Data Protection Atlas

Japan

Tier 2 Comprehensive law Asia-Pacific

Principal framework: APPI (as amended) (2003). Regulator: PPC. Mutual adequacy with the EU since 2019; the APPI runs on a three-year review cycle, with the next amendment round in progress.

At a glance

Principal law
APPI (as amended)
Regulator
PPC
Breach notification
Prompt report to the PPC (preliminary, then final within 30/60 days) and notice to individuals
Maximum penalty
Corporate fines up to JPY 100m for order violations
DPO required
No general mandate
Digital consent age
No statutory age; guardian consent in practice for minors
Extraterritorial reach
Yes — supplying goods or services to persons in Japan

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
JP

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No
Holds EU adequacy
Yes
Granted
23 January 2019
Review
4-year review (first done 2023)

GDPR Art.45; first GDPR adequacy decision and first mutual finding.

Instruments

No instrument profiled yet.

Sources

Never independently verified — seeded from the prototype.