Japan
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Japan lets personal data leave the country, but you need paperwork. Only Europe and the United Kingdom are pre-approved. For anywhere else you either sign a contract that binds the recipient to Japanese-standard protection, or you get the person's consent after telling them which country the data goes to. There is no general rule forcing data to stay in Japan.
Eight questions about Japan
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Japan's rules apply to my company?
Yes. Japan's privacy law reaches a foreign company with no office and no staff in Japan, as long as it handles the personal information of people in Japan while supplying them goods or services. There is no size, revenue or headcount threshold to fall below. Unlike Europe, the privacy law does not make you appoint a representative in Japan — but the telecoms law does, if your service counts as a telecommunications service.
Extraterritorial reach sits in Article 171 of the Act on the Protection of Personal Information. Since the 2020 amendment took effect on 1 April 2022 the Personal Information Protection Commission can use its full toolkit against foreign operators, including demands for reports, on-site inspection, guidance, recommendations and orders. The Commission's own FAQ confirms the law bites whether the operator collects from individuals in Japan directly or receives the data from another Japanese business. Separately, the Ministry of Internal Affairs and Communications takes the view that the Telecommunications Business Act applies to services provided from abroad to people in Japan where the service is clearly aimed at Japan (Japanese-language interface, yen pricing, Japan-targeted marketing), and those providers must register or file a notification and name a representative or agent in Japan.
Sources
- Official sourcePersonal Information Protection CommissionPPC FAQ — does the Act apply to a foreign operator supplying services to people in Japan? (Article 171)
ppc.go.jp
Link checked 18 August 2026
- Official sourceMinistry of Internal Affairs and CommunicationsHow the Telecommunications Business Act applies where a foreign entity carries on a telecommunications business, 12 February 2021
soumu.go.jp
Link checked 18 August 2026
Can I store my users' data outside Japan?
Yes, with paperwork. Japan's general rating is conditional: personal data may go abroad once you have one of three things in place. There is no across-the-board law keeping data in Japan, and no financial, insurance, securities or health localisation rule of the kind India or China have — we searched for one and did not find it. The real wall is government work: anything running on the national Government Cloud must sit in data centres inside Japan.
Sector by sector, checked 18 August 2026: - Government and public sector — closed The Digital Agency's Government Cloud procurement specification states that information assets are to be kept inside Japan and requires domestic data centres spread across several Japanese regions. Cloud providers must first be listed under the Information system Security Management and Assessment Program (ISMAP). The single carve-out in the 2026 round is a separately walled 'overseas AI inference environment' for frontier models unavailable in Japan. - Telecoms — conditional No storage-location mandate, but secrecy of communications is a criminal duty, designated large providers must file an internal handling code for 'specified user information' with the ministry, and the external transmission rules force disclosure of what user information is sent to third parties. - Critical infrastructure (16 named sectors including finance, medical care, telecoms, energy, transport, credit cards) — conditional Before installing critical equipment, the operator must notify the responsible minister, who reviews supplier ownership, foreign-government ties and whether foreign law could force the supplier to break its contract. The minister can order changes. - Banking, payments, insurance, securities — open The Financial Services Agency regulates by risk, not geography. Its October 2024 cybersecurity guidelines expressly cover outsourced work carried out overseas but set no storage location. Supervisory guidance requires the bank to be able to monitor and trace customer data at an outsourcer, and to write audit rights into the contract. - Health — data can leave once conditions are met, medium confidence. The three-ministry guideline framework (health ministry guideline version 7.0, June 2026; economy and communications ministries' supplier guideline version 2.0, revised March 2025) is guidance, not statute. We found no clause in the versions we could open requiring domestic storage, but hospitals must stay accountable and understand the legal environment where the data sits. - Mapping and geospatial — no export restriction found, checked 18 August 2026, medium confidence. The Geospatial Information Authority's published approval procedures cover copying and using survey results and say nothing about taking them out of Japan. - Defence — no geographic rule found, checked 18 August 2026. The defence procurement information security standard controls encryption, access and designated handling facilities rather than country of storage.
Sources
- Official sourcePersonal Information Protection CommissionGuidelines on the Act on the Protection of Personal Information (Provision to a Third Party in a Foreign Country)
ppc.go.jp
“個人の権利利益を保護する上で我が国と同等の水準にあると認められる個人情報の保護に関する制度を有している外国は、EU及び英国が該当する”
Link checked 18 August 2026
- Official sourceDigital AgencyProvision of cloud services for the Government Cloud — 2026 procurement specification
digital.go.jp
“ガバメントクラウドでは情報資産は日本国内に保管されることとしている”
Link checked 18 August 2026
- Official sourceCabinet OfficeOutline of the system for securing stable provision of specified critical infrastructure services under the Economic Security Promotion Act, 17 June 2026
cao.go.jp
Link checked 18 August 2026
- Official sourceFinancial Services AgencyGuidelines on Cybersecurity in the Financial Sector, 4 October 2024
fsa.go.jp
“形式上、外部委託契約が結ばれていなくともその実態において外部委託と同視しうる場合や当該外部委託された業務等が海外で行われる場合も含む”
Link checked 18 August 2026
- Official sourceMinistry of Health, Labour and WelfareGuidelines for the Safety Management of Medical Information Systems, version 7.0, June 2026
mhlw.go.jp
Link checked 18 August 2026
- Official sourceGeospatial Information Authority of JapanProcedures for using survey results (Survey Act approval for copying and use)
gsi.go.jp
Link checked 18 August 2026
What do I need in place before data leaves Japan?
The model is an allowlist, and the list has exactly two entries: the European Union and the United Kingdom. Send data there and it is treated almost like a domestic transfer. For every other destination you need one of two things instead. Either the recipient is contractually bound to protect the data to Japanese standards and you keep checking that it does, or you get the person's consent after first telling them the destination country, what its privacy law is like, and what the recipient will do to protect the data.
Article 28 of the Act sets the three routes: a country designated by Commission rule as having equivalent protection (only the European Economic Area and the United Kingdom are designated, by Commission Notice No. 1 of 2019); a recipient that has put in place a system conforming to the standards set by Commission rule, which in practice means an intra-group or vendor contract, binding internal rules, or Asia-Pacific Economic Cooperation Cross-Border Privacy Rules certification; or the individual's prior consent supported by the information disclosure required by Article 28(2). The second route carries a continuing duty under Article 28(3) to check the recipient is still complying and to tell the individual about it on request. Where you rely on consent, one-off consent covering an unspecified 'overseas' is not enough — the country has to be named where it can be identified. Data that arrived in Japan from Europe or the United Kingdom under their adequacy decisions carries an extra layer: the Commission's Supplementary Rules restrict onward transfer more tightly than the Act itself.
Sources
- Official sourcePersonal Information Protection CommissionGuidelines on the Act on the Protection of Personal Information (Provision to a Third Party in a Foreign Country), Article 28
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionForeign countries recognised as having a personal information protection system equivalent to Japan's (Commission Notice No. 1 of 2019)
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionSupplementary Rules for handling personal data transferred from the EU and the UK under adequacy
ppc.go.jp
Link checked 18 August 2026
Who enforces the rules in Japan, and what can they do?
The Personal Information Protection Commission, and it is genuinely working. It has a chair, eight commissioners and a staff ceiling of 231 people. In the year to March 2025 it handled just over 19,000 breach reports, gave 395 pieces of formal guidance and made one recommendation. In the first six months of the following year it sharpened up: two recommendations and its first emergency order, against a company misusing personal information. What it cannot do yet is fine you — Japan has no administrative money penalty for privacy breaches until the 2026 amendment starts.
Enforcement is rated active rather than aggressive because the volume is low relative to the caseload and the tools are soft. Figures for the first half of the 2025 financial year (April to September 2025): 8,928 breach reports from private-sector operators, 11 demands for a report, 2 on-site inspections, 236 pieces of guidance and advice, 2 recommendations, 1 order. The recommendations went to Business Planning Ltd and Chuo Business Service Ltd; the emergency order went to Business Planning Ltd, requiring it to stop providing personal information in breach of the prohibition on improper use. Sector regulators run in parallel and are all fully operational: the Financial Services Agency, the Ministry of Internal Affairs and Communications for telecoms, the Digital Agency for government systems, the Cabinet Office for economic security screening, and the Ministry of Health, Labour and Welfare for medical information.
Sources
- Official sourcePersonal Information Protection CommissionActivity results of the Personal Information Protection Commission, first half of the 2025 financial year, 12 November 2025
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionPersonal Information Protection Commission annual report for the 2024 financial year
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionPublication of the Commission's annual report for the 2025 financial year, 7 July 2026
ppc.go.jp
Link checked 18 August 2026
How long do I have to keep the data?
The floor is firm and the ceiling is soft. Tax law makes you keep books and records for seven years, stretching to ten if you carry a loss forward. Company accounting books run ten years. Against that, the privacy law only asks you to try to delete personal data once you no longer need it — it is a best-efforts duty, not a hard deadline. So when the two collide, the keep-it rule wins in practice.
Floors: corporate tax books and transaction documents, seven years from the day after the filing deadline, extended to ten years for a business year in which a blue-return loss arises that is carried forward. Company accounting books and supporting materials, ten years under the Companies Act. Medical records, five years under the Medical Practitioners Act. Telecoms operators have no general statutory log-retention period. Ceiling: Article 22 of the privacy Act is drafted as an endeavour obligation — the operator 'shall endeavour to erase' personal data without delay once it is no longer needed. There is no equivalent of Europe's storage-limitation principle enforced with fines, and no maximum period fixed by statute. The practical consequence is the opposite of most jurisdictions: in Japan the risk sits in keeping too little, not too much.
Sources
- Official sourceNational Tax AgencyRetention periods for books and records (No. 5930)
nta.go.jp
“その帳簿と取引等に関して作成または受領した書類を、その事業年度の確定申告書の提出期限の翌日から7年間保存しなければなりません。”
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionGuidelines on the Act on the Protection of Personal Information (General Rules) — erasure of data no longer needed
ppc.go.jp
Link checked 18 August 2026
What happens if there is a breach?
Count three clocks. For a personal data breach you file a first report to the privacy regulator within three to five days of finding out, and a full report within 30 days — 60 days if someone did it on purpose. You must also tell the people affected. Critical infrastructure operators have a separate cyber incident duty with a report to the government within 30 days. Telecoms operators report leaks of communications to the communications ministry on their own timetable.
The privacy duty bites only for four categories of breach: sensitive personal information; data whose misuse could cause financial loss, such as card numbers or payment credentials; anything caused deliberately, including hacking and rogue employees; and any breach affecting more than 1,000 people. Below those thresholds reporting is voluntary. The first report is due 'promptly', which the Commission reads as three to five days from discovery; the full report is due within 30 days, extended to 60 where the breach may have been done for an improper purpose. Notification to affected individuals is a separate duty and runs in parallel. The Act on the Prevention of Damage from Unauthorised Acts against Important Computers (Act No. 42 of 2025) adds a second regime for designated critical infrastructure: a prompt first alert followed by a detailed report within 30 days. Where the incident touches communications, the Telecommunications Business Act adds a third. The overlap is where operations fail: three regimes, three recipients, three formats, one incident.
Sources
- Official sourcePersonal Information Protection CommissionWhat to do when a personal data breach occurs — reporting categories and deadlines
ppc.go.jp
“個人データに係る本人の数が1,000人を超える漏えい等”
Link checked 18 August 2026
- Official sourceCabinet SecretariatAct on the Prevention of Damage from Unauthorised Acts against Important Computers (Act No. 42 of 2025) — explanatory material
cas.go.jp
Link checked 18 August 2026
- Official sourceCabinet OfficeApproach to implementing the public-private provisions of the Cyber Response Capability Enhancement Act, December 2025
cao.go.jp
Link checked 18 August 2026
What trips people up in Japan?
Five. (1) Putting data on a foreign server is often not a 'transfer' at all — if the provider is contractually barred from touching it — but you then have to work out that country's privacy law and publish the country's name to your users. Most people miss this. (2) The privacy law has no fines: the sanctions are criminal, and a company can be fined about $650,000 for a staff member stealing a customer database. (3) Leaking a communication is a crime punishable with prison, and telecoms staff face a longer term than outsiders. (4) The telecoms rules catch ordinary websites and apps, not just phone companies, and reach foreign operators with no office in Japan. (5) Consent to send data 'overseas' is not valid — you have to name the country.
Trap 1 in detail. The Commission's FAQ says storing personal data on a server run by a foreign provider is not provision to a third party in a foreign country, provided the contract stops that provider handling the data and access controls back it up. But Articles 23 and 32 then require you to understand the external environment: identify the country where the provider sits and the country where the servers sit, take security measures suited to that country's legal regime, and put the country names and the measures where the individual can find them. If you genuinely cannot pin down the server location, you must publish the reason instead. Trap 2 in detail. Ignoring a Commission order is punishable by up to one year's imprisonment or a fine of up to 1 million yen (about $6,500) for the individual, and up to 100 million yen (about $650,000) for the company. The same 100 million yen corporate ceiling applies to the offence of improperly providing or stealing a personal information database. Failing to answer a demand for a report carries up to 500,000 yen (about $3,300). Trap 3 in detail. Violating the secrecy of communications is punishable by up to two years' imprisonment or a fine of up to 1 million yen (about $6,500); for someone engaged in the telecommunications business it rises to three years or 2 million yen (about $13,000). Attempts are punishable. Trap 4 in detail. The external transmission rules, in force since 16 June 2023, require any covered online service to tell users what information about them is sent to third parties, to whom and why, before it is sent. The communications ministry's own guidance confirms foreign providers serving Japan are covered. Trap 5 in detail. Where the destination country can be identified, naming it is part of the information you must give before consent. Blanket wording about 'servers outside Japan' does not carry the consent.
Sources
- Official sourcePersonal Information Protection CommissionPPC FAQ — 'understanding the external environment' where a foreign cloud service stores personal data
ppc.go.jp
“クラウドサービス提供事業者が所在する外国の名称及び個人データが保存されるサーバが所在する外国の名称を明らかにし”
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionPPC FAQ — is storing personal data on a server in a foreign country a provision to a third party?
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionPPC FAQ — measures and criminal penalties where a business violates the Act
ppc.go.jp
“刑事罰(1年以下の拘禁刑又は100万円以下の罰金)が科される可能性があります”
Link checked 18 August 2026
- Official sourceMinistry of Internal Affairs and CommunicationsGuideline on issuing business improvement orders where secrecy of communications is impaired — penalties under Article 179
soumu.go.jp
“三年以下の懲役又は二百万円以下の罰金に処する。”
Link checked 18 August 2026
- Official sourceMinistry of Internal Affairs and CommunicationsExternal transmission rules — telling users when their information is sent to third parties
soumu.go.jp
Link checked 18 August 2026
What is changing soon in Japan?
The big one has already passed. On 17 July 2026 Japan published a large amendment to its privacy law. It introduces the country's first money penalty for privacy breaches, sets 16 as the age below which a guardian must be involved, adds rules for face and other biometric data, and raises the criminal penalties. It is not in force yet: the government has up to two years to switch it on by order, and no date has been announced. The other thing to watch is the new cyber defence law, which is being switched on in stages through 2027.
Dates and switches, checked 18 August 2026. Already enacted, not yet in force: the Act partially amending the Act on the Protection of Personal Information and related acts, promulgated 17 July 2026, commencing on a date to be fixed by cabinet order within two years of promulgation — so at the latest 17 July 2028. Content: a surcharge payable to the state for serious violations of the bans on improper use, improper acquisition and unlawful third-party provision, aimed at cases involving 1,000 or more people and calculated on the financial benefit obtained; involvement of a legal guardian for anyone under 16; a publication duty and an opt-out ban for facial-feature and similar biometric data; an exemption from consent where data is used only to produce statistics, which is designed to unblock artificial-intelligence training; rationalised breach reporting so that low-risk cases need not be notified to individuals; wider emergency order powers; and heavier criminal penalties, with the database-misuse offence rising from one year to two and from 500,000 yen to 1 million yen, plus a new offence of obtaining personal information by deception. Being switched on in stages: the Act on the Prevention of Damage from Unauthorised Acts against Important Computers, Act No. 42 of 2025, Japan's 'active cyber defence' law. Its basic policy was settled in December 2025 and the public-private reporting machinery has been coming into operation through 2026, with the remaining provisions phased to 2027. Dormant switches — powers already held that could change the picture with no consultation: the Commission may add or remove countries from the equivalence list by its own notice, so the European Union and United Kingdom designations are revocable; the Digital Agency rewrites the Government Cloud specification at each procurement round and could widen or close the new overseas artificial-intelligence inference carve-out; the responsible ministers may add categories of critical equipment and further operators to the economic security screening system; and the communications ministry may designate additional telecoms providers into the specified user information regime.
Sources
- Official sourcePersonal Information Protection CommissionPromulgation of the Act partially amending the Act on the Protection of Personal Information, 17 July 2026
ppc.go.jp
“改正法は、一部を除き、公布日から起算して2年以内で政令で定める日から施行されます。”
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionExplanation of the Act partially amending the Act on the Protection of Personal Information, July 2026
ppc.go.jp
Link checked 18 August 2026
- Official sourceCabinet OfficeOutline of the basic policy under the Cyber Response Capability Enhancement Act, December 2025
cao.go.jp
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
4 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
3 rules here
Layer 3
Contract-imposed rule
Binds you because you signed something, typically a government contract.
1 rule here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules4 rules
個人情報の保護に関する法律
Act of parliament · Act on the Protection of Personal Information, Act No. 57 of 2003
Japan's general privacy law. Data may go abroad, but only to the European Union or United Kingdom without extra work; anywhere else needs a standards-conforming recipient or informed consent naming the country. There is no administrative fine — the sanctions are criminal, and the corporate ceiling for database misuse is 100 million yen (about $650,000).
Enforced by Personal Information Protection Commission
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Explicit consent, Someone's life is at risk, Important public interest
What it makes you do
- Tell people what you doPurpose of use must be stated or published.
- Get consentConsent is required for sensitive information, for third-party provision and for use beyond the stated purpose — not as a general basis for all processing.
- Put a transfer safeguard in placeArticle 28: designated country, standards-conforming recipient, or informed consent naming the destination country.
- Secure the dataIncludes 'understanding the external environment' — identifying the legal regime of any country where the data is handled.
- Report breaches to the regulator — within 120 hoursFirst report promptly, read by the regulator as 3 to 5 days; full report within 30 days, or 60 days where the breach may have been deliberate.
- Tell affected people
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people objectRight to demand a stop to use or third-party provision in defined circumstances.
- Written vendor contractNecessary and appropriate supervision of any processor.
- Delete data after a periodBest-efforts duty only: erase without delay once the data is no longer needed.
What it costs if you get it wrong
- Criminal liability: 1年以下の拘禁刑又は100万円以下の罰金 — about $7 thousandIndividual ignoring an order of the Personal Information Protection Commission
- Criminal liability: 1億円以下の罰金 — about $650 thousandCorporate liability for improper provision or theft of a personal information database by an officer or employee
- Criminal liability: 50万円以下の罰金 — about $3 thousandFailing to respond to a demand for a report
- Order to stopCommission order, including an emergency order to stop providing personal information
Sources
- Official sourcee-Gov, Digital Agency個人情報の保護に関する法律 (Act No. 57 of 2003), consolidated text
laws.e-gov.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionLaws, guidelines and related documents
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionGuidelines — provision to a third party in a foreign country
ppc.go.jp
Link checked 18 August 2026
個人情報の保護に関する法律等の一部を改正する法律
Act of parliament · Act partially amending the Act on the Protection of Personal Information and related acts, promulgated 17 July 2026
Passed and published on 17 July 2026 but not yet in force. It brings Japan its first money penalty for privacy breaches, sets the child threshold at 16, regulates facial and other biometric data, and lets data be used without consent where the only output is statistics. The start date will be fixed by cabinet order within two years and has not been announced.
Enforced by Personal Information Protection Commission
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent
What it makes you do
- Get a parent's consent for children — applies at: under 16Guardian involvement becomes a statutory duty, with an express duty to give priority to the child's best interests. Not yet in force.
- Tell people what you doNew publication duty for businesses handling facial-feature and similar biometric data: name, address, representative, the fact of such handling and the purpose.
- Tell affected peopleRelaxed where the risk to the individual's rights and interests is low.
What it costs if you get it wrong
- Fixed maximum fine: 違反行為によって得られた財産的利益等に相当する額Surcharge for serious breaches of the bans on improper use, improper acquisition and unlawful third-party provision, aimed at cases affecting 1,000 or more people. Amount is set by reference to the financial benefit obtained, not a fixed ceiling.
- Criminal liability: 2年以下の拘禁刑又は100万円以下の罰金 — about $7 thousandImproper provision of a personal information database, raised from one year and 500,000 yen, and extended to acts done with intent to cause harm
- Criminal liability: 1年以下の拘禁刑又は50万円以下の罰金 — about $3 thousandNew offence of obtaining personal information by deception
Sources
- Official sourcePersonal Information Protection CommissionThe 2026 amendment to the Act on the Protection of Personal Information
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionExplanation of the Act partially amending the Act on the Protection of Personal Information, July 2026
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionCabinet decision on the bill, 7 April 2026
ppc.go.jp
Link checked 18 August 2026
経済施策を一体的に講ずることによる安全保障の確保の推進に関する法律(経済安全保障推進法)
Act of parliament · Economic Security Promotion Act, Act No. 43 of 2022 — critical infrastructure provisions
Japan's quiet supply-chain screen. Operators in sixteen critical sectors — including finance, credit cards, medical care, telecoms, energy and transport — must tell their minister before installing important systems, and wait. The review looks at who owns the supplier, where the kit is made, and whether a foreign government could lean on it. It is not a storage-location rule, but it can stop a foreign cloud deployment.
Enforced by Cabinet Office, Economic Security
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyDesignated operators must notify the responsible minister before introducing critical equipment, including cloud and systems supply. Standard standstill of 30 days, extendable to four months.
- Do not hand data to foreign authorities on demandThe review asks whether foreign law or an external instruction could force the supplier to breach its contract with the operator.
- Written vendor contractNotification covers supplier ownership, shareholders holding 5 per cent or more of voting rights, place of manufacture, component suppliers and risk-management measures.
What it costs if you get it wrong
- Order to stopMinister's recommendation or order to change or halt the introduction of the equipment
Sources
- Official sourceCabinet OfficeOutline of the system for securing stable provision of specified critical infrastructure services, 17 June 2026
cao.go.jp
“30日間(延長・短縮あり)”
Link checked 18 August 2026
- Official sourceCabinet OfficeSystem for securing stable provision of critical infrastructure services
cao.go.jp
Link checked 18 August 2026
重要電子計算機に対する不正な行為による被害の防止に関する法律(サイバー対処能力強化法)
Act of parliament · Act on the Prevention of Damage from Unauthorised Acts against Important Computers, Act No. 42 of 2025
Japan's active cyber defence law, passed in May 2025 and being switched on in stages. It creates a second incident-reporting duty for critical infrastructure operators alongside the privacy one, and gives the government new powers over communications information. Some parts are running, others are still to commence.
Enforced by Cabinet Office, Cyber Security
Transfer model: Approval each time
What it makes you do
- Report cyber incidentsDesignated critical infrastructure operators give a prompt first alert, then a detailed report within 30 days.
- Secure the data
Sources
- Official sourceCabinet SecretariatAct on the Prevention of Damage from Unauthorised Acts against Important Computers (Act No. 42 of 2025) — explanatory material
cas.go.jp
Link checked 18 August 2026
- Official sourceCabinet OfficeApproach to implementing the public-private provisions, December 2025
cao.go.jp
Link checked 18 August 2026
- Official sourceCabinet OfficeOutline of the basic policy under the Act, December 2025
cao.go.jp
Link checked 18 August 2026
Industry rules3 rules
電気通信事業法
Act of parliament · Telecommunications Business Act, Act No. 86 of 1984; external transmission rules and specified user information rules added by the 2022 amendment · Telecoms
No storage-location rule, but the sharpest criminal exposure in Japan: leaking a communication is a prison offence. The Act reaches services provided from abroad to people in Japan, needs a representative in Japan, and since 16 June 2023 makes ordinary websites and apps disclose what user information they send to third parties.
Enforced by Ministry of Internal Affairs and Communications
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Appoint a local representativeA foreign provider must name a representative or agent in Japan to receive official notices.
- Register or notifyRegistration or notification with the communications ministry, depending on the service.
- Tell people what you do — from 16 June 2023External transmission rules: tell users what information about them is sent to a third party, to whom and why, before it is sent.
- Secure the dataDesignated providers of large-scale services must adopt an internal handling code for specified user information, appoint a chief administrator and report annually.
- Report breaches to the regulatorLeakage of specified user information affecting more than 1,000 users is reportable to the ministry.
What it costs if you get it wrong
- Criminal liability: 2年以下の懲役又は100万円以下の罰金 — about $7 thousandViolating the secrecy of a communication handled by a telecommunications carrier
- Criminal liability: 3年以下の懲役又は200万円以下の罰金 — about $13 thousandThe same act by a person engaged in the telecommunications business
- Order to stopBusiness improvement order where the secrecy of communications is impaired
Sources
- Official sourceMinistry of Internal Affairs and CommunicationsHow the Telecommunications Business Act applies where a foreign entity carries on a telecommunications business, 12 February 2021
soumu.go.jp
Link checked 18 August 2026
- Official sourceMinistry of Internal Affairs and CommunicationsRules on the proper handling of specified user information
soumu.go.jp
Link checked 18 August 2026
- Official sourceMinistry of Internal Affairs and CommunicationsGuideline on business improvement orders where secrecy of communications is impaired — Article 179 penalties
soumu.go.jp
“二年以下の懲役又は百万円以下の罰金に処する。”
Link checked 18 August 2026
医療情報システムの安全管理に関するガイドライン 第7.0版 / 医療情報を取り扱う情報システム・サービスの提供事業者における安全管理ガイドライン 第2.0版
Regulator guideline · Health ministry guideline version 7.0, June 2026; economy and communications ministries' supplier guideline version 2.0, August 2020 as revised March 2025 · Health and social care
Japan's medical data rules are guidance, not statute, and we found no requirement in the current versions that medical information be stored inside Japan. What they do require is that the hospital stays responsible, that the split of duties with the supplier is written down, and that generative artificial-intelligence services only receive data where the contract stops the input being retained for training.
Enforced by Ministry of Health, Labour and Welfare
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataThe hospital or clinic stays accountable for medical information wherever it is stored, including at a cloud supplier.
- Written vendor contractResponsibility split with the supplier must be documented. Version 7.0 adds a dedicated part for maintenance contractors.
- Keep data for a minimum period — 5 yearsMedical records: five years under the Medical Practitioners Act.
Sources
- Official sourceMinistry of Health, Labour and WelfareGuidelines for the Safety Management of Medical Information Systems, version 7.0, June 2026
mhlw.go.jp
Link checked 18 August 2026
- Official sourceMinistry of Health, Labour and WelfareQuestions and answers on version 6.0 of the guidelines, May 2025 — generative AI and overseas servers
mhlw.go.jp
Link checked 18 August 2026
- Official sourceLink may be brokenMinistry of Economy, Trade and IndustrySafety management guideline for providers of information systems and services handling medical information, version 2.0, revised March 2025
meti.go.jp
Link checked 18 August 2026
主要行等向けの総合的な監督指針 / 金融分野におけるサイバーセキュリティに関するガイドライン
Regulator guideline · Comprehensive Supervisory Guidelines for Major Banks; Guidelines on Cybersecurity in the Financial Sector, 4 October 2024 · Finance
The surprise here is an absence. Japan puts no residency rule on banking, payments, insurance or securities data. The Financial Services Agency regulates by risk: overseas outsourcing is expressly in scope, but what it demands is oversight, traceability and audit rights, not a Japanese data centre.
Enforced by Financial Services Agency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contractThe outsourcing contract must set out the split of duties, audit rights, sub-contracting procedure and service levels.
- Secure the dataThe firm must be able to monitor and trace how customer data is handled at the outsourcer, wherever it sits.
- Independent audit
What it costs if you get it wrong
- Order to stopBusiness improvement order under the Banking Act or the Financial Instruments and Exchange Act
Sources
- Official sourceFinancial Services AgencyComprehensive Supervisory Guidelines for Major Banks — evaluation points, outsourcing
fsa.go.jp
“外部委託先における顧客データの運用状況を、委託元が監視、追跡できる態勢となっているか。”
Link checked 18 August 2026
- Official sourceFinancial Services AgencyGuidelines on Cybersecurity in the Financial Sector, 4 October 2024
fsa.go.jp
Link checked 18 August 2026
Contract-imposed rule1 rule
デジタル庁におけるガバメントクラウド等の整備のためのクラウドサービスの提供 — 令和8年度募集 調達仕様書
Government policy document · Government Cloud procurement specification, 2026 application round, published 26 December 2025 · Government
The hardest wall in Japan, and it is a procurement condition rather than a statute. Anything running on the national Government Cloud is stored in Japanese data centres. Central government systems and the standardised systems of every local authority sit on it. The 2026 round adds one deliberate exception: a separately walled overseas environment for running artificial-intelligence models that are not available in Japan.
Enforced by Digital Agency
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryInformation assets are kept inside Japan, on domestic data centres spread across several Japanese regions for disaster resilience.
- Hold a security certificateThe provider must be registered on the Information system Security Management and Assessment Program (ISMAP) cloud service list before it can be procured.
- Prove the data stays under local control
What it costs if you get it wrong
- Loss of your licenceLoss of Government Cloud provider status or removal from the ISMAP list; commercially, exclusion from central and local government procurement
Sources
- Official sourceDigital AgencyGovernment Cloud procurement specification, 2026 application round
digital.go.jp
“ガバメントクラウドでは情報資産は日本国内に保管されることとしている”
Link checked 18 August 2026
- Official sourceISMAP Steering CommitteeOverview of the Information system Security Management and Assessment Program (ISMAP)
ismap.go.jp
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact promulgation date of the 2026 privacy amendment — 10 or 17 July 2026 — and its law number
The Commission's press release page is dated 17 July 2026 and says the Act was promulgated; the Commission's own explanatory PDF appears to give 10 July 2026, which is more likely the date the Diet passed it. We could not locate the gazette entry carrying the law number. Plan to the earlier date.
When the 2026 privacy amendment actually commences, and whether any provisions commence earlier than the rest
The Act says commencement is fixed by cabinet order within two years of promulgation, and no cabinet order had been published as at 18 August 2026. Until it is, the surcharge, the age-16 threshold and the biometric rules are not binding.
Whether the health ministry's medical information guidelines contain any requirement that medical data be stored inside Japan
We searched version 7.0 of the overview part, the 2005 external-storage notification and the 2025 questions and answers, and found no domestic-storage clause. The economy ministry's supplier guideline would not load for us. The finding is a searched-and-not-found, not a proven absence, so this is medium confidence.
Whether any Survey Act provision restricts taking survey results out of Japan
The Geospatial Information Authority's published procedures cover copying and using survey results and are silent on export. We could not open a consolidated statute text to check whether an export-approval provision survives. Treat this sector as unresearched rather than clear.
The precise commencement dates for each phase of the 2025 cyber defence Act
The Cabinet Office planning papers we could open give a roadmap rather than gazetted dates, and the fetched summary of those dates was internally inconsistent.
The in-force date of the specified user information regime for designated telecoms providers
The ministry's own page returned a date that appears to relate to an older provision. The connected external transmission rules are confirmed as in force from 16 June 2023.
Ten-year retention of company accounting books and five-year retention of medical records
Both are well established in the Companies Act and the Medical Practitioners Act, but we did not open a government page stating them during this run. The seven and ten year tax periods are confirmed from the National Tax Agency.
Whether the Personal Information Protection Commission has issued any further orders or recommendations between October 2025 and August 2026
The full annual report for the 2025 financial year was published on 7 July 2026 but we could only read the announcement page, not the report itself. Figures quoted are for the first half of that year.
60-day cadence. The single biggest variable is the cabinet order that switches on the 2026 amendment: it can be published at any time between now and 17 July 2028 and it changes penalties, children's data and biometric rules at once. The equivalence list, the Government Cloud specification and the critical-equipment categories are all changeable by administrative act with no consultation.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.