Mandatory scheme
Act on the Protection of Personal Information (APPI) compliance
Act on the Protection of Personal Information (APPI) compliance — mandatory scheme, Japan. It binds business operators handling personal information in Japan.
- Jurisdiction
- Japan
- Record class
- Mandatory scheme
- Last verified
Where this applies
This record is scoped to Japan. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.
Instrument
Act on the Protection of Personal Information (Act No. 57 of 2003, as amended, Act No. 37 of 2021)
Who it binds
Business operators handling personal information in Japan
What it requires
Art. 21(1) requires promptly notifying the purpose of use to the individual, or making it public, on acquiring personal information. Art. 23 requires taking necessary and appropriate security-management measures, including preventing leaks, loss or damage of personal data. Art. 26(1) requires reporting a data breach to the Personal Information Protection Commission (PPC), and Art. 26(2) requires notifying the affected individual — each subject to narrow exceptions stated in the Act.
Route to the authority
Last verified:
Related records and requirements
- Personal Information Protection and Electronic Documents Act (PIPEDA) (Canada) — PIPEDA is Canada's federal general-compliance data-protection law, binding organisations that collect, use or disclose personal information in the course of commercial activity.
- Act Respecting the Protection of Personal Information in the Private Sector (Québec) (Canada) — Québec's own private-sector privacy law is the general-compliance regime for private-sector businesses handling personal information within Québec — it takes the place of PIPEDA for that in-province activity.
- Privacy Act 1988 — Australian Privacy Principles (Australia) — The Privacy Act 1988 binds Australian government agencies and covered organisations to 13 Australian Privacy Principles — the small-business turnover exemption has documented exceptions.
- Personal Data (Privacy) Ordinance compliance (Hong Kong SAR China) — Hong Kong's Cap. 486 sets six Data Protection Principles binding data users in Hong Kong, overseen by the PCPD.
- Personal data protection compliance (Vietnam) — Vietnam's Decree 13/2023 and, from 1 January 2026, Law 91/2025 bind organisations processing personal data in Vietnam to a general data-protection compliance regime.
- Federal personal data protection compliance (Mexico) — Mexico's federal private-sector data-protection law, replaced in full on 20 March 2025, binds private-sector personal-data processing nationwide.
- Personal Data Protection Law (PDPL) compliance (Saudi Arabia) — Saudi Arabia's PDPL (Royal Decree M/19) binds entities processing personal data in Saudi Arabia to a general data-protection compliance law.
- Federal personal data protection compliance (United Arab Emirates) — The UAE's federal PDPL (Federal Decree-Law No. 45 of 2021) binds organisations processing personal data inside or outside the UAE where the processing relates to the UAE — separate from DIFC's and ADGM's own free-zone regimes.
- Privacy Act 2020 — notifiable privacy breach (New Zealand) — New Zealand's Privacy Act 2020 requires notifying the Privacy Commissioner and affected individuals of a breach causing, or likely to cause, serious harm, using the Commissioner's NotifyUs tool.
- Privacy Act 1988 — Australian Privacy Principles (Australia) — Australia's Notifiable Data Breaches scheme requires notifying both affected individuals and the OAIC of a data breach likely to cause serious harm.
This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.