Our Expert in Japan
No results available
Japan’s three‑year review of the personal data law has reached a decisive stage, with the Personal Information Protection Commission (PPC) publishing an outline of system reform that places biometric information and children’s personal data squarely within the scope of a forthcoming amendment bill. The review, mandated by supplementary provisions of the Act on the Protection of Personal Information (APPI), represents the most consequential set of proposed changes since the 2020 overhaul that took effect in 2022. For businesses that collect facial‑recognition templates, fingerprint data, or information from users under sixteen, the proposals signal material new obligations around consent, processing safeguards, and governance.
This article explains what the amendment bill proposes, maps out the legislative timeline, and provides a phased compliance checklist that in‑house counsel, data protection officers, and product teams can act on immediately.
The reform package also addresses data reuse for artificial intelligence training, strengthens the PPC’s enforcement powers, and contemplates tighter cross‑border transfer rules, all topics that intersect with Japan’s broader AI and data protection policy direction. Below, each major proposal is examined alongside practical steps, comparison tables, and an FAQ designed to answer the questions legal teams are asking right now.
The APPI contains a built‑in sunset mechanism that requires the government to review the statute’s operation roughly every three years and, where necessary, to propose legislative amendments. This “Every‑Three‑Year Review” obligation, set out in the supplementary provisions of the APPI, ensures the law keeps pace with technological change and evolving privacy expectations. The PPC oversees the review, publishes interim reports, solicits public comment, and ultimately transmits an outline of proposed reforms to the Cabinet for drafting into a bill.
The current cycle of Japan’s three‑year review of the personal data law began formally in 2024, following the previous round of amendments that entered into force in April 2022. Over the course of expert‑panel meetings, the PPC identified biometric data governance, protections for children, and the secondary use of data for AI as priority areas requiring statutory attention. The resulting Outline of the System Reform was published in stages, culminating in a consolidated set of proposals now progressing toward a formal amendment bill.
| Milestone | Date / Period | Status |
|---|---|---|
| 2020 APPI amendment enacted | June 2020 | Complete, entered into force April 2022 |
| Current Every‑Three‑Year Review launched | 2024 | Complete, expert panels concluded |
| PPC interim report and public comment | 2025 | Complete |
| PPC Outline of System Reform published | 2025–2026 | Published |
| Amendment bill submitted to Diet | 2026 (expected) | In progress |
| Amended APPI enters into force | 2027 (anticipated) | Pending enactment |
The PPC’s reform outline covers six interconnected pillars. Each carries direct compliance implications for businesses operating in or targeting Japan. The following summary draws on the PPC’s published materials, the IAPP’s reporting on the PPC interim summary, and practitioner analyses from leading Japanese law firms.
Under the current APPI, certain biometric identifiers such as facial‑recognition data and fingerprint codes already qualify as “personal identification codes” and therefore as personal information. The amendment bill, however, goes substantially further by creating a distinct higher‑risk processing category for biometric data, with dedicated obligations that do not apply to ordinary personal information.
According to the PPC’s reform outline and detailed analysis published by Mori Hamada & Matsumoto, the proposals define regulated biometric data broadly, encompassing not only raw captures (photographs, voice recordings) but also the mathematical templates and feature vectors derived from them. The practical effect, industry observers expect, will be that any organisation converting a face scan into a numerical embedding for authentication or analytics will need to comply with the new enhanced‑consent and safeguard regime, even if the raw image is immediately deleted.
The amendment is also expected to distinguish between biometric processing for security or authentication purposes (which would remain permissible under specified safeguards) and biometric processing for profiling, behavioural analysis, or commercial targeting (which would face the strictest constraints). As reported by Biometric Update, the PPC has signalled that continuous surveillance‑style facial recognition in public spaces would require a particularly robust legal basis and transparency measures.
| Type of Biometric | Proposed Treatment | Practical Action for Businesses |
|---|---|---|
| Facial‑feature templates (embeddings) | Higher‑risk classification; explicit consent required; purpose limitation to stated use case; retention caps | Audit all facial‑recognition deployments; implement granular consent flow; set automatic deletion schedules |
| Fingerprint and palm‑vein data | Enhanced safeguards; encryption‑at‑rest and in‑transit mandated; access‑control logging | Upgrade encryption protocols; deploy access‑audit trails; restrict processing to named personnel |
| Voiceprints and gait patterns | Included in biometric definition; same consent and safeguard obligations as facial data | Identify all voice/gait collection points (call centres, IoT); retrofit consent mechanisms |
| Behavioural biometrics (keystroke dynamics, typing cadence) | Scope still under discussion; early indications suggest inclusion where used for unique identification | Map behavioural‑biometric data flows; prepare contingency consent and disclosure language |
Organisations that process biometric data in Japan should begin gap analyses now, even before the bill’s final text is settled. Early indications suggest that the new regime will require documented necessity assessments, similar in concept, though not identical in form, to the GDPR’s data‑protection impact assessment.
The current APPI does not contain a standalone provision addressing children’s personal data. The amendment bill is expected to change that materially. Based on practitioner reporting from Baker McKenzie and the IAPP, the PPC’s proposals introduce an explicit age threshold, reported as under‑16, below which additional protections apply. These protections mirror, in structural terms, the approach taken in the EU’s GDPR, but with Japan‑specific implementation details.
Under the proposals, any business that provides an online service directed at children, or that has actual knowledge that a user is under the specified age, would be required to obtain verifiable guardian consent before collecting, using, or sharing that child’s personal data. The scope of “verifiable” consent is expected to be clarified in implementing guidelines, but early indications suggest it will go beyond a simple tick‑box, potentially requiring identity verification of the consenting guardian.
Marketing activities directed at children would also face restrictions. Profiling minors for targeted advertising, or using children’s behavioural data to personalise content in ways that could be harmful, is expected to be either prohibited outright or subject to strict conditions. These proposals carry significant implications for gaming platforms, social‑media services, ed‑tech providers, and any app with a meaningful under‑16 user base, including services related to matters such as family and child custody in Japan that handle sensitive data involving minors.
One of the most commercially sensitive elements of Japan’s three‑year review of the personal data law concerns the secondary use of personal data for AI model training. Japan has historically maintained a comparatively permissive stance toward data use for research and statistical purposes, but the PPC’s proposals signal a recalibration in response to the rapid proliferation of generative AI.
The amendment is expected to require organisations that repurpose personal data for AI training to apply robust pseudonymisation or de‑identification before ingestion into training datasets. Where full anonymisation is not feasible, dataset assemblers would need to document provenance, recording the original lawful basis for collection, the transformation steps applied, and any residual re‑identification risk. This documentation obligation effectively creates an auditable chain of custody for training data.
Practitioners at Nishimura & Asahi and Baker McKenzie have noted that the proposals stop short of a blanket prohibition on AI training with personal data. Instead, the likely practical effect will be a tiered framework: fully anonymised data remains unrestricted; pseudonymised data may be used under documented safeguards; and identifiable personal data used for AI training would require explicit consent or a compelling public‑interest justification. Businesses developing or deploying AI systems in Japan should review their data‑supply pipelines against these emerging requirements and consider commissioning technical audits of pseudonymisation effectiveness. More detailed guidance on Japan’s evolving AI and data protection framework is available separately.
The PPC’s reform outline proposes a meaningful expansion of the Commission’s enforcement toolkit. Under the current APPI, the PPC can issue recommendations and orders, but financial penalties are modest compared with regimes such as the GDPR. The amendment bill is expected to increase maximum penalty amounts and introduce the possibility of revenue‑based fines for serious or repeated violations.
Breach‑notification obligations are also set to tighten. The current rule requires notification to the PPC and affected individuals “promptly” following discovery of a qualifying breach. The proposals would introduce a defined reporting window, early indications suggest a mandatory initial notification within a set number of days of discovery, with a fuller report to follow. Businesses that have not already implemented a structured breach‑reporting procedure for Japan should treat this as an immediate priority.
On governance, the proposals contemplate mandatory appointment of a privacy officer (or equivalent role) for businesses that handle personal data above a specified volume threshold or that engage in high‑risk processing categories, including biometric data and children’s data. Periodic DPIAs would become a formal requirement for these organisations, rather than a best‑practice recommendation. The likely practical effect will be additional headcount or advisory costs for mid‑sized and larger companies.
The APPI amendment bill is advancing through Japan’s established legislative pipeline. The table below summarises the key milestones based on PPC publications and reporting from the IAPP and practitioner firms.
| Stage | Expected Timing | What to Monitor |
|---|---|---|
| PPC Outline of System Reform | Published (2025–2026) | Final consolidated text on PPC website |
| Cabinet drafting of amendment bill | 2026 | Bill text publication on official government channels |
| Diet deliberation and passage | 2026 (expected) | Committee hearings; any last‑minute scope changes |
| PPC implementing guidelines and rules | 2026–2027 (expected) | Detailed guidance on biometric safeguards, children’s consent, AI reuse |
| Amended APPI enters into force | 2027 (anticipated) | Official gazette publication of effective date |
Industry observers expect that the PPC will release draft implementing guidelines for public comment before the effective date, providing a further window for businesses to refine their compliance programmes. Monitoring the PPC’s English‑language pages at ppc.go.jp/en remains the most reliable way to track developments.
The following phased checklist is designed for in‑house counsel, data protection officers, and compliance leads preparing for the expected amendments. It is organised into three time horizons to allow teams to prioritise resources effectively.
Companies operating across sectors such as fintech, where data protection intersects with licensing requirements under Japan’s Payment Services Act, and those with multinational workforces who need to navigate foreign‑worker hiring and ID verification rules should coordinate these compliance streams to avoid duplication and gaps.
For multinational organisations subject to both the APPI and the EU’s General Data Protection Regulation, the table below provides a concise side‑by‑side comparison. Industry observers expect that convergence with GDPR principles, particularly around biometric classification, will simplify compliance for companies already operating under European standards, although important differences remain.
| Topic | Proposed APPI Amendment | GDPR |
|---|---|---|
| Biometric data classification | Biometric data (facial features, templates, voiceprints) flagged as higher‑risk; stricter consent and purpose‑limitation rules; dedicated safeguard requirements | Special category data under Article 9; processing generally prohibited unless explicit consent or another specific legal basis; DPIA required for large‑scale processing |
| Children’s data | Proposed explicit protection threshold (reported as under‑16); guardian‑consent and age‑verification duties; marketing restrictions | Article 8 sets default at 16 (member states may lower to 13); parental consent required for information‑society services; child‑friendly privacy notices recommended |
| AI training and data reuse | Expected tiered framework: anonymised data unrestricted; pseudonymised data permitted with documented safeguards; identifiable data requires explicit consent or public‑interest basis | No blanket prohibition; lawful‑basis requirement applies; DPIA for high‑risk processing; emerging AI‑specific guidance at national and EU level |
| Breach notification | Shortened mandatory reporting window (specific timeframe to be confirmed in guidelines); notification to PPC and affected individuals | 72‑hour notification to supervisory authority under Article 33; notification to data subjects “without undue delay” where high risk |
| Penalties | Increased maximums expected; possible introduction of revenue‑based fines | Up to €20 million or 4 % of global annual turnover, whichever is higher |
Once the amendment bill’s final text is published, organisations should prioritise the following contract and policy updates:
Japan’s three‑year review of the personal data law is no longer a policy discussion, it is a legislative process with an amendment bill moving toward enactment. The proposals affecting biometric data classification, children’s data protections, AI training oversight, and PPC enforcement authority represent the most significant evolution of Japan data protection law since the 2020 reforms. Businesses operating in Japan, or processing the personal data of individuals in Japan, should treat the compliance checklist above as a working roadmap: begin data mapping and gap analysis now, redesign consent and governance structures in the coming months, and stand ready to implement technical and contractual updates as the final text and implementing guidelines emerge.
The PPC’s English‑language portal and the full text of the APPI remain the authoritative reference points for tracking developments as the amendment bill advances through the Diet.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Noboru Kitayama at Mori Hamada & Matsumoto, a member of the Global Law Experts network.
posted 5 minutes ago
posted 6 minutes ago
posted 6 minutes ago
posted 10 minutes ago
posted 11 minutes ago
posted 12 minutes ago
posted 12 minutes ago
posted 4 hours ago
posted 6 hours ago
posted 7 hours ago
posted 7 hours ago
posted 7 hours ago
No results available
Find the right Advisory Expert for your business
Sign up for the latest advisor briefings and news within Global Advisory Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Advisory Experts is dedicated to providing exceptional advisory services to clients around the world. With a vast network of highly skilled and experienced advisors, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message