Japan
Tier 2 Comprehensive law Asia-PacificPrincipal framework: APPI (as amended) (2003). Regulator: PPC. Mutual adequacy with the EU since 2019; the APPI runs on a three-year review cycle, with the next amendment round in progress.
At a glance
- Principal law
- APPI (as amended)
- Regulator
- PPC
- Breach notification
- Prompt report to the PPC (preliminary, then final within 30/60 days) and notice to individuals
- Maximum penalty
- Corporate fines up to JPY 100m for order violations
- DPO required
- No general mandate
- Digital consent age
- No statutory age; guardian consent in practice for minors
- Extraterritorial reach
- Yes — supplying goods or services to persons in Japan
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- JP
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- No
- EEA member
- No
- Holds EU adequacy
- Yes
- Granted
- 23 January 2019
- Review
- 4-year review (first done 2023)
GDPR Art.45; first GDPR adequacy decision and first mutual finding.
Instruments
No instrument profiled yet.
Sources
- Regulator Personal Information Protection Commission (PPC)
- Primary Adequacy decision
- Regulator PPC — regulator and APPI
Never independently verified — seeded from the prototype.