Japan APPI vs GDPR: Key Differences Compared (2026)

Japan's Act on the Protection of Personal Information (APPI) and the EU's GDPR both regulate personal data, but they solve the core compliance problems differently. The clearest example is third-party data sharing: APPI lets a business disclose personal data to third parties on an opt-out basis after filing with the regulator, something the GDPR has no equivalent for at all.
Both frameworks give individuals rights over their personal information and both are enforced by a national data-protection regulator, but the resemblance is mostly structural. APPI's opt-out third-party transfer channel, its codified two-tier system for de-identified data, and its origin-dependent rules for EU/UK-sourced personal data have no direct GDPR parallel, and organizations that assume APPI simply mirrors GDPR compliance work will miss real operational gaps.
Information last verified on 2026-07-23. This article has not yet been reviewed by a licensed lawyer.
Jurisdiction scope: This article compares Japan's Act on the Protection of Personal Information (APPI), administered by the Personal Information Protection Commission (PPC), with the EU's General Data Protection Regulation (GDPR). It covers the current, in-force version of APPI plus the amendment enacted July 10, 2026 and promulgated July 17, 2026 -- which is explicitly flagged throughout as NOT YET IN FORCE. For the full history and current status of Japanese privacy law, see our Japan data privacy laws guide. For a full walkthrough of the GDPR itself, see What Is GDPR.
Japan APPI vs GDPR: At a Glance
| Feature | GDPR | Japan APPI |
|---|---|---|
| Regulator | National DPAs, coordinated by the EDPB | Personal Information Protection Commission (PPC) |
| Lawful-basis structure | Enumerated Article 6 list (six bases, including legitimate interests) | No enumerated list; purpose specification (Art. 17) plus consent required only at specific checkpoints |
| Opt-out third-party transfer | Not available -- every non-consent disclosure needs an individually justified lawful basis | Available under Art. 27(2) after a PPC filing, subject to hard exclusions |
| Pseudonymization | A security/risk-mitigation measure; the data remains fully in scope of GDPR | A distinct legal status (Art. 2(5)) carrying its own obligations, including a ban on third-party transfer |
| Anonymization | Undefined in the operative articles; threshold set by guidance and case law | A codified technical standard (Cabinet Order Art. 34); once met, the data falls outside the Act |
| Countries with "adequate" status | Dozens of countries and territories hold EU adequacy decisions | Only the EU/EEA and the UK hold Japan's Art. 28 adequate-country designation |
| Rules for EU/UK-sourced personal data | N/A | Stricter PPC Supplementary Rules apply on top of ordinary APPI |
| Administrative monetary penalty | Up to EUR 20 million or 4% of global annual turnover (Art. 83(5)) | No administrative fine currently exists; an economic-benefit-based surcharge (課徴金) was enacted July 2026 but is not yet in force |
| Collective/injunction rights | Available through various member-state mechanisms | Proposed for the 2026 reform, then dropped before the bill passed |
| Dominant real-world enforcement tool | Formal investigations and administrative fines | PPC guidance (指導) -- FY2025: 455 guidance actions against 1 formal order |

Background and Legislative Context
Japan's current privacy framework is the Act on the Protection of Personal Information, enforced by the PPC, with a mutual adequacy arrangement with the EU dating to January 23, 2019 -- reaffirmed after the EU's first periodic review in 2023, with the next review expected around 2027.
The APPI is now mid-reform. The PPC finalized its "System Reform Policy" under Japan's triennial statutory review on January 9, 2026, and the Cabinet approved the resulting bill and submitted it to the 221st Diet on April 7, 2026. The bill passed both houses of the Diet on July 10, 2026, and was promulgated on July 17, 2026. It is not yet in force: Japanese practice brings a promulgated law into effect through a subsequent cabinet order, and here that order is due within roughly two years of promulgation (no later than around July 2028), with the PPC now drafting the implementing order, rules, and guidelines. Every reform-related provision discussed on this page -- the administrative surcharge, the new biometric-data category, the children's-consent changes, and the rest -- should be read as enacted but not yet operative unless stated otherwise.
The GDPR, by contrast, has been fully in force across the EEA since May 25, 2018 and is not currently mid-amendment in the way APPI is.

Scope and Application
This article focuses on the operational compliance differences between the two frameworks: how lawfulness is established, how consent and third-party sharing work, how cross-border transfers are structured, and how each regime enforces its rules. For the country-level detail on how APPI developed and its full territorial application, see the Japan data privacy laws guide.
Both regimes are administered by a single dedicated authority model at the national level: Japan's PPC handles the entire APPI, while the GDPR is enforced by each EU member state's own data protection authority, with cross-border consistency coordinated through the European Data Protection Board framework the GDPR establishes.

Definitions and Protected Data
| Concept | GDPR | APPI |
|---|---|---|
| Protected individual | Data subject | Individual |
| Protected data | Personal data | Personal information (個人情報) |
| Sensitive-category data | Special categories (Art. 9) | Special Care-Required Personal Information, also translated "sensitive personal information" (Art. 2(3)) |
| De-identified but re-identifiable | Pseudonymisation (Art. 4(5)) -- a security measure; the data remains personal data | Pseudonymously Processed Information (仮名加工情報, Art. 2(5)) -- a distinct legal status with its own rulebook |
| Irreversibly de-identified | Anonymisation (Recital 26) -- outside GDPR scope once the threshold is met, but the threshold itself is set by guidance and case law, not statute | Anonymously Processed Information (匿名加工情報, Art. 2(6)) -- outside the Act once processed to a Cabinet-Order-codified technical standard |
| Regulator | National DPAs + EDPB | Personal Information Protection Commission (PPC) |
APPI Article 2(3) defines Special Care-Required Personal Information as personal information relating to an identifiable person's race, creed, social status, medical history, criminal record, the fact of having suffered damage by a crime, "or other identifiers or their equivalent prescribed by Cabinet Order as those of requiring special care so as not to cause unjust discrimination, prejudice or other disadvantages to that person." The implementing Cabinet Order adds physical, intellectual, or mental disability status; the results of a medical check-up or screening; medical guidance or treatment given based on a check-up; and specific criminal or juvenile-protection procedural facts, such as having been arrested, searched, seized, or prosecuted as a suspect or defendant, or having been the subject of a juvenile-case investigation or protective measure. That last category is procedural-history-specific -- it covers whether someone was arrested or prosecuted, not a general "criminal record" catch-all.
Compared to GDPR Article 9's special categories -- racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for unique identification, health data, and sex life or sexual orientation data -- Japan's list is broader on two fronts GDPR does not enumerate at all: general "social status" and having been the victim of a crime. GDPR is broader on identity, biometric, and genetic axes, and separately regulates criminal-conviction data under its own Article 10 (official-authority-only processing), a structurally distinct regime from APPI's approach of folding criminal-procedure facts into the general sensitive-data bucket.

Legal Bases for Processing: No Article 6 Equivalent
The GDPR requires an affirmative lawful basis under Article 6 for every processing activity: consent, contract performance, legal obligation, vital interests, public task, or legitimate interests. APPI has no equivalent enumerated list. There is no "legitimate interest," "contract necessity," or "public task" ground that independently authorizes processing the way GDPR structures it.
Instead, APPI's architecture works like this: acquisition and use of personal information is lawful by default once a business specifies its purpose of use "as much as possible" (Art. 17(1), the purpose-specification duty) and does not then use the data beyond that specified purpose without the individual's advance consent (Art. 18(1)). Consent is not a precondition for ordinary first-party processing itself -- it becomes an affirmative gate mainly at specific higher-risk junctures: acquiring sensitive personal information (Art. 20(2)) and disclosing personal information to a third party, whether domestic (Art. 27(1)) or foreign (Art. 28(1)).
In practice, this means APPI's "legal basis" question is really a purpose-specification-plus-targeted-consent-checkpoints model, not a basis-per-processing-activity model the way GDPR Article 6 works.
Consent Requirements
Because consent under APPI is a checkpoint mechanism rather than a general precondition, it surfaces at three specific moments:
- Acquiring sensitive personal information (Art. 20(2)). Businesses generally may not acquire Special Care-Required Personal Information without advance consent. The Act sets out enumerated exceptions, including where acquisition is required by law, where it protects a person's life, body, or property and consent is hard to obtain, where it serves public-health or child-welfare purposes and consent is hard to obtain, where it supports a government body's statutory function and consent would impede that function, for certain academic-research purposes that avoid undue rights-infringement risk, for information received from an academic institution for joint research, and for information the individual, the government, or a prescribed entity has already made public. The exact clause-by-clause statutory wording of these exceptions was not independently confirmed verbatim for this article; the exception categories themselves are drawn from the government's own English translation of the Act.
- Disclosing to a domestic third party (Art. 27(1)). Advance consent is the default rule -- covered in detail in the next section, because APPI also provides a non-consent alternative here that GDPR does not have.
- Transferring to a foreign third party (Art. 28(1)). Discussed in the cross-border transfers section below.
The enacted-but-not-yet-in-force 2026 reform adds a guardian-consent requirement for individuals under 16 and simplified deletion procedures for minors' data; neither is currently operative.
Third-Party Data Transfers: The Article 27 Opt-Out Regime
This is the area where APPI diverges most sharply from GDPR, and it has no GDPR equivalent at all.
APPI Article 27(1) sets advance consent as the default rule for giving personal data to a third party. But Article 27(2) lets a business skip that consent requirement entirely if it: (a) notifies the individual in advance of the specified items being provided, or makes that information easily accessible; (b) files a notification with the PPC; and (c) commits to stop providing the individual's data on request (the opt-out). The PPC notification is a filing, not a licensing or pre-approval process -- the PPC does not vet or approve these filings before they take effect; it maintains them for public and individual reference and for its own enforcement purposes.
The opt-out route does not cover everything. The official government translation of Article 27(2)'s proviso states that the opt-out mechanism does not apply "in cases in which personal data which is to be provided to a third party is sensitive personal information [Special Care-Required Personal Information], has been acquired in violation of the provisions of Article 21, paragraph (1) [improper acquisition], or has been provided by another business handling personal information pursuant to the provisions of the main clause of this paragraph" -- meaning data that itself already arrived through someone else's opt-out chain cannot be re-opted-out and passed along further. In short: no sensitive data, no improperly-acquired data, and no daisy-chaining.
Secondary legal commentary describes a 2022 tightening (already in force, separate from the 2026 reform) that requires businesses to verify the identity of the recipient and confirm the recipient's intended purpose of use before relying on the opt-out provision, a response to opt-out registries having been exploited by fraud and list-broker operations. The exact statutory article number for this requirement was not independently confirmed against primary text for this article.
Why this is fundamentally unlike GDPR: GDPR Article 6 has no "notify-the-regulator-and-proceed" self-service disclosure channel for ordinary commercial data. Every non-consent transfer under GDPR must fit a specific lawful basis -- contract, legitimate interest, and so on -- individually justified and, for legitimate interests, subject to a balancing test against the individual's rights. Japan's opt-out is a procedural permission (file, disclose, and honor opt-out requests) rather than a substantive balancing-of-interests test. The tradeoff for that procedural ease is the hard carve-outs above: a business cannot use the opt-out route for the data categories where the risk of harm is highest.
Pseudonymized and Anonymized Information: Japan's Two-Tier System
APPI splits de-identified data into two codified, distinct legal statuses. GDPR has one concept (pseudonymisation) that functions as a security measure, plus an undefined "anonymous data" endpoint that sits outside the regulation entirely -- Japan's structure is materially different from both.
Pseudonymously Processed Information (仮名加工情報, Art. 2(5)) is information processed so that it "cannot be [identified] unless collated with other information" -- re-identifiable in principle if matched against a retained key, but not identifiable standing alone. It is still "personal information" under APPI; it is not exempted from the Act. Under Article 41, a business that holds this status:
- May change its purpose of use for the data without needing fresh consent, unlike ordinary personal data under Article 18 -- the core utility of the status is that a business can repurpose pseudonymized data for new internal analysis without going back to data subjects.
- Must not provide pseudonymized personal data to a third party at all (Art. 41(6)) -- a stricter rule than for ordinary personal data, which can be shared with consent or via the Article 27 opt-out described above. Pseudonymization trades "no re-consent needed to repurpose" for "this data cannot leave the business."
- Must not attempt to re-identify individuals by collating the data with the deleted or other related information (Art. 41(7)).
- Must not use the data for direct-marketing contact by phone, mail, or fax (Art. 41(8)).
- Is exempted from the breach-notification duty (Art. 26) and from the individual disclosure, correction, and suspension-of-use rights (Arts. 32-39) -- Article 41(9) explicitly disapplies those provisions.
- Still carries a security-management duty over the "deleted/other related information" -- the re-identification key itself (Art. 41(2)).
Anonymously Processed Information (匿名加工情報, Art. 2(6)) is processed so that identification is impossible even with collation -- an irreversible de-identification standard. Once data is anonymized to the technical standard the implementing Cabinet Order prescribes (Article 34: deleting or replacing identifiers using a no-regularity method, deleting linking codes, deleting or generalizing outlier or idiosyncratic identifiers, plus a residual "appropriate action" catch-all), it falls outside the "personal information" definition entirely and outside most of the Act's restrictions. The business handling it is no longer bound by purpose-limitation, consent, or third-party-provision-consent rules for that data. Publication and disclosure duties around the fact of anonymization, and a prohibition on attempting re-identification, still apply under Articles 43 through 46, which are not detailed further in this article.
How this compares to GDPR. GDPR Article 4(5) pseudonymisation is purely a security and risk-mitigation measure. Pseudonymised data remains personal data in full, subject to the complete GDPR regime, with pseudonymisation counting only as a factor in a security risk assessment (Art. 32) and a facilitator for compatible secondary use (Art. 6(4)(e)). GDPR gives it no special reduced-obligation legal status. Japan's Pseudonymously Processed Information tier is materially more consequential: it is a defined, codified status that unlocks specific regulatory relief -- freer internal repurposing, exemption from breach notice and individual rights -- in exchange for a hard no-third-party-transfer rule. It is a structured trade, not just a security control.
On the anonymization side, GDPR's truly-anonymous endpoint (Recital 26) reaches the same practical result as Japan's Anonymously Processed Information -- data outside the regulation's scope -- but GDPR leaves the threshold for getting there to guidance and case law (built on the pre-GDPR Article 29 Working Party's Opinion 05/2014 framework) rather than statute. Japan instead codifies the technical and procedural bar in the Cabinet Order itself.
Data Subject Rights
APPI grants individuals a set of rights that broadly track GDPR's, though the underlying grounds and mechanics differ:
- Disclosure/access -- individuals can request to know what personal information a business holds about them and request its disclosure.
- Correction, addition, or deletion of inaccurate personal information.
- Suspension of use, erasure, or cessation of third-party provision on specified grounds: improper acquisition, use beyond the specified purpose, the information no longer being needed, a breach having occurred, or a risk to the individual's rights or interests. The 2020 amendment broadened these grounds beyond the original, narrower list.
According to comparative-law commentary reviewed for this article -- not independently re-verified against the primary text of APPI's individual-rights chapter (Articles 32-39) in this research -- APPI does not include a standalone data-portability right comparable to GDPR Article 20 (the right to receive data in a structured, machine-readable format and transmit it to another controller), and does not include a general right to object in the GDPR Article 21 sense (objecting to processing on legitimate-interest or public-task grounds, or to direct marketing at any time). On this account, Japan's closest analogue is the narrower suspension-of-use request described above, tied to the specific statutory grounds, rather than a free-standing objection right. Organizations that need a definitive answer on this specific point should confirm it directly against the PPC's current guidance rather than relying on this summary alone.
One gap is confirmed directly from the primary Article 41 text discussed above: Pseudonymously Processed Information is explicitly exempted from all of these individual rights (Art. 41(9)) -- a further divergence with no GDPR parallel, since GDPR's pseudonymised data keeps the data subject's full rights.
Supervisory Structure: The PPC's Guidance-First Culture
Japan uses a single dedicated regulator, the Personal Information Protection Commission (PPC), for the entire APPI. The PPC's escalation ladder runs from guidance (指導), to a formal recommendation, to a binding order -- with criminal liability attaching to noncompliance with an order (see Enforcement, below).
The PPC's own FY2025 annual report (published July 7, 2026) shows how that ladder is actually used: 17,139 breach-report matters, 19 report demands, 455 guidance actions, 2 recommendations, and just 1 formal order, against roughly 17,000 private-sector breaches -- near a record. In practice, guidance -- not prosecution -- is the PPC's dominant enforcement tool. Criminal referral and prosecution are rare, even though hard criminal penalties exist on the books for order noncompliance.
The GDPR's structure is different: each EU member state designates its own independent supervisory authority (DPA), and the European Data Protection Board coordinates consistency across those DPAs, including binding decisions in cross-border disputes. Where GDPR enforcement is distributed across 30-plus national authorities with EU-level coordination, APPI enforcement runs through one national body whose day-to-day posture leans heavily toward informal guidance over formal action.
Cross-Border Data Transfers and the EU/UK Mutual Adequacy Arrangement
APPI Article 28 provides three distinct routes for transferring personal data outside Japan.
Adequate-country designation (Art. 28(1) parenthetical). A transfer to a country the PPC has "prescribed... as a foreign country that has established a personal information protection system recognized to have equivalent standards to that in Japan" needs no additional consent -- it is treated like a domestic transfer. Only the EU/EEA (all member states plus Iceland, Liechtenstein, and Norway under the EEA Agreement) and the UK hold this status. This is a mutual, reciprocal designation: the PPC designated the EU under Article 28 on the same day, January 23, 2019, that the European Commission decided Japan offers an adequate level of protection under GDPR Article 45. No other country -- not the United States, South Korea, or Singapore -- holds this whitelist status with Japan.
Consent-based transfer with disclosure duties (Art. 28(1)-(2)). For any other foreign country, the business must obtain the individual's advance, transfer-specific consent, and before seeking that consent must proactively disclose information about the destination country's personal-information-protection system and the measures the receiving third party takes to protect the data. This is more procedurally specific than GDPR's Article 49 derogations, since explicit consent is also a GDPR transfer mechanism, but GDPR does not mandate the same pre-consent, country-system disclosure as a statutory element.
Equivalent-measures contractual route (Art. 28(1) main exclusion + Cabinet Order Art. 16). A recipient that has established a system ensuring continuous "equivalent measures" to APPI's Part IV Section 2 obligations is carved out of Article 28 entirely, treated like the adequate-country case. This is established either through an appropriate method ensuring the recipient implements measures matching the Act's substantive rules -- a contract, another binding agreement, or a binding intra-group arrangement, Japan's rough functional equivalent of GDPR's Standard Contractual Clauses or Binding Corporate Rules -- or through the recipient holding certification under an internationally recognized personal-information-handling framework. The business must also proactively give the data subject information on these measures on request (Art. 28(3)).
The Supplementary Rules Asymmetry: Same Data, Different Rules by Origin
Japan does not treat the EU/UK adequacy arrangement as simple mutual recognition with identical domestic rules applying on both sides. The PPC's Supplementary Rules -- adopted under Act Article 6, binding, and PPC-enforceable -- impose a materially higher bar specifically on personal data inbound from the EU or UK, layered on top of ordinary APPI:
- Broader sensitive-data category. Sex life, sexual orientation, and trade-union membership -- GDPR special categories that are not on Japan's own Article 2(3) sensitive-data list -- must be handled as if they were Special Care-Required Personal Information whenever the underlying data came from the EU or UK.
- Purpose-of-use tracking follows the data. A business must keep tracing its purpose of use back to the purpose originally disclosed at the point of transfer from the EU or UK.
- Restricted onward transfer. Sending EU/UK-sourced data on to a third country requires consent, unless that third country is itself on Japan's adequate-country list or equivalent contractual measures are in place -- EU-sourced data cannot be forwarded to a non-adequate third country on Japan's ordinarily laxer domestic terms.
- Statistical-only pseudonymization. Pseudonymized information made from EU/UK-sourced data may only be used for statistical purposes.
- Stricter anonymization. Anonymized information made from EU/UK-sourced data must be irreversibly de-identified including deletion of the re-identification key -- a stricter bar than the general Article 43 standard, which permits retaining that key under security controls for domestically collected data.
The practical result: identical categories of personal information are governed by different rules inside the same Japanese business, depending on whether the data originated in the EU/UK or was collected domestically. A compliance program built only around Japan's general APPI rules will under-protect EU/UK-sourced data; a compliance program built only around GDPR assumptions will miss that Japan's baseline domestic rules are looser than the EU/UK-inbound layer sitting on top of them.
Enforcement and Penalties: In Force vs Not Yet in Force
It is important to separate what is currently operative from what the 2026 reform enacted but has not yet activated.
Currently in force. Violating a PPC order sits at the top of the PPC's escalation ladder (guidance, then recommendation, then order) and carries criminal liability. Secondary legal-commentary sources cite a corporate fine that can reach JPY 100 million following the 2022 amendment's penalty increase, though this research was not able to independently confirm the exact statutory figure and article number against primary text, so it should be treated as a reported figure rather than a verified one. Separately, secondary sources describe criminal liability -- imprisonment and/or a fine, with reported fine amounts varying across sources -- for database misuse by a business or its employees for wrongful personal or third-party gain; again, exact figures were not independently confirmed against primary text for this article. What is confirmed directly from the PPC's own FY2025 report is the enforcement mix described above: guidance overwhelmingly outnumbers formal orders, meaning criminal exposure, while real, is rarely triggered in practice.
Not yet in force. The 2026 reform's headline addition is Japan's first-ever administrative monetary surcharge (課徴金) for APPI violations. As enacted, it is calculated as the economic benefit gained from the violation, multiplied by 1.5 for a repeat violation within 10 years, with a 50% reduction available for self-reporting. Its scope was narrowed during Diet deliberation before passage; the exact narrowed scope was not independently confirmed for this article. Structurally, this is Japan's functional answer to GDPR's Article 83 administrative-fine regime, but it works differently: it is a disgorgement-of-gain penalty, not a percentage-of-global-turnover cap. GDPR's maximum administrative fine of up to EUR 20 million or 4% of annual worldwide turnover has no direct APPI parallel even after the reform takes effect. Because Japan's surcharge is capped at what a violator actually gained rather than a share of its revenue, it could in theory land smaller than a comparable GDPR fine for a large multinational, or larger relative to a small violator whose specific violation produced a high per-incident gain.
None of this surcharge regime is currently enforceable. It becomes operative only once the implementing cabinet order takes effect, which is due within roughly two years of the July 17, 2026 promulgation.
Recent Developments: The 2026 APPI Reform
The enacted-but-not-yet-in-force amendment's substance, beyond the administrative surcharge described above:
- A new "Specific Biometric Personal Information" category (facial and fingerprint data), carrying heightened duties and a consent requirement for third-party transfer.
- Children's data changes: guardian consent required under age 16, plus simplified deletion procedures for minors' data.
- A risk-based breach-notice exception: businesses may skip individual notice for PPC-designated low-risk breaches.
- An AI/statistical-use exception: consent is not required for statistical or AI-training use of personal information under specified conditions, with disclosure obligations attached.
- Collective action / injunction rights (団体訴訟) were deferred out of the bill before it was submitted to the Diet -- they are not part of the enacted 2026 amendment, despite having been part of the PPC's earlier reform policy discussion.
None of the material this research reviewed indicates that the 2026 reform touches the Article 27 opt-out mechanism, the Article 28 cross-border transfer routes, or the Pseudonymously/Anonymously Processed Information tiers described above. That should be read as an absence of evidence that those provisions are changing, not as confirmation that they are staying the same -- the comparison spine on this page reflects current, stable law as understood at time of writing, and should be re-checked once the PPC finalizes its implementing rules and guidelines for the 2026 amendment.
Dual-Compliance Guidance
Organizations subject to both GDPR and APPI face several points where the two regimes pull in different directions.
| Issue | GDPR Requirement | APPI Requirement | Compliance Approach |
|---|---|---|---|
| Third-party data sharing | Needs an individually justified lawful basis for every disclosure | Can use the Art. 27 opt-out route after a PPC filing, except for sensitive, improperly-acquired, or already-opted-out data | Maintain a GDPR-valid basis for EU-side sharing; for Japan-side sharing, confirm the data does not fall into one of the Art. 27(2) exclusions before relying on opt-out |
| De-identification strategy | Pseudonymised data stays fully in scope of GDPR regardless of technique used | Pseudonymously Processed Information gets specific regulatory relief (repurposing without consent, exemption from breach notice and individual rights) but can never be shared with a third party | Do not assume a GDPR pseudonymization program automatically qualifies for or maps onto Japan's Art. 2(5) status; the two concepts award different rights and impose different restrictions |
| Data received from the EU or UK | N/A (this is the GDPR-origin side of the transfer) | Governed by the PPC's stricter Supplementary Rules on top of ordinary APPI (broader sensitive category, tracked purpose, onward-transfer limits, statistical-only pseudonymization, no-retained-key anonymization) | Tag EU/UK-origin personal data at ingestion and apply the Supplementary Rules layer specifically to that dataset, rather than Japan's general domestic rules |
| Lawful basis for ordinary processing | Must fit one of six enumerated Art. 6 bases | No enumerated list; lawful by default once purpose is specified (Art. 17) and use stays within that purpose (Art. 18) | Document a GDPR Art. 6 basis for EU processing; for Japan, document the specified purpose of use and monitor for any use that exceeds it |
| Administrative-fine exposure | Up to EUR 20M / 4% of global turnover, actively enforced | No administrative fine currently exists; a disgorgement-based surcharge was enacted but is not yet in force | Do not build a Japan risk model around an active administrative-fine regime yet; track the cabinet order that will bring the surcharge into force |
| Individual rights response | Structured rights chapter (Arts. 15-22) with defined mechanics | Disclosure/correction/suspension-of-use rights on specified grounds; portability and general objection rights are not confirmed to exist (per secondary sources, not independently verified here) | Build the EU-side rights workflow to the GDPR standard; for Japan, route requests through the suspension-of-use grounds and confirm current PPC guidance before promising a portability or objection response |
For the EU side of this comparison in more depth, see our guide to GDPR breach notification and other EU-specific mechanics, and for how GDPR compares to the leading US state framework, see GDPR vs CCPA.
Disclaimer
This article presents general legal information about Japan's Act on the Protection of Personal Information (APPI) and the EU's General Data Protection Regulation (GDPR). It does not constitute legal advice. Several points in this article -- including specific criminal penalty figures, exact breach-notification timelines, and the confirmed scope of APPI's individual-rights chapter -- rely on secondary legal-commentary sources rather than independently verified primary statutory text, and are flagged as such throughout. The 2026 APPI amendment discussed here has been enacted and promulgated but is not yet in force. Organizations subject to APPI or GDPR should consult a lawyer licensed in the relevant jurisdiction, and confirm reform-specific details against the PPC's official guidance as it is published, before relying on this article for a compliance decision.
Authorities Cited
- Personal Information Protection Commission (PPC), Japan -- official English portal. https://www.ppc.go.jp/en/
- Act on the Protection of Personal Information (APPI), official Japanese government English translation. https://www.japaneselawtranslation.go.jp/en/laws/view/4241/en
- Personal Information Protection Commission. Supplementary Rules under the Act on the Protection of Personal Information for the Handling of Personal Data Transferred from the EU and the United Kingdom based on an Adequacy Decision. https://www.ppc.go.jp/files/pdf/Supplementary_Rules_en.pdf
- Personal Information Protection Commission. Legal and policy documents index. https://www.ppc.go.jp/en/legal/
- Personal Information Protection Commission. 2026 APPI reform ("令和8年改正個人情報保護法") information page. https://www.ppc.go.jp/personalinfo/legal/r8kaiseihogohou/
- Personal Information Protection Commission. Press release confirming promulgation, July 17, 2026. https://www.ppc.go.jp/news/press/2026/260717/
- Personal Information Protection Commission. Press release, FY2025 Annual Report, July 7, 2026. https://www.ppc.go.jp/news/press/2026/260707/
- Personal Information Protection Commission. Triennial Review 2026 System Reform Policy. https://www.ppc.go.jp/en/topix/triennial_review_2026_02/
- Regulation (EU) 2016/679 (General Data Protection Regulation). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
- European Commission. Adequacy decisions. https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en
Last updated: 2026-07-23. Laws cited reflect their in-force versions as of 2026-07-23; the 2026 APPI amendment is described throughout as enacted and promulgated but NOT yet in force.
Frequently Asked Questions
What is Japan's Article 27 opt-out transfer, and why doesn't GDPR have anything like it?
APPI Article 27(2) lets a business transfer personal data to a third party without individual consent, as long as it discloses the transfer to individuals in advance (or makes that information easily accessible), files a notification with the PPC, and honors opt-out requests. GDPR requires an individually justified lawful basis under Article 6 for every non-consent disclosure -- there is no filed-registry, notify-and-proceed mechanism in GDPR for ordinary commercial third-party sharing.
What data can never be transferred using the Article 27 opt-out route?
The opt-out mechanism excludes sensitive personal information (Special Care-Required Personal Information), data that was acquired in violation of APPI's improper-acquisition rule, and data that itself already arrived at the business through someone else's opt-out chain. That last exclusion prevents opted-out data from being daisy-chained through multiple businesses.
What is the difference between Pseudonymously Processed Information and Anonymously Processed Information under APPI?
Pseudonymously Processed Information (Art. 2(5)) is still personal information under APPI -- it is re-identifiable in principle if matched against a retained key. Holding this status lets a business repurpose the data internally without fresh consent, but bars any third-party transfer and exempts the business from breach-notice and individual-rights duties for that data. Anonymously Processed Information (Art. 2(6)) is processed to a codified, irreversible technical standard set by Cabinet Order; once met, the data falls outside the definition of personal information and outside most of the Act's restrictions entirely.
Does GDPR pseudonymisation work the same way as APPI's pseudonymized-information status?
No. GDPR Article 4(5) pseudonymisation is a security and risk-mitigation measure -- pseudonymised data remains fully subject to GDPR regardless of the technique used. APPI's Pseudonymously Processed Information is a distinct, codified legal status that unlocks specific regulatory relief (freer internal repurposing, exemption from breach notice and individual rights) in exchange for a hard rule that the data can never be shared with a third party. It is a structured trade-off, not simply a security control.
Why does personal data from the EU or UK get stricter treatment in Japan than data collected domestically?
Japan's mutual adequacy arrangement with the EU and UK comes with a condition: the PPC's Supplementary Rules impose obligations on EU/UK-sourced personal data that go beyond ordinary APPI, including treating additional categories (sex life, sexual orientation, trade-union membership) as sensitive data, tracking purpose of use back to the original EU/UK-disclosed purpose, restricting onward transfer to non-adequate third countries, limiting pseudonymized versions of that data to statistical use only, and requiring deletion of the re-identification key for any anonymized version of that data. These rules apply specifically because the data originated in the EU or UK; they do not apply to data collected domestically in Japan.
Is Japan's 2026 APPI amendment currently in force?
No. The bill passed both houses of the Diet on July 10, 2026, and was promulgated on July 17, 2026, but it has not taken effect. Japan brings a promulgated law into force through a subsequent cabinet order, and that order is due within roughly two years of promulgation -- no later than around July 2028. The PPC is currently drafting the implementing order, rules, and guidelines. Every provision of the 2026 reform, including the new administrative surcharge, remains not yet operative.
Which countries does Japan currently recognize as 'adequate' for cross-border data transfers?
Only the EU/EEA (all EU member states plus Iceland, Liechtenstein, and Norway) and the United Kingdom hold Japan's Article 28 adequate-country designation. This is a mutual arrangement: the PPC designated the EU as adequate on the same day, January 23, 2019, that the European Commission found Japan adequate under GDPR Article 45. No other country, including the United States, currently holds this status with Japan.
Does APPI have a GDPR-style administrative fine?
Not yet. Currently, APPI backs its rules with criminal liability for noncompliance with a PPC order, not an administrative fine comparable to GDPR's. The 2026 reform enacted Japan's first-ever administrative monetary surcharge (課徴金), calculated as the economic benefit gained from the violation rather than a percentage of global turnover, but this surcharge is not yet in force -- it activates only once the implementing cabinet order takes effect, expected no later than around July 2028.
Updates
Initial publication. Covers the current-law APPI/GDPR comparison spine (Article 27 opt-out transfers, the Pseudonymously/Anonymously Processed Information two-tier system, and the EU/UK Supplementary Rules asymmetry) plus the APPI amendment enacted July 10, 2026 and promulgated July 17, 2026, which is not yet in force.
Sources and References
- Personal Information Protection Commission (PPC), Japan -- official English portal(ppc.go.jp).gov
- Act on the Protection of Personal Information (APPI), official government English translation(japaneselawtranslation.go.jp).gov
- PPC Supplementary Rules for Personal Data Transferred from the EU and UK based on an Adequacy Decision(ppc.go.jp).gov
- PPC Legal and Policy Documents Index(ppc.go.jp).gov
- PPC 2026 APPI Reform Information Page(ppc.go.jp).gov
- PPC Press Release: APPI Amendment Promulgation, July 17, 2026(ppc.go.jp).gov
- PPC Press Release: FY2025 Annual Report, July 7, 2026(ppc.go.jp).gov
- PPC Triennial Review 2026 System Reform Policy(ppc.go.jp).gov
- Regulation (EU) 2016/679 (General Data Protection Regulation) Full Text(eur-lex.europa.eu).gov
- European Commission Adequacy Decisions(commission.europa.eu).gov