Skip to content
TB
TeamBenchResources

APPI Compliance: Data Protection Documentation Under Japan's Privacy Law

Japan's APPI has created documentation requirements comparable to GDPR, with an EU adequacy decision in place. Here's what documentation you need, key differences from GDPR, and how to review.

TeamBench· Content Quality PlatformFebruary 9, 202611 min read

Japan's Act on the Protection of Personal Information (APPI) — significantly amended in 2022 — has established a data protection framework that earned an EU adequacy decision, enabling free data flows between Japan and the EU. The Personal Information Protection Commission (PPC) actively enforces the APPI with expanding investigative powers and increasing willingness to take public enforcement action.

The 2022 amendments strengthened individual rights, introduced mandatory data breach notification, expanded cross-border transfer requirements, and created new obligations around pseudonymously processed information. Organisations that complied with the pre-amendment APPI likely have documentation gaps under the current law.

APPI Core Obligations

ObligationRequirementDocumentation Implication
Utilisation purpose specificationSpecify the purpose of use as concretely as possiblePurpose statements published and maintained
Use limitationUse personal information only within the specified purposeProcessing records aligned with stated purposes
Proper acquisitionObtain personal information through proper meansAcquisition records, consent documentation
AccuracyKeep data accurate and up to dateData quality procedures
Security managementTake necessary and appropriate measuresSecurity documentation
Supervision of employeesSupervise employees handling personal dataTraining records, access controls
Supervision of contractorsSupervise contractors handling personal dataContractor agreements, oversight records
Third-party provision restrictionsObtain consent before providing to third partiesConsent records, third-party provision records
Cross-border transfer restrictionsAdditional requirements for overseas transfersTransfer documentation, consent or safeguards

Required APPI Documentation

1. Utilisation Purpose Notice (Privacy Policy)

Must be publicly available and provided to the individual at or before the time of acquisition:

ElementRequirement
Business operator identityName and contact information
Utilisation purposesSpecific purposes for each category of personal information — "as concretely as possible"
Third-party provisionWhether personal information will be provided to third parties, and if so, categories of data, means of provision, and how to opt out
Shared useIf data is shared within a group — scope of shared use, categories of data, purpose, and responsible entity
Cross-border transfersCountries to which data may be transferred, the protection system in those countries
Individual rightsHow to request disclosure, correction, cessation of use, and deletion
ComplaintsContact for complaints about personal information handling
Cookies and trackingIf applicable — use of cookies and tracking technologies

APPI specificity requirement: The PPC requires utilisation purposes to be "as concrete as possible." A purpose stated as "for our business operations" is insufficient. Purposes should be specific enough that the individual can reasonably predict how their information will be used.

2. Records of Third-Party Provision

The APPI requires both the provider and the recipient to maintain records when personal information is provided to or received from third parties:

Provider Records (Article 29)

FieldDetail
Date of provisionWhen the information was provided
Name of recipientThe third party receiving the information
Categories of dataWhat personal information was provided
Individual identificationName or other identifier of the data subject

Recipient Records (Article 30)

FieldDetail
Date of receiptWhen the information was received
Name of providerThe third party providing the information
Acquisition circumstancesHow the provider acquired the information
Categories of dataWhat personal information was received
Individual identificationName or other identifier of the data subject
PPC confirmationConfirmation that the provider legally acquired the data

Retention: These records must be retained for 3 years (for providers) or the period of use plus 6 months (for recipients, minimum 1 year).

3. Consent Documentation

Consent TypeWhen RequiredDocumentation
Third-party provisionBefore providing personal information to third partiesConsent record with date, scope, and method
Cross-border transferBefore transferring to overseas third partiesConsent specifying the country and protection system
Sensitive personal informationBefore acquiring personal information requiring special careExplicit consent record
Purpose changeWhen changing the utilisation purpose beyond the original scopeConsent for the new purpose
Opt-out schemeIf using opt-out instead of prior consent for third-party provisionPPC notification, public disclosure

4. Security Management Measures Documentation

The APPI requires "necessary and appropriate" security measures. The PPC guidelines specify four categories:

CategoryDocumentation Required
Organisational measuresResponsible person appointed, handling rules established, regular audits conducted
Personnel measuresTraining programme, confidentiality obligations, access management
Physical measuresFacility security, device management, document/media controls
Technical measuresAccess control systems, intrusion detection, encryption, logging

Additionally document:

  • Security incident response procedures
  • Regular security assessment results
  • Employee training records
  • Contractor security oversight

5. Data Breach Notification Documentation

Mandatory since the 2022 amendment for breaches involving: sensitive personal information, property damage risk, wrongful purpose, or affecting 1,000+ individuals.

DocumentRequirement
Breach response planDetection, assessment, containment, notification procedures
PPC notificationPreliminary report "promptly" and detailed report within 30 days (60 days for wrongful purpose breaches)
Individual notificationNotification to affected individuals "promptly"
Breach registerRecord of all breaches including those below the notification threshold
Post-breach reviewRoot cause analysis and preventive measures

6. Cross-Border Transfer Documentation

The 2022 amendment significantly strengthened cross-border transfer requirements:

Transfer MechanismDocumentation Required
Consent-based transferConsent specifying the country, the country's data protection system, and the recipient's measures — must provide this information to the individual before obtaining consent
Adequacy countryVerification that the country is on the PPC's list of countries with equivalent protection (currently: EU/EEA and UK)
Equivalent measuresEvidence that the recipient has measures equivalent to APPI — documented assessment, contractual provisions, monitoring
APEC CBPR certificationRecipient certified under the APEC Cross-Border Privacy Rules system

Key 2022 change: Before obtaining consent for cross-border transfers, the business operator must provide information about the destination country's personal information protection system and the recipient's measures. This creates a substantial documentation obligation.

7. Pseudonymously Processed Information Documentation

New category introduced in the 2022 amendment:

DocumentRequirement
Processing methodologyHow personal information is pseudonymised (which elements removed/replaced)
Deleted information managementHow the information used to restore identity is managed
Utilisation purposePurposes for which pseudonymously processed information is used
Security measuresMeasures to prevent re-identification

Key Differences: APPI vs GDPR

AspectAPPIGDPR
Legal basis frameworkConsent-focused; limited "legitimate interest" equivalentSix legal bases including legitimate interest
Sensitive data"Personal information requiring special care" — racial/ethnic origin, beliefs, medical history, criminal historySpecial categories — broader list
Third-party provisionOpt-out scheme available (with PPC notification)Consent or other legal basis required
Cross-border transfersConsent (with country information), adequacy, equivalent measures, or CBPRAdequacy, SCCs, BCRs, or derogations
Breach notificationPPC: "promptly" + 30 days; individuals: "promptly"DPA: 72 hours; individuals: "without undue delay"
EnforcementPPC recommendations, orders, fines (up to ¥100M for corporations)Administrative fines up to €20M or 4% turnover
Record-keepingSpecific third-party provision/receipt records requiredRecords of processing activities

Common APPI Compliance Gaps

Gap 1: Utilisation Purposes Not Specific Enough

Purpose statements that are too broad or abstract for individuals to understand how their information will actually be used. The PPC has issued guidance emphasising the "as concrete as possible" standard.

Gap 2: Cross-Border Transfer Consent Not Meeting 2022 Requirements

Consent for overseas transfers obtained without providing the required information about the destination country's protection system and the recipient's measures. Pre-2022 consent may not meet current requirements.

Gap 3: No Third-Party Provision Records

The record-keeping obligation for third-party provision and receipt is specific to the APPI and has no direct GDPR equivalent. Many organisations have not implemented the required record-keeping system.

Gap 4: Security Management Measures Not Documented Across All Four Categories

Security documentation that covers technical measures but not organisational, personnel, or physical measures as specified in PPC guidelines.

Gap 5: Breach Notification Plan Not Updated for 2022 Requirements

Breach response plans that don't reflect the mandatory notification requirements introduced in the 2022 amendment, including the specific thresholds, timelines, and PPC reporting format.

Reviewing APPI Documentation

Privacy Policy Review Criteria

CriterionWeightWhat to Check
Purpose specificity3Utilisation purposes are "as concrete as possible"
Completeness3All APPI-required elements present
Cross-border information2Country, protection system, and recipient measures disclosed
Third-party provision disclosure2Categories, means, and opt-out mechanism documented
Currency1Reflects current processing activities and purposes

Cross-Border Transfer Review Criteria

CriterionWeightWhat to Check
Country information provided3Protection system of each destination country documented and disclosed
Transfer mechanism3Each transfer has an identified legal mechanism (consent, adequacy, equivalent measures, CBPR)
Consent adequacy2Consent obtained after providing required country information
Recipient assessment2Equivalent measures assessment documented for non-adequacy countries

Frequently Asked Questions

Does the APPI apply to foreign companies?

The APPI applies to any business operator that handles personal information of individuals in Japan, including foreign companies that provide goods or services to individuals in Japan or collect personal information of individuals in Japan.

What is the EU-Japan adequacy arrangement?

The EU and Japan have mutual adequacy decisions, enabling free data flows between the two jurisdictions. Japanese organisations receiving EU personal data must comply with supplementary rules that address differences between the APPI and GDPR (e.g., sensitive data categories, retention limitations, onward transfer restrictions).

How do the 2022 amendments affect existing compliance?

Key changes: mandatory data breach notification (previously voluntary), strengthened cross-border transfer requirements (country information must be provided before consent), individual rights expanded (right to request cessation of use and deletion), and pseudonymously processed information framework introduced. All existing documentation should be reviewed against the 2022 requirements.

Can AI review help with APPI documentation?

AI review can check privacy policies for utilisation purpose specificity, verify third-party provision records contain all required fields, assess cross-border transfer documentation for 2022 requirements, and check security documentation across all four PPC categories. Legal adequacy under Japanese law requires qualified Japanese data protection professionals.

Key Takeaways

  • APPI's 2022 amendments significantly strengthened documentation requirements — breach notification, cross-border transfers, and individual rights all expanded.
  • Utilisation purposes must be "as concrete as possible" — vague purpose statements are the most common compliance gap.
  • Cross-border transfers require country-specific information to be provided to individuals before obtaining consent.
  • Third-party provision records are a specific APPI requirement with no direct GDPR equivalent — both providers and recipients must maintain records.
  • Security documentation must cover all four PPC categories — organisational, personnel, physical, and technical measures.
  • AI review checks specificity, completeness, and 2022 compliance — legal adequacy requires qualified Japanese professionals.
  • Japan's EU adequacy decision creates supplementary obligations for Japanese organisations receiving EU personal data.

This article is for informational purposes only. The APPI and PPC guidelines are subject to amendment and interpretation. Consult a qualified Japanese data protection professional or legal adviser for guidance specific to your organisation's personal information handling.

appi-compliancejapan-data-protectionppc-japanprivacy-documentationappi-japanpersonal-information-protection

Need consistent content quality across your team?

TeamBench lets you create custom AI reviewers that score content against your specific criteria. Submit content, get instant scored feedback, and improve with one click.

  • Create custom AI reviewers for your brand
  • Score content against your specific criteria
  • Instant feedback, one-click improvement
  • Free to start — no credit card required