[codicts-css-switcher id=”346″]

Global Law Experts Logo
japans threeyear review personal data law

Japan's Three‑year Review of the Personal Data Law Moves Toward an Amendment Bill, Biometric and Children's Data in Scope

By Global Law Experts
– posted 1 hour ago

Last updated: August 5, 2026

Japan’s three‑year review of the personal data law, the Act on the Protection of Personal Information (APPI), has progressed from a routine statutory check‑up into a concrete path toward an amendment bill that could reshape how every organisation operating in the country handles sensitive personal information. The Personal Information Protection Commission (PPC), the independent regulator charged with administering the APPI, has released interim and draft reports that single out two categories for significantly stricter treatment: biometric data and children’s data. For compliance officers, in‑house counsel and technology vendors serving the Japanese market, the proposals signal new consent obligations, tighter cross‑border transfer safeguards and sector‑specific duties that will require operational changes well before any final enforcement date.

This article unpacks the current status of the review, explains what the draft proposals contain, and provides a practical compliance checklist businesses can act on immediately.

Background, The APPI Three‑Year Review and How Amendments Proceed

The APPI contains a built‑in mechanism for continuous improvement. A supplementary provision requires the government to review the state of the law roughly every three years and, where necessary, to take legislative measures to adapt the framework to technological and social change. The PPC, established under the APPI as Japan’s dedicated data protection authority, leads the review process, publishes discussion papers and interim reports, solicits public comment, and ultimately recommends whether an amendment bill should be submitted to the Diet (Japan’s parliament).

This is not the first time the cycle has produced major change. The 2015 amendments (enforced in 2017) created the PPC itself and introduced the concept of “anonymously processed information.” The 2020 amendments (enforced in April 2022) added individual rights such as the right to request deletion, tightened rules on cross‑border transfers, and introduced penalties for data‑handling business operators that violate orders. Each round has expanded the law’s scope and sharpened its teeth.

Legislative Process and Likely Timeline

Under the statutory review framework outlined in the PPC’s “Every‑Three‑Year Review” documentation, the process follows a broadly predictable sequence: the PPC publishes a draft interim report, opens it for public comment, refines the proposals, and then delivers final recommendations to the Cabinet. The Cabinet then drafts a bill and submits it to the Diet. Based on previous cycles, passage through both houses typically takes one to two Diet sessions, with a transitional period before enforcement begins. Industry observers expect the current review cycle to yield a bill in 2026 or early 2027, with full enforcement following after a preparation window of approximately one to two years.

Milestone Indicative timing Status
PPC interim report published 2024 Completed
Public comment period on draft proposals 2024–2025 Completed
Final PPC recommendations to Cabinet 2025–2026 In progress
Amendment bill submitted to Diet 2026–2027 (expected) Pending
Diet deliberation and enactment 2027 (expected) Pending
Enforcement after transitional period 2028–2029 (expected) Pending

What the Draft and Interim Reports Propose Under Japan’s Three‑Year Review of the Personal Data Law

The PPC’s interim report and subsequent draft proposals cover a wide range of items, but the most significant changes cluster around a handful of themes. Practitioner analyses published by leading law firms confirm that the review has moved well beyond incremental tweaks and is contemplating structural additions to the APPI framework.

The key areas flagged in the draft proposals include the following:

  • Biometric data categorisation. Proposals to create explicit rules for the collection, processing and security of biometric identifiers such as facial recognition templates, fingerprints and voiceprints, moving beyond the current approach of treating them as ordinary personal data subject only to general security management obligations.
  • Children’s data protections. Draft recommendations for enhanced consent mechanisms when processing data of minors, including discussion of a parental consent threshold and restrictions on profiling and behavioural targeting aimed at children.
  • Cross‑border data transfer tightening. Further refinement of the rules governing international transfers of personal data, including clearer standards for “equivalent protection” in the receiving country and more prescriptive requirements for contractual safeguards.
  • Strengthened enforcement powers. Discussion of expanded PPC authority to conduct inspections, issue binding orders and impose administrative penalties, particularly in cases involving sensitive personal information.
  • Data breach notification refinements. Proposals to clarify notification timelines and expand the categories of breaches that trigger mandatory reporting, including incidents involving biometric databases.

Where Proposals Are High‑Level Versus Specific

Not all draft items carry the same level of detail. The biometric data and children’s data provisions are among the most developed, with specific language in discussion papers pointing toward new statutory definitions and consent requirements. By contrast, proposals around algorithmic transparency and AI‑related data processing remain at a more conceptual stage. For businesses, the practical implication is clear: biometric and children’s data compliance should be prioritised now, while other areas can be monitored as they mature through the legislative process.

Biometric Data, Proposed Rules and Business Impact Under the APPI Amendment Bill

Under the current APPI, biometric data is not singled out as a standalone category of sensitive personal information. Facial recognition templates, fingerprint data and iris scans are treated as personal data, subject to the same general obligations, purpose specification, security management measures, and limitations on third‑party provision, that apply to any other identifier. The draft proposals from Japan’s three‑year review of the personal data law would change this fundamentally.

The PPC’s review materials indicate that biometric data would be subject to explicit handling rules, including stricter collection limitations (purpose must be specific and narrowly defined), enhanced security requirements beyond the current “necessary and appropriate” standard, and, in certain contexts, a requirement for explicit, informed consent before collection. The likely practical effect will be that organisations can no longer rely on general privacy notices to cover biometric processing; instead, they will need granular, purpose‑specific consent flows.

Three real‑world scenarios illustrate the impact:

  • HR and workplace access control. An employer using fingerprint scanners for office entry will need to obtain explicit consent from each employee, document the specific purpose, set a retention period, and implement enhanced encryption and access controls for the stored biometric templates.
  • Payment biometrics. A fintech company offering palm‑vein or facial‑recognition payment authentication will face stricter requirements around informing users how biometric data is processed, where it is stored, and whether it is transferred to third parties or overseas servers.
  • Device authentication. A software vendor embedding voice‑recognition login into its application will need to conduct a data protection impact assessment (DPIA) before launch and demonstrate that the biometric processing is proportionate to the security objective.
Topic Current APPI (summary) Draft proposals / expected change
Treatment of biometric data Not explicitly regulated as a separate category; treated as personal data requiring reasonable security measures. Explicit handling rules for biometric data, stricter collection limits, enhanced security, potential parental consent where minors are involved.
Consent requirement Consent or other legal bases under APPI for processing personal data; no biometric‑specific consent obligation. Stronger consent and notice requirements; explicit informed consent for biometric collection in designated contexts; DPIA expected before deployment.
Cross‑border transfer Subject to existing cross‑border rules (safeguards, contractual measures, or adequacy‑based transfer). Potentially tighter transfer conditions and clearer requirements for international transfers of biometric profiles and templates.

Technical and Operational Controls for Biometrics

Early indications suggest the amendment will effectively mandate a set of technical and operational controls that many organisations do not yet have in place for biometric processing. Businesses should prepare by implementing the following measures:

  • Data minimisation. Collect only the biometric data strictly necessary for the stated purpose. Avoid storing raw biometric images where a mathematical template is sufficient.
  • Pseudonymisation and encryption. Store biometric templates in pseudonymised form with robust encryption at rest and in transit. Separate the template from the identifier linking it to an individual.
  • Storage time limits. Define and enforce maximum retention periods. Delete biometric data promptly when the purpose has been fulfilled or consent is withdrawn.
  • Vendor contract obligations. Where biometric processing is outsourced, update contracts to include specific security standards, audit rights, breach notification obligations and restrictions on sub‑processing.
  • Data protection impact assessments. Conduct DPIAs before deploying any new biometric system, documenting the necessity, proportionality, risks to data subjects and mitigating controls.

Children’s Data, Proposed Protections and Consent Changes Under the APPI

The treatment of children’s data under the APPI amendment bill is one of the most closely watched aspects of Japan’s three‑year review of the personal data law. The PPC’s review materials and practitioner commentary indicate that the proposals would introduce a distinct consent framework for minors, bringing the APPI closer to the approach taken by the EU’s General Data Protection Regulation (GDPR) and other international frameworks.

Key elements discussed in the draft proposals and analysed by leading Japanese law firms include the following:

  • Parental consent threshold. Discussion of a requirement for verifiable parental consent before collecting or processing personal data of children below a specified age. Commentary from practitioner advisories has referenced a threshold of under 16, though the final age cut‑off remains subject to legislative deliberation.
  • Enhanced rights for minors. Proposals to give children (or their guardians) stronger rights to access, correct and delete personal data, with shorter response timeframes for data‑handling business operators.
  • Retention limitations. Stricter limits on how long children’s data may be retained, particularly for data collected through educational platforms, gaming services and social media.
  • Profiling and behavioural targeting restrictions. Discussion of restrictions on using children’s data for profiling, behavioural advertising or algorithmic recommendation systems, an area of growing regulatory concern worldwide.

Practical Steps for Services Aimed at Children

Organisations that provide digital services used by minors, including educational technology providers, gaming platforms, social media apps and children’s content services, should begin preparing now. Priority actions include designing age‑verification mechanisms that are reliable but proportionate, building parental consent workflows that can capture and record verifiable consent, reviewing data retention schedules for children’s accounts, and auditing any profiling or personalisation features that use children’s data. Industry observers expect that the PPC will issue supplementary guidelines detailing acceptable age‑verification methods once the amendment text is finalised.

Cross‑Border Transfers and International Data Flows

The APPI already imposes conditions on cross‑border transfers of personal data. Under the current framework, a data‑handling business operator may transfer personal data to a third party in a foreign country only if one of three conditions is met: the individual has given consent after being informed about the transfer, the receiving country has a data protection system recognised as equivalent by the PPC, or the receiving party has established a system conforming to APPI standards (typically via contractual safeguards).

The draft proposals signal further tightening. Industry commentary suggests the amendment may introduce more prescriptive requirements for contractual safeguards, potentially moving toward a model resembling standard contractual clauses (SCCs), and may require data‑handling business operators to conduct and document assessments of the legal environment in the receiving country before transferring sensitive personal information, including biometric data and children’s data.

For Multinational Controllers, What to Update in Data Processing Agreements

Multinational organisations that transfer personal data out of Japan should review and, where necessary, update their data processing agreements (DPAs) to reflect the anticipated changes. Specifically, DPAs should address the categories of sensitive personal information being transferred (including biometric and children’s data), the specific legal basis for the transfer, the security measures applied by the receiving party, and the mechanism for notifying the transferring party of any legal changes in the receiving country that could affect the level of protection. The likely practical effect will be that boilerplate DPA language will no longer be sufficient for transfers involving high‑sensitivity data categories.

Enforcement, Penalties and Regulatory Expectations

The PPC has steadily expanded its enforcement activity over successive APPI amendment cycles. Under the current law, the PPC may issue guidance, recommendations and orders to data‑handling business operators. Failure to comply with a PPC order can result in criminal penalties, including fines. The 2020 amendments increased the maximum fine for corporations to ¥100 million for violations of PPC orders.

The draft proposals under the current review indicate that the PPC is seeking further tools, potentially including the power to impose administrative fines directly (without requiring a prior order and non‑compliance sequence) and expanded inspection authority. For biometric data and children’s data specifically, early indications suggest the PPC will treat breaches with particular seriousness, given the irreversible nature of biometric identifiers and the vulnerability of minors. Organisations should factor reputational risk into their compliance calculus: PPC enforcement actions are published and increasingly attract media coverage.

Practical Compliance Checklist, Immediate Actions for the APPI Amendment Bill

Businesses do not need to wait for final legislative text to begin preparing. The following compliance checklist APPI covers the steps that can, and should, be taken now based on the direction set by the PPC’s draft proposals.

  • Inventory biometric data. Identify all biometric data currently collected, processed or stored across the organisation, including fingerprint, facial recognition, voiceprint and iris data.
  • Inventory children’s data. Map all personal data processing activities that involve individuals below the age of 18, with particular attention to those under 16.
  • Map data flows. Document where biometric and children’s data flows, internally, to vendors, and across borders, and identify the legal basis for each transfer.
  • Revise privacy notices. Update privacy policies and collection notices to include specific, granular disclosures about biometric data processing and children’s data handling.
  • Update consent flows. Design or redesign consent mechanisms to support explicit, informed consent for biometric data collection and verifiable parental consent for children’s data.
  • Implement parental consent mechanisms. For services accessed by minors, build age‑gate and parental verification workflows that can withstand regulatory scrutiny.
  • Conduct DPIAs. Perform data protection impact assessments for all existing and planned biometric processing activities and for services that process children’s data at scale.
  • Audit vendors and processors. Review contracts with all third‑party vendors that handle biometric or children’s data; ensure contracts include updated security, breach notification and sub‑processing provisions.
  • Review cross‑border transfer mechanisms. Assess whether current transfer safeguards (contractual clauses, adequacy determinations) will meet the stricter standards expected under the amendment.
  • Tighten retention policies. Set and enforce maximum retention periods for biometric templates and children’s data; implement automated deletion schedules.
  • Update incident response plans. Ensure breach response procedures specifically address biometric data breaches (which may require accelerated notification) and incidents involving children’s data.
  • Train staff. Deliver targeted training to employees who collect or process biometric and children’s data, covering the new obligations and heightened sensitivity.
  • Update internal policies and contracts. Revise internal data governance policies, employee handbooks and inter‑company data sharing agreements to reflect the proposed rules.
  • Establish a monitoring process. Assign responsibility for tracking PPC announcements, public comment periods and legislative developments so the organisation can respond promptly when the bill is tabled and when enforcement dates are confirmed.

Sector‑Specific Notes

Health Tech and Medical Devices

Healthcare providers and medical device manufacturers that process biometric data (e.g., patient identification via facial recognition, wearable health monitors collecting biometric signals) should expect heightened scrutiny. The intersection of medical data, already a category of sensitive personal information under the APPI, and biometric data will likely require dual‑layer compliance measures and reinforced consent protocols.

Education and EdTech

Schools, universities and educational technology platforms collect large volumes of children’s data. Draft proposals suggest that educational institutions will need verifiable parental consent for data processing activities that go beyond core educational delivery, such as learning analytics, behavioural monitoring and third‑party platform integrations.

HR and Employers

Employers using biometric access controls, attendance tracking or identity verification must prepare for explicit employee consent requirements that go beyond current practice. Multinational employers transferring employee biometric data to overseas HR systems will face the tightened cross‑border transfer rules discussed above.

Advertising Technology

AdTech companies that use facial recognition or behavioural profiling of minors are directly in scope. The likely practical effect of the proposed profiling restrictions will be to require opt‑in consent for any personalised advertising directed at children, with strict limits on the data that can be used for targeting.

Timeline and Next Steps for Businesses, Japan’s Three‑Year Review of the Personal Data Law

The legislative timeline remains subject to change. The table below reflects the best current understanding based on PPC publications and practitioner commentary. Businesses should treat these dates as planning benchmarks and monitor PPC announcements for updates.

Phase Expected window Action for businesses
PPC final recommendations delivered Late 2025 – mid‑2026 Review final recommendation text; begin detailed gap analysis
Amendment bill submitted to Diet 2026–2027 Finalise compliance project plans; allocate budget
Diet deliberation and enactment 2027 (expected) Confirm final text; update legal analysis
Transitional period 1–2 years post‑enactment Implement all technical and operational changes
Full enforcement 2028–2029 (expected) Achieve full compliance; commence ongoing monitoring

Conclusion

Japan’s three‑year review of the personal data law is no longer a background regulatory exercise, it is actively shaping an amendment bill that will impose materially new obligations on organisations processing biometric data and children’s data. The central compliance question for every business operating in Japan is straightforward: can your current data collection, consent, security and cross‑border transfer practices withstand the stricter standards the PPC has signalled? For most organisations, the honest answer is “not yet. ” The time to begin closing that gap is now, while the transitional runway still exists. Inventory your data, run impact assessments, update your consent mechanisms and vendor contracts, and assign a team to track the bill’s progress through the Diet.

Proactive preparation will be far less costly than reactive remediation after enforcement begins.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Noboru Kitayama at Mori Hamada & Matsumoto, a member of the Global Law Experts network.

Sources

  1. Personal Information Protection Commission (PPC), English Portal
  2. PPC, “The Every‑Three‑Year Review” (Outline of the System Reform)
  3. Act on the Protection of Personal Information (APPI), Japan Law Translation
  4. Lexology, Draft Interim Report Coverage
  5. Mori Hamada, Insight on Proposed Children’s Data Protections
  6. GlobalComplianceNews, PPC Interim Report Coverage
  7. DLA Piper, Data Protection Laws of the World (Japan)
  8. Mainichi English, APPI Amendments Coverage (July 14, 2026)
  9. WTO Briefing, Japan’s Personal Information Protection

FAQs

What is the APPI three‑year review and why does it matter?
The APPI requires periodic review of the law by the PPC. The current review has produced draft proposals that could become amendments, affecting how businesses process sensitive categories such as biometric and children’s data.
Drafts and interim reports recommend clearer, stricter handling for biometric data. Businesses should expect new obligations on collection, retention, security and consent, including requirements for data protection impact assessments.
Proposals include tighter parental consent rules for minors, enhanced access and deletion rights, retention limits, and restrictions on profiling. Sectors serving children should prepare consent flows and age‑verification mechanisms now.
Final timelines are not yet confirmed. Based on previous cycles and PPC publications, the amendment bill could be enacted around 2027, with full enforcement following after a transitional period of one to two years.
Inventory biometric and children’s data, conduct DPIAs, update privacy notices and consent mechanisms, audit vendors, tighten security controls, and prepare to modify cross‑border transfer agreements.
Current indications point to more prescriptive safeguards, such as detailed contractual clauses and country‑level assessments, rather than an outright ban. Businesses should review existing adequacy and contractual measures proactively.
The Personal Information Protection Commission enforces the APPI. Current penalties include fines of up to ¥100 million for corporations that violate PPC orders, and the draft proposals may introduce direct administrative fines.
For jurisdiction‑specific and sector‑specific compliance planning related to Japan’s data protection framework, consult an information technology lawyer experienced in APPI matters through the Global Law Experts directory.
By Mandy Simpson

posted 1 hour ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Japan's Three‑year Review of the Personal Data Law Moves Toward an Amendment Bill, Biometric and Children's Data in Scope

Send welcome message

Custom Message