Skip to the content
Global Data RulesData governance rules, country by country

Japan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Japan — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Active

You can send personal data out of Japan, but you need paperwork. Only Europe and the United Kingdom are pre-approved. For anywhere else you need one of two things. Either you sign a contract that binds the recipient to Japanese-standard protection. Or you get the person's consent after telling them which country the data goes to. There is no general rule forcing data to stay in Japan.

Data governance in Japan

The eight things that decide how you handle data about people in Japan. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Japan's privacy law reaches a foreign company with no office and no staff in Japan. It applies as long as you handle personal information about people in Japan while supplying them goods or services. There is no size, revenue or headcount threshold to fall below. Unlike Europe, the privacy law does not make you appoint a representative in Japan. The telecoms law does, if your service counts as a telecommunications service.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, with paperwork. Personal data may go abroad once you have one of three things in place. There is no across-the-board law keeping data in Japan. We searched for a banking, insurance, securities or health rule forcing data to stay in the country. India and China have rules like that. Japan does not. The one exception is government work. Anything running on the national Government Cloud must sit in data centres inside Japan.

What to do: Get the paperwork for one of the routes below signed before any data leaves Japan.

Sending data out of the country

You can only send data to approved countries without extra work, and that list has exactly two entries: the European Union and the United Kingdom. Send data there and it is treated almost like a transfer inside Japan. For every other destination you need one of two things. Either the recipient is bound by contract to protect the data to Japanese standards, and you keep checking that it does. Or you get the person's consent. Before they consent, tell them the destination country, what its privacy law is like, and what the recipient will do to protect the data.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Explicit consent

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Personal Information Protection Commission, and it is really working. It has a chair, eight commissioners and a staff ceiling of 231 people. In the year to March 2025 it handled just over 19,000 breach reports, gave 395 pieces of formal guidance and made one recommendation. In the first six months of the following year it stepped up. It made two recommendations and issued its first emergency order, against a company misusing personal information. What it cannot do yet is fine you. Japan has no money penalty from the regulator for privacy breaches until the 2026 amendment starts.

How long you must keep it — and when to delete it

The minimum is firm and the maximum is soft. Tax law makes you keep books and records for seven years. That stretches to ten if you carry a loss forward. Company accounting books run ten years. Against that, the privacy law only asks you to try to delete personal data once you no longer need it. It is a best-efforts duty, not a hard deadline. So when the two collide, keeping the data wins.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

Count three clocks. For a personal data breach you file a first report to the privacy regulator within three to five days of finding out. You file a full report within 30 days, or 60 days if someone did it on purpose. You must also tell the people affected. Critical infrastructure operators have a separate cyber incident duty, with a report to the government within 30 days. Telecoms operators report leaks of communications to the communications ministry on their own timetable.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. One. Putting data on a foreign server is often not a transfer abroad at all, if the provider is barred by contract from touching it. But you then have to work out that country's privacy law and publish the country's name to your users. Two. The privacy law brings no fines from the regulator. The punishments are criminal, and a company can be fined about 650,000 United States dollars for a staff member stealing a customer database. Three. Leaking a communication is a crime punishable with prison, and telecoms staff face a longer term than outsiders. Four. The telecoms rules catch ordinary websites and apps, not just phone companies, and they reach foreign operators with no office in Japan. Five. Consent to send data 'overseas' is not valid. You have to name the country.

What you have to do here:
Secure the data · Tell people what you do · Put a transfer safeguard in place
What it costs if you get it wrong:
Criminal liability

What's changing next

The big one has already passed. On 17 July 2026 Japan published a large amendment to its privacy law. It brings in the country's first money penalty for privacy breaches. It sets 16 as the age below which a guardian must be involved. It adds rules for face and other biometric data. And it raises the criminal penalties. It is not in force yet. The government has up to two years to switch it on by order, and no date has been announced. The other thing to watch is the new cyber defence law, which is being switched on in stages through 2027.

What to do: Diarise 17 July 2028 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data rules

Official name: 電気通信事業法 · Telecommunications Business Act, Act No. 86 of 1984; external transmission rules and specified user information rules added by the 2022 amendment · Act of parliament

In forceYes, with paperwork

There is no rule about where data is stored. But this carries the sharpest criminal risk in Japan. Leaking a communication can put you in prison. The Act reaches services provided from abroad to people in Japan. It requires a representative in Japan. And since 16 June 2023 it makes ordinary websites and apps disclose what user information they send to third parties.

In force since 1 April 1985Enforced from 16 June 2023

Enforced by Ministry of Internal Affairs and Communications

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.
Health and social care

Health data rules

Official name: 医療情報システムの安全管理に関するガイドライン 第7.0版 / 医療情報を取り扱う情報システム・サービスの提供事業者における安全管理ガイドライン 第2.0版 · Health ministry guideline version 7.0, June 2026; economy and communications ministries' supplier guideline version 2.0, August 2020 as revised March 2025 · Regulator guideline

In forceYes, with paperwork

Japan's medical data rules are guidance, not law. We found no requirement in the current versions that medical information be stored inside Japan. What they do require is that the hospital stays responsible. The split of duties with the supplier must be written down. And generative artificial intelligence services may only receive data where the contract stops the input being kept for training.

In force since 1 June 2026

Enforced by Ministry of Health, Labour and Welfare

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.
Finance

Cloud and outsourcing rules (Finance)

Official name: 主要行等向けの総合的な監督指針 / 金融分野におけるサイバーセキュリティに関するガイドライン · Comprehensive Supervisory Guidelines for Major Banks; Guidelines on Cybersecurity in the Financial Sector, 4 October 2024 · Regulator guideline

In forceYes — store it anywhere

The surprise here is an absence. Japan has no rule saying banking, payments, insurance or securities data must stay in the country. The Financial Services Agency regulates by risk. Outsourcing overseas is expressly covered. But what the Agency demands is oversight, traceability and audit rights, not a Japanese data centre.

In force since 4 October 2024

Enforced by Financial Services Agency

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: 個人情報の保護に関する法律 · Act on the Protection of Personal Information, Act No. 57 of 2003 · Act of parliament

In forceYes, with paperwork

Japan's general privacy law. Data may go abroad. Only the European Union and the United Kingdom take it without extra work. Anywhere else, the recipient must meet Japanese standards, or the person must consent after being told the destination country. The regulator cannot fine you. The punishments are criminal, and the company ceiling for database misuse is 100 million yen (about 650,000 United States dollars).

In force since 1 April 2005Enforced from 1 April 2022

Enforced by Personal Information Protection Commission

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Explicit consent, To save someone’s life, Important public interest

Children's data rules

Official name: 個人情報の保護に関する法律等の一部を改正する法律 · Act partially amending the Act on the Protection of Personal Information and related acts, promulgated 17 July 2026 · Act of parliament

Passed, not yet fully in forceYes, with paperwork

Passed and published on 17 July 2026, but not yet in force. It brings Japan its first money penalty for privacy breaches. It sets the child threshold at 16. It regulates facial and other biometric data. And it lets data be used without consent where the only output is statistics. The start date will be fixed by cabinet order within two years and has not been announced.

Enforced by Personal Information Protection Commission

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent

Cloud and outsourcing rules

Official name: 経済施策を一体的に講ずることによる安全保障の確保の推進に関する法律(経済安全保障推進法) · Economic Security Promotion Act, Act No. 43 of 2022 — critical infrastructure provisions · Act of parliament

In forceYes, with paperwork

Japan's quiet supply-chain screen. Operators in sixteen critical sectors must tell their minister before installing important systems, and then wait. Those sectors include finance, credit cards, medical care, telecoms, energy and transport. The review looks at who owns the supplier, where the kit is made, and whether a foreign government could lean on it. It is not a rule about where data is stored, but it can stop a foreign cloud deployment.

In force since 17 November 2023Enforced from 17 May 2024

Enforced by Cabinet Office, Economic Security

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies only if you signed a contract1 rule

Usually a government or enterprise contract that adds rules of its own.

Government

Government data must stay in the country

Official name: デジタル庁におけるガバメントクラウド等の整備のためのクラウドサービスの提供 — 令和8年度募集 調達仕様書 · Government Cloud procurement specification, 2026 application round, published 26 December 2025 · Government policy document

In forceNo — it stays put

The strictest rule in Japan, and it is a purchasing condition rather than a law. Anything running on the national Government Cloud is stored in Japanese data centres. Central government systems sit on it, and so do the standardised systems of every local authority. The 2026 round adds one deliberate exception: a separately walled overseas environment for running artificial intelligence models that are not available in Japan.

In force since 26 December 2025

Enforced by Digital Agency

How this country controls where data goes: Not allowed

Who you would hear from

  • 個人情報保護委員会

    General privacy law and the My Number Act, private and public sector

    Fully set up. It has a chair, eight commissioners, five expert members and a staff ceiling of 231, as at 31 March 2025. In the first half of the 2025 financial year it issued 236 pieces of guidance, 2 recommendations and 1 emergency order. It cannot impose a money penalty until the 2026 amendment starts.

  • 総務省

    Telecommunications: secrecy of communications, specified user information, external transmission rules

  • デジタル庁

    Government Cloud, government system standards, ISMAP

  • 金融庁

    Banking, payments, insurance, securities

  • 厚生労働省

    Medical information systems and records

  • 内閣府 経済安全保障推進室

    Critical infrastructure equipment screening under the Economic Security Promotion Act

    Notification system operating since 17 May 2024 across sixteen designated sectors.

  • 内閣府 政策統括官(サイバー安全保障担当)

    Active cyber defence, critical infrastructure incident reporting

    Basic policy settled in December 2025. The reporting machinery is phasing in through 2026 and 2027.

  • 国土地理院

    Survey results and mapping data approvals

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact promulgation date of the 2026 privacy amendment — 10 or 17 July 2026 — and its law number

    We could not confirm the exact date or the law number. The Commission's press release page is dated 17 July 2026 and says the Act was published. The Commission's own explanatory document appears to give 10 July 2026, which is more likely the date the Diet passed it. We could not find the gazette entry carrying the law number. Plan around the earlier date.

  • When the 2026 privacy amendment actually commences, and whether any provisions commence earlier than the rest

    There is no start date yet. The Act says a cabinet order fixes the start date within two years of publication. No cabinet order had appeared as at 18 August 2026. Until one does, the surcharge, the age-16 threshold and the biometric rules do not bind you.

  • Whether the health ministry's medical information guidelines contain any requirement that medical data be stored inside Japan

    We found no clause requiring medical data to be stored in Japan. We checked version 7.0 of the overview part, the 2005 external storage notification, and the 2025 questions and answers. We could not check the economy ministry's supplier guideline. This is medium confidence. If you handle medical data, check before you rely on it.

  • Whether any Survey Act provision restricts taking survey results out of Japan

    We found no rule stopping survey results leaving Japan. The Geospatial Information Authority's published procedures cover copying and using survey results, and say nothing about sending them abroad. We could not check the full text of the Survey Act itself. Treat this industry as unresearched rather than settled.

  • The precise commencement dates for each phase of the 2025 cyber defence Act

    We could not confirm the start dates for each phase. The Cabinet Office planning papers give a roadmap rather than official dates, and the dates we found did not agree with each other. Ask the Cabinet Office if a specific phase matters to you.

  • The in-force date of the specified user information regime for designated telecoms providers

    We could not confirm this start date. The ministry's own page gave a date that appears to relate to an older rule. The related external transmission rules are confirmed as in force from 16 June 2023.

  • Ten-year retention of company accounting books and five-year retention of medical records

    Both are well established in the Companies Act and the Medical Practitioners Act. But we did not confirm them against a government page. The seven and ten year tax periods are confirmed from the National Tax Agency.

  • Whether the Personal Information Protection Commission has issued any further orders or recommendations between October 2025 and August 2026

    We could not confirm the later figures. The full annual report for the 2025 financial year was published on 7 July 2026. We could only read the announcement page, not the report itself. The figures quoted here are for the first half of that year.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.