Japan
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Japan — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send personal data out of Japan, but you need paperwork. Only Europe and the United Kingdom are pre-approved. For anywhere else you need one of two things. Either you sign a contract that binds the recipient to Japanese-standard protection. Or you get the person's consent after telling them which country the data goes to. There is no general rule forcing data to stay in Japan.
Data governance in Japan
The eight things that decide how you handle data about people in Japan. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Japan's privacy law reaches a foreign company with no office and no staff in Japan. It applies as long as you handle personal information about people in Japan while supplying them goods or services. There is no size, revenue or headcount threshold to fall below. Unlike Europe, the privacy law does not make you appoint a representative in Japan. The telecoms law does, if your service counts as a telecommunications service.
- What you have to do here:
- Appoint a representative
The law applies even if you have no office in Japan. That is Article 171 of the Act on the Protection of Personal Information. The 2020 amendment took effect on 1 April 2022. Since then the Personal Information Protection Commission can use its full set of powers against foreign companies. That includes demands for reports, on-site inspection, guidance, recommendations and orders. The Commission's own frequently asked questions confirm two things. The law applies if you collect from people in Japan directly. It also applies if you receive the data from another Japanese business. The Ministry of Internal Affairs and Communications takes a separate view on the Telecommunications Business Act. It says that Act applies to services provided from abroad to people in Japan, where the service is clearly aimed at Japan. Signs of that are a Japanese-language interface, prices in yen, and marketing aimed at Japan. Those providers must register or file a notification, and name a representative or agent in Japan.
Sources
- Official sourcePersonal Information Protection CommissionPPC FAQ — does the Act apply to a foreign operator supplying services to people in Japan? (Article 171)
ppc.go.jp
Link checked 18 August 2026
- Official sourceMinistry of Internal Affairs and CommunicationsHow the Telecommunications Business Act applies where a foreign entity carries on a telecommunications business, 12 February 2021
soumu.go.jp
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. Personal data may go abroad once you have one of three things in place. There is no across-the-board law keeping data in Japan. We searched for a banking, insurance, securities or health rule forcing data to stay in the country. India and China have rules like that. Japan does not. The one exception is government work. Anything running on the national Government Cloud must sit in data centres inside Japan.
Sector by sector, checked 18 August 2026: - Government and public sector — data must stay in the country The Digital Agency's Government Cloud purchase specification says information assets are to be kept inside Japan. It requires data centres in Japan, spread across several Japanese regions. Cloud providers must first be listed under the Information system Security Management and Assessment Program (ISMAP). The 2026 round has one exception: a separately walled 'overseas AI inference environment' for frontier models that are not available in Japan. - Telecoms — data can leave only if conditions are met There is no rule about where data is stored. But keeping communications secret is a criminal duty. Designated large providers must file an internal handling code for 'specified user information' with the ministry. And the external transmission rules make you disclose what user information you send to third parties. - Critical infrastructure — data can leave only if conditions are met This covers 16 named sectors, including finance, medical care, telecoms, energy, transport and credit cards. Before installing critical equipment you must notify the responsible minister. The minister reviews who owns the supplier, its ties to foreign governments, and whether foreign law could force the supplier to break its contract. The minister can order changes. - Banking, payments, insurance, securities — data can leave freely The Financial Services Agency regulates by risk, not by geography. Its October 2024 cybersecurity guidelines expressly cover outsourced work done overseas, but set no storage location. Supervisory guidance requires the bank to be able to monitor and trace customer data at an outsourcer, and to write audit rights into the contract. - Health — data can leave only if conditions are met, medium confidence. Three ministries publish guidelines. The health ministry guideline is version 7.0, of June 2026. The economy and communications ministries' supplier guideline is version 2.0, revised March 2025. These are guidance, not law. We found no clause in the versions we could open requiring storage in Japan. But hospitals must stay accountable and must understand the law where the data sits. - Mapping and geospatial — we found no export restriction, checked 18 August 2026, medium confidence. The Geospatial Information Authority's published approval procedures cover copying and using survey results. They say nothing about taking them out of Japan. - Defence — we found no rule about location, checked 18 August 2026. The defence purchasing information security standard controls encryption, access and designated handling facilities, not the country of storage.
Sources
- Official sourcePersonal Information Protection CommissionGuidelines on the Act on the Protection of Personal Information (Provision to a Third Party in a Foreign Country)
ppc.go.jp
“個人の権利利益を保護する上で我が国と同等の水準にあると認められる個人情報の保護に関する制度を有している外国は、EU及び英国が該当する”
Link checked 18 August 2026
- Official sourceDigital AgencyProvision of cloud services for the Government Cloud — 2026 procurement specification
digital.go.jp
“ガバメントクラウドでは情報資産は日本国内に保管されることとしている”
Link checked 18 August 2026
- Official sourceCabinet OfficeOutline of the system for securing stable provision of specified critical infrastructure services under the Economic Security Promotion Act, 17 June 2026
cao.go.jp
Link checked 18 August 2026
- Official sourceFinancial Services AgencyGuidelines on Cybersecurity in the Financial Sector, 4 October 2024
fsa.go.jp
“形式上、外部委託契約が結ばれていなくともその実態において外部委託と同視しうる場合や当該外部委託された業務等が海外で行われる場合も含む”
Link checked 18 August 2026
- Official sourceMinistry of Health, Labour and WelfareGuidelines for the Safety Management of Medical Information Systems, version 7.0, June 2026
mhlw.go.jp
Link checked 18 August 2026
- Official sourceGeospatial Information Authority of JapanProcedures for using survey results (Survey Act approval for copying and use)
gsi.go.jp
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Japan.
Sending data out of the country
You can only send data to approved countries without extra work, and that list has exactly two entries: the European Union and the United Kingdom. Send data there and it is treated almost like a transfer inside Japan. For every other destination you need one of two things. Either the recipient is bound by contract to protect the data to Japanese standards, and you keep checking that it does. Or you get the person's consent. Before they consent, tell them the destination country, what its privacy law is like, and what the recipient will do to protect the data.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Explicit consent
Article 28 of the Act sets three routes. One. The country has been named by Commission rule as giving equivalent protection. Only the European Economic Area and the United Kingdom are named, by Commission Notice No. 1 of 2019. Two. The recipient has a system that meets the standards set by Commission rule. That usually means a contract inside your group or with a supplier, binding internal rules, or Asia-Pacific Economic Cooperation Cross-Border Privacy Rules certification. This route brings a continuing duty under Article 28(3). You must keep checking that the recipient still complies, and tell the person about it if they ask. Three. The person consents in advance, after you give them the information required by Article 28(2). One-off consent covering an unnamed 'overseas' is not enough. You have to name the country where it can be identified. Data that arrived in Japan from Europe or the United Kingdom, under their official decisions that Japan is safe enough, carries an extra layer. The Commission's Supplementary Rules limit passing it on more tightly than the Act itself.
Sources
- Official sourcePersonal Information Protection CommissionGuidelines on the Act on the Protection of Personal Information (Provision to a Third Party in a Foreign Country), Article 28
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionForeign countries recognised as having a personal information protection system equivalent to Japan's (Commission Notice No. 1 of 2019)
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionSupplementary Rules for handling personal data transferred from the EU and the UK under adequacy
ppc.go.jp
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Personal Information Protection Commission, and it is really working. It has a chair, eight commissioners and a staff ceiling of 231 people. In the year to March 2025 it handled just over 19,000 breach reports, gave 395 pieces of formal guidance and made one recommendation. In the first six months of the following year it stepped up. It made two recommendations and issued its first emergency order, against a company misusing personal information. What it cannot do yet is fine you. Japan has no money penalty from the regulator for privacy breaches until the 2026 amendment starts.
We rate enforcement active rather than aggressive. The number of actions is low next to the caseload, and the tools are soft. Here are the figures for the first half of the 2025 financial year, April to September 2025. There were 8,928 breach reports from private-sector businesses. There were 11 demands for a report and 2 on-site inspections. There were 236 pieces of guidance and advice, 2 recommendations and 1 order. The recommendations went to Business Planning Ltd and Chuo Business Service Ltd. The emergency order went to Business Planning Ltd, requiring it to stop providing personal information in breach of the ban on improper use. Sector regulators run alongside, and all of them are working. They are the Financial Services Agency, and the Ministry of Internal Affairs and Communications for telecoms. Also the Digital Agency for government systems, and the Cabinet Office for economic security screening. And the Ministry of Health, Labour and Welfare for medical information.
Sources
- Official sourcePersonal Information Protection CommissionActivity results of the Personal Information Protection Commission, first half of the 2025 financial year, 12 November 2025
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionPersonal Information Protection Commission annual report for the 2024 financial year
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionPublication of the Commission's annual report for the 2025 financial year, 7 July 2026
ppc.go.jp
Link checked 18 August 2026
How long you must keep it — and when to delete it
The minimum is firm and the maximum is soft. Tax law makes you keep books and records for seven years. That stretches to ten if you carry a loss forward. Company accounting books run ten years. Against that, the privacy law only asks you to try to delete personal data once you no longer need it. It is a best-efforts duty, not a hard deadline. So when the two collide, keeping the data wins.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
How long you must keep data. Corporate tax books and transaction documents: seven years from the day after the filing deadline. That extends to ten years for a business year in which a blue-return loss arises and is carried forward. Company accounting books and supporting materials: ten years under the Companies Act. Medical records: five years under the Medical Practitioners Act. Telecoms operators have no general log-keeping period set by law. How long you may keep data. Article 22 of the privacy Act is written as a best-efforts duty. You 'shall endeavour to erase' personal data without delay once you no longer need it. Japan has no equivalent of Europe's storage-limitation rule backed by fines, and no maximum period set by law. The result is the opposite of most countries. In Japan the risk sits in keeping too little, not too much.
Sources
- Official sourceNational Tax AgencyRetention periods for books and records (No. 5930)
nta.go.jp
“その帳簿と取引等に関して作成または受領した書類を、その事業年度の確定申告書の提出期限の翌日から7年間保存しなければなりません。”
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionGuidelines on the Act on the Protection of Personal Information (General Rules) — erasure of data no longer needed
ppc.go.jp
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
Count three clocks. For a personal data breach you file a first report to the privacy regulator within three to five days of finding out. You file a full report within 30 days, or 60 days if someone did it on purpose. You must also tell the people affected. Critical infrastructure operators have a separate cyber incident duty, with a report to the government within 30 days. Telecoms operators report leaks of communications to the communications ministry on their own timetable.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The privacy duty applies to only four kinds of breach. Sensitive personal information. Data whose misuse could cause financial loss, such as card numbers or payment credentials. Anything done deliberately, including hacking and rogue employees. And any breach affecting more than 1,000 people. Below those thresholds, reporting is voluntary. The first report is due 'promptly'. The Commission reads that as three to five days from discovery. The full report is due within 30 days. That extends to 60 days where the breach may have been done for an improper purpose. Telling the affected people is a separate duty and runs at the same time. The Act on the Prevention of Damage from Unauthorised Acts against Important Computers (Act No. 42 of 2025) adds a second set of rules for designated critical infrastructure. You give a prompt first alert, then a detailed report within 30 days. Where the incident touches communications, the Telecommunications Business Act adds a third. The overlap is where operations fail: three sets of rules, three recipients, three formats, one incident.
Sources
- Official sourcePersonal Information Protection CommissionWhat to do when a personal data breach occurs — reporting categories and deadlines
ppc.go.jp
“個人データに係る本人の数が1,000人を超える漏えい等”
Link checked 18 August 2026
- Official sourceCabinet SecretariatAct on the Prevention of Damage from Unauthorised Acts against Important Computers (Act No. 42 of 2025) — explanatory material
cas.go.jp
Link checked 18 August 2026
- Official sourceCabinet OfficeApproach to implementing the public-private provisions of the Cyber Response Capability Enhancement Act, December 2025
cao.go.jp
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. One. Putting data on a foreign server is often not a transfer abroad at all, if the provider is barred by contract from touching it. But you then have to work out that country's privacy law and publish the country's name to your users. Two. The privacy law brings no fines from the regulator. The punishments are criminal, and a company can be fined about 650,000 United States dollars for a staff member stealing a customer database. Three. Leaking a communication is a crime punishable with prison, and telecoms staff face a longer term than outsiders. Four. The telecoms rules catch ordinary websites and apps, not just phone companies, and they reach foreign operators with no office in Japan. Five. Consent to send data 'overseas' is not valid. You have to name the country.
- What you have to do here:
- Secure the data · Tell people what you do · Put a transfer safeguard in place
- What it costs if you get it wrong:
- Criminal liability
Trap 1 in detail. The Commission's frequently asked questions cover this. Storing personal data on a server run by a foreign provider is not giving it to a third party in a foreign country. That holds as long as your contract stops that provider handling the data, and access controls back it up. But Articles 23 and 32 then require you to understand the outside environment. You must identify the country where the provider sits, and the country where the servers sit. You must take security measures suited to that country's law. And you must put the country names and the measures where the person can find them. If you truly cannot pin down the server location, you must publish the reason instead. Trap 2 in detail. Ignoring a Commission order can bring up to one year's imprisonment. For an individual it can also bring a fine of up to 1 million yen (about 6,500 United States dollars). For a company the fine goes up to 100 million yen (about 650,000 United States dollars). The same 100 million yen company ceiling applies to improperly providing or stealing a personal information database. Failing to answer a demand for a report carries up to 500,000 yen (about 3,300 United States dollars). Trap 3 in detail. Breaking the secrecy of communications can bring up to two years' imprisonment. It can also bring a fine of up to 1 million yen (about 6,500 United States dollars). For someone working in the telecommunications business it rises to three years or 2 million yen (about 13,000 United States dollars). Attempts are punishable too. Trap 4 in detail. The external transmission rules have been in force since 16 June 2023. Any covered online service must tell users what information about them is sent to third parties, to whom and why, before it is sent. The communications ministry's own guidance confirms that foreign providers serving Japan are covered. Trap 5 in detail. Where the destination country can be identified, you must name it before you ask for consent. Blanket wording about 'servers outside Japan' does not carry the consent.
Sources
- Official sourcePersonal Information Protection CommissionPPC FAQ — 'understanding the external environment' where a foreign cloud service stores personal data
ppc.go.jp
“クラウドサービス提供事業者が所在する外国の名称及び個人データが保存されるサーバが所在する外国の名称を明らかにし”
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionPPC FAQ — is storing personal data on a server in a foreign country a provision to a third party?
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionPPC FAQ — measures and criminal penalties where a business violates the Act
ppc.go.jp
“刑事罰(1年以下の拘禁刑又は100万円以下の罰金)が科される可能性があります”
Link checked 18 August 2026
- Official sourceMinistry of Internal Affairs and CommunicationsGuideline on issuing business improvement orders where secrecy of communications is impaired — penalties under Article 179
soumu.go.jp
“三年以下の懲役又は二百万円以下の罰金に処する。”
Link checked 18 August 2026
- Official sourceMinistry of Internal Affairs and CommunicationsExternal transmission rules — telling users when their information is sent to third parties
soumu.go.jp
Link checked 18 August 2026
What's changing next
The big one has already passed. On 17 July 2026 Japan published a large amendment to its privacy law. It brings in the country's first money penalty for privacy breaches. It sets 16 as the age below which a guardian must be involved. It adds rules for face and other biometric data. And it raises the criminal penalties. It is not in force yet. The government has up to two years to switch it on by order, and no date has been announced. The other thing to watch is the new cyber defence law, which is being switched on in stages through 2027.
Dates and switches, checked 18 August 2026. Already passed, not yet in force. The Act partially amending the Act on the Protection of Personal Information and related acts was published on 17 July 2026. It starts on a date to be fixed by cabinet order within two years of publication, so at the latest 17 July 2028. Here is what it contains. A surcharge paid to the state for serious breaches of three bans: improper use, improper acquisition, and unlawfully giving data to a third party. That surcharge targets cases involving 1,000 or more people, and is worked out from the money gained. A legal guardian must be involved for anyone under 16. If you handle facial-feature or similar biometric data, you must publish that fact, and you cannot rely on opt-out. You will not need consent where data is used only to produce statistics. That change is meant to unblock artificial intelligence training. Breach reporting gets simpler, so low-risk cases need not be reported to individuals. Emergency order powers get wider. And criminal penalties get heavier. The database-misuse offence rises from one year to two, and from 500,000 yen to 1 million yen. There is also a new offence of obtaining personal information by deception. Being switched on in stages. The Act on the Prevention of Damage from Unauthorised Acts against Important Computers, Act No. 42 of 2025, is Japan's 'active cyber defence' law. Its basic policy was settled in December 2025. The public-private reporting machinery has been coming into operation through 2026, and the rest is phased to 2027. Powers the government already holds, which could change the answer with no consultation. The Commission may add or remove countries from the equivalence list by its own notice. So the European Union and United Kingdom designations can be revoked. The Digital Agency rewrites the Government Cloud specification at each purchasing round, and could widen or close the new overseas artificial intelligence inference exception. The responsible ministers may add categories of critical equipment, and more operators, to the economic security screening system. And the communications ministry may designate more telecoms providers into the specified user information rules.
Sources
- Official sourcePersonal Information Protection CommissionPromulgation of the Act partially amending the Act on the Protection of Personal Information, 17 July 2026
ppc.go.jp
“改正法は、一部を除き、公布日から起算して2年以内で政令で定める日から施行されます。”
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionExplanation of the Act partially amending the Act on the Protection of Personal Information, July 2026
ppc.go.jp
Link checked 18 August 2026
- Official sourceCabinet OfficeOutline of the basic policy under the Cyber Response Capability Enhancement Act, December 2025
cao.go.jp
Link checked 18 August 2026
What to do: Diarise 17 July 2028 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms data rules
Official name: 電気通信事業法 · Telecommunications Business Act, Act No. 86 of 1984; external transmission rules and specified user information rules added by the 2022 amendment · Act of parliament
There is no rule about where data is stored. But this carries the sharpest criminal risk in Japan. Leaking a communication can put you in prison. The Act reaches services provided from abroad to people in Japan. It requires a representative in Japan. And since 16 June 2023 it makes ordinary websites and apps disclose what user information they send to third parties.
Enforced by Ministry of Internal Affairs and Communications
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Appoint a representativeA foreign provider must name a representative or agent in Japan to receive official notices.
- Register or notifyRegistration or notification with the communications ministry, depending on the service.
- Tell people what you do — from 16 June 2023External transmission rules: tell users what information about them is sent to a third party, to whom and why, before it is sent.
- Secure the dataDesignated providers of large-scale services must adopt an internal handling code for specified user information, appoint a chief administrator and report annually.
- Report breaches to the regulatorLeakage of specified user information affecting more than 1,000 users is reportable to the ministry.
What it costs if you get it wrong
- Criminal liability: 2年以下の懲役又は100万円以下の罰金 — about $7 thousandViolating the secrecy of a communication handled by a telecommunications carrier
- Criminal liability: 3年以下の懲役又は200万円以下の罰金 — about $13 thousandThe same act by a person engaged in the telecommunications business
- Order to stopBusiness improvement order where the secrecy of communications is impaired
Sources
- Official sourceMinistry of Internal Affairs and CommunicationsHow the Telecommunications Business Act applies where a foreign entity carries on a telecommunications business, 12 February 2021
soumu.go.jp
Link checked 18 August 2026
- Official sourceMinistry of Internal Affairs and CommunicationsRules on the proper handling of specified user information
soumu.go.jp
Link checked 18 August 2026
- Official sourceMinistry of Internal Affairs and CommunicationsGuideline on business improvement orders where secrecy of communications is impaired — Article 179 penalties
soumu.go.jp
“二年以下の懲役又は百万円以下の罰金に処する。”
Link checked 18 August 2026
Health data rules
Official name: 医療情報システムの安全管理に関するガイドライン 第7.0版 / 医療情報を取り扱う情報システム・サービスの提供事業者における安全管理ガイドライン 第2.0版 · Health ministry guideline version 7.0, June 2026; economy and communications ministries' supplier guideline version 2.0, August 2020 as revised March 2025 · Regulator guideline
Japan's medical data rules are guidance, not law. We found no requirement in the current versions that medical information be stored inside Japan. What they do require is that the hospital stays responsible. The split of duties with the supplier must be written down. And generative artificial intelligence services may only receive data where the contract stops the input being kept for training.
Enforced by Ministry of Health, Labour and Welfare
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataThe hospital or clinic stays accountable for medical information wherever it is stored, including at a cloud supplier.
- Written vendor contractResponsibility split with the supplier must be documented. Version 7.0 adds a dedicated part for maintenance contractors.
- Keep data for a minimum period — 5 yearsMedical records: five years under the Medical Practitioners Act.
Sources
- Official sourceMinistry of Health, Labour and WelfareGuidelines for the Safety Management of Medical Information Systems, version 7.0, June 2026
mhlw.go.jp
Link checked 18 August 2026
- Official sourceMinistry of Health, Labour and WelfareQuestions and answers on version 6.0 of the guidelines, May 2025 — generative AI and overseas servers
mhlw.go.jp
Link checked 18 August 2026
- Official sourceLink may be brokenMinistry of Economy, Trade and IndustrySafety management guideline for providers of information systems and services handling medical information, version 2.0, revised March 2025
meti.go.jp
Link checked 18 August 2026
Cloud and outsourcing rules (Finance)
Official name: 主要行等向けの総合的な監督指針 / 金融分野におけるサイバーセキュリティに関するガイドライン · Comprehensive Supervisory Guidelines for Major Banks; Guidelines on Cybersecurity in the Financial Sector, 4 October 2024 · Regulator guideline
The surprise here is an absence. Japan has no rule saying banking, payments, insurance or securities data must stay in the country. The Financial Services Agency regulates by risk. Outsourcing overseas is expressly covered. But what the Agency demands is oversight, traceability and audit rights, not a Japanese data centre.
Enforced by Financial Services Agency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contractThe outsourcing contract must set out the split of duties, audit rights, sub-contracting procedure and service levels.
- Secure the dataThe firm must be able to monitor and trace how customer data is handled at the outsourcer, wherever it sits.
- Independent audit
What it costs if you get it wrong
- Order to stopBusiness improvement order under the Banking Act or the Financial Instruments and Exchange Act
Sources
- Official sourceFinancial Services AgencyComprehensive Supervisory Guidelines for Major Banks — evaluation points, outsourcing
fsa.go.jp
“外部委託先における顧客データの運用状況を、委託元が監視、追跡できる態勢となっているか。”
Link checked 18 August 2026
- Official sourceFinancial Services AgencyGuidelines on Cybersecurity in the Financial Sector, 4 October 2024
fsa.go.jp
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: 個人情報の保護に関する法律 · Act on the Protection of Personal Information, Act No. 57 of 2003 · Act of parliament
Japan's general privacy law. Data may go abroad. Only the European Union and the United Kingdom take it without extra work. Anywhere else, the recipient must meet Japanese standards, or the person must consent after being told the destination country. The regulator cannot fine you. The punishments are criminal, and the company ceiling for database misuse is 100 million yen (about 650,000 United States dollars).
Enforced by Personal Information Protection Commission
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Explicit consent, To save someone’s life, Important public interest
What you have to do
- Tell people what you doPurpose of use must be stated or published.
- Get consentYou need consent for sensitive information, for giving data to a third party, and for use beyond the purpose you stated. You do not need consent as a general basis for everything you do with data.
- Put a transfer safeguard in placeArticle 28. Three routes: an approved country, a recipient that meets the standards, or consent given after you name the destination country.
- Secure the dataIncludes 'understanding the external environment'. You must identify the law of any country where the data is handled.
- Report breaches to the regulator — within 120 hoursFirst report promptly. The regulator reads that as 3 to 5 days. Full report within 30 days, or 60 days where the breach may have been deliberate.
- Tell affected people
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people objectIn set circumstances, a person can demand that you stop using their data or giving it to others.
- Written vendor contractYou must supervise any supplier that handles data for you, as far as is necessary and appropriate.
- Delete data after a periodA best-efforts duty only. Erase without delay once you no longer need the data.
What it costs if you get it wrong
- Criminal liability: 1年以下の拘禁刑又は100万円以下の罰金 — about $7 thousandIndividual ignoring an order of the Personal Information Protection Commission
- Criminal liability: 1億円以下の罰金 — about $650 thousandCorporate liability for improper provision or theft of a personal information database by an officer or employee
- Criminal liability: 50万円以下の罰金 — about $3 thousandFailing to respond to a demand for a report
- Order to stopCommission order, including an emergency order to stop providing personal information
Sources
- Official sourcee-Gov, Digital Agency個人情報の保護に関する法律 (Act No. 57 of 2003), consolidated text
laws.e-gov.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionLaws, guidelines and related documents
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionGuidelines — provision to a third party in a foreign country
ppc.go.jp
Link checked 18 August 2026
Children's data rules
Official name: 個人情報の保護に関する法律等の一部を改正する法律 · Act partially amending the Act on the Protection of Personal Information and related acts, promulgated 17 July 2026 · Act of parliament
Passed and published on 17 July 2026, but not yet in force. It brings Japan its first money penalty for privacy breaches. It sets the child threshold at 16. It regulates facial and other biometric data. And it lets data be used without consent where the only output is statistics. The start date will be fixed by cabinet order within two years and has not been announced.
Enforced by Personal Information Protection Commission
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent
What you have to do
- Get a parent's consent for children — applies at: under 16Involving a guardian becomes a legal duty. You must also put the child's best interests first. Not yet in force.
- Tell people what you doIf you handle facial-feature or similar biometric data, you must publish your name, address and representative, the fact that you handle such data, and why.
- Tell affected peopleEased where the risk to the person's rights and interests is low.
What it costs if you get it wrong
- Fixed maximum fine: 違反行為によって得られた財産的利益等に相当する額Surcharge for serious breaches of the bans on improper use, improper acquisition and unlawful third-party provision, aimed at cases affecting 1,000 or more people. Amount is set by reference to the financial benefit obtained, not a fixed ceiling.
- Criminal liability: 2年以下の拘禁刑又は100万円以下の罰金 — about $7 thousandImproper provision of a personal information database, raised from one year and 500,000 yen, and extended to acts done with intent to cause harm
- Criminal liability: 1年以下の拘禁刑又は50万円以下の罰金 — about $3 thousandNew offence of obtaining personal information by deception
Sources
- Official sourcePersonal Information Protection CommissionThe 2026 amendment to the Act on the Protection of Personal Information
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionExplanation of the Act partially amending the Act on the Protection of Personal Information, July 2026
ppc.go.jp
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionCabinet decision on the bill, 7 April 2026
ppc.go.jp
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: 経済施策を一体的に講ずることによる安全保障の確保の推進に関する法律(経済安全保障推進法) · Economic Security Promotion Act, Act No. 43 of 2022 — critical infrastructure provisions · Act of parliament
Japan's quiet supply-chain screen. Operators in sixteen critical sectors must tell their minister before installing important systems, and then wait. Those sectors include finance, credit cards, medical care, telecoms, energy and transport. The review looks at who owns the supplier, where the kit is made, and whether a foreign government could lean on it. It is not a rule about where data is stored, but it can stop a foreign cloud deployment.
Enforced by Cabinet Office, Economic Security
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyDesignated operators must notify the responsible minister before introducing critical equipment, including cloud and systems supply. Standard standstill of 30 days, extendable to four months.
- Do not hand data to foreign authorities on demandThe review asks whether foreign law, or an order from outside, could force the supplier to break its contract with you.
- Written vendor contractNotification covers supplier ownership, shareholders holding 5 per cent or more of voting rights, place of manufacture, component suppliers and risk-management measures.
What it costs if you get it wrong
- Order to stopMinister's recommendation or order to change or halt the introduction of the equipment
Sources
- Official sourceCabinet OfficeOutline of the system for securing stable provision of specified critical infrastructure services, 17 June 2026
cao.go.jp
“30日間(延長・短縮あり)”
Link checked 18 August 2026
- Official sourceCabinet OfficeSystem for securing stable provision of critical infrastructure services
cao.go.jp
Link checked 18 August 2026
Breach reporting rules
Official name: 重要電子計算機に対する不正な行為による被害の防止に関する法律(サイバー対処能力強化法) · Act on the Prevention of Damage from Unauthorised Acts against Important Computers, Act No. 42 of 2025 · Act of parliament
Japan's active cyber defence law. It passed in May 2025 and is being switched on in stages. It adds a second incident-reporting duty for critical infrastructure operators, on top of the privacy one. It also gives the government new powers over communications information. Some parts are running. Others have not started yet.
Enforced by Cabinet Office, Cyber Security
How this country controls where data goes: Approval each time
What you have to do
- Report cyber incidentsDesignated critical infrastructure operators give a prompt first alert, then a detailed report within 30 days.
- Secure the data
Sources
- Official sourceCabinet SecretariatAct on the Prevention of Damage from Unauthorised Acts against Important Computers (Act No. 42 of 2025) — explanatory material
cas.go.jp
Link checked 18 August 2026
- Official sourceCabinet OfficeApproach to implementing the public-private provisions, December 2025
cao.go.jp
Link checked 18 August 2026
- Official sourceCabinet OfficeOutline of the basic policy under the Act, December 2025
cao.go.jp
Link checked 18 August 2026
Applies only if you signed a contract1 rule
Usually a government or enterprise contract that adds rules of its own.
Government data must stay in the country
Official name: デジタル庁におけるガバメントクラウド等の整備のためのクラウドサービスの提供 — 令和8年度募集 調達仕様書 · Government Cloud procurement specification, 2026 application round, published 26 December 2025 · Government policy document
The strictest rule in Japan, and it is a purchasing condition rather than a law. Anything running on the national Government Cloud is stored in Japanese data centres. Central government systems sit on it, and so do the standardised systems of every local authority. The 2026 round adds one deliberate exception: a separately walled overseas environment for running artificial intelligence models that are not available in Japan.
Enforced by Digital Agency
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryInformation assets are kept inside Japan, on domestic data centres spread across several Japanese regions for disaster resilience.
- Hold a security certificateThe provider must be registered on the Information system Security Management and Assessment Program (ISMAP) cloud service list before it can be procured.
- Prove the data stays under local control
What it costs if you get it wrong
- Loss of your licenceLoss of Government Cloud provider status or removal from the ISMAP list; commercially, exclusion from central and local government procurement
Sources
- Official sourceDigital AgencyGovernment Cloud procurement specification, 2026 application round
digital.go.jp
“ガバメントクラウドでは情報資産は日本国内に保管されることとしている”
Link checked 18 August 2026
- Official sourceISMAP Steering CommitteeOverview of the Information system Security Management and Assessment Program (ISMAP)
ismap.go.jp
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact promulgation date of the 2026 privacy amendment — 10 or 17 July 2026 — and its law number
We could not confirm the exact date or the law number. The Commission's press release page is dated 17 July 2026 and says the Act was published. The Commission's own explanatory document appears to give 10 July 2026, which is more likely the date the Diet passed it. We could not find the gazette entry carrying the law number. Plan around the earlier date.
When the 2026 privacy amendment actually commences, and whether any provisions commence earlier than the rest
There is no start date yet. The Act says a cabinet order fixes the start date within two years of publication. No cabinet order had appeared as at 18 August 2026. Until one does, the surcharge, the age-16 threshold and the biometric rules do not bind you.
Whether the health ministry's medical information guidelines contain any requirement that medical data be stored inside Japan
We found no clause requiring medical data to be stored in Japan. We checked version 7.0 of the overview part, the 2005 external storage notification, and the 2025 questions and answers. We could not check the economy ministry's supplier guideline. This is medium confidence. If you handle medical data, check before you rely on it.
Whether any Survey Act provision restricts taking survey results out of Japan
We found no rule stopping survey results leaving Japan. The Geospatial Information Authority's published procedures cover copying and using survey results, and say nothing about sending them abroad. We could not check the full text of the Survey Act itself. Treat this industry as unresearched rather than settled.
The precise commencement dates for each phase of the 2025 cyber defence Act
We could not confirm the start dates for each phase. The Cabinet Office planning papers give a roadmap rather than official dates, and the dates we found did not agree with each other. Ask the Cabinet Office if a specific phase matters to you.
The in-force date of the specified user information regime for designated telecoms providers
We could not confirm this start date. The ministry's own page gave a date that appears to relate to an older rule. The related external transmission rules are confirmed as in force from 16 June 2023.
Ten-year retention of company accounting books and five-year retention of medical records
Both are well established in the Companies Act and the Medical Practitioners Act. But we did not confirm them against a government page. The seven and ten year tax periods are confirmed from the National Tax Agency.
Whether the Personal Information Protection Commission has issued any further orders or recommendations between October 2025 and August 2026
We could not confirm the later figures. The full annual report for the 2025 financial year was published on 7 July 2026. We could only read the announcement page, not the report itself. The figures quoted here are for the first half of that year.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.