Statutory breach notification obligation — Article 26 APPI
Japan's Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, as amended by Act No. 37 of 2021) imposes mandatory breach notification obligations on personal information handling business operators (個人情報取扱事業者) when a breach meets specified statutory thresholds. Article 26 of the APPI, which became effective April 1, 2022, requires dual reporting: to the Personal Information Protection Commission (PPC, the national supervisory authority) and to affected data subjects.
## Who is obligated
Any business handling personal information in Japan falls within scope. The APPI defines a personal information handling business operator as an entity that uses a personal information database in its business. There is no small-enterprise exemption; even businesses processing personal data of a small number of individuals must comply if a breach meets the Article 26(1) notification triggers. Foreign operators offering goods or services to individuals in Japan are subject to extraterritorial application under Article 171 of the APPI.
## Triggering events — Article 26(1)
Article 26(1) requires notification to the PPC when a leak, loss, or damage of personal data occurs (or is suspected) and the breach falls within one of four statutory categories prescribed by Order of the Personal Information Protection Commission:
- Sensitive personal information (要配慮個人情報) — Breach involving special care-required personal information as defined in Article 2(3) of the APPI, including data concerning race, creed, social status, medical history, criminal record, or the fact of being a victim of a crime.
- Property damage risk — Breach of personal data that, if misused, may cause property damage to data subjects (e.g., leaked credit card numbers or financial account credentials).
- Improper use or cyberattack — Breach resulting from, or suspected to result from, an intentional wrongful act, including unauthorized access, ransomware attacks, and other malicious conduct.
- Volume threshold — Breach (actual or suspected) involving the personal data of 1,000 or more individuals.
A breach that meets any one of these triggers activates both the PPC reporting duty under Article 26(1) and, subject to limited exceptions, the data-subject notification duty under Article 26(2).
## PPC reporting deadlines and stages
Article 26(1) and the PPC enforcement rules establish a two-stage reporting process:
- Preliminary report: Business operators must submit a preliminary report to the PPC promptly after becoming aware of the breach or potential breach. PPC Guidelines clarify that "promptly" generally means within three to five business days of recognition.
- Final report: A detailed final report is due 30 days from the date the business operator became aware of the breach. If the breach was, or is likely to have been, committed for an improper purpose (e.g., a cyberattack under trigger category 3 above), the final report deadline extends to 60 days.
The PPC Enforcement Rules (Rules of the Personal Information Protection Commission No. 3 of 2016, as amended) prescribe nine mandatory items for the final report. If certain items cannot yet be ascertained despite reasonable efforts by the deadline, the business operator may submit an interim final report disclosing known items and supplement the report as additional facts are confirmed.
## Notification to data subjects — Article 26(2)
Article 26(2) requires business operators to notify affected data subjects promptly when a breach meeting the Article 26(1) triggers occurs. The APPI does not prescribe a numeric deadline (e.g., "within 72 hours"), but PPC guidance emphasizes that notification should occur without undue delay and as soon as the operator has sufficient information to inform individuals of the nature and scope of the breach and any protective measures they should take.
Notification to data subjects may be excused when the breach presents negligible risk to individuals' rights and interests. The PPC is considering regulatory amendments to formalize carve-outs for low-risk incidents, such as breaches involving only internal management IDs that cannot be correlated with identifying information by an unauthorized recipient.
## Processor obligations
When a processor (outsourcee handling personal data on behalf of a controller/outsourcer) experiences a breach meeting the Article 26(1) triggers, the processor must notify the controller of the breach. If the processor notifies the controller in the manner prescribed by PPC Order, the processor's direct obligation to report to the PPC and to data subjects is deemed satisfied; the controller bears primary responsibility for onward reporting. This avoids duplicative filings but does not relieve the processor of the duty to inform the controller immediately.
## Supervisory authority
The Personal Information Protection Commission (個人情報保護委員会) is the independent administrative commission with jurisdiction over APPI enforcement. The PPC accepts breach reports through its online portal and issues guidance, recommendations, and orders under Articles 146–147 and 150 of the APPI. Non-compliance with Article 26 reporting obligations can trigger administrative orders, public naming, and referral for criminal penalties.
Source: Act on the Protection of Personal Information (consolidated as of April 1, 2023), Articles 2, 26, 146–147, 150, 171; Personal Information Protection Commission enforcement materials
Breach notification content requirements — PPC final report and data-subject disclosure
Japan's Act on the Protection of Personal Information (APPI) and the Personal Information Protection Commission (PPC) enforcement rules prescribe specific disclosure items for both the final breach report to the PPC and the notification to affected data subjects. These content requirements ensure that business operators provide sufficient detail for the PPC to assess the incident and that data subjects can take protective measures.
## PPC final report — nine mandatory items
The PPC Enforcement Rules (Rules of the Personal Information Protection Commission No. 3 of 2016, as amended) require the final breach report submitted to the PPC under Article 26(1) of the APPI to contain nine items. If a business operator cannot ascertain one or more items despite reasonable efforts by the final-report deadline (30 or 60 days, depending on the nature of the breach), the operator may submit an interim final report disclosing the known items and supplement the report as additional facts become available.
The nine mandatory items prescribed by the PPC Enforcement Rules address the following categories:
- Overview of the breach — a factual description of the leak, loss, or damage that occurred (or is suspected to have occurred), including the date and time of discovery and, if known, the date and time the breach occurred.
- Categories and volume of personal data involved — the types of personal data affected (e.g., names, contact information, financial account numbers, sensitive personal information under Article 2(3) of the APPI) and the number of affected data subjects. When the precise count is unknown at the time of the final report, a reasonable estimate with supporting explanation is acceptable.
- Cause of the breach — the identified or suspected cause, such as unauthorized external access (cyberattack, ransomware), employee error, accidental disclosure, physical theft, or system failure.
- Status of secondary damage — whether unauthorized use or further dissemination of the breached personal data has been confirmed, suspected, or ruled out. For example, whether stolen credentials have been used for fraudulent transactions or whether the data has appeared on public file-sharing sites.
- Response measures taken — the steps the business operator has taken immediately following discovery to contain the breach, prevent further loss, and mitigate harm to data subjects. This includes technical remediation (e.g., closing the vulnerability, revoking compromised credentials) and organizational measures (e.g., establishing an internal incident response team, engaging forensic experts).
- Measures to prevent recurrence — the controls and process changes the business operator has implemented or will implement to prevent similar breaches in the future, such as enhanced access controls, staff training, system monitoring, or third-party security audits.
- Scope of notification to data subjects — the number of data subjects notified, the method of notification (direct contact, public announcement, or a combination), and any difficulties encountered in notifying individuals directly.
- Consultation and cooperation with external parties — whether the business operator has reported the incident to other authorities (e.g., sectoral regulators, law enforcement), engaged external counsel or forensic investigators, or coordinated with affected third parties.
- Other relevant matters — any additional information material to the PPC's assessment of the breach and the business operator's response.
The PPC has not published an official English-language consolidated list enumerating all nine items by number in a single statute or rule document. The items above are reconstructed from PPC guidance, APPI commentary, and secondary legal sources citing the Enforcement Rules. Business operators should consult the Japanese-language Enforcement Rules or seek advice from counsel familiar with PPC practice when preparing final reports.
## Data-subject notification — five required items
Article 26(2) of the APPI requires business operators to notify affected data subjects promptly when a breach meeting the Article 26(1) triggers occurs. The PPC Enforcement Rules and APPI commentary indicate that data-subject notification must include a subset of the items disclosed in the PPC final report—specifically, the items that enable individuals to understand the nature and scope of the breach and take protective measures.
According to authoritative APPI commentary, data subjects must be notified of the following five items, corresponding to items (i), (ii), (iv), (v), and (ix) of the nine-item PPC final report:
- Overview of the breach (item i) — what happened, when the breach was discovered, and what type of incident occurred.
- Categories and volume of personal data involved (item ii) — which data elements were compromised and how many individuals are affected (or an estimate if the precise count is unknown).
- Status of secondary damage (item iv) — whether unauthorized use or further dissemination has been confirmed or suspected, and whether individuals face immediate risks such as identity theft or financial fraud.
- Response measures taken (item v) — the steps the business operator has taken to contain the breach and protect the personal data, including technical fixes and organizational changes.
- Other relevant matters (item ix) — contact information for the business operator's breach response team or customer service line, resources available to assist affected individuals (such as credit monitoring if financial data was breached), and any recommended protective actions (e.g., changing passwords, monitoring account statements).
When direct notification to individual data subjects is impractical—for example, because contact information for a large number of affected individuals is unavailable or the breach itself involved destruction of contact records—the business operator may satisfy the Article 26(2) notification duty by making a public announcement in a manner reasonably calculated to inform affected individuals. The PPC Guidelines recommend posting a detailed notice on the business operator's website and, when appropriate, publishing a notice in a major national or regional newspaper. The public notice should include the same five items listed above and establish a dedicated inquiry contact point (phone line, email address, or web form) for affected individuals to obtain further information.
## Preliminary report content
The preliminary report submitted to the PPC promptly (generally within three to five business days) after recognition of the breach need only provide a concise summary of the known facts at that time: that a breach has occurred or is suspected, the general category of personal data involved, and the approximate number of affected individuals. The PPC understands that many details will remain under investigation at the preliminary-report stage. The purpose of the preliminary report is to alert the PPC to the incident and initiate supervisory engagement; the detailed factual and remedial analysis is reserved for the final report.
## Format and submission
The PPC accepts breach reports through its online portal. The portal provides structured forms corresponding to the preliminary and final report requirements. Business operators that cannot access the online portal (for example, due to system outages caused by the breach itself) may submit reports by email or, in exceptional cases, by postal mail to the PPC's Tokyo headquarters. The PPC has indicated that reports should be in Japanese; foreign operators without Japanese-language capacity should engage local counsel to prepare and submit the reports.
Source: Act on the Protection of Personal Information (consolidated as of April 1, 2023), Article 26; Personal Information Protection Commission enforcement materials
Penalties for breach notification violations — Article 178 criminal sanctions and PPC administrative enforcement
Japan's Act on the Protection of Personal Information (APPI) establishes both administrative and criminal penalties for violations of the Article 26 breach notification obligations. In April 2026, significant amendments were enacted that materially impacted the enforcement landscape, effective as of that date.
## Administrative and Criminal Penalties — 2026 Amendments
The APPI's amended enforcement regime, effective April 2026, includes both criminal and administrative sanctions for breach notification failures and related violations:
Enhanced Criminal Penalties — Article 178 (as amended)
Following the 2026 amendments, Article 178 imposes substantially increased criminal penalties for failure to comply with a legally binding order from the Personal Information Protection Commission (PPC) under Article 148. As of April 2026:
- Imprisonment: Up to 3 years (previously up to 1 year)
- Criminal fine: Up to ¥5,000,000 (previously up to ¥1,000,000)
These penalties apply to responsible individuals (e.g., directors, officers) who fail to comply with a PPC order regarding breach notification or related APPI duties. The amendment also expands the scope of covered conduct to include breaches resulting in not only monetary harm but also non-economic harms such as harassment or discrimination motivated misuse.
PPC Administrative Fines (Surcharge Orders)
For the first time, the 2026 amendments authorize the PPC to impose administrative fines (surcharges) for certain serious APPI violations. While the administrative surcharge regime primarily targets unlawful data disclosures and misuse rather than breach notification failures per se, business operators found to have derived economic benefit from a covered violation may be ordered to pay an amount equivalent to the benefit.
- Administrative surcharges are calculated based on the economic benefit obtained by the violator due to the violation, with specific coverage detailed in Article 148-3 and related PPC regulations.
- The amendment does not generally apply these surcharges to mere procedural breach notification failures under Article 26, unless such failures are linked to substantive personal data misuse.
Other Penalties — Obstruction and Corporate Liability
Enforcement under Articles 179 and 180 continues to prescribe criminal penalties for obstructing PPC investigations—including fines for failure to submit reports or for submitting false information. Article 184 further provides for vicarious corporate liability for certain violations, with criminal fines for corporations of up to ¥100,000,000.
## Enforcement and Referral
The PPC retains its administrative authority under Articles 146–148: it may require reports, conduct inspections, issue guidance, make recommendations, and issue legally binding orders. Failure to comply can result in both direct administrative fines and referral for criminal prosecution under the higher 2026 thresholds.
## Key Legislative Changes (Effective April 2026)
- Tripling of maximum criminal penalties under Article 178 (to 3 years' imprisonment/¥5 million).
- Broadening of criminal coverage to include non-monetary harms.
- Introduction of administrative surcharges for benefit-linked serious violations (not for procedural breach notification violations alone).
- Reinforcement of PPC’s supervisory and enforcement discretion.
Source: Act on the Protection of Personal Information (official, as amended April 1, 2026), Articles 146–148, 178–180, 184; Japanese e-Gov APPI text (updated 2025/2026); Personal Information Protection Commission — Laws and Policies
No statutory breach recordkeeping obligation — contrast to GDPR Article 33(5)
Japan's Act on the Protection of Personal Information (APPI) does not impose a statutory obligation on business operators to maintain internal records or logs of personal data breaches, including breaches that do not meet the Article 26(1) reporting thresholds. This contrasts sharply with the European Union's General Data Protection Regulation (GDPR), which requires controllers under Article 33(5) GDPR to document all personal data breaches (whether notifiable to a supervisory authority or not) to enable the supervisory authority to verify compliance with the notification obligation.
## APPI Article 26 — notification but not recordkeeping
Article 26 of the APPI establishes the breach notification obligation to the Personal Information Protection Commission (PPC) and to affected data subjects when a breach meets one of the four statutory triggers: (1) sensitive personal information (要配慮個人情報) under Article 2(3); (2) personal data that may cause property damage if misused; (3) breaches resulting from intentional wrongful acts or cyberattacks; or (4) breaches involving 1,000 or more individuals.
Article 26 does not, however, mandate that business operators keep internal records of breaches that fall below these thresholds or that do not meet the notification triggers. A business operator that experiences a breach of personal data affecting fewer than 1,000 individuals, not involving sensitive information or property-damage risk, and not resulting from a cyberattack, is not required under Article 26 to report the incident to the PPC or to maintain a record of the incident for future reference.
The APPI Enforcement Rules (Rules of the Personal Information Protection Commission No. 3 of 2016, as amended) prescribe detailed recordkeeping obligations for third-party provision of personal data under Articles 29–30 of the APPI (formerly Articles 25–26 in pre-2022 numbering). Business operators must create and maintain records when providing personal data to third parties or receiving personal data from third parties, and these records must be kept for a retention period prescribed by PPC rules (generally three years from the last provision). These recordkeeping obligations under Articles 29–30, however, apply only to the ordinary course third-party provision compliance regime and do not extend to breaches as defined in Article 26(1).
## PPC investigation authority and de facto expectation
Although the APPI does not impose a statutory duty to maintain breach records, the PPC has supervisory and investigative powers under Article 146 of the APPI to require business operators to submit reports and to conduct on-site inspections of business facilities, systems, and records to verify compliance with the APPI. Under Article 146, the PPC may require a business operator to report on its handling of personal data, including past breaches, as part of an investigation or compliance review.
As a practical matter, business operators that cannot produce contemporaneous records of past breach incidents when the PPC exercises its Article 146 authority may face scrutiny regarding whether the operator has implemented appropriate safety management measures under Article 23 of the APPI. Article 23 requires business operators to take necessary and appropriate measures for the security control of personal data to prevent leak, loss, or damage. A business operator that experiences repeated breaches but has maintained no internal documentation of those incidents, the root causes, or the remedial steps taken may be unable to demonstrate to the PPC that it has implemented or improved its safety management measures in response to previous incidents.
The PPC's Guidelines for the Act on the Protection of Personal Information (個人情報の保護に関する法律についてのガイドライン, General Rules volume, published by the PPC) do not prescribe a specific breach-recordkeeping obligation, but the guidelines emphasize that business operators should conduct internal investigations when a breach or suspected breach occurs and should implement corrective measures based on the findings. Maintaining records of such investigations is implicit in the PPC's expectation that business operators will be able to explain their breach response and demonstrate accountability when the PPC conducts oversight activities.
## GDPR Article 33(5) documentation requirement — a comparative reference
The GDPR imposes an explicit breach-documentation duty. Article 33(5) GDPR provides that the controller "shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken." This documentation requirement applies to all personal data breaches, including those that the controller determines are unlikely to result in a risk to the rights and freedoms of natural persons and therefore do not require notification to a supervisory authority under Article 33(1) GDPR.
The European Data Protection Board (EDPB) Guidelines 9/2022 on personal data breach notification (formerly WP29 Guidelines WP250 rev.01, adopted by the EDPB) clarify that the Article 33(5) documentation obligation enables the supervisory authority to verify whether the controller has correctly assessed which breaches are notifiable. The PPC has published a Japanese translation of the EDPB Guidelines 9/2022 on its website as a reference for Japanese business operators handling EU personal data, acknowledging the GDPR's more extensive breach-recordkeeping framework.
Japanese business operators subject to both the APPI and the GDPR (for example, operators offering goods or services to individuals in the European Union or monitoring EU data subjects) must comply with the GDPR Article 33(5) documentation requirement for breaches involving EU personal data, even though the APPI imposes no parallel obligation for breaches of Japan-resident personal data. Such operators often implement a unified breach log covering all personal data breaches to satisfy the GDPR requirement and to maintain a consistent incident-response practice across jurisdictions.
## Best practice and industry standards
Although not statutorily mandated under the APPI, maintaining an internal breach log is widely recognized as a best practice in Japan's privacy-compliance community. Industry standards such as the JIS Q 15001 (PrivacyMark certification standard administered by the Japan Institute for Promotion of Digital Economy and Community, JIPDEC) and the ISO/IEC 27001 information security management system standard recommend that organizations document all security incidents, including personal data breaches, to support continuous improvement of information security controls.
The Japan Federation of Bar Associations (日本弁護士連合会, JFBA) and privacy-practitioner associations have published guidance recommending that business operators establish incident logs that record the date of discovery, the scope of personal data involved, the cause or suspected cause of the breach, the immediate containment measures taken, and the results of any internal investigation. Such logs enable operators to track breach trends, identify systemic vulnerabilities, and demonstrate diligence when the PPC or another authority requests information under Article 146.
Business operators that voluntarily maintain breach logs should ensure that the logs are secured and access-controlled to prevent unauthorized disclosure, as the logs themselves may contain details about vulnerabilities and affected individuals. The retention period for breach logs is a matter of internal policy; many operators retain breach logs for three to five years in alignment with the three-year retention period prescribed for third-party provision records under the APPI Enforcement Rules, though no statutory requirement mandates a specific retention period for breach logs.
## Summary
The APPI Article 26 requires business operators to report breaches meeting specified triggers to the PPC and to notify affected data subjects, but it does not require business operators to maintain internal records of all breaches, including non-reportable incidents. This distinguishes the APPI from the GDPR, which mandates comprehensive breach documentation under Article 33(5). Japanese business operators are nonetheless well-advised to maintain internal breach logs as a best practice to support PPC investigations under Article 146, to demonstrate continuous improvement of safety management measures under Article 23, and to satisfy industry certification standards. Operators subject to both the APPI and the GDPR must maintain breach records for EU personal data breaches in compliance with GDPR Article 33(5), and many adopt a unified breach-logging practice for all jurisdictions.
Source: Act on the Protection of Personal Information (consolidated as of April 1, 2023), Articles 23, 26, 29–30, 146; Enforcement Rules for the Act on the Protection of Personal Information, Articles 12–18; Personal Information Protection Commission — Laws and Policies
Defining "leak, loss, or damage" — Article 26(1) threshold event
Japan's Act on the Protection of Personal Information (APPI) establishes the breach notification obligation in Article 26(1) by reference to three threshold events: "leak, loss, or damage" (漏えい、滅失又は毀損) of personal data. A business operator must report to the Personal Information Protection Commission (PPC) and notify affected data subjects when a leak, loss, or damage (1) has occurred or is suspected to have occurred and (2) falls within one of the four statutory notification triggers prescribed by PPC Order (sensitive personal information, property-damage risk, improper use or cyberattack, or 1,000+ individuals).
The APPI does not define these three threshold terms in Article 26 or elsewhere in the statute. The PPC has not published comprehensive English-language interpretive guidance elaborating the boundaries of "leak," "loss," and "damage" under the APPI. The following interpretation derives from the statutory language, the structure of the APPI's security-control obligations under Article 23, and authoritative APPI commentary by Japanese privacy practitioners.
## "Leak" (漏えい)
"Leak" refers to unauthorized disclosure of or access to personal data by a person who is not authorized to receive or access the data. This includes:
- External unauthorized access: Cyberattacks, hacking, ransomware, or other intrusion by external threat actors that result in access to or exfiltration of personal data.
- Accidental external disclosure: Sending personal data to the wrong recipient by email, posting personal data on a publicly accessible website or cloud storage location due to misconfiguration, or physically mailing documents to the wrong address.
- Internal unauthorized access: Access by employees or other insiders who do not have authorization under the business operator's access-control policies to view or handle the personal data in question. For example, if an employee in the marketing department accesses customer health records stored in a separate database to which the employee has no business need or authorization, this may constitute a "leak" even though the employee is an insider.
A "leak" occurs when personal data is disclosed to or accessed by a person (internal or external) who is not authorized to receive or view it under the business operator's security-control measures. Unauthorized access without confirmed exfiltration can constitute a reportable leak if one of the four Article 26(1) triggers applies. For instance, if system logs show that an unauthorized external actor accessed a database containing 1,000+ individuals' personal data, but forensic analysis has not yet confirmed whether the data was copied or exfiltrated, the business operator must file a preliminary breach report to the PPC within three to five business days based on the suspected leak, because the volume trigger (1,000+ individuals) is met.
## "Loss" (滅失)
"Loss" means that personal data no longer exists in a form accessible to the business operator, or that the business operator has lost control over or possession of the personal data. Loss includes:
- Permanent deletion or destruction: Data deleted from systems or physically destroyed (e.g., paper records shredded or incinerated) such that the business operator can no longer retrieve the data, even from backups.
- Loss of access due to encryption or system failure: For example, if a ransomware attack encrypts personal data and the business operator cannot decrypt the data because the decryption key is held by the attacker or has been lost, this is a "loss" even if the encrypted data files remain on the business operator's servers.
- Physical loss: Theft or misplacement of electronic media (laptops, USB drives, backup tapes) or paper documents containing personal data, such that the business operator no longer has the data in its possession.
The PPC has clarified in the context of ransomware attacks that encryption of personal data by ransomware constitutes both unauthorized access (a "leak") and, if the business operator cannot restore access from a backup, a loss of availability. If the business operator can restore the encrypted data from a secure backup without paying the ransom, the incident may be characterized as a leak (unauthorized access) rather than a permanent loss, but the Article 26(1) reporting obligation may still apply under the "improper use or cyberattack" trigger.
## "Damage" (毀損)
"Damage" refers to alteration, corruption, or incompleteness of personal data such that the data is no longer accurate, intact, or usable in its original form. Damage includes:
- Unauthorized alteration: Modification of personal data by an unauthorized party (e.g., an attacker changing customer account balances, contact information, or transaction records in a database).
- Data corruption: Technical failure, malware, or user error that corrupts data files, rendering the personal data unreadable or unreliable (e.g., database corruption following a power failure or disk error).
- Partial deletion: Deletion of fields or records within a personal data set such that the remaining data is incomplete. For example, if an attacker deletes the "date of birth" field for all records in a customer database, the personal data has been damaged even if names and addresses remain intact.
Damage is distinct from loss: damaged personal data still exists but is no longer in its original, accurate, or complete form. If the damage affects sensitive personal information, creates property-damage risk, results from a cyberattack, or affects 1,000+ individuals, the Article 26(1) notification triggers apply.
## "Suspected" leak, loss, or damage
Article 26(1) applies not only when a leak, loss, or damage has been confirmed, but also when such an event is "suspected" (おそれ). A business operator that becomes aware of facts suggesting that a breach may have occurred—for example, a security alert indicating possible unauthorized access, missing backup tapes, or user reports of suspicious account activity—must conduct an immediate investigation. If the preliminary investigation suggests that a leak, loss, or damage meeting one of the four triggers may have occurred, the business operator must file a preliminary report to the PPC within three to five business days, even if the full scope and impact of the incident are not yet confirmed. The PPC does not require absolute certainty before a preliminary report is due; reasonable suspicion based on available evidence is sufficient.
The business operator's final report, due 30 or 60 days after recognition of the breach, should include the results of the completed investigation and state whether the suspected leak, loss, or damage was confirmed or ruled out. If the investigation concludes that no reportable breach occurred (for example, the suspected unauthorized access was a false positive generated by a misconfigured intrusion-detection system), the business operator should update the PPC in the final report.
## Summary
Under the APPI Article 26(1), a business operator must report a breach to the PPC when (1) a leak (unauthorized disclosure or access), loss (destruction or loss of possession/control), or damage (alteration, corruption, or incompleteness) of personal data has occurred or is suspected, and (2) the breach meets one of the four statutory triggers. The PPC has not published detailed English-language guidance defining these three threshold terms; the definitions above reflect the statutory language and authoritative APPI commentary. When in doubt about whether an incident constitutes a leak, loss, or damage, business operators should consult with Japanese privacy counsel and, if a reporting trigger is met, file a preliminary report to the PPC promptly to preserve compliance with the Article 26(1) timeline.
Source: Act on the Protection of Personal Information (consolidated as of April 1, 2023), Articles 23, 26; Personal Information Protection Commission enforcement materials
Encryption and necessary-measures exemption — when breach notification is not required
Japan's Act on the Protection of Personal Information (APPI) Article 26, effective April 1, 2022, requires business operators to report breaches to the Personal Information Protection Commission (PPC) and notify affected data subjects when a leak, loss, or damage of personal data occurs and meets one of four statutory triggers. Widely cited commentary and PPC guidance materials describe a "necessary measures" exemption under which notification may not be required when robust technical safeguards—principally encryption—render the breach low-risk. This section reviews that exemption as understood in practice, notes a proposed 2026 legislative amendment introducing an additional low-risk carve-out, and distinguishes the exemptions from categorical exclusions for pseudonymized and anonymized data.
## Encryption exemption — "necessary measures" as described in commentary
Privacy practitioners and PPC guidance materials consistently describe an exemption from Article 26 notification obligations when a business operator has taken "necessary measures to prevent harm to the rights and interests of data subjects." The exemption is most commonly invoked when personal data was encrypted using a robust algorithm (e.g., AES-256) and the encryption key was not compromised in the breach. Under this interpretation, a breach involving encrypted personal data does not trigger the Article 26(1) PPC reporting or Article 26(2) data-subject notification obligations when the encryption renders the data unintelligible to unauthorized parties and the key management practices ensure the key was not accessible to the unauthorized recipient.
The exemption does not apply if the encryption key or security credentials were also compromised. If an attacker obtains both the encrypted database and the decryption key—because the key was stored on the same stolen device or the attacker infiltrated the key-management system—the necessary-measures threshold is not met and the business operator must report the breach as required by Article 26.
Unable to confirm the precise citation to the PPC Order, Enforcement Rules, or official guideline provision establishing the encryption exemption from primary sources as of 2026-06-02. The description above reflects the consensus interpretation in Japanese privacy-compliance practice and is consistent with PPC guidance materials referenced by practitioners, but the author has not verified the specific regulatory or statutory text specifying the exemption criteria. Business operators considering reliance on the exemption should consult PPC guidance directly or seek advice from counsel familiar with PPC enforcement practice.
## Proposed 2026 low-risk exemption — pending Diet deliberation
On April 7, 2026, the Japanese Cabinet approved a bill to amend the APPI and submitted it to the Diet. The bill proposes a risk-based exemption from the data-subject notification obligation under Article 26(2) for breaches presenting a "low risk of harming the rights and interests of the individual." Under the proposed amendment, business operators would be exempt from directly notifying affected individuals if PPC regulations (to be issued after enactment) designate the breach as low-risk and the business operator implements necessary alternative measures to protect data subjects, such as posting a public announcement.
The PPC reporting obligation under Article 26(1) would continue to apply even for low-risk breaches under the proposed amendment. The exemption applies only to data-subject notification, not to preliminary and final reports to the PPC.
The Diet is expected to deliberate the bill during 2026. If enacted, the PPC will issue implementing regulations defining which categories of breaches qualify as low-risk for purposes of the data-subject notification exemption. The regulations are expected to take effect in 2027 or 2028, though the implementation timeline has not been finalized as of June 2026.
## Categorical exemptions for pseudonymized and anonymized information
The APPI establishes categorical exemptions from Article 26 for breaches of pseudonymously processed information (PPI) under Article 41 and anonymized personal information (API) under Article 43. Article 41 provides that business operators handling PPI are exempt from the Article 26 breach notification obligations. PPI is defined in Article 2(5) as personal information processed so that it cannot be used to identify a specific individual without collation with other information. Article 43 similarly exempts API from the Article 26 notification obligations. API is defined in Article 2(6) as information processed from personal information so that a specific individual cannot be identified and the original personal information cannot be restored.
If the breached data qualifies as PPI or API at the time of the breach, Article 26 does not apply regardless of the number of affected individuals, the sensitivity of the underlying data, or the nature of the breach (cyberattack, accidental disclosure, etc.). These categorical exemptions are express statutory exclusions and do not require a case-by-case risk assessment.
The encryption / necessary-measures exemption described above, by contrast, applies to personal data (個人データ) that remains fully identifiable but is protected by technical safeguards such that the breach does not pose a risk warranting notification. Business operators analyzing whether a breach is notifiable must first determine whether the breached data is personal data, PPI, or API under Articles 2(1), 2(5), and 2(6), and then—if it is personal data—whether an exemption (encryption or, if enacted, the proposed low-risk carve-out) applies.
## Analytic comparison — GDPR Article 34(3)(a) encryption exemption
The encryption exemption described in Japanese privacy-compliance practice parallels the European Union GDPR Article 34(3)(a), which provides that notification to data subjects is not required when the controller has applied "appropriate technical and organisational protection measures" rendering the data unintelligible to unauthorized persons—specifically, encryption. Under both the APPI as interpreted in practice and the GDPR, robust encryption with the key not compromised serves as a mitigating factor that can eliminate the data-subject notification obligation.
A key difference in the GDPR framework: the encryption exemption under Article 34(3)(a) applies only to data-subject notification. The controller must still report the breach to the supervisory authority under Article 33 within 72 hours. The APPI necessary-measures exemption, as described in PPC guidance and Japanese commentary, applies to both the PPC reporting obligation and the data-subject notification obligation—when the threshold is met, neither the preliminary/final PPC report nor the data-subject notification is required. This broader exemption reflects the APPI's focus on harm to data subjects as the trigger for notification, rather than the occurrence of a breach per se.
Source: Act on the Protection of Personal Information (consolidated as of April 1, 2023), Articles 2, 26, 41, 43
Notification procedure — filing a breach report with the PPC (Personal Information Protection Commission)
Japan's Act on the Protection of Personal Information (APPI) Article 26 requires business operators to notify the Personal Information Protection Commission (PPC) of qualifying personal data breaches. The PPC has established an official procedure for submitting breach notifications, primarily via its dedicated online reporting portal. Understanding the technical steps to file (and alternatives when the portal is inaccessible) is critical for timely and compliant notification.
PPC online portal
- The PPC provides an online "Personal Information Leakage Report Submission" form for both preliminary and final reports.
- The portal is accessible at https://www.ppc.go.jp/personalinfo/legal/leakAction/ (“【漏えい等事案報告受付フォーム】” in Japanese) and requires entry of specific report fields as set by the PPC.
- Users must submit reports in Japanese. There is no official English-language submission form; foreign operators should secure Japanese-capable representation or engage local counsel.
- The forms require upload or entry of: operator identification (name, address, representative), contact point for follow-up, breach details (as required by the Enforcement Rules), date of occurrence/recognition, volume/types of data affected, containment and remedial actions, and other prescribed details.
- Upon submission, the reporting party receives an acknowledgment by email with a reference number. The PPC may request supplemental documentation or clarification by contacting the reporting party point-of-contact.
Alternative filing methods
- If the online portal is unavailable due to a technical outage or a breach disabling the operator’s systems, the PPC accepts reports by email (to the address listed on the PPC's official website) or, if electronic submission is impossible, by postal mail.
- In urgent or complex incidents requiring discussion, initial notification by telephone to the PPC’s incident reporting hotline is permitted, but this does not substitute for formal written (electronic) submission.
- The PPC advises business operators to retain screenshots or records of filed notifications for their own internal compliance file.
Post-submission process
- The PPC reviews incoming reports and may request investigative cooperation or additional submissions.
- Operators must respond promptly to any PPC requests for further details or remedial updates.
Official guidance and reference
- The PPC maintains step-by-step guidance, FAQs, and the breach reporting portal landing page in Japanese at https://www.ppc.go.jp/personalinfo/legal/leakAction/. All official procedural updates and downloadable templates are available from this portal.
Source: PPC official breach reporting procedures page (Japanese)
Breach notification for personal information entrusted to a processor — controller-outsourcer/processor allocation under APPI Article 26
Japan’s Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, as amended) addresses breach notification when a data breach occurs at a service provider or downstream processor (known as an "entrusted party" — 委託先) handling personal data on behalf of a controller (the "personal information handling business operator" under APPI, 個人情報取扱事業者). Under Article 26, the primary statutory obligation to notify the Personal Information Protection Commission (PPC) and affected individuals rests with the personal information handling business operator (controller/outsourcer). However, APPI and PPC guidance impose specific notification duties for processors when they discover a qualifying breach.
Immediate notification from processor to controller — Article 26(5)
Article 26(5) of the APPI requires a processor entrusted with handling personal data to promptly notify the controller if it discovers or suspects a breach that meets any of the four statutory notification triggers (sensitive information, property-damage risk, improper use/cyberattack, or a volume involving 1,000 or more individuals; see Article 26(1) and PPC Enforcement Order Article 8). The entrusted party is not required to report directly to the PPC unless contractually or statutorily classified as the business operator itself—a situation uncommon for a typical outsourcing relationship.
After receiving notice from the processor, the controller must file the required notifications to the PPC and to affected data subjects following the standard Article 26 timeline (preliminary report within 3–5 business days, final report within 30 or 60 days—see consolidated APPI and PPC Enforcement Rules).
This allocation reflects the APPI’s principle that the entity deciding the purpose and means of processing (the business operator/controller) remains ultimately responsible for statutory compliance, regardless of outsourcing. Entrusted processors/委託先 must promptly inform the controller, but are generally not subject to direct regulatory penalties for breach notification failures unless acting outside legal and contractual boundaries.
PPC official commentary and best practice
The PPC’s official breach notification Q&A confirms this allocation: “When a personal data breach arises in an entrusted business [委託先], the entrusted business must inform the entrusting business [the controller] promptly, and the entrusting business shall promptly notify the PPC and affected persons.” (PPC FAQ Q20 and PPC Guidelines commentary; official Japanese.)
Best practice—both under PPC guidance and industry standards—is to require in outsourcing contracts: (1) processors’ duty to notify the controller without undue delay; (2) the form and content of such reports; and (3) the processor’s cooperation in the controller’s investigation, documentation, and onward notifications. This model is analogous to GDPR Article 33(2)-(3): Japan’s APPI is functionally aligned but does not directly expose the processor to statutory reporting obligations.
Source: Act on the Protection of Personal Information (consolidated as of April 1, 2023), Article 26(5); Personal Information Protection Commission — Official FAQ/Q&A (Japanese)
Negligible or low risk to data subjects — PPC practice and exceptions to breach notification duty
Japan’s Act on the Protection of Personal Information (APPI) Article 26 requires breach notification to both the Personal Information Protection Commission (PPC) and affected data subjects when certain thresholds are met. However, both the statute and official guidance allow for notification carve-outs when an incident presents "negligible" or "low" risk to individuals’ rights and interests. This section examines how the PPC interprets and applies these risk-based exceptions in practice, distinguishing them from formal statutory exclusions (such as for anonymized or pseudonymized information—see /guides/japan/breach-notification#encryption-exemption-necessary-measures).
## PPC's risk-of-harm standard While Article 26(2) does not enumerate a specific low-risk exception, PPC guidance (as reflected in the Guidelines for the Act on the Protection of Personal Information and published Q&As) recognizes that data-subject notification is not required where a leak, loss, or damage of personal data is clearly insignificant and does not risk harming individuals. Typical examples considered "negligible risk" include:
- Sending internal IDs that, by themselves, cannot identify any individual and cannot be correlated with personal information by an unauthorized recipient.
- The unintentional forwarding of personal data to a trusted business partner who confirms deletion without having viewed or used the data.
- Loss of encrypted storage devices where the encryption key is securely managed and not compromised.
The common theme is that no actual risk of identity theft, financial harm, reputational damage, or other concrete damage to the individual can realistically materialize. The PPC expects a careful, documented reasoned assessment—including technical, organizational, and contextual factors—before concluding that notification is not required under this carve-out.
## Procedural expectations — documenting low-risk determinations The PPC’s Q&A and Guidelines expect the operator to document the reasoning for treating a breach as "low or negligible risk." If challenged later (for example, in a PPC investigation under APPI Article 146), the operator should be able to demonstrate that all relevant facts were considered, and that all reasonable protective and remedial measures were taken. The PPC distinguishes these non-notified minor incidents from notifiable breaches by the risk assessment, not by strict data type or volume.
## Legislative and regulatory evolution As of 2026, the PPC is considering regulatory amendments (awaiting Diet approval) that would formalize the low-risk carve-out, including model categories for carve-out eligibility and explicit documentation requirements. Until those rules are promulgated, the current practice continues to rest on PPC guidance and established compliance norms.
## Advisory note Operators should not apply the "negligible risk" exemption lightly. The burden is on the operator to show that the risk of harm is objectively minimal, and the PPC has authority to investigate and overrule low-risk determinations it disagrees with.
Source: Personal Information Protection Commission — Guidelines for the Act on the Protection of Personal Information (English), PPC Official Breach Notification Q&A (Japanese, updated 2025).
Sector-specific breach notification overlays — banking, telecom, and healthcare regimes alongside APPI Article 26
While the Act on the Protection of Personal Information (APPI) Article 26 establishes the baseline statutory breach notification duty for most Japanese business operators, certain regulated sectors are subject to parallel or stricter breach notification rules under sector-specific legislation. Practitioners handling incidents in finance, telecommunications, and healthcare must assess sectoral overlays that either supplement or supersede general APPI requirements. As of June 2026:
1. Financial sector (Banking Act, Insurance Business Act, related ordinances)
- Under the Banking Act (Act No. 59 of 1981, as amended), Article 21 and related Cabinet Office Ordinances impose reporting obligations on banks and certain financial institutions for incidents involving customer data. The Financial Services Agency (FSA) requires prompt notification for any incident potentially impacting customers or the financial system—even where the APPI threshold is not met. Reporting channels typically include both the FSA and the Personal Information Protection Commission (PPC) for incidents involving personal data leaks, with the FSA recommending notification “immediately” upon discovery. The Insurance Business Act imposes parallel requirements for insurers.
Source: Banking Act (Japanese Law Translation, Article 21)
2. Telecommunications sector (Telecommunications Business Act, MIC guidelines)
- The Telecommunications Business Act (Act No. 86 of 1984, as amended) Art. 4, and the Ministry of Internal Affairs and Communications (MIC) “Guidelines for Protection of Personal Information in Telecommunications Business,” require telecommunications carriers to promptly report leaks or improper disclosure of user information to MIC and notify affected subscribers, regardless of whether the breach triggers APPI Article 26. Specific reporting forms and timelines are set by MIC circulars.
- See: Telecommunications Business Act (Japanese Law Translation, Article 4)
- See sector-specific PPC guideline (Japanese): PPC Guidelines for the Protection of Personal Information in Telecommunications Business
[Note: The previously cited MIC English-language guidance page is no longer available as of June 2026; current official regulatory material is available through the PPC sectoral guideline page.]
3. Healthcare sector (Medical Care Act, Act on Anonymized Medical Data Use, MHLW guidance)
- For hospitals and medical institutions, the Medical Care Act (Act No. 205 of 1948) and associated MHLW guidelines require notification to supervising health authorities in addition to any APPI notification. Entities handling medical care information may also be subject to the Act on Anonymized Medical Data Use (Act No. 28 of 2017).
These sectoral requirements can diverge from APPI Article 26 in scope, reporting deadlines, format, and authorities to notify. In a multi-regulated incident (e.g., a telemedicine provider breach), operators should map obligations under both APPI and relevant sectoral rules and file in parallel where required. Sector-specific obligations are enforced by supervisory agencies (FSA, MIC, MHLW) in coordination with the PPC.
Source: Medical Care Act (Japanese Law Translation), PPC Personal Information Guidelines for the Telecommunications Sector
Substitute public announcement for data-subject notification — procedure and PPC expectations under Article 26(2) APPI
Under Japan’s Act on the Protection of Personal Information (APPI) Article 26(2), business operators must notify affected data subjects “promptly” of a notifiable breach. When direct notification to each individual is not feasible—typically where contact information is incomplete, destroyed in the breach, or the volume of affected individuals makes individual notification unduly difficult—the operator may fulfill its obligation by making a substitute “public announcement” (公表), as provided for in the PPC Guidelines and official Q&A.
Legal standard for substitute notification:
- Article 26(2) APPI establishes the duty to notify data subjects but does not spell out substitute notification procedure. PPC Guidelines clarify that public announcement is appropriate only if direct notification is either impossible or would require disproportionate effort relative to the risk involved. Scenarios include mass breaches where contact details are lost, or incidents where direct notification would create a major delay, frustrating the goal of enabling prompt risk mitigation by individuals.
Procedural steps and content expectations:
- The PPC expects public announcement “without undue delay,” remaining accessible for a reasonable period—typically 30 days or more, though no hard rule exists. The operator should post the notice in a highly visible place on its website (homepage, banner, or persistent notification), and may also use newspapers for broader reach when appropriate. Public notice is permitted only if operators genuinely cannot notify all individuals directly—not as a matter of convenience.
- The content must match what would be provided in direct notice, as detailed in [/guides/japan/breach-notification#notification-content-requirements]: summary of the incident, types and volume of data involved, status of investigation, remedial and protective measures, operator contact point, and recommended steps for affected persons.
- The announcement should be easy to find, free of technical jargon, and written in Japanese. The PPC expects operators to capture evidence of posting (screenshots, URLs, logs) in case of audit or investigation under Article 146 APPI.
Duration and format:
- While neither APPI nor PPC rules mandate a specific minimum display period, PPC compliance practice commonly expects at least 30 days, and the announcement should not be removed until risk-mitigation objectives have been reasonably met.
Comparative note — GDPR Article 34(2):
- The Japanese substitute notification mechanism closely parallels GDPR Article 34(2), which allows “public communication or similar measures” when individual contact is impossible or disproportionately burdensome, though PPC stresses more extensive documentation of why individual notice was not possible.
Source: Act on the Protection of Personal Information (consolidated as of April 1, 2023), Article 26(2), PPC Guidelines for the Act on the Protection of Personal Information (General Rules), Section 2-7-2, PPC Official Breach Notification Q&A (Japanese)
Extraterritorial breach notification obligation — Article 171 APPI for foreign business operators
Japan’s Act on the Protection of Personal Information (APPI), as amended effective April 1, 2022, affirmatively extends its breach notification obligations to certain foreign business operators handling personal data about individuals in Japan. Article 171 of the APPI establishes this extraterritorial effect: any entity (regardless of its place of incorporation or physical establishment) that uses a personal information database in the course of providing goods or services to individuals in Japan, or that otherwise has business activities directed at Japan, is subject to the APPI, including the Article 26 statutory breach notification duties.
Who is in scope?
- Article 171(1) applies to any foreign business operator (e.g., a U.S. or EU company) that acquires personal information relating to individuals located in Japan in connection with offering goods or services within Japan, even if the operator has no physical presence or legal entity in Japan.
- This includes cross-border e-commerce platforms, SaaS providers, and apps/hardware vendors serving Japanese residents.
Obligation to notify
- When a personal information breach occurs that meets any of the four Article 26(1) notification triggers (sensitive personal information, property-damage risk, improper use/cyberattack, or 1,000+ affected individuals), a foreign operator with APPI exposure must:
- File the preliminary and final breach reports with the Personal Information Protection Commission (PPC), using the same procedure as Japanese-domiciled businesses.
- Notify affected data subjects in Japan, in Japanese, “promptly” (no strict deadline, but typically as soon as facts sufficient for notification are established; see PPC Guidelines).
Filing mechanics and language support
- The PPC breach report portal and notifications must be submitted in Japanese. There is currently no English-language portal or form. For foreign entities without Japanese-language personnel, the PPC expects the engagement of local Japanese counsel or a representative to prepare and file the required notifications. The PPC may reject filings, request clarifications, or issue supplementary information requests in Japanese.
- Foreign operators are also expected to establish an in-country point of contact for PPC investigations or follow-up. Absent such arrangements, the PPC may publicize the breach and take additional supervisory actions—particularly with respect to failure to notify affected individuals.
Jurisdictional enforcement
- If a foreign operator fails to comply with Article 26 notification requirements, the PPC can issue orders and may alert the Japanese public or affected data subjects, even if direct enforcement against the foreign entity is logistically or legally challenging. Moreover, failure to comply can impact the operator's ability to do business in Japan and risks significant reputational harm. The APPI’s extraterritorial enforcement posture is robust in light of increased cross-border data flows and repeated amendments confirmed by Article 171.
Comparative note: GDPR extraterritoriality
- APPI’s extraterritorial provision (Article 171) is structurally analogous to GDPR Article 3. However, APPI does not require designation of a representative in Japan (unlike GDPR Article 27), but in practice, effective notification almost always requires local representation due to language and procedural expectations.
Legal sources and guidance
- Statutory text: Article 171 APPI, as indicated in the official Japanese and MOJ English translation.
- PPC guidance summarizing foreign operator duties: PPC Official Website — English Guidance for Foreign Entities. Important to check PPC updates for evolving administrative expectations as of 2026.
Source: Act on the Protection of Personal Information (consolidated as of April 1, 2023), Article 171; PPC Guidance for Overseas Business Operators (English).
The four statutory breach notification triggers — APPI Article 26(1) and PPC Enforcement Order Article 8 detailed analysis
Japan’s Act on the Protection of Personal Information (APPI) Article 26(1) requires notification to the Personal Information Protection Commission (PPC) and affected data subjects only if a breach (leak, loss, or damage) falls within one of four statutorily prescribed categories. These triggers are further defined by Article 8 of the PPC Enforcement Order (Order No. 3 of 2016, as amended), which is the controlling instrument for what constitutes a notifiable breach. Clarity on these triggers is critical for compliance professionals making incident determinations.
1. Sensitive personal information (要配慮個人情報) Any leak, loss, or damage involving “special care-required personal information” as defined by Article 2(3) APPI is notifiable, regardless of the number of individuals involved. This covers personal data revealing race, creed, social status, medical history, criminal record, history of being a crime victim, and other attributes with potential for discrimination or harm. Article 8(i) of the Enforcement Order cross-references this definition directly; if any portion of the breached data falls into this category, notification is triggered.
2. Data with risk of property damage Notification is triggered if the breached data “may, through improper use, cause property damage to an individual” (Article 8(ii)). This typically means personal data such as credit card numbers, bank account information, e-commerce login details, or authentication credentials, but may extend to identity documents or other data usable in fraud. The PPC FAQ confirms this includes not just direct monetary loss, but broader risk of financial harm, fraud, or identity theft (“財産的被害のおそれがある場合”—if there is a risk that improper use may cause property damage). The determination is case-by-case: if the breached dataset could realistically enable unauthorized financial transactions or fraud, the threshold is met.
3. Leak due to wrongful purpose or improper act (including cyberattacks) Notification is required for leaks, losses, or damage “when there is a suspicion that improper use by wrongful means caused the incident” (Article 8(iii)). This is often engaged in cyberattacks, malware/ransomware events, or intentional actions by insiders, but does not require proof—a reasonable suspicion, based on available facts, suffices. The PPC Enforcement Order and official Q&A clarify that both confirmed and suspected scenarios are covered. The trigger applies regardless of the affected data type or number of individuals.
4. Volume threshold — 1,000 or more individuals If a breach (confirmed or reasonably suspected) involves personal data relating to 1,000 or more individuals, notification is mandatory (Article 8(iv)). There is no special limitation by data type: this applies to any qualifying personal data set. The count should be based on the maximum number reasonably believed to have been affected, and, per PPC FAQ guidance, estimates are permitted where an exact count is unavailable at time of notification. If later investigation reveals fewer affected, an update may be filed with the PPC.
Summary of application Under Article 26(1) APPI and Article 8 Enforcement Order, meeting any one of these four triggers — special care-required information, risk of property damage, breach through improper act, or 1,000+ individuals affected — makes both PPC notification and (with limited carve-outs) data-subject notification mandatory. The PPC expects risk assessments and threshold determinations to be documented, drawing directly from the order and evolving FAQ guidance. Threshold application is fact-specific and should be anchored in primary sources for each incident.
Source: Act on the Protection of Personal Information (consolidated as of April 1, 2023), Article 26(1), Article 2(3), Personal Information Protection Commission Enforcement Order (Order No. 3 of 2016, as amended), Article 8 (Japanese), PPC FAQ on Personal Data Leakage Incidents (Japanese)
Communicating breaches to third-party recipients of personal data — PPC expectations and APPI guidance
Japan’s Act on the Protection of Personal Information (APPI) does not expressly require notification to third-party recipients of personal data in the event of a breach, but the Personal Information Protection Commission (PPC) has adopted a clear expectation that business operators will take prompt and reasonable steps to notify downstream recipients (such as partner companies or vendors) if the incident poses ongoing risks of unauthorized use, onward transfer, or harm. This expectation is grounded in the PPC Guidelines for the Act on the Protection of Personal Information (General Rules, Section 2-7-3-2) and the official Breach Notification Q&A.
The PPC Guidelines (General Rules, Japanese §2-7-3-2) advise that when a leak, loss, or damage of personal data occurs, the operator should, in addition to filing reports required by Article 26, also “contact any third parties who have received the relevant personal data if there is a risk that improper use or further leakage may result.” The Guidelines emphasize cooperation:
- The operator should promptly inform the third party of the facts and urge deletion, suspension of use, or necessary containment steps to minimize risk to individuals.
- Documentation of the content and timing of this communication should be retained as part of the incident-response record, as the PPC may request evidence of risk-minimization steps in the event of audit or post-breach investigation under APPI Article 146.
The PPC’s Official Breach Notification Q&A similarly calls on organizations to work with third parties to prevent further proliferation or misuse of the breached data, and to verify that partners implement appropriate technical or organizational remedial measures (such as access suspension, account verification, or secure deletion).
This duty to notify and cooperate with third-party recipients flows from the broader APPI requirement to take “necessary and appropriate” action to protect data subjects following a breach (APPI Art. 23, safety management measures), as well as the PPC’s power to oversee incident response. Operators are not subject to administrative penalties solely for failure to contact third parties, but PPC may publicly identify organizations whose breach response is found to be inadequate due to missed opportunities to contain risk through partner communication.
Operators should consult the full Guidelines and Q&A (Japanese originals) for current language and compliance expectations when managing supplier or partner communications after a breach involving shared or transferred personal data—this is a consistently scrutinized aspect of post-incident PPC practice.
Source: Personal Information Protection Commission Guidelines for the Act on the Protection of Personal Information (General Rules), PPC Official Breach Notification Q&A (Japanese)
Definition of 'personal data' for breach notification — APPI Article 2 and scope of Article 26 duty
Japan’s Act on the Protection of Personal Information (APPI) establishes breach notification obligations under Article 26 only for incidents involving "personal data" (個人データ). Understanding exactly what constitutes personal data—and distinguishing it from other categories such as general "personal information" (個人情報), "retained personal data" (保有個人データ), and pseudonymized/anonymized information—is essential for any practitioner assessing breach-reporting duties.
## Legal definitions: personal information vs. personal data
- Personal information (個人情報) is defined in Article 2(1) APPI as information about a living individual that can identify the individual by name, date of birth, or other descriptions, or that contains individual identification codes (e.g., driver’s license or passport numbers).
- Personal data (個人データ) is a subset of personal information, defined in Article 2(6) as personal information that comprises part of a "personal information database, etc." (個人情報データベース等)—meaning a systematic collection of information that enables search or aggregation by computer or by structured manual means.
- Retained personal data is a further subset (Article 2(7)), relevant for data subject access but not for breach reporting.
Under Article 26, breach notification duties only attach to leaks, loss, or damage concerning personal data—not merely any information about individuals. If information subject to an incident does not qualify as part of a personal information database (for example, random notes or unstructured paper files not systematically organized for search), the Article 26 notification triggers do not apply.
## Exclusions: pseudonymized and anonymized information
- Pseudonymously processed information (PPI) (仮名加工情報), defined in Article 2(5), and anonymized personal information (API) (匿名加工情報), Article 2(6), are categorically excluded from the Article 26 breach regime (see Article 41 and Article 43): breaches involving only PPI or API are not notifiable to the Personal Information Protection Commission (PPC) or data subjects, regardless of the volume or sensitivity of the data affected.
## Practical impact and PPC guidance
PPC Guidelines clarify that the scope of breach reporting is coextensive with the operator’s holdings of personal data as defined by Article 2(6): only systematic, searchable sets of personal information—whether stored electronically or in structured paper files for regular retrieval—fall within the statutory scope. Occasional handwritten notes, one-off paper records, or information irreversibly anonymized fall outside the duty. For any incident, a threshold question for practitioners is whether the compromised information meets the strict definition of personal data under APPI.
This statutory scoping also governs breach notifications by processors and applies to both domestic and foreign operators (see Article 171 extraterritorial effect). Definitions and exclusions should be reviewed at the outset of breach assessment.
Source: Act on the Protection of Personal Information (consolidated as of April 1, 2023), Articles 2(1), (5)-(7), 26, 41, 43; Personal Information Protection Commission Guidelines for the Act on the Protection of Personal Information (General Rules)