Japan - Personal Information Protection Amendment (Act No. 44/2020)
Amendment to the Act on the Protection of Personal Information
個人情報の保護に関する法律の一部を改正する法律
Japan
RAI-JP-NA-APPIAXX-2020The 2020 amendment (Act No. 44 of 2020) substantially updated Japan's Act on the Protection of Personal Information to strengthen data subject rights, require breach reporting and notification, create new legal categories (pseudonymized and personal-related information), tighten restrictions on third‑party and cross‑border transfers, and enhance the enforcement powers of the Personal Information Protection Commission (PPC). Most provisions entered into force on April 1, 2022, with transitional measures (including opt-out notification regimes) phased in earlier.
Summary
Background and purpose: The Amendment to the Act on the Protection of Personal Information (APPI), enacted by the National Diet in June 2020 (Act No. 44 of 2020), implements a major update of Japan’s privacy framework to balance individual rights with socially valuable data use. It responds to technological change, cross‑border data flows, and domestic policy reviews that followed the 2015 reform which mandated periodic legislative review. The amendment seeks to: (a) strengthen protections and remedies for individuals; (b) clarify and modernize definitions and legal categories for data processing (including pseudonymized and personal‑related information); (c) require notification and reporting of serious security incidents; (d) tighten controls on third‑party provision and cross‑border transfers of personal data; and (e) strengthen the independence, investigative and enforcement powers of the Personal Information Protection Commission (PPC).
Key legal innovations: The amendment (i) introduced a statutory definition and governance regime for "pseudonymized personal information" (仮名加工情報), enabling controlled secondary use while requiring safeguards and limits on re‑identification; (ii) created the category of "personal‑related information" (個人関連情報) — information that relates to an identifiable individual when combined with other data (used to regulate targeted profiling and cookie / tracking practices); (iii) mandated reporting to the PPC and, in many cases, notification to affected data subjects where a security incident is likely to cause substantial harm to rights and interests; (iv) strengthened transparency through mandated recordkeeping and public disclosure obligations for held personal data and for some third‑party transfers; and (v) required enhanced prior information to data subjects when seeking consent to provide personal data to third parties abroad.
Operational and compliance effects: Businesses handling personal information were required to revisit policies, update privacy notices, implement technical and organizational security measures (including measures for pseudonymization and anonymization), and introduce incident response and reporting processes. The law also introduced a certification / accreditation scheme and more formalized administrative supervision by the PPC. The amendment tightened opt‑out rules (requiring registration/notification in some cases) and introduced additional obligations for operators that provide targeted profiling services or operate databases of personal‑related information.
Enforcement and sanctions: The 2020 amendment strengthened the PPC’s enforcement tools. Criminal and administrative sanctions remain in the statute: the consolidated APPI includes penal provisions (e.g., certain violations carry potential imprisonment or fines for individuals, and significant corporate fines for specified criminal offenses—Article 184 refers to corporate fines up to JPY 100,000,000 in relation to particular offences). The PPC may issue corrective orders and, where parties fail to comply, matters may be referred to prosecutors. The amendment also expanded the PPC’s powers to issue guidance, require reports, and coordinate cross‑border enforcement and adequacy mechanisms.
International context: The amendments were framed to facilitate international data flows while assuring adequate protection for Japanese data subjects. They interact with adequacy frameworks (e.g., the EU adequacy decision recognizing Japan’s protection regime) and with bilateral and multilateral dialogues that the PPC conducts with other data protection authorities. The law signals Japan’s intent to remain interoperable with global privacy regimes while enabling domestic data use for innovation, subject to safeguards.
Implementation timeline and guidance: The law was enacted on June 5, 2020 and promulgated on June 12, 2020; many provisions became effective by April 1, 2022, while transitional measures (including changes to the opt‑out notification regime) were phased in from October 1, 2021 and earlier depending on rulemaking. The PPC and other ministries issued implementing regulations, enforcement rules, and guidance documents in the run‑up to enforcement; businesses had to align privacy policies and operational controls accordingly.
Practical impact: For companies—Japanese and multinational—the amendment required careful review of cross‑border transfer practices, vendor arrangements, cookie/advertising stacks, breach‑response playbooks, and documentation practices (including records of transfers). For individuals, the amendments expanded rights and transparency and introduced stronger administrative oversight and avenues for redress. The PPC’s guidance and the English consolidated texts are available from the Personal Information Protection Commission and the official law translation services for review and compliance planning.
Full article
Read full text ↗Overview
The 2020 Amendment to the Act on the Protection of Personal Information (APPI) ("Act No. 44 of 2020") was enacted by the Diet on 2020‑06‑05 and promulgated on 2020‑06‑12. The amendment modernizes Japan's data protection framework by introducing new legal categories (notably "pseudonymized personal information" and "personal‑related information"), by requiring reporting of serious data security incidents and, in many cases, notifying affected persons, and by strengthening obligations for cross‑border transfers and transparency. The Personal Information Protection Commission (PPC) was tasked with producing implementing regulations, guidance, and enforcement standards and the PPC published explanatory materials and the official law text in both Japanese and English. For primary sources and the official PPC announcement see PPC: "公布について" (2020‑06‑12) and the consolidated Act as published in English at Japanese Law Translation: Act on the Protection of Personal Information. The majority of the amendment's provisions entered into force on 2022‑04‑01 (with transitional measures beginning earlier), after the PPC and relevant ministries issued implementing regulations and detailed guidelines.
Definitions
The amendment refines and expands statutory terms. Key definitions added or clarified include: "pseudonymized personal information" (仮名加工情報) — personal information processed to prevent direct identification without additional information (subject to processing and re‑identification controls); "personal‑related information" (個人関連情報) — information about a living person that does not itself identify them but may do so when combined with other information (the law establishes special rules for the collection, transfer and notice associated with such data, particularly relevant to cookie/online tracking ecosystems); "anonymized information" (匿名加工情報) — subject to requirements for safe secondary use; and expanded definitions of "personal data" and "business operator handling personal information" to align with modern processing contexts. The amendment differentiates obligations depending on whether data is identifiable, pseudonymized, or anonymized and sets out rules for preparation, provision, and management of these categories.
Governance and Institutional Framework
The Personal Information Protection Commission (PPC) remains the central independent regulator; the amendment both reinforces its authority and requires the PPC to promulgate implementing rules and guidance, publish registries (such as opt‑out registrants) and manage certification schemes. The PPC’s responsibilities under the amendment include issuing rules on cross‑border transfer safeguards, specifying circumstances requiring breach reporting and subject notification, defining technical and organizational measures for pseudonymization and anonymization, and maintaining guidelines for sectoral compliance. The PPC has published explanatory materials and consolidated law texts in English and Japanese; see the PPC legal page at PPC: Laws & Policies (English). The amendment also anticipates coordination with other ministries and agencies (e.g., Digital Agency, Ministry of Internal Affairs and Communications) for sectoral implementation and enforcement, and it establishes administrative procedures for receiving and publishing opt‑out notifications and other registries.
Key Focus Areas
The amendment focuses on several interlocking areas: (1) Rights and remedies for data subjects — improved transparency (access, correction, deletion/cessation), clearer disclosure obligations for held personal data and expanded grounds for cessation of use; (2) Security incident handling — mandatory reporting to the PPC and notification to affected individuals when incidents are likely to cause significant harm; (3) Data categories — statutory treatment of pseudonymized and anonymized information to enable responsible data reuse while reducing re‑identification risk; (4) Third‑party provision and cross‑border transfers — stronger requirements for prior information to data subjects, enhanced recordkeeping and in certain cases extra procedural steps prior to transfer to a foreign third party; (5) Business accountability — requirements for documenting transfers, supervisory arrangements for contractors, and certification schemes to promote best practices; (6) Regulatory enforcement — stronger investigative powers and clarified penal provisions for non‑compliance; and (7) Market and innovation balance — allowing controlled secondary use (for research and innovation) while embedding privacy safeguards. These focus areas collectively aim to create a predictable compliance environment that supports both rights protection and socially useful data utilization.
Implementation Framework
The law established a multi‑layer implementation framework: national laws set baseline duties; the PPC issues enforcement rules, Cabinet Orders and PPC regulations further specify technical and procedural measures; and sectoral guidance provides industry‑specific clarifications (e.g., health care, finance). Business operators were required to update privacy statements, implement breach detection and reporting protocols, adopt pseudonymization/anonymization techniques where appropriate, and maintain records of transfers to third parties and to foreign recipients. The PPC also established registration and public disclosure processes for certain opt‑out third‑party transfers and developed an accreditation/certification regime to recognize compliance schemes. In practice businesses needed to audit data flows, vendor arrangements, cross‑border transfer clauses, and online tracking stacks (cookies) to bring them into compliance with the amendment’s notice and consent/opt‑out rules.
Monitoring and Evaluation
Monitoring relies primarily on PPC supervision, mandatory reporting of incidents, and public complaint channels. The PPC receives incident reports, publishes summaries, carries out inspections, and can require remedial measures. The law also expands the PPC’s authority to collect information, issue corrective orders, and maintain registries (e.g., opt‑out registrants). The PPC’s annual reports and guidance documents publish statistics on reported breaches and enforcement actions, enabling evaluation of the law’s practical impact. The amendment also envisioned periodic review cycles (building on the three‑year review mechanism introduced earlier) so that the PPC and the Diet can assess whether statutory rules remain effective in the face of technological change.
Penalties, Liability, and Appeals
The APPI retains a mix of administrative, civil and criminal remedies. The PPC can issue orders, require corrective action and public disclosures. Criminal and monetary penalties remain for certain offenses: the consolidated text includes penal provisions (e.g., imprisonment and fines for unauthorized provision or misuse of personal information, and for failing to comply with inspection or reporting duties). The law’s penal chapter specifies individual fines and imprisonment terms and provides for corporate fines in relation to certain offences (Article 184 includes corporate fines up to JPY 100,000,000 for specified violations). Parties ordered by the PPC may face criminal referral if they fail to comply. Data subjects retain access to civil remedies and may seek judicial redress for damages; administrative appeal routes against PPC decisions and orders are also available under the law’s procedural chapters.
Relationship to Other Instruments
The 2020 amendment was designed to work with existing national instruments (such as sectoral laws on health and finance) and with later reforms that integrated public‑sector data handling under a unified framework (subsequent amendments in 2021/2023 furthered integration). It complements Cabinet Orders, PPC enforcement rules and multiple PPC guidelines (general guidance, cross‑border transfer guidance, pseudonymization/anonymous information guidance, and opt‑out procedural guidance). The law also interacts with international arrangements (e.g., Japan‑EU adequacy recognition), and it references implementing regulations and guidance that operationalize key duties (security measures, definitions of reportable incidents, and recordkeeping obligations). For implementing materials and consolidated guidance see the PPC resources at PPC Laws & Policies (English) and the e‑Gov data portal English resources.
International Alignment
The amendment aimed to maintain Japan's international compatibility by strengthening individual protections while allowing for defined pathways for cross‑border data flows. Japan’s regulatory framework, including the amendment, was assessed in the context of the EU adequacy decision (which recognized Japan as providing adequate protection for personal data under the GDPR) and in dialogues with the EU, UK, US and other DPAs. The law increases the information required to be provided to data subjects for transfers abroad and tasks the PPC with specifying the mechanics for ensuring equivalent protection. The amendment positions Japan to participate in bilateral and plurilateral frameworks for data flows while preserving regulatory tools for enforcement and redress.
Implementation Timeline
| Event | Date |
|---|---|
| Bill submitted to the Diet | 2020-03-10 |
| Diet enacted the amendment (passed) | 2020-06-05 |
| Promulgation (official publication) | 2020-06-12 |
| Opt‑out procedure transition / registration start (transitional measures) | 2021-10-01 |
| Main provisions (most obligations) entered into force (full enforcement) | 2022-04-01 |
| Ongoing PPC guidance, regulations and sectoral rules published (implementation window) | 2020-2022 (and thereafter) |
Sources and References
Requirements for a company
What an organisation has to do under Japan - Personal Information Protection Amendment (Act No. 44/2020), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
9- Report serious data security incidents to the PPC and notify affected individuals.Business operators handling personal information.
- Implement stronger requirements for cross-border transfers, including prior information to data subjects.Business operators transferring personal information to foreign third parties.
- Maintain records of third-party transfers, especially those to foreign recipients.Business operators transferring personal information.
- Update privacy statements to include new disclosure elements and cross-border transfer information.Business operators handling personal information.
- Implement procedures for preparing, providing, and managing pseudonymized and anonymized information.Business operators processing pseudonymized or anonymized information.
- Review and update vendor agreements to ensure contractual safeguards for data processing.Business operators engaging third-party contractors.
- +3 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Japan - Personal Information Protection Amendment (Act No. 44/2020), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Business operators handling personal information. | Report serious data security incidents to the PPC and notify affected individuals. “mandatory reporting to the PPC and notification to affected individuals when incidents are likely to cause significant harm” | Apr 1, 2022 | — | Critical |
| 2 | Business operators transferring personal information to foreign third parties. | Implement stronger requirements for cross-border transfers, including prior information to data subjects. “stronger requirements for prior information to data subjects... prior to transfer to a foreign third party” | Apr 1, 2022 | — | Critical |
| 3 | Business operators transferring personal information. | Maintain records of third-party transfers, especially those to foreign recipients. “enhanced recordkeeping and in certain cases extra procedural steps prior to transfer to a foreign third party” | Apr 1, 2022 | — | Important |
| 4 | Business operators handling personal information. | Update privacy statements to include new disclosure elements and cross-border transfer information. “Business operators were required to update privacy statements, implement breach detection and reporting protocols” | Apr 1, 2022 | — | Important |
| 5 | Business operators processing pseudonymized or anonymized information. | Implement procedures for preparing, providing, and managing pseudonymized and anonymized information. “sets out rules for preparation, provision, and management of these categories.” | Apr 1, 2022 | — | Important |
| 6 | Business operators engaging third-party contractors. | Review and update vendor agreements to ensure contractual safeguards for data processing. “supervisory arrangements for contractors” | Apr 1, 2022 | — | Important |
| 7 | Business operators handling personal information. | Map personal data flows and classify data into identifiable, pseudonymized, or anonymized categories. “The amendment differentiates obligations depending on whether data is identifiable, pseudonymized, or anonymized” | Apr 1, 2022 | — | Important |
| 8 | Business operators handling personal information. | Provide data subjects with improved access, correction, deletion, and cessation of use rights. “improved transparency (access, correction, deletion/cessation), clearer disclosure obligations for held personal data” | Apr 1, 2022 | — | Important |
| 9 | Business operators making opt-out third-party transfers. | File opt-out notifications for certain third-party transfers where applicable. “registration and public disclosure processes for certain opt‑out third‑party transfers” | Oct 1, 2021 | — | Important |
Related Regulations
Personal Information Protection Act (amendment including provisions on automated decision-making/AI)
South Korea86% similar
Personal Information Protection Law of the People's Republic of China (PIPL)
China86% similar
Privacy Act 2020
New Zealand86% similar
Personal Data Protection Act B.E. 2562 (2019)
Thailand85% similar
Contract Guidelines on Utilization of AI and Data
Japan84% similar
© Regulations.AI · updated on 13-Jun-2026