Skip to main content
Category: Laws and Regulations

Act on the Protection of Personal Information

Also known as: APPI, Japanese Act on the Protection of Personal Information, Japan's Data Protection Act
Simply put

The APPI is Japan's national data protection law, which sets rules for how organizations handle personal information about individuals. It aims to protect the rights and interests of people while allowing personal data to be used in a proper and orderly way. Note that the acronym 'APPI' is also used by unrelated organizations, but in a privacy context it refers to this Japanese law.

Formal definition

The Act on the Protection of Personal Information (APPI) is Japan's principal data protection statute governing the handling of personal information by businesses and organizations. According to the evidence, its stated objective is to protect the rights and interests of individuals while ensuring the smooth and proper management of processes or services and considering the appropriate utilization of personal data. The evidence provided does not detail the APPI's specific provisions on cookies, online tracking technologies, or consent standards; any application of the APPI to cookie consent obligations would require reference to the Act's actual text and to guidance from the relevant Japanese authority, which are out of scope here. Practitioners should also be aware that Japan's rules on cookie consent may differ substantially from EU frameworks under the ePrivacy Directive and GDPR.

Why it matters

The APPI is Japan's principal national framework for the protection of personal information, and it is significant for any organization that handles data about individuals in Japan or offers goods and services to people there. Its stated objective is to protect the rights and interests of individuals while ensuring the smooth and proper management of processes or services and allowing for the appropriate utilization of personal data. For privacy officers and compliance teams operating across multiple jurisdictions, the APPI represents a distinct regime that cannot be assumed to mirror EU or US rules; compliance with the GDPR or a US state privacy law does not automatically satisfy the APPI, and vice versa.

For cookie consent and online tracking specifically, practitioners should be cautious. The evidence provided here does not detail how the APPI treats cookies, tracking pixels, SDKs, or similar technologies, nor does it establish a specific consent standard for them. Any conclusion about whether and how the APPI applies to cookie consent obligations would require reference to the actual text of the Act and to guidance from the relevant Japanese authority, both of which are out of scope for this entry. Readers should therefore treat the APPI's application to online tracking as an open question to be resolved against primary sources rather than inferred from EU frameworks.

It is also worth noting that the acronym 'APPI' is used by several unrelated organizations outside the data protection field. In a privacy and compliance context, however, APPI refers to Japan's Act on the Protection of Personal Information, and this entry addresses only that meaning.

Who it's relevant to

Privacy officers and data protection professionals with Japan exposure
Organizations that handle personal information about individuals in Japan, or that target the Japanese market, fall within the scope of the APPI. Privacy teams should treat it as a separate regime from EU or US frameworks and verify its specific requirements against the Act's text and official guidance rather than assuming equivalence with rules they already follow.
Legal counsel managing cross-border compliance
Counsel advising multinational organizations need to account for the APPI as a distinct national framework. Because compliance under one regime does not automatically satisfy another, and because the APPI's treatment of cookies and online tracking is not established by the evidence here, legal teams should consult the Act and relevant Japanese authority guidance directly when assessing obligations.
Web developers and marketing compliance teams operating internationally
Teams deploying cookies, pixels, SDKs, or similar tracking technologies on properties reaching users in Japan should be aware that Japan's consent expectations may differ from EU practice under the ePrivacy Directive and GDPR. This entry does not specify APPI consent standards for such technologies, so those requirements should be confirmed against primary sources before configuring consent behavior for Japanese users.

Inside APPI

Act on the Protection of Personal Information (APPI)
Japan's principal data protection statute governing the handling of personal information by businesses. It sets rules on the acquisition, use, transfer, and security of personal information, and is overseen by Japan's Personal Information Protection Commission (PPC). Its scope and terminology differ from the EU's GDPR, and it should not be assumed to impose identical obligations.
Personal Information and Related Categories
The APPI operates with its own defined categories of information, including personal information and further classifications used in the Act. These definitions are distinct from GDPR concepts such as 'personal data,' so terms should not be treated as interchangeable across regimes.
Personal Information Protection Commission (PPC)
The Japanese supervisory authority responsible for administering and enforcing the APPI, issuing guidance, and handling regulatory matters. Its enforcement positions and guidance may evolve over time.
Cross-Border Data Transfer Rules
The APPI contains provisions addressing the transfer of personal information to third parties located outside Japan, which may involve conditions or safeguards. The specific requirements depend on facts not covered by a general definition and should be confirmed against current PPC guidance.
Relationship to Cookies and Online Tracking
Where cookies, pixels, SDKs, or similar technologies collect information that falls within the APPI's categories, the Act's handling rules may apply. However, the APPI's approach to online identifiers and tracking differs from the EU's ePrivacy and GDPR framework, so EU-style consent expectations should not be assumed to apply in Japan.

Common questions

Answers to the questions practitioners most commonly ask about APPI.

Does the APPI regulate cookies the same way the EU ePrivacy Directive does?
No. Japan's Act on the Protection of Personal Information (APPI) is a general data protection law and does not contain a dedicated consent-before-placement rule for cookies equivalent to the EU ePrivacy Directive. Under the ePrivacy regime, the act of storing or accessing information on a user's device generally triggers a consent requirement regardless of whether personal data is involved. The APPI instead focuses on the handling of personal information and related categories, so cookie obligations under Japanese law arise mainly where cookie data connects to or is treated as regulated information rather than from the mere act of setting a cookie. Organizations operating across both regimes should not assume that satisfying one framework satisfies the other.
If we have a GDPR-compliant consent banner, are we automatically compliant with the APPI?
Not necessarily. The APPI and the GDPR are separate legal regimes with different structures, defined terms, and obligations, so consent mechanics designed for the EU do not automatically transfer. The two frameworks differ in how they classify data, when they require consent, and what disclosures they expect. A banner built around EU opt-in consent standards may address some APPI expectations but may not map cleanly onto Japanese requirements around specific data categories or third-party transfers. Whether a given approach meets APPI obligations depends on facts, including the nature of the data and how it is shared, and typically warrants review under Japanese law rather than reliance on EU compliance alone.
How should we determine whether our cookie-related data falls within the APPI's scope?
Start by analyzing what each cookie or similar technology collects and how it is used, then assess whether that data falls within the categories the APPI regulates. Because the APPI centers on personal information and related concepts rather than the act of setting a cookie, the analysis turns on whether cookie-derived data can be linked to individuals or to regulated categories. Similar technologies such as pixels, SDKs, local storage, and fingerprinting can raise comparable questions and should be reviewed under the same lens. This determination depends on specific facts and often benefits from legal review under Japanese law; a general definition cannot resolve borderline cases.
What should our consent or notice practices account for when we handle third-party data sharing under the APPI?
Third-party sharing is an area where the APPI's requirements can differ from other frameworks, so it typically warrants separate attention in your implementation. Where cookie or tracking data is provided to third parties, you should map the data flows, identify the recipients, and confirm what disclosures or permissions Japanese law expects for those transfers. Because the specific obligations depend on how the data is categorized and the nature of the sharing arrangement, organizations generally should confirm the applicable requirements under the APPI rather than applying assumptions carried over from EU or US practice. This entry does not cover the detailed transfer rules, which should be verified against current Japanese guidance.
Can a consent management platform (CMP) handle our APPI obligations for us?
A CMP can support APPI-related implementation by helping present notices, capture user choices, and maintain records, but it does not replace legal judgment or guarantee compliance. Many CMPs are built primarily around EU frameworks such as opt-in consent and the IAB Transparency and Consent Framework, which may not align directly with APPI concepts. Using such a tool for Japan generally requires configuring it to reflect Japanese requirements and confirming that its categories and workflows map to how the APPI treats the relevant data. Tooling assists compliance, but responsibility for meeting APPI obligations remains with the organization.
What records should we keep to demonstrate our handling of cookie data under the APPI?
As a practical matter, maintaining documentation of your data handling, the choices offered to users, and any third-party sharing arrangements supports accountability and helps you respond to inquiries. Keeping a clear inventory of cookies and similar technologies, the data they collect, and the legal basis or permissions relied on is generally advisable across privacy regimes, including under the APPI. The precise record-keeping expectations under Japanese law are not fully detailed in this entry and can depend on the data involved and current regulatory guidance, so organizations should confirm the applicable requirements rather than assuming a fixed standard.

Common misconceptions

APPI is essentially Japan's version of the GDPR, so GDPR-compliant cookie practices automatically satisfy it.
While both are data protection regimes, the APPI uses its own definitions, categories, and obligations, and is enforced by the PPC rather than EU authorities. Compliance with the GDPR does not automatically establish compliance with the APPI, and each regime should be assessed on its own terms.
The APPI requires the same prior opt-in consent for analytics and advertising cookies as EU law does.
The EU model of prior, opt-in consent for non-essential cookies derives from the ePrivacy Directive and GDPR standards. The APPI's approach to online identifiers and tracking technologies differs, and requirements should not be presumed identical; the applicable obligations depend on how the collected information is categorized under the Act and on current PPC guidance.
Cookie technologies fall outside the APPI because it only concerns traditional personal information.
Where information collected via cookies, pixels, SDKs, or similar technologies falls within the APPI's defined categories of personal information, the Act's handling rules may apply. Whether a given identifier is in scope depends on facts and on how it is classified under the statute.

Best practices

Assess APPI obligations independently rather than assuming GDPR or EU cookie compliance carries over; map how each tracking technology's collected data is categorized under the APPI.
Consult current guidance from Japan's Personal Information Protection Commission (PPC), recognizing that enforcement positions and interpretations may evolve over time.
Where cookies, pixels, SDKs, or comparable technologies are used, evaluate whether the information collected falls within the APPI's categories of personal information before relying on assumptions about scope.
Review cross-border data transfer arrangements separately, since the APPI contains its own conditions for transferring personal information outside Japan that differ from other regimes.
Use qualified, jurisdiction-specific compliance documentation, clearly stating that measures designed for the EU, UK, or US state laws may not satisfy the APPI.
Obtain Japan-specific legal advice for contested or fact-dependent questions, treating consent management tools as support for compliance rather than a substitute for legal judgment.