APPI Japan
Definition
APPI Japan
APPI Japan refers to the Act on the Protection of Personal Information, the statute governing personal data handling by businesses operating in Japan. Entrusting data triggers a supervision duty, which is the provision that outsourcing buyers most often overlook.
The Act dates from 2003 and has been amended repeatedly, with the consolidated text reflecting amendments in force from April 2023.
Japan’s regime is administered by the Personal Information Protection Commission, which publishes the official English translation businesses rely on.
The design is notably practical. Where European law prescribes contract contents, Japanese law imposes a duty to supervise — and leaves you to work out what adequate supervision looks like.
Key takeaways
- Entrusting personal data handling creates a statutory duty to supervise the entrusted party.
- The Act separates entrustment from third party provision, and the distinction changes the consent position.
- Transfers to recipients in other countries carry their own consent and disclosure duties.
- Japan holds a European adequacy decision, which shapes how buyers structure work.
How it works
The supervision duty is short and broad. If a business entrusts another person with all or part of the handling of personal data, it must exercise the necessary and adequate supervision over the person it entrusts.
That framing matters commercially — entrustment is not treated as provision to a third party, so it does not need the consent that a genuine third party disclosure would require.
Third party provision is the stricter path. A business must not provide personal data to a third party without the individual’s prior consent, subject to defined exceptions.
| Arrangement | Consent needed? | Duty that applies |
|---|---|---|
| Entrusting handling to a provider | No | Necessary and adequate supervision |
| Providing data to a genuine third party | Yes | Prior consent, with exceptions |
| Providing to a recipient abroad | Yes | Consent plus information about that country’s regime |
| Joint use with named parties | No | Advance notification of the arrangement |
| Business succession | No | Purpose limits carry across |
Cross-border work adds a disclosure step — before providing personal data to a third party in a foreign country, the business must obtain consent and provide information on that country’s personal information protection system.
The Commission maintains the authoritative materials, including the consolidated text as of April 2023 with all amended Acts in full force.
Examples
Japanese companies outsource heavily within Asia, and the supervision duty follows every arrangement. Each arrangement here shows the rule colliding with a delivery model it never anticipated.
A Tokyo insurer runs policy data entry from Cebu. The arrangement is entrustment rather than third party provision, so no customer consent is needed, but the insurer must supervise the Philippine team in practice.
A retailer moves its customer analytics to a Singapore affiliate. Because the recipient sits abroad and the arrangement is provision rather than entrustment, consent and a country disclosure both apply.
A Japanese manufacturer uses an Indian development partner for a system that touches employee records. Supervision here means reviewing access logs and test data handling, not collecting an annual questionnaire.
A bank entrusts card dispute handling to a domestic vendor that subcontracts overnight cover. The bank’s supervision duty extends to that second tier, which its original assessment never examined.
Related terms
Japanese terminology sits between the European and Anglo-American traditions, and the borrowed words do not always carry borrowed meanings. The terms here are related but not interchangeable, which is the whole point.
- GDPR outsourcing: the European processor contract, which prescribes what Japan leaves to judgement.
- PDPA outsourcing: the Singapore regime, with a comparable intermediary structure.
- ISO 27001 outsourcing: the security certification often used as supervision evidence.
- Vendor management outsourcing: the programme through which supervision actually happens.
- Back office outsourcing: the work type that creates most entrustment relationships.
- Knowledge process outsourcing (KPO): higher-judgement work carrying richer personal data.
- Compliance outsourcing: contracting the compliance function itself rather than the processing.
FAQ
What counts as adequate supervision?
The Act does not define it exhaustively. In practice it means selecting the provider carefully, setting terms, and checking performance often enough to notice a problem.
Is entrustment the same as a third party transfer?
No. Entrustment is handling on your behalf and does not require consent, while genuine provision to a third party does.
Does the Act reach providers outside Japan?
The duty sits on the Japanese business. Offshore providers feel it through the contract and the supervision that business is obliged to perform.
Why does Japan’s adequacy decision matter?
It allows personal data to move from Europe to Japan without additional safeguards, which affects how multinational delivery models are structured.
Are there breach notification duties?
Yes. Businesses must report qualifying leaks to the Commission and notify affected individuals, following the amendments consolidated in the current text.
Who publishes the official English text?
The Personal Information Protection Commission, alongside the government translation service, maintains the versions businesses should work from.
Compare Outsource Accelerator and keep the providers who treat the obligation as theirs too.







Independent




