or mental disability; medical examination results; sexual orientation (PPC guidelines)
  • Pseudonymously processed information (仮名加工情報): Personal information processed to the extent that the specific individual cannot be identified without collating with other information — created by removing/replacing identifying elements and destroying the reference table (or access-controlling it separately)
  • Anonymously processed information (匿名加工情報): Information processed to the extent that the specific individual cannot be identified and the original personal information cannot be restored — irreversible processing meeting the five PPC processing standards
  • Personal related information (個人関連情報): Information related to a living individual that is not personal information, pseudonymously processed information, or anonymously processed information — including cookie data, location data, browsing history, or interest data that could become personal information when received by a third party who links it with their own data

Purpose Specification Requirements (Articles 17–18)

A foundational APPI obligation: business operators must specify the purpose of use of personal information as concretely and specifically as possible. The purpose must be:

  • Specified before or at the time of acquisition — via privacy policy, collection notice, or terms of use
  • Publicly announced (for non-direct collection) or notified to the data subject (for direct collection) immediately after acquisition
  • Purpose limitation: Information may not be used beyond the specified purpose without prior notification or public announcement of the new purpose — if the change is materially different, re-notification or explicit consent is required

Third-Party Provision Rules (Articles 27–29)

Personal information may generally only be provided to third parties with opt-in consent. The 2022 amendments introduced two new restrictions on opt-out (オプトアウト) provision:

  • Sensitive personal information may not be provided via the opt-out procedure (requires opt-in consent)
  • Personal information that was itself received from a third party via opt-out may not be further provided via opt-out (breaks the chain)

Provision records (提供記録) and acquisition records (受領記録) — introduced in 2017 and strengthened in 2022:

  • When providing personal information to a third party: keep provision records (date, recipient, items provided, reason for provision) for 3 years
  • When receiving personal information from a third party: keep acquisition records (date, provider, items received, reason provider believed consent/exception applied) for 3 years
  • These records are subject to PPC inspection and must be maintained in searchable format

Mandatory Breach Notification (Article 26)

The 2022 amendments introduced Japan's first mandatory personal information leakage notification requirement:

  • Speed report (速報) to PPC within 5 business days of the business operator becoming aware of a notifiable leakage — PPC guidance clarifies that "awareness" means reaching a point where the operator judges there is reasonable certainty a reportable leakage has occurred
  • Supplementary report (確報) within 30 days with full investigation findings, root cause analysis, and remediation measures
  • Individual notification without undue delay when the notification conditions are met

Notifiable leakage conditions (any one triggers notification):

  • Sensitive personal information (要配慮個人情報) is affected
  • 1,000 or more data subjects affected
  • The leakage was systematic (not accidental) — e.g., unauthorised disclosure by an employee with malicious intent
  • The leakage occurred for the purpose of crime facilitation

Pseudonymously Processed Information (Articles 41–42)

The 2022 amendments introduced a new intermediate category — pseudonymously processed information (仮名加工情報) — designed to enable internal analytics and data science while reducing compliance burden compared to personal information.

How to create pseudonymously processed information:

  1. Delete or replace portions of the description that could identify the specific individual (name, address, DOB)
  2. Delete or replace individual identification codes (My Number, passport number, biometric codes)
  3. Delete or replace account passwords or other information that could cause property damage if leaked
  4. The reference table (mapping pseudonymous ID to original data) must either be destroyed or access-controlled separately from the pseudonymous dataset

Key restrictions on pseudonymous information:

  • No third-party provision — except to processors (委託先) under consignment agreements, or in business succession contexts
  • Purpose limitation — may only be used for the stated purpose; purpose change requires public announcement
  • No combination with identifying information — must not be matched or combined with other data that would re-identify the individual
  • Re-identification prohibition — active prohibition on attempting to re-identify pseudonymous data
  • Data subject rights suspended — rights to disclosure, correction, suspension, and deletion do not apply to pseudonymously processed information (key compliance benefit)

Cross-Border Transfer Consent (Article 24)

The 2022 amendments significantly strengthened cross-border transfer requirements. When obtaining consent for overseas transfers, the business operator must disclose to the data subject:

  • The name of the destination country (if multiple: "certain foreign countries including [named countries]"); or alternatively describe the region if multiple countries are involved
  • Information about the personal information protection system in the destination country (i.e., inform the data subject that APPI-equivalent protections may not apply in that country)
  • The measures taken by the recipient to protect personal information

Alternative to consent — contractual measures: Where the recipient country provides equivalent protection through domestic law or where the business operator and recipient enter into agreements meeting PPC standards, consent is not required. PPC has published standard clauses and maintains a list of adequate countries (currently EU/EEA and UK).

Data subjects' right to information on demand (2022 Amendment): When a data subject requests information about overseas recipients, the operator must provide: the destination country, the personal information protection system there, and the measures taken — even where contractual measures were used instead of consent.

Strengthened Data Subject Rights (Articles 33–39)

The 2022 amendments added three new grounds for suspension of use (利用停止等) or suspension of third-party provision:

  • When continued use would harm the rights or interests of the data subject (新設)
  • When the personal information is no longer necessary for the specified purpose (新設)
  • When consent has been withdrawn (新設)

These grounds are in addition to the pre-existing grounds (unlawful processing, processing exceeding purpose). The practical effect is that the right to erasure under APPI is now much closer to the GDPR right to erasure — data subjects have expanded grounds to demand deletion or processing suspension.

PPC Enforcement and Penalties

The Personal Information Protection Commission (PPC) has enhanced enforcement authority under the 2022 amendments:

  • Recommendations (勧告): PPC may recommend corrective measures and make the recommendation public
  • Orders (命令): PPC may issue binding orders; failure to comply is a criminal offence
  • Criminal penalties: Up to JPY 1 million per violation for business operator; up to JPY 100 million for corporations under dual liability (両罰規定)
  • PPC enforcement cases are published on the PPC website — increasingly active since 2022

Use the free Japan APPI 2022 Amendments Compliance Checker to assess your organisation across all 42 key obligations, generate a tailored AI compliance report, and build a prioritised remediation roadmap addressing the latest APPI requirements.