APPI Compliance: Data Protection Documentation Under Japan's Privacy Law
Japan's APPI has created documentation requirements comparable to GDPR, with an EU adequacy decision in place. Here's what documentation you need, key differences from GDPR, and how to review.
Japan's Act on the Protection of Personal Information (APPI) — significantly amended in 2022 — has established a data protection framework that earned an EU adequacy decision, enabling free data flows between Japan and the EU. The Personal Information Protection Commission (PPC) actively enforces the APPI with expanding investigative powers and increasing willingness to take public enforcement action.
The 2022 amendments strengthened individual rights, introduced mandatory data breach notification, expanded cross-border transfer requirements, and created new obligations around pseudonymously processed information. Organisations that complied with the pre-amendment APPI likely have documentation gaps under the current law.
APPI Core Obligations
| Obligation | Requirement | Documentation Implication |
|---|---|---|
| Utilisation purpose specification | Specify the purpose of use as concretely as possible | Purpose statements published and maintained |
| Use limitation | Use personal information only within the specified purpose | Processing records aligned with stated purposes |
| Proper acquisition | Obtain personal information through proper means | Acquisition records, consent documentation |
| Accuracy | Keep data accurate and up to date | Data quality procedures |
| Security management | Take necessary and appropriate measures | Security documentation |
| Supervision of employees | Supervise employees handling personal data | Training records, access controls |
| Supervision of contractors | Supervise contractors handling personal data | Contractor agreements, oversight records |
| Third-party provision restrictions | Obtain consent before providing to third parties | Consent records, third-party provision records |
| Cross-border transfer restrictions | Additional requirements for overseas transfers | Transfer documentation, consent or safeguards |
Required APPI Documentation
1. Utilisation Purpose Notice (Privacy Policy)
Must be publicly available and provided to the individual at or before the time of acquisition:
| Element | Requirement |
|---|---|
| Business operator identity | Name and contact information |
| Utilisation purposes | Specific purposes for each category of personal information — "as concretely as possible" |
| Third-party provision | Whether personal information will be provided to third parties, and if so, categories of data, means of provision, and how to opt out |
| Shared use | If data is shared within a group — scope of shared use, categories of data, purpose, and responsible entity |
| Cross-border transfers | Countries to which data may be transferred, the protection system in those countries |
| Individual rights | How to request disclosure, correction, cessation of use, and deletion |
| Complaints | Contact for complaints about personal information handling |
| Cookies and tracking | If applicable — use of cookies and tracking technologies |
APPI specificity requirement: The PPC requires utilisation purposes to be "as concrete as possible." A purpose stated as "for our business operations" is insufficient. Purposes should be specific enough that the individual can reasonably predict how their information will be used.
2. Records of Third-Party Provision
The APPI requires both the provider and the recipient to maintain records when personal information is provided to or received from third parties:
Provider Records (Article 29)
| Field | Detail |
|---|---|
| Date of provision | When the information was provided |
| Name of recipient | The third party receiving the information |
| Categories of data | What personal information was provided |
| Individual identification | Name or other identifier of the data subject |
Recipient Records (Article 30)
| Field | Detail |
|---|---|
| Date of receipt | When the information was received |
| Name of provider | The third party providing the information |
| Acquisition circumstances | How the provider acquired the information |
| Categories of data | What personal information was received |
| Individual identification | Name or other identifier of the data subject |
| PPC confirmation | Confirmation that the provider legally acquired the data |
Retention: These records must be retained for 3 years (for providers) or the period of use plus 6 months (for recipients, minimum 1 year).
3. Consent Documentation
| Consent Type | When Required | Documentation |
|---|---|---|
| Third-party provision | Before providing personal information to third parties | Consent record with date, scope, and method |
| Cross-border transfer | Before transferring to overseas third parties | Consent specifying the country and protection system |
| Sensitive personal information | Before acquiring personal information requiring special care | Explicit consent record |
| Purpose change | When changing the utilisation purpose beyond the original scope | Consent for the new purpose |
| Opt-out scheme | If using opt-out instead of prior consent for third-party provision | PPC notification, public disclosure |
4. Security Management Measures Documentation
The APPI requires "necessary and appropriate" security measures. The PPC guidelines specify four categories:
| Category | Documentation Required |
|---|---|
| Organisational measures | Responsible person appointed, handling rules established, regular audits conducted |
| Personnel measures | Training programme, confidentiality obligations, access management |
| Physical measures | Facility security, device management, document/media controls |
| Technical measures | Access control systems, intrusion detection, encryption, logging |
Additionally document:
- Security incident response procedures
- Regular security assessment results
- Employee training records
- Contractor security oversight
5. Data Breach Notification Documentation
Mandatory since the 2022 amendment for breaches involving: sensitive personal information, property damage risk, wrongful purpose, or affecting 1,000+ individuals.
| Document | Requirement |
|---|---|
| Breach response plan | Detection, assessment, containment, notification procedures |
| PPC notification | Preliminary report "promptly" and detailed report within 30 days (60 days for wrongful purpose breaches) |
| Individual notification | Notification to affected individuals "promptly" |
| Breach register | Record of all breaches including those below the notification threshold |
| Post-breach review | Root cause analysis and preventive measures |
6. Cross-Border Transfer Documentation
The 2022 amendment significantly strengthened cross-border transfer requirements:
| Transfer Mechanism | Documentation Required |
|---|---|
| Consent-based transfer | Consent specifying the country, the country's data protection system, and the recipient's measures — must provide this information to the individual before obtaining consent |
| Adequacy country | Verification that the country is on the PPC's list of countries with equivalent protection (currently: EU/EEA and UK) |
| Equivalent measures | Evidence that the recipient has measures equivalent to APPI — documented assessment, contractual provisions, monitoring |
| APEC CBPR certification | Recipient certified under the APEC Cross-Border Privacy Rules system |
Key 2022 change: Before obtaining consent for cross-border transfers, the business operator must provide information about the destination country's personal information protection system and the recipient's measures. This creates a substantial documentation obligation.
7. Pseudonymously Processed Information Documentation
New category introduced in the 2022 amendment:
| Document | Requirement |
|---|---|
| Processing methodology | How personal information is pseudonymised (which elements removed/replaced) |
| Deleted information management | How the information used to restore identity is managed |
| Utilisation purpose | Purposes for which pseudonymously processed information is used |
| Security measures | Measures to prevent re-identification |
Key Differences: APPI vs GDPR
| Aspect | APPI | GDPR |
|---|---|---|
| Legal basis framework | Consent-focused; limited "legitimate interest" equivalent | Six legal bases including legitimate interest |
| Sensitive data | "Personal information requiring special care" — racial/ethnic origin, beliefs, medical history, criminal history | Special categories — broader list |
| Third-party provision | Opt-out scheme available (with PPC notification) | Consent or other legal basis required |
| Cross-border transfers | Consent (with country information), adequacy, equivalent measures, or CBPR | Adequacy, SCCs, BCRs, or derogations |
| Breach notification | PPC: "promptly" + 30 days; individuals: "promptly" | DPA: 72 hours; individuals: "without undue delay" |
| Enforcement | PPC recommendations, orders, fines (up to ¥100M for corporations) | Administrative fines up to €20M or 4% turnover |
| Record-keeping | Specific third-party provision/receipt records required | Records of processing activities |
Common APPI Compliance Gaps
Gap 1: Utilisation Purposes Not Specific Enough
Purpose statements that are too broad or abstract for individuals to understand how their information will actually be used. The PPC has issued guidance emphasising the "as concrete as possible" standard.
Gap 2: Cross-Border Transfer Consent Not Meeting 2022 Requirements
Consent for overseas transfers obtained without providing the required information about the destination country's protection system and the recipient's measures. Pre-2022 consent may not meet current requirements.
Gap 3: No Third-Party Provision Records
The record-keeping obligation for third-party provision and receipt is specific to the APPI and has no direct GDPR equivalent. Many organisations have not implemented the required record-keeping system.
Gap 4: Security Management Measures Not Documented Across All Four Categories
Security documentation that covers technical measures but not organisational, personnel, or physical measures as specified in PPC guidelines.
Gap 5: Breach Notification Plan Not Updated for 2022 Requirements
Breach response plans that don't reflect the mandatory notification requirements introduced in the 2022 amendment, including the specific thresholds, timelines, and PPC reporting format.
Reviewing APPI Documentation
Privacy Policy Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Purpose specificity | 3 | Utilisation purposes are "as concrete as possible" |
| Completeness | 3 | All APPI-required elements present |
| Cross-border information | 2 | Country, protection system, and recipient measures disclosed |
| Third-party provision disclosure | 2 | Categories, means, and opt-out mechanism documented |
| Currency | 1 | Reflects current processing activities and purposes |
Cross-Border Transfer Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Country information provided | 3 | Protection system of each destination country documented and disclosed |
| Transfer mechanism | 3 | Each transfer has an identified legal mechanism (consent, adequacy, equivalent measures, CBPR) |
| Consent adequacy | 2 | Consent obtained after providing required country information |
| Recipient assessment | 2 | Equivalent measures assessment documented for non-adequacy countries |
Frequently Asked Questions
Does the APPI apply to foreign companies?
The APPI applies to any business operator that handles personal information of individuals in Japan, including foreign companies that provide goods or services to individuals in Japan or collect personal information of individuals in Japan.
What is the EU-Japan adequacy arrangement?
The EU and Japan have mutual adequacy decisions, enabling free data flows between the two jurisdictions. Japanese organisations receiving EU personal data must comply with supplementary rules that address differences between the APPI and GDPR (e.g., sensitive data categories, retention limitations, onward transfer restrictions).
How do the 2022 amendments affect existing compliance?
Key changes: mandatory data breach notification (previously voluntary), strengthened cross-border transfer requirements (country information must be provided before consent), individual rights expanded (right to request cessation of use and deletion), and pseudonymously processed information framework introduced. All existing documentation should be reviewed against the 2022 requirements.
Can AI review help with APPI documentation?
AI review can check privacy policies for utilisation purpose specificity, verify third-party provision records contain all required fields, assess cross-border transfer documentation for 2022 requirements, and check security documentation across all four PPC categories. Legal adequacy under Japanese law requires qualified Japanese data protection professionals.
Key Takeaways
- APPI's 2022 amendments significantly strengthened documentation requirements — breach notification, cross-border transfers, and individual rights all expanded.
- Utilisation purposes must be "as concrete as possible" — vague purpose statements are the most common compliance gap.
- Cross-border transfers require country-specific information to be provided to individuals before obtaining consent.
- Third-party provision records are a specific APPI requirement with no direct GDPR equivalent — both providers and recipients must maintain records.
- Security documentation must cover all four PPC categories — organisational, personnel, physical, and technical measures.
- AI review checks specificity, completeness, and 2022 compliance — legal adequacy requires qualified Japanese professionals.
- Japan's EU adequacy decision creates supplementary obligations for Japanese organisations receiving EU personal data.
This article is for informational purposes only. The APPI and PPC guidelines are subject to amendment and interpretation. Consult a qualified Japanese data protection professional or legal adviser for guidance specific to your organisation's personal information handling.