[codicts-css-switcher id=”346″]

Global Law Experts Logo
japans threeyear review personal data law

Japan's Three‑year APPI Review Advances: Biometric and Children's Data Included in Amendment Bill

By Global Law Experts
– posted 2 hours ago

Japan’s three‑year review of the personal data law has reached a decisive stage, with the Personal Information Protection Commission (PPC) publishing an outline of system reform that places biometric information and children’s personal data squarely within the scope of a forthcoming amendment bill. The review, mandated by supplementary provisions of the Act on the Protection of Personal Information (APPI), represents the most consequential set of proposed changes since the 2020 overhaul that took effect in 2022. For businesses that collect facial‑recognition templates, fingerprint data, or information from users under sixteen, the proposals signal material new obligations around consent, processing safeguards, and governance.

This article explains what the amendment bill proposes, maps out the legislative timeline, and provides a phased compliance checklist that in‑house counsel, data protection officers, and product teams can act on immediately.

The reform package also addresses data reuse for artificial intelligence training, strengthens the PPC’s enforcement powers, and contemplates tighter cross‑border transfer rules, all topics that intersect with Japan’s broader AI and data protection policy direction. Below, each major proposal is examined alongside practical steps, comparison tables, and an FAQ designed to answer the questions legal teams are asking right now.

What Is the Every‑Three‑Year Review and Why Now?

The APPI contains a built‑in sunset mechanism that requires the government to review the statute’s operation roughly every three years and, where necessary, to propose legislative amendments. This “Every‑Three‑Year Review” obligation, set out in the supplementary provisions of the APPI, ensures the law keeps pace with technological change and evolving privacy expectations. The PPC oversees the review, publishes interim reports, solicits public comment, and ultimately transmits an outline of proposed reforms to the Cabinet for drafting into a bill.

The current cycle of Japan’s three‑year review of the personal data law began formally in 2024, following the previous round of amendments that entered into force in April 2022. Over the course of expert‑panel meetings, the PPC identified biometric data governance, protections for children, and the secondary use of data for AI as priority areas requiring statutory attention. The resulting Outline of the System Reform was published in stages, culminating in a consolidated set of proposals now progressing toward a formal amendment bill.

Milestone Date / Period Status
2020 APPI amendment enacted June 2020 Complete, entered into force April 2022
Current Every‑Three‑Year Review launched 2024 Complete, expert panels concluded
PPC interim report and public comment 2025 Complete
PPC Outline of System Reform published 2025–2026 Published
Amendment bill submitted to Diet 2026 (expected) In progress
Amended APPI enters into force 2027 (anticipated) Pending enactment

Key Proposals in the APPI Amendment Bill, Executive Summary

The PPC’s reform outline covers six interconnected pillars. Each carries direct compliance implications for businesses operating in or targeting Japan. The following summary draws on the PPC’s published materials, the IAPP’s reporting on the PPC interim summary, and practitioner analyses from leading Japanese law firms.

  • Higher‑risk classification for biometric data. Facial features, voiceprints, gait patterns, and biometric templates would be treated as requiring enhanced protections, including stricter consent requirements and purpose‑limitation controls (PPC Outline; Mori Hamada & Matsumoto newsletter).
  • Explicit protections for children’s personal data. The proposals introduce an age threshold, industry reports indicate under‑16, triggering guardian‑consent obligations, age‑verification duties, and marketing restrictions for services directed at or knowingly used by minors (Baker McKenzie; IAPP).
  • Data reuse rules for AI training and dataset assembly. Businesses seeking to repurpose personal data for AI model training would face new obligations regarding pseudonymisation, dataset provenance documentation, and de‑identification standards (Nishimura & Asahi; Baker McKenzie).
  • Strengthened PPC enforcement powers. The Commission would gain expanded authority to issue administrative orders, impose higher financial penalties, and shorten mandatory breach‑notification windows (PPC Outline; IAPP).
  • Tighter cross‑border data transfer mechanisms. Proposed amendments contemplate additional safeguards, potentially including contractual‑clause requirements, for transfers of personal data to jurisdictions not recognised as providing an adequate level of protection (PPC Outline; DLA Piper).
  • Governance and accountability obligations. Larger data handlers may face mandatory appointment of dedicated privacy officers and periodic data‑protection impact assessments (DPIAs) for high‑risk processing activities (IAPP; PPC).

Biometric Data Japan, What the Amendment Would Change

Under the current APPI, certain biometric identifiers such as facial‑recognition data and fingerprint codes already qualify as “personal identification codes” and therefore as personal information. The amendment bill, however, goes substantially further by creating a distinct higher‑risk processing category for biometric data, with dedicated obligations that do not apply to ordinary personal information.

According to the PPC’s reform outline and detailed analysis published by Mori Hamada & Matsumoto, the proposals define regulated biometric data broadly, encompassing not only raw captures (photographs, voice recordings) but also the mathematical templates and feature vectors derived from them. The practical effect, industry observers expect, will be that any organisation converting a face scan into a numerical embedding for authentication or analytics will need to comply with the new enhanced‑consent and safeguard regime, even if the raw image is immediately deleted.

The amendment is also expected to distinguish between biometric processing for security or authentication purposes (which would remain permissible under specified safeguards) and biometric processing for profiling, behavioural analysis, or commercial targeting (which would face the strictest constraints). As reported by Biometric Update, the PPC has signalled that continuous surveillance‑style facial recognition in public spaces would require a particularly robust legal basis and transparency measures.

Biometric Data: Proposed Treatment and Practical Actions

Type of Biometric Proposed Treatment Practical Action for Businesses
Facial‑feature templates (embeddings) Higher‑risk classification; explicit consent required; purpose limitation to stated use case; retention caps Audit all facial‑recognition deployments; implement granular consent flow; set automatic deletion schedules
Fingerprint and palm‑vein data Enhanced safeguards; encryption‑at‑rest and in‑transit mandated; access‑control logging Upgrade encryption protocols; deploy access‑audit trails; restrict processing to named personnel
Voiceprints and gait patterns Included in biometric definition; same consent and safeguard obligations as facial data Identify all voice/gait collection points (call centres, IoT); retrofit consent mechanisms
Behavioural biometrics (keystroke dynamics, typing cadence) Scope still under discussion; early indications suggest inclusion where used for unique identification Map behavioural‑biometric data flows; prepare contingency consent and disclosure language

Organisations that process biometric data in Japan should begin gap analyses now, even before the bill’s final text is settled. Early indications suggest that the new regime will require documented necessity assessments, similar in concept, though not identical in form, to the GDPR’s data‑protection impact assessment.

Children’s Data Under the APPI, Age Thresholds and Consent

The current APPI does not contain a standalone provision addressing children’s personal data. The amendment bill is expected to change that materially. Based on practitioner reporting from Baker McKenzie and the IAPP, the PPC’s proposals introduce an explicit age threshold, reported as under‑16, below which additional protections apply. These protections mirror, in structural terms, the approach taken in the EU’s GDPR, but with Japan‑specific implementation details.

Under the proposals, any business that provides an online service directed at children, or that has actual knowledge that a user is under the specified age, would be required to obtain verifiable guardian consent before collecting, using, or sharing that child’s personal data. The scope of “verifiable” consent is expected to be clarified in implementing guidelines, but early indications suggest it will go beyond a simple tick‑box, potentially requiring identity verification of the consenting guardian.

Marketing activities directed at children would also face restrictions. Profiling minors for targeted advertising, or using children’s behavioural data to personalise content in ways that could be harmful, is expected to be either prohibited outright or subject to strict conditions. These proposals carry significant implications for gaming platforms, social‑media services, ed‑tech providers, and any app with a meaningful under‑16 user base, including services related to matters such as family and child custody in Japan that handle sensitive data involving minors.

Practical Checklist for Services Used by Minors

  • Age‑gate implementation. Deploy an age‑verification mechanism at registration or first data collection; document its design rationale.
  • Guardian‑consent workflow. Build a verifiable parental‑consent process, email‑plus‑confirmation, ID upload, or equivalent, and test it for user experience.
  • Data‑minimisation review. Audit all data fields collected from under‑16 users and eliminate any that are not strictly necessary for the service.
  • Marketing restrictions. Disable behavioural‑advertising targeting for users identified as children; switch to contextual advertising only.
  • Retention limits. Set shorter retention periods for children’s data and automate deletion once the purpose has been fulfilled.

Data Reuse and AI, How the Amendment Addresses AI Training and Datasets

One of the most commercially sensitive elements of Japan’s three‑year review of the personal data law concerns the secondary use of personal data for AI model training. Japan has historically maintained a comparatively permissive stance toward data use for research and statistical purposes, but the PPC’s proposals signal a recalibration in response to the rapid proliferation of generative AI.

The amendment is expected to require organisations that repurpose personal data for AI training to apply robust pseudonymisation or de‑identification before ingestion into training datasets. Where full anonymisation is not feasible, dataset assemblers would need to document provenance, recording the original lawful basis for collection, the transformation steps applied, and any residual re‑identification risk. This documentation obligation effectively creates an auditable chain of custody for training data.

Practitioners at Nishimura & Asahi and Baker McKenzie have noted that the proposals stop short of a blanket prohibition on AI training with personal data. Instead, the likely practical effect will be a tiered framework: fully anonymised data remains unrestricted; pseudonymised data may be used under documented safeguards; and identifiable personal data used for AI training would require explicit consent or a compelling public‑interest justification. Businesses developing or deploying AI systems in Japan should review their data‑supply pipelines against these emerging requirements and consider commissioning technical audits of pseudonymisation effectiveness. More detailed guidance on Japan’s evolving AI and data protection framework is available separately.

Reporting, Governance and Penalties, Enforcement Changes

The PPC’s reform outline proposes a meaningful expansion of the Commission’s enforcement toolkit. Under the current APPI, the PPC can issue recommendations and orders, but financial penalties are modest compared with regimes such as the GDPR. The amendment bill is expected to increase maximum penalty amounts and introduce the possibility of revenue‑based fines for serious or repeated violations.

Breach‑notification obligations are also set to tighten. The current rule requires notification to the PPC and affected individuals “promptly” following discovery of a qualifying breach. The proposals would introduce a defined reporting window, early indications suggest a mandatory initial notification within a set number of days of discovery, with a fuller report to follow. Businesses that have not already implemented a structured breach‑reporting procedure for Japan should treat this as an immediate priority.

On governance, the proposals contemplate mandatory appointment of a privacy officer (or equivalent role) for businesses that handle personal data above a specified volume threshold or that engage in high‑risk processing categories, including biometric data and children’s data. Periodic DPIAs would become a formal requirement for these organisations, rather than a best‑practice recommendation. The likely practical effect will be additional headcount or advisory costs for mid‑sized and larger companies.

Timeline and Legislative Process, What to Watch Next

The APPI amendment bill is advancing through Japan’s established legislative pipeline. The table below summarises the key milestones based on PPC publications and reporting from the IAPP and practitioner firms.

Stage Expected Timing What to Monitor
PPC Outline of System Reform Published (2025–2026) Final consolidated text on PPC website
Cabinet drafting of amendment bill 2026 Bill text publication on official government channels
Diet deliberation and passage 2026 (expected) Committee hearings; any last‑minute scope changes
PPC implementing guidelines and rules 2026–2027 (expected) Detailed guidance on biometric safeguards, children’s consent, AI reuse
Amended APPI enters into force 2027 (anticipated) Official gazette publication of effective date

Industry observers expect that the PPC will release draft implementing guidelines for public comment before the effective date, providing a further window for businesses to refine their compliance programmes. Monitoring the PPC’s English‑language pages at ppc.go.jp/en remains the most reliable way to track developments.

Practical Compliance Checklist for Japan’s Three‑Year Review of the Personal Data Law

The following phased checklist is designed for in‑house counsel, data protection officers, and compliance leads preparing for the expected amendments. It is organised into three time horizons to allow teams to prioritise resources effectively.

Immediate Actions (0–3 Months)

  • Data mapping. Identify all processing activities involving biometric data and children’s personal data. Document data sources, purposes, retention periods, and third‑party sharing.
  • Gap analysis. Compare current practices against the PPC’s published reform outline. Flag areas where existing controls fall short of proposed requirements.
  • Breach‑response review. Update your incident‑response playbook to accommodate a shorter mandatory notification window. Assign clear escalation roles and rehearse with a tabletop exercise. Refer to the step‑by‑step guide on reporting a data breach in Japan.
  • Board briefing. Prepare a summary for senior management and the board on the amendment bill’s expected impact, resource implications, and timeline.

Short‑Term Actions (3–9 Months)

  • Consent‑flow redesign. For biometric processing, build explicit‑consent mechanisms that meet the higher threshold. For children’s data, design and test guardian‑consent workflows and age‑verification tools.
  • DPIA programme. Establish a formal DPIA process for high‑risk processing activities, starting with biometric and children’s use cases.
  • AI data‑supply audit. Review all personal data used in AI training pipelines. Document pseudonymisation steps, provenance records, and residual‑risk assessments.
  • Vendor and processor contracts. Identify contracts with third‑party processors that handle biometric or children’s data. Prepare amendment clauses aligned with the expected new obligations.
  • Privacy‑officer appointment. If your organisation meets the anticipated threshold, designate or recruit a privacy officer and define reporting lines.

Medium‑Term Actions (9–18 Months)

  • Cross‑border transfer review. Audit all international data transfers and confirm that contractual protections or adequacy findings remain valid under the amended rules. Prepare fallback mechanisms (updated standard contractual clauses or binding corporate rules).
  • Technical safeguards upgrade. Implement or upgrade encryption‑at‑rest and in‑transit for biometric stores. Deploy access‑control logging and automated retention‑expiry for children’s data.
  • Training and awareness. Roll out mandatory training for all employees who handle biometric or children’s data, covering the new obligations, consent procedures, and breach‑reporting expectations.
  • Policy and notice updates. Revise external privacy notices and internal data‑handling policies to reflect the new categories, rights, and safeguards once the final text is enacted.
  • Ongoing monitoring. Subscribe to PPC guideline updates and industry‑association bulletins. Schedule quarterly compliance‑status reviews through the effective date.

Companies operating across sectors such as fintech, where data protection intersects with licensing requirements under Japan’s Payment Services Act, and those with multinational workforces who need to navigate foreign‑worker hiring and ID verification rules should coordinate these compliance streams to avoid duplication and gaps.

Comparative Snapshot, Proposed APPI Amendment vs GDPR on Biometric and Children’s Data

For multinational organisations subject to both the APPI and the EU’s General Data Protection Regulation, the table below provides a concise side‑by‑side comparison. Industry observers expect that convergence with GDPR principles, particularly around biometric classification, will simplify compliance for companies already operating under European standards, although important differences remain.

Topic Proposed APPI Amendment GDPR
Biometric data classification Biometric data (facial features, templates, voiceprints) flagged as higher‑risk; stricter consent and purpose‑limitation rules; dedicated safeguard requirements Special category data under Article 9; processing generally prohibited unless explicit consent or another specific legal basis; DPIA required for large‑scale processing
Children’s data Proposed explicit protection threshold (reported as under‑16); guardian‑consent and age‑verification duties; marketing restrictions Article 8 sets default at 16 (member states may lower to 13); parental consent required for information‑society services; child‑friendly privacy notices recommended
AI training and data reuse Expected tiered framework: anonymised data unrestricted; pseudonymised data permitted with documented safeguards; identifiable data requires explicit consent or public‑interest basis No blanket prohibition; lawful‑basis requirement applies; DPIA for high‑risk processing; emerging AI‑specific guidance at national and EU level
Breach notification Shortened mandatory reporting window (specific timeframe to be confirmed in guidelines); notification to PPC and affected individuals 72‑hour notification to supervisory authority under Article 33; notification to data subjects “without undue delay” where high risk
Penalties Increased maximums expected; possible introduction of revenue‑based fines Up to €20 million or 4 % of global annual turnover, whichever is higher

What to Update in Contracts and Policies

Once the amendment bill’s final text is published, organisations should prioritise the following contract and policy updates:

  • Data processing agreements (DPAs). Add or amend annexes that specifically address biometric data handling, covering permitted purposes, technical safeguards, sub‑processor restrictions, and deletion obligations.
  • Consent language. Revise user‑facing consent forms to include clear, specific disclosures about biometric data collection and processing. For children’s data, ensure guardian‑consent language complies with the age‑verification requirements once PPC guidelines are finalised.
  • Cross‑border transfer clauses. Update standard contractual clauses and intra‑group transfer agreements to incorporate any new safeguard requirements introduced by the amendment.
  • Privacy policies and notices. Refresh external privacy notices to reflect the new data categories, the enhanced rights of data subjects (particularly children and guardians), and updated breach‑notification procedures.
  • Employee and vendor training materials. Ensure that onboarding documents, codes of conduct, and vendor due‑diligence questionnaires reference the amended APPI obligations.

Conclusion and Next Steps

Japan’s three‑year review of the personal data law is no longer a policy discussion, it is a legislative process with an amendment bill moving toward enactment. The proposals affecting biometric data classification, children’s data protections, AI training oversight, and PPC enforcement authority represent the most significant evolution of Japan data protection law since the 2020 reforms. Businesses operating in Japan, or processing the personal data of individuals in Japan, should treat the compliance checklist above as a working roadmap: begin data mapping and gap analysis now, redesign consent and governance structures in the coming months, and stand ready to implement technical and contractual updates as the final text and implementing guidelines emerge.

The PPC’s English‑language portal and the full text of the APPI remain the authoritative reference points for tracking developments as the amendment bill advances through the Diet.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Noboru Kitayama at Mori Hamada & Matsumoto, a member of the Global Law Experts network.

Sources

  1. Personal Information Protection Commission (PPC), English pages
  2. PPC, Outline of the System Reform (Every‑Three‑Year Review)
  3. Act on the Protection of Personal Information, English translation
  4. IAPP, Japan’s DPA publishes interim summary of amendments
  5. Baker McKenzie, Japan APPI reform key changes
  6. Mori Hamada & Matsumoto, Newsletter on proposed APPI amendments
  7. Biometric Update, Japan introduces new rules on biometric data
  8. Nishimura & Asahi, Data protection newsletter
  9. DLA Piper, Data Protection Laws of the World (Japan)

FAQs

What is being changed by Japan's three‑year review of the APPI?
The PPC is advancing amendments that would tighten rules for biometric data, introduce explicit protections for children’s personal data, clarify obligations around AI data reuse, strengthen enforcement powers, and refine cross‑border transfer safeguards. These proposals are documented in the PPC’s Outline of System Reform and corroborated by the IAPP’s reporting on the interim summary.
No. The proposals do not impose a blanket ban on biometric data processing. Instead, biometric data, including facial‑feature templates, voiceprints, and fingerprint codes, would be classified as higher‑risk, triggering stricter consent requirements, purpose‑limitation controls, and enhanced technical safeguards. Businesses must assess the necessity of each biometric use case and implement the required protections.
The draft proposals introduce an explicit age threshold, reported as under‑16, below which verifiable guardian consent is required before a child’s personal data can be collected or processed. Services directed at children would also face restrictions on behavioural profiling and targeted advertising. Age‑verification mechanisms and data‑minimisation obligations would apply.
The amendment bill is expected to be submitted to the Diet in 2026. Based on PPC publications and reporting from practitioner firms, an anticipated effective date in 2027 is widely expected, though the precise date will be confirmed upon enactment. Businesses should monitor the PPC’s official English‑language pages for updates.
Start with a comprehensive data map covering all biometric and children’s data processing activities. Conduct a gap analysis against the PPC’s published reform outline. Update breach‑response procedures, redesign consent flows, implement age‑verification tools, and begin DPIAs for high‑risk processing. Strengthen vendor contracts and prepare cross‑border transfer mechanisms for potential new requirements.
The proposals contemplate additional safeguards for international transfers of personal data, potentially including enhanced contractual‑clause requirements for transfers to jurisdictions without an adequacy finding. Businesses that transfer personal data out of Japan should review existing transfer mechanisms and prepare contingency measures, such as updated standard contractual clauses, to ensure continued compliance once the new rules take effect.
By Mandy Simpson

posted 49 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Japan's Three‑year APPI Review Advances: Biometric and Children's Data Included in Amendment Bill

Send welcome message

Custom Message