Skip to the content
Global Data RulesData governance rules, country by country

Japan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: MediumEnforcement: Active

Japan lets personal data leave the country, but you need paperwork. Only Europe and the United Kingdom are pre-approved. For anywhere else you either sign a contract that binds the recipient to Japanese-standard protection, or you get the person's consent after telling them which country the data goes to. There is no general rule forcing data to stay in Japan.

Eight questions about Japan

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Japan's rules apply to my company?

Yes. Japan's privacy law reaches a foreign company with no office and no staff in Japan, as long as it handles the personal information of people in Japan while supplying them goods or services. There is no size, revenue or headcount threshold to fall below. Unlike Europe, the privacy law does not make you appoint a representative in Japan — but the telecoms law does, if your service counts as a telecommunications service.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside Japan?

Yes, with paperwork. Japan's general rating is conditional: personal data may go abroad once you have one of three things in place. There is no across-the-board law keeping data in Japan, and no financial, insurance, securities or health localisation rule of the kind India or China have — we searched for one and did not find it. The real wall is government work: anything running on the national Government Cloud must sit in data centres inside Japan.

High confidenceYes, with paperworkAllowlist

What do I need in place before data leaves Japan?

The model is an allowlist, and the list has exactly two entries: the European Union and the United Kingdom. Send data there and it is treated almost like a domestic transfer. For every other destination you need one of two things instead. Either the recipient is contractually bound to protect the data to Japanese standards and you keep checking that it does, or you get the person's consent after first telling them the destination country, what its privacy law is like, and what the recipient will do to protect the data.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesCertification schemeExplicit consent

Who enforces the rules in Japan, and what can they do?

The Personal Information Protection Commission, and it is genuinely working. It has a chair, eight commissioners and a staff ceiling of 231 people. In the year to March 2025 it handled just over 19,000 breach reports, gave 395 pieces of formal guidance and made one recommendation. In the first six months of the following year it sharpened up: two recommendations and its first emergency order, against a company misusing personal information. What it cannot do yet is fine you — Japan has no administrative money penalty for privacy breaches until the 2026 amendment starts.

High confidenceActive

How long do I have to keep the data?

The floor is firm and the ceiling is soft. Tax law makes you keep books and records for seven years, stretching to ten if you carry a loss forward. Company accounting books run ten years. Against that, the privacy law only asks you to try to delete personal data once you no longer need it — it is a best-efforts duty, not a hard deadline. So when the two collide, the keep-it rule wins in practice.

Medium confidenceKeep data for a minimum periodDelete data after a period

What happens if there is a breach?

Count three clocks. For a personal data breach you file a first report to the privacy regulator within three to five days of finding out, and a full report within 30 days — 60 days if someone did it on purpose. You must also tell the people affected. Critical infrastructure operators have a separate cyber incident duty with a report to the government within 30 days. Telecoms operators report leaks of communications to the communications ministry on their own timetable.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Japan?

Five. (1) Putting data on a foreign server is often not a 'transfer' at all — if the provider is contractually barred from touching it — but you then have to work out that country's privacy law and publish the country's name to your users. Most people miss this. (2) The privacy law has no fines: the sanctions are criminal, and a company can be fined about $650,000 for a staff member stealing a customer database. (3) Leaking a communication is a crime punishable with prison, and telecoms staff face a longer term than outsiders. (4) The telecoms rules catch ordinary websites and apps, not just phone companies, and reach foreign operators with no office in Japan. (5) Consent to send data 'overseas' is not valid — you have to name the country.

High confidenceSecure the dataTell people what you doCriminal liabilityPut a transfer safeguard in place

What is changing soon in Japan?

The big one has already passed. On 17 July 2026 Japan published a large amendment to its privacy law. It introduces the country's first money penalty for privacy breaches, sets 16 as the age below which a guardian must be involved, adds rules for face and other biometric data, and raises the criminal penalties. It is not in force yet: the government has up to two years to switch it on by order, and no date has been announced. The other thing to watch is the new cyber defence law, which is being switched on in stages through 2027.

High confidencePassed, not yet fully in forcePartly in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    4 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    3 rules here

  3. Layer 3

    Contract-imposed rule

    Binds you because you signed something, typically a government contract.

    1 rule here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules4 rules

個人情報の保護に関する法律

Act of parliament · Act on the Protection of Personal Information, Act No. 57 of 2003

In forceYes, with paperwork

Japan's general privacy law. Data may go abroad, but only to the European Union or United Kingdom without extra work; anywhere else needs a standards-conforming recipient or informed consent naming the country. There is no administrative fine — the sanctions are criminal, and the corporate ceiling for database misuse is 100 million yen (about $650,000).

In force since 1 April 2005But only enforceable from 1 April 2022

Enforced by Personal Information Protection Commission

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Explicit consent, Someone's life is at risk, Important public interest

High confidence

個人情報の保護に関する法律等の一部を改正する法律

Act of parliament · Act partially amending the Act on the Protection of Personal Information and related acts, promulgated 17 July 2026

Passed, not yet fully in forceYes, with paperwork

Passed and published on 17 July 2026 but not yet in force. It brings Japan its first money penalty for privacy breaches, sets the child threshold at 16, regulates facial and other biometric data, and lets data be used without consent where the only output is statistics. The start date will be fixed by cabinet order within two years and has not been announced.

Enforced by Personal Information Protection Commission

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent

High confidence

経済施策を一体的に講ずることによる安全保障の確保の推進に関する法律(経済安全保障推進法)

Act of parliament · Economic Security Promotion Act, Act No. 43 of 2022 — critical infrastructure provisions

In forceYes, with paperwork

Japan's quiet supply-chain screen. Operators in sixteen critical sectors — including finance, credit cards, medical care, telecoms, energy and transport — must tell their minister before installing important systems, and wait. The review looks at who owns the supplier, where the kit is made, and whether a foreign government could lean on it. It is not a storage-location rule, but it can stop a foreign cloud deployment.

In force since 17 November 2023But only enforceable from 17 May 2024

Enforced by Cabinet Office, Economic Security

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Industry rules3 rules

電気通信事業法

Act of parliament · Telecommunications Business Act, Act No. 86 of 1984; external transmission rules and specified user information rules added by the 2022 amendment · Telecoms

In forceYes, with paperwork

No storage-location rule, but the sharpest criminal exposure in Japan: leaking a communication is a prison offence. The Act reaches services provided from abroad to people in Japan, needs a representative in Japan, and since 16 June 2023 makes ordinary websites and apps disclose what user information they send to third parties.

In force since 1 April 1985But only enforceable from 16 June 2023

Enforced by Ministry of Internal Affairs and Communications

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

医療情報システムの安全管理に関するガイドライン 第7.0版 / 医療情報を取り扱う情報システム・サービスの提供事業者における安全管理ガイドライン 第2.0版

Regulator guideline · Health ministry guideline version 7.0, June 2026; economy and communications ministries' supplier guideline version 2.0, August 2020 as revised March 2025 · Health and social care

In forceYes, with paperwork

Japan's medical data rules are guidance, not statute, and we found no requirement in the current versions that medical information be stored inside Japan. What they do require is that the hospital stays responsible, that the split of duties with the supplier is written down, and that generative artificial-intelligence services only receive data where the contract stops the input being retained for training.

In force since 1 June 2026

Enforced by Ministry of Health, Labour and Welfare

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

主要行等向けの総合的な監督指針 / 金融分野におけるサイバーセキュリティに関するガイドライン

Regulator guideline · Comprehensive Supervisory Guidelines for Major Banks; Guidelines on Cybersecurity in the Financial Sector, 4 October 2024 · Finance

In forceYes — store it anywhere

The surprise here is an absence. Japan puts no residency rule on banking, payments, insurance or securities data. The Financial Services Agency regulates by risk: overseas outsourcing is expressly in scope, but what it demands is oversight, traceability and audit rights, not a Japanese data centre.

In force since 4 October 2024

Enforced by Financial Services Agency

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Contract-imposed rule1 rule

デジタル庁におけるガバメントクラウド等の整備のためのクラウドサービスの提供 — 令和8年度募集 調達仕様書

Government policy document · Government Cloud procurement specification, 2026 application round, published 26 December 2025 · Government

In forceNo — it stays put

The hardest wall in Japan, and it is a procurement condition rather than a statute. Anything running on the national Government Cloud is stored in Japanese data centres. Central government systems and the standardised systems of every local authority sit on it. The 2026 round adds one deliberate exception: a separately walled overseas environment for running artificial-intelligence models that are not available in Japan.

In force since 26 December 2025

Enforced by Digital Agency

Transfer model: Not allowed

High confidence

Who you would hear from

  • 個人情報保護委員会

    General privacy law and the My Number Act, private and public sector

    Fully constituted: a chair, eight commissioners, five expert members and a staff ceiling of 231 as at 31 March 2025. In the first half of the 2025 financial year it issued 236 pieces of guidance, 2 recommendations and 1 emergency order. It has no power to levy a money penalty until the 2026 amendment commences.

  • 総務省

    Telecommunications: secrecy of communications, specified user information, external transmission rules

  • デジタル庁

    Government Cloud, government system standards, ISMAP

  • 金融庁

    Banking, payments, insurance, securities

  • 厚生労働省

    Medical information systems and records

  • 内閣府 経済安全保障推進室

    Critical infrastructure equipment screening under the Economic Security Promotion Act

    Notification system operating since 17 May 2024 across sixteen designated sectors.

  • 内閣府 政策統括官(サイバー安全保障担当)

    Active cyber defence, critical infrastructure incident reporting

    Basic policy settled December 2025; reporting machinery phasing in through 2026 and 2027.

  • 国土地理院

    Survey results and mapping data approvals

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact promulgation date of the 2026 privacy amendment — 10 or 17 July 2026 — and its law number

    The Commission's press release page is dated 17 July 2026 and says the Act was promulgated; the Commission's own explanatory PDF appears to give 10 July 2026, which is more likely the date the Diet passed it. We could not locate the gazette entry carrying the law number. Plan to the earlier date.

  • When the 2026 privacy amendment actually commences, and whether any provisions commence earlier than the rest

    The Act says commencement is fixed by cabinet order within two years of promulgation, and no cabinet order had been published as at 18 August 2026. Until it is, the surcharge, the age-16 threshold and the biometric rules are not binding.

  • Whether the health ministry's medical information guidelines contain any requirement that medical data be stored inside Japan

    We searched version 7.0 of the overview part, the 2005 external-storage notification and the 2025 questions and answers, and found no domestic-storage clause. The economy ministry's supplier guideline would not load for us. The finding is a searched-and-not-found, not a proven absence, so this is medium confidence.

  • Whether any Survey Act provision restricts taking survey results out of Japan

    The Geospatial Information Authority's published procedures cover copying and using survey results and are silent on export. We could not open a consolidated statute text to check whether an export-approval provision survives. Treat this sector as unresearched rather than clear.

  • The precise commencement dates for each phase of the 2025 cyber defence Act

    The Cabinet Office planning papers we could open give a roadmap rather than gazetted dates, and the fetched summary of those dates was internally inconsistent.

  • The in-force date of the specified user information regime for designated telecoms providers

    The ministry's own page returned a date that appears to relate to an older provision. The connected external transmission rules are confirmed as in force from 16 June 2023.

  • Ten-year retention of company accounting books and five-year retention of medical records

    Both are well established in the Companies Act and the Medical Practitioners Act, but we did not open a government page stating them during this run. The seven and ten year tax periods are confirmed from the National Tax Agency.

  • Whether the Personal Information Protection Commission has issued any further orders or recommendations between October 2025 and August 2026

    The full annual report for the 2025 financial year was published on 7 July 2026 but we could only read the announcement page, not the report itself. Figures quoted are for the first half of that year.

60-day cadence. The single biggest variable is the cabinet order that switches on the 2026 amendment: it can be published at any time between now and 17 July 2028 and it changes penalties, children's data and biometric rules at once. The equivalence list, the Government Cloud specification and the critical-equipment categories are all changeable by administrative act with no consultation.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.