Our Expert in Japan
No results available
Last updated: August 5, 2026
Japan’s three‑year review of the personal data law, the Act on the Protection of Personal Information (APPI), has progressed from a routine statutory check‑up into a concrete path toward an amendment bill that could reshape how every organisation operating in the country handles sensitive personal information. The Personal Information Protection Commission (PPC), the independent regulator charged with administering the APPI, has released interim and draft reports that single out two categories for significantly stricter treatment: biometric data and children’s data. For compliance officers, in‑house counsel and technology vendors serving the Japanese market, the proposals signal new consent obligations, tighter cross‑border transfer safeguards and sector‑specific duties that will require operational changes well before any final enforcement date.
This article unpacks the current status of the review, explains what the draft proposals contain, and provides a practical compliance checklist businesses can act on immediately.
The APPI contains a built‑in mechanism for continuous improvement. A supplementary provision requires the government to review the state of the law roughly every three years and, where necessary, to take legislative measures to adapt the framework to technological and social change. The PPC, established under the APPI as Japan’s dedicated data protection authority, leads the review process, publishes discussion papers and interim reports, solicits public comment, and ultimately recommends whether an amendment bill should be submitted to the Diet (Japan’s parliament).
This is not the first time the cycle has produced major change. The 2015 amendments (enforced in 2017) created the PPC itself and introduced the concept of “anonymously processed information.” The 2020 amendments (enforced in April 2022) added individual rights such as the right to request deletion, tightened rules on cross‑border transfers, and introduced penalties for data‑handling business operators that violate orders. Each round has expanded the law’s scope and sharpened its teeth.
Under the statutory review framework outlined in the PPC’s “Every‑Three‑Year Review” documentation, the process follows a broadly predictable sequence: the PPC publishes a draft interim report, opens it for public comment, refines the proposals, and then delivers final recommendations to the Cabinet. The Cabinet then drafts a bill and submits it to the Diet. Based on previous cycles, passage through both houses typically takes one to two Diet sessions, with a transitional period before enforcement begins. Industry observers expect the current review cycle to yield a bill in 2026 or early 2027, with full enforcement following after a preparation window of approximately one to two years.
| Milestone | Indicative timing | Status |
|---|---|---|
| PPC interim report published | 2024 | Completed |
| Public comment period on draft proposals | 2024–2025 | Completed |
| Final PPC recommendations to Cabinet | 2025–2026 | In progress |
| Amendment bill submitted to Diet | 2026–2027 (expected) | Pending |
| Diet deliberation and enactment | 2027 (expected) | Pending |
| Enforcement after transitional period | 2028–2029 (expected) | Pending |
The PPC’s interim report and subsequent draft proposals cover a wide range of items, but the most significant changes cluster around a handful of themes. Practitioner analyses published by leading law firms confirm that the review has moved well beyond incremental tweaks and is contemplating structural additions to the APPI framework.
The key areas flagged in the draft proposals include the following:
Not all draft items carry the same level of detail. The biometric data and children’s data provisions are among the most developed, with specific language in discussion papers pointing toward new statutory definitions and consent requirements. By contrast, proposals around algorithmic transparency and AI‑related data processing remain at a more conceptual stage. For businesses, the practical implication is clear: biometric and children’s data compliance should be prioritised now, while other areas can be monitored as they mature through the legislative process.
Under the current APPI, biometric data is not singled out as a standalone category of sensitive personal information. Facial recognition templates, fingerprint data and iris scans are treated as personal data, subject to the same general obligations, purpose specification, security management measures, and limitations on third‑party provision, that apply to any other identifier. The draft proposals from Japan’s three‑year review of the personal data law would change this fundamentally.
The PPC’s review materials indicate that biometric data would be subject to explicit handling rules, including stricter collection limitations (purpose must be specific and narrowly defined), enhanced security requirements beyond the current “necessary and appropriate” standard, and, in certain contexts, a requirement for explicit, informed consent before collection. The likely practical effect will be that organisations can no longer rely on general privacy notices to cover biometric processing; instead, they will need granular, purpose‑specific consent flows.
Three real‑world scenarios illustrate the impact:
| Topic | Current APPI (summary) | Draft proposals / expected change |
|---|---|---|
| Treatment of biometric data | Not explicitly regulated as a separate category; treated as personal data requiring reasonable security measures. | Explicit handling rules for biometric data, stricter collection limits, enhanced security, potential parental consent where minors are involved. |
| Consent requirement | Consent or other legal bases under APPI for processing personal data; no biometric‑specific consent obligation. | Stronger consent and notice requirements; explicit informed consent for biometric collection in designated contexts; DPIA expected before deployment. |
| Cross‑border transfer | Subject to existing cross‑border rules (safeguards, contractual measures, or adequacy‑based transfer). | Potentially tighter transfer conditions and clearer requirements for international transfers of biometric profiles and templates. |
Early indications suggest the amendment will effectively mandate a set of technical and operational controls that many organisations do not yet have in place for biometric processing. Businesses should prepare by implementing the following measures:
The treatment of children’s data under the APPI amendment bill is one of the most closely watched aspects of Japan’s three‑year review of the personal data law. The PPC’s review materials and practitioner commentary indicate that the proposals would introduce a distinct consent framework for minors, bringing the APPI closer to the approach taken by the EU’s General Data Protection Regulation (GDPR) and other international frameworks.
Key elements discussed in the draft proposals and analysed by leading Japanese law firms include the following:
Organisations that provide digital services used by minors, including educational technology providers, gaming platforms, social media apps and children’s content services, should begin preparing now. Priority actions include designing age‑verification mechanisms that are reliable but proportionate, building parental consent workflows that can capture and record verifiable consent, reviewing data retention schedules for children’s accounts, and auditing any profiling or personalisation features that use children’s data. Industry observers expect that the PPC will issue supplementary guidelines detailing acceptable age‑verification methods once the amendment text is finalised.
The APPI already imposes conditions on cross‑border transfers of personal data. Under the current framework, a data‑handling business operator may transfer personal data to a third party in a foreign country only if one of three conditions is met: the individual has given consent after being informed about the transfer, the receiving country has a data protection system recognised as equivalent by the PPC, or the receiving party has established a system conforming to APPI standards (typically via contractual safeguards).
The draft proposals signal further tightening. Industry commentary suggests the amendment may introduce more prescriptive requirements for contractual safeguards, potentially moving toward a model resembling standard contractual clauses (SCCs), and may require data‑handling business operators to conduct and document assessments of the legal environment in the receiving country before transferring sensitive personal information, including biometric data and children’s data.
Multinational organisations that transfer personal data out of Japan should review and, where necessary, update their data processing agreements (DPAs) to reflect the anticipated changes. Specifically, DPAs should address the categories of sensitive personal information being transferred (including biometric and children’s data), the specific legal basis for the transfer, the security measures applied by the receiving party, and the mechanism for notifying the transferring party of any legal changes in the receiving country that could affect the level of protection. The likely practical effect will be that boilerplate DPA language will no longer be sufficient for transfers involving high‑sensitivity data categories.
The PPC has steadily expanded its enforcement activity over successive APPI amendment cycles. Under the current law, the PPC may issue guidance, recommendations and orders to data‑handling business operators. Failure to comply with a PPC order can result in criminal penalties, including fines. The 2020 amendments increased the maximum fine for corporations to ¥100 million for violations of PPC orders.
The draft proposals under the current review indicate that the PPC is seeking further tools, potentially including the power to impose administrative fines directly (without requiring a prior order and non‑compliance sequence) and expanded inspection authority. For biometric data and children’s data specifically, early indications suggest the PPC will treat breaches with particular seriousness, given the irreversible nature of biometric identifiers and the vulnerability of minors. Organisations should factor reputational risk into their compliance calculus: PPC enforcement actions are published and increasingly attract media coverage.
Businesses do not need to wait for final legislative text to begin preparing. The following compliance checklist APPI covers the steps that can, and should, be taken now based on the direction set by the PPC’s draft proposals.
Healthcare providers and medical device manufacturers that process biometric data (e.g., patient identification via facial recognition, wearable health monitors collecting biometric signals) should expect heightened scrutiny. The intersection of medical data, already a category of sensitive personal information under the APPI, and biometric data will likely require dual‑layer compliance measures and reinforced consent protocols.
Schools, universities and educational technology platforms collect large volumes of children’s data. Draft proposals suggest that educational institutions will need verifiable parental consent for data processing activities that go beyond core educational delivery, such as learning analytics, behavioural monitoring and third‑party platform integrations.
Employers using biometric access controls, attendance tracking or identity verification must prepare for explicit employee consent requirements that go beyond current practice. Multinational employers transferring employee biometric data to overseas HR systems will face the tightened cross‑border transfer rules discussed above.
AdTech companies that use facial recognition or behavioural profiling of minors are directly in scope. The likely practical effect of the proposed profiling restrictions will be to require opt‑in consent for any personalised advertising directed at children, with strict limits on the data that can be used for targeting.
The legislative timeline remains subject to change. The table below reflects the best current understanding based on PPC publications and practitioner commentary. Businesses should treat these dates as planning benchmarks and monitor PPC announcements for updates.
| Phase | Expected window | Action for businesses |
|---|---|---|
| PPC final recommendations delivered | Late 2025 – mid‑2026 | Review final recommendation text; begin detailed gap analysis |
| Amendment bill submitted to Diet | 2026–2027 | Finalise compliance project plans; allocate budget |
| Diet deliberation and enactment | 2027 (expected) | Confirm final text; update legal analysis |
| Transitional period | 1–2 years post‑enactment | Implement all technical and operational changes |
| Full enforcement | 2028–2029 (expected) | Achieve full compliance; commence ongoing monitoring |
Japan’s three‑year review of the personal data law is no longer a background regulatory exercise, it is actively shaping an amendment bill that will impose materially new obligations on organisations processing biometric data and children’s data. The central compliance question for every business operating in Japan is straightforward: can your current data collection, consent, security and cross‑border transfer practices withstand the stricter standards the PPC has signalled? For most organisations, the honest answer is “not yet. ” The time to begin closing that gap is now, while the transitional runway still exists. Inventory your data, run impact assessments, update your consent mechanisms and vendor contracts, and assign a team to track the bill’s progress through the Diet.
Proactive preparation will be far less costly than reactive remediation after enforcement begins.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Noboru Kitayama at Mori Hamada & Matsumoto, a member of the Global Law Experts network.
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message