Japanese privacy compliance is not only about consent; it asks what data will be used for and where it will go. These FAQs cover purpose, identification, third-party and cross-border transfers, cookies, outsourcing, and data-subject requests, helping teams test policy against actual data flows.
It depends. The determining factor is not what the data consists of, but whether your company can use it to identify a specific individual. Typical examples of personal information are names, addresses, dates of birth and facial photographs. Job titles and departmental affiliations, purchase histories, browsing histories, cookies and device IDs cannot on their own identify a specific individual. But once they have been linked to a specific individual, they become personal information. Data from which you cannot identify a specific individual has a separate category in Japan, called personally referable information (個人関連情報). The term refers to data that relates to an individual but is not sufficient on its own to identify that individual. Browsing histories, purchase histories and service usage histories collected through device identifiers such as cookies fall into this category. Before you provide data in this category to a Japanese advertising partner, you have to confirm that the principal (本人), meaning the individual the data is about, has given consent.
WhyThere is a point in this rule that runs against intuition. What decides whether you can provide the data to a partner is not the nature of the data your company holds, but how the party receiving it intends to use it. If the recipient is expected to link the data to its own database and acquire it as personal data, there are steps you have to take before you provide it. So when you negotiate a partnership, establish first what data the recipient holds and what it plans to do with your data.
What To Do1. Start with a check inside your own company. List the cookies, device IDs and browsing histories you hold, and go through them category by category. For each category, ask whether your company can readily collate the data with other information it holds and identify a specific individual, or whether the data contains an individual identification code (個人識別符号). If either applies, that data is already personal information and does not fall under personally referable information. If neither applies, go to step 2. 2. Before you provide personally referable information to a partner, confirm two things. First, will the partner link it to its existing database and acquire it as personal data? If so, you have to confirm first that the principal has consented to the provision of the data to that partner. Second, if the partner receiving your data is located outside Japan, you have to confirm not only that the principal has consented to the provision, but also that information on the system for the protection of personal information in the country where the recipient is located has been provided to the principal. 3. If you hold personal data collected previously and want to analyse it internally, there is another route: process it into pseudonymously processed information (仮名加工情報). This means processing the data so that a specific individual cannot be identified without collating it with other information. Once you have done this, you can use the data for purposes other than the purpose of utilization you notified to the principal or publicly announced, without obtaining consent again. This route is designed with internal analysis in mind, and pseudonymously processed information cannot in principle be provided to third parties. For distribution outside your company, there is a different category, called anonymously processed information.
No. Prior consent is not required. The key question is not whether the data crosses a border, but whether the recipient is part of the same legal entity as your company. Under Japan's Act on the Protection of Personal Information (APPI), whether a recipient is a third party depends on whether it is part of the same legal entity. The same test applies when determining whether the recipient is a third party in a foreign country. A branch is not a separate legal entity: it is part of the same company as its head office. Therefore, when a Japanese company provides personal data to its own branch or office overseas, or when the Tokyo branch of a foreign company provides personal data to that company's head office, neither arrangement constitutes a provision of personal data to a third party in a foreign country. The result is different for a subsidiary established as a separate Japanese company. A subsidiary is a separate company. Even if its shares are held by your Taiwanese company, the two are separate legal entities. Providing personal data from your Japanese subsidiary to your Taiwanese parent company constitutes a provision to a third party in a foreign country, and in principle prior consent from the individuals concerned is required.
WhyA common trap for Taiwanese teams operating in Japan is treating data synchronisation within a corporate group, or access by a Taiwanese development team, as internal company use. When this happens, the step of determining whether Japanese law treats the arrangement as a provision to a third party, or as a provision to a third party in a foreign country, is skipped entirely. In other contexts, the distinction between a branch and a subsidiary looks like a mere difference in registration procedure. When it comes to whether prior consent is required, the two produce opposite results. And even when the recipient is part of the same legal entity and no consent is required, one obligation remains. Under the APPI, understanding the external environment, which includes understanding the personal information protection system of the country where the data is stored, is part of the required security control measures. Consent is not required, but responsibility for keeping that personal data secure remains with your company.
What To Do1. First, determine whether the recipient is part of the same legal entity as your company or is a separate legal entity. A transfer from your Japanese branch to your head office in Taiwan is an internal transfer within the same legal entity. A transfer from your Japanese subsidiary to your Taiwanese parent company, to another company in Taiwan, or to an external service provider is a transfer to a separate entity. 2. If the recipient is part of the same legal entity, consent is not required, but you must understand the external environment. Understand the personal information protection system of the country where the data is actually stored, and determine and implement appropriate security control measures on that basis. The Personal Information Protection Commission has published model wording stating that a company implements security control measures after understanding the personal information protection system of Country A, where the personal data is stored. Your public disclosure also has to state that you take these steps. 3. If the recipient is a separate legal entity, there are two routes. The first is to obtain prior consent from the individuals concerned. Before obtaining consent, you must provide them with three categories of information: the name of the country to which the data will be transferred, information on that country's personal information protection system, and information on the measures the recipient will take to protect the personal information. The second route is to establish, by contract or a similar arrangement with the recipient, a system ensuring that the recipient continuously implements measures equivalent to those required under the APPI. In practice, decide which route to use before preparing the necessary documents.
No. What the two regimes require takes a different shape, and translation does not close that gap. Japan does not require the consent of the individuals concerned for everything. It sets separate rules for separate situations, and you have to work through them one situation at a time. Taiwan and Japan do have common ground in how they regulate personal data: both require you to handle personal data properly, and both require you to explain what you are doing to the individuals concerned. The difference lies in the structure. The APPI does not make "consent is required for collection and use" a general rule. It sets separate rules for separate situations, one set of rules for each. By situation we mean what you do with the data and what kind of data it is. The situations that carry separate rules include: the purpose for which you collect the data, whether you use it for a purpose you did not state at the outset, whether you provide it to a third party, whether it includes special care-required personal information, and whether you provide it to a third party in a foreign country. Translating your Taiwanese privacy policy into Japanese may therefore leave gaps in the explanations, the consents and the cross-border arrangements the APPI requires. Two common omissions in Taiwanese companies' privacy policies are these: which parties in Taiwan the data will be provided to, and what Taiwan's personal information protection system looks like. Without these two, once the data goes to your Taiwanese parent company or another business in Taiwan, you run the risk of breaching the APPI.
WhyThe difference between Taiwan and Japan is not only in the text of the law. It is also in who supervises and how firmly the law is enforced. Japan has established the Personal Information Protection Commission as its supervisory authority, and for certain types of violation a company can face a fine of up to 100 million yen. Other types of violation may also be subject to various penalties. Do not look only at what the provisions say. Build the strength of enforcement into your assessment of personal data compliance risk. There is one more point that is easily skipped. Behind the single phrase "synchronising data back to Taiwan" there may be two different data flows. In one, your Japanese company collects the personal data and provides it to your Taiwanese parent company. In the other, your Taiwanese company collects the personal information directly from users in Japan. The two may be treated differently under Japanese law. What Japanese law looks at is the data flow underneath, not the outcome of synchronising data back to Taiwan.
What To Do1. Do not take a privacy policy translated from Taiwan and use it as it is in Japan. Go through your data flows situation by situation. The situations to go through include: the purpose for which you collect the data, whether you use it for a purpose you did not state at the outset, whether you provide it to a third party, whether it includes special care-required personal information, and whether you provide it to a third party in a foreign country. Japanese law sets different rules for each situation, so check them one at a time. 2. First establish the three parties involved in the data flow: which company provides the service in Japan, which company actually collects the data from the individuals concerned, and which company in Taiwan views and uses it. If the three answers differ, the rules that apply under Japanese law also differ. Establish this first, then decide what to do. 3. Even before you have everything in place, start by adding two items to your existing privacy policy. First, which parties in Taiwan the data will be provided to. Second, what Taiwan's personal information protection system looks like. These two are common omissions in a policy translated from Taiwan.
Japan's Act on the Protection of Personal Information (APPI) requires you to make the purposes for which you will use personal information known to the individuals to whom it relates. At a minimum, two basic tasks have to be completed first. 1. Define the purposes for which you will use the personal information. 2. Prepare the information you will provide to those individuals. The individuals here are not only the users you serve or sell to in Japan, but also your employees. The timing depends on how the personal information is acquired. There are two main situations. The first is ordinary acquisition. If you have already made the purpose of utilization public, you do not need to give further notice when acquiring the information. Otherwise, you must promptly notify the individual after acquisition, or make the purpose public. The second is acquisition on entering into a contract. Where the personal information of an individual is set out in a contract or another written document as you enter into that contract, you must state the purpose of utilization to that individual expressly in advance, that is, tell them clearly. When defining the purposes of use, consider foreseeable future uses at the same time. The APPI limits later changes. Any revised purpose must remain within a scope that can reasonably be regarded as related to the purpose before the change. If you want to add a use you did not write down at the outset, you first have to judge whether it falls within that scope, and in practice that judgement is not always easy. The safer approach is therefore to bring together the departments inside your company that will use the data, before you acquire any personal information, and work through the uses you may need in future so that none are missed.
WhyThe contract is not signed and no data has come in, so this preparation can look as though it could wait. But the relevant trigger under the APPI is the act of acquisition. The moment the first personal information for your Japan operations reaches you, the duty to inform has already arisen, and what you have to inform those individuals of is precisely your purpose of utilization. If the purpose of utilization is not settled, you cannot write what you have to tell them. That is why this work must be completed before the data arrives. There is one more thing to think through at the same time. Writing a privacy policy of the standard the APPI requires depends on first mapping your end-to-end data flows. What personal information you collect, what you use it for, how you manage it, whether you provide it to anyone else, whether you use services outside Japan: you need answers to all of these first.
What To Do1. Before you acquire any personal information for your Japan operations, specify the purposes of use as far as you can. Do not leave this to a single department: bring together every department that will use the data. 2. Put what you are going to tell those individuals into writing, then decide, according to how you acquire the data, when it must be presented or made available to them. If you are going to make it public in advance, publish it before your website goes live. If you acquire personal information on entering into a contract, state it expressly before signing. 3. Take an e-commerce site as an example. First work through the following. What personal information you will collect, what you will use it for, and how you will manage it. Whether you will provide personal information to, or outsource its handling to, delivery companies, payment processors, marketing-tool providers and similar service providers. Whether you will use businesses or cloud services outside Japan, whether you will use the same personal information jointly with another company, and whether you will transform the personal information before using it further. How you will respond when a user requests disclosure or correction of their personal information. Once you have checked and thought through each of these, use the results to draft a privacy policy your readers can understand. If you skip this step, the policy can easily omit practices that your business actually carries out.
That wording is not specific enough. Japan's Act on the Protection of Personal Information (APPI) requires the purpose of utilization to be stated clearly enough for both the business and the individual to understand how the personal information will be used. The statutory wording is that the purpose of utilization must be specified "as much as possible". To meet that standard, the wording must be clear from two perspectives. From the business's perspective, it must clearly identify the purposes for which the personal information may be used. From the individual's perspective, it must enable the individual to reasonably anticipate how their personal information will be used. Japan's Personal Information Protection Commission (PPC) gives two examples of wording that does not meet this standard: "for our business activities" and "to improve customer service". Both describe only a broad objective and do not specify the purpose of utilization as much as possible. Your current wording is likewise not specific enough.
WhyThe APPI provides a benchmark for the required level of specificity. Both the business and the individual must be able to generally and reasonably anticipate and assess how the personal information will be used. The key question is whether the intended use is reasonably foreseeable to both. There is no universal template that can simply be copied. The required level of specificity depends on the nature of the personal information and the type of business involved. You can reuse the structure, but not the wording itself.
What To Do1. Find every statement of purpose in your current privacy policy and put each one through two tests. (1) Read it yourself. Can you say clearly which uses it covers and which it does not? (2) Show it to someone who was not involved, for example a colleague who has not worked on that product line. Can that person explain what the company intends to use the personal information for? If either test fails, rewrite that statement. 2. When you rewrite a statement, build it around three elements. (1) Who will handle or use the personal information, including whether this is limited to your own company. (2) What kind of business you are in. (3) What you will specifically do with the personal information. A statement that meets the standard reads like this: "当社が発行する住宅地図の作成・販売のため", which means "for the production and sale of the residential maps we publish", a residential map being a Japanese map product that marks house numbers and households. All three elements are there. "Our company" identifies the handling entity, "the residential maps we publish" identifies the relevant line of business, and "production and sale" states what is specifically done. 3. Of these three elements, the handling entity is particularly easy to omit. Before drafting, determine whether anyone outside your own company will use the personal information. If your company alone will use it, say so. If other group companies or external service providers will also use it, do not identify your company as the sole user.
They can take you to court. Under Japan's Act on the Protection of Personal Information (APPI), all three of these requests, to see the data, to have it corrected and to have its use stopped, are rights the individual holds. They are understood to be legal rights that can be asserted in court. They cannot go straight to court the moment you refuse. The APPI requires them to make the request to you outside court first. The email you have received is that step. Once two weeks have passed from the day that out-of-court request for disclosure reached you, they can bring proceedings. If you refuse the request outright, they do not have to wait the two weeks and can bring proceedings straight away. The procedure for exercising all three of these rights is the same, so work out how to handle the request to see the data, that is, the disclosure request, and the other two follow the same steps. Disclosure requests are thought to be the most common of the three. Typical subjects of a disclosure request include a request to a medical institution for medical records, and a request to a financial institution or a credit information agency for transaction histories and credit information.
WhyThe two weeks run from the day the email reached you, not from the day you decide to deal with it. If you put the email into your ordinary customer support queue, the risk is high. By the time you remember it, or the queue reaches it, the day on which they can bring proceedings may already have arrived. This prior request is deemed to have arrived at the time when it ordinarily should have arrived. Therefore, even if its arrival is delayed or prevented for reasons attributable to your company, the individual will be in a position to bring proceedings once two weeks have passed. There are two more situations you cannot leave unanswered. The first is where you decide not to disclose because a ground for non-disclosure applies. The second is where you have checked and hold no personal data on the person making the request. In either case, you are understood to be required to notify the individual without delay. Not handing over the data and not replying are two different things. Providing notice is what the APPI requires. It is not merely a courtesy.
What To Do1. When an email like this arrives, the first thing to do is record the date it reached you. The two weeks run from that date. Keep this step separate from how you plan to reply. Decide in advance where that date is recorded, so that it does not sit only with the person who received the email. 2. Check which method the person is asking you to use. The APPI lets the individual specify the method, and there are three options. The first is provision of an electromagnetic record, that is, giving the individual the data as an electronic file. The second is delivery of a paper document, that is, printing out the data and giving it to the individual. The third is another method designated by the business operator, that is, one your company has set itself. If your company has not designated such a method, that third option is unavailable. 3. The two situations in which you do not hand over the data also call for a reply. When you decide not to disclose because a ground for non-disclosure applies, notify the individual. When you have checked and hold no personal data on that person, notify the individual as well. Do both without delay.
It does. The decisive point is not where your company is based, but whom you provide goods or services to. Japan's Act on the Protection of Personal Information (APPI) has a provision written for exactly this situation, known as extraterritorial application. It means that, where the specified conditions are met, the APPI applies even when personal information is handled outside Japan. Three conditions have to be met together for the provision to operate. The first is that you are a business operator that handles personal information. The second is that your handling of the data relates to the provision of goods or services to persons in Japan. The third is that the individuals whose personal information you handle are persons in Japan. What the third condition looks at is whether the person is in Japan, not which country's passport they hold. Whether you obtained the data directly from the individual does not affect the answer. Where extraterritorial application applies, it is not limited to a foreign operator that obtains the data directly from the individual. It also covers a foreign operator that receives the data from a third party and handles it. Once you fall within the provision, if you breach the APPI, Japan's Personal Information Protection Commission may issue guidance, advice, a recommendation or an order.
WhyThis provision was amended once, in 2020. Before the amendment, an investigation by the Personal Information Protection Commission into a foreign operator could take only the form of a voluntary investigation, such as interviews and other voluntary inquiries. A voluntary investigation rests on the operator agreeing to cooperate. Where the operator did not cooperate, it was difficult for the Commission to obtain any further material or information from that operator. The 2020 amendment brought demands for reports, on-site inspections and orders within the scope of extraterritorial application. These three additions were considered particularly significant in practice. Since the amendment, the Commission can demand a report from a foreign operator and can issue that operator an order, and failure to comply with an order carries penalties. There is one further measure beyond penalties. Where an operator fails to comply with an order, the Commission can make that fact public. After this amendment, the view that "we have no company in Japan, so this does not concern us" is no longer readily tenable.
What To Do1. Ask yourself two questions and check where your company stands. (1) Do you provide goods or services to persons in Japan? (2) Are the individuals whose personal information you handle persons in Japan? If the answer to both is yes, the handling you carry out in Taiwan falls within the scope of Japan's personal information law. 2. Do not treat "we did not obtain this data directly from the individual" as a reason for assuming that the Act does not apply. Data you received from a partner or another third party and then handled yourself falls within the same scope. 3. Check yourself against the three cases set out in the guidelines issued by Japan's Personal Information Protection Commission. If any one of them applies, the handling falls within the APPI's extraterritorial scope. (1) A foreign online retailer handles the personal information of consumers in Japan in connection with selling and delivering goods to them. (2) A foreign email service provider handles the personal information of consumers in Japan in connection with providing an email service to them. (3) A foreign app provider handles pseudonymously processed information created from the personal information of consumers in Japan for the development of a new service, in connection with providing services to those consumers. Pseudonymously processed information (仮名加工情報) means information processed so that a specific individual cannot be identified unless it is collated with other information.
You have to address two separate sets of requirements at the same time. The first is the cross-border provision of personal data. The second is the necessary and appropriate supervision of the overseas service provider. Where you entrust personal data to a business operator in a foreign country, that provider is a third party in a foreign country. There are two ways to meet the cross-border provision requirements. One is to obtain the prior consent of the individuals to the provision of their personal data to a third party in a foreign country. The other is to establish, by contract or a similar arrangement with the provider, a system under which the provider continuously implements measures equivalent to those required under Japan's Act on the Protection of Personal Information (APPI). You also have to establish a process for supervising the provider. Where you entrust all or part of the handling of personal data to another party, necessary and appropriate supervision of that party is required. The purpose of supervision is to ensure that the personal data whose handling you have entrusted is kept properly secure. Outsourcing the work does not shift responsibility away from your company. Where the provider handles personal data in breach of the APPI, including a leak of personal data, you as the entrusting party will be called to account for a breach of your duty of supervision.
WhyThe APPI does not set one fixed answer for how far supervision has to go. It is for you to assess the risk. The guidelines issued by Japan's Personal Information Protection Commission set out the points a business has to look at, and the greater the risk indicated by these factors, the stronger the supervision has to be. (1) The content of the personal data whose handling you entrust. (2) The scale of the harm to the rights and interests of the individuals if a data breach or similar incident occurs. (3) The scale and nature of the business you entrust. (4) How the personal data is actually handled, including the nature and volume of the data involved. There is a point here that runs against intuition. Concluding an outsourcing agreement is not itself an obligation the APPI places on a business. The obligation is supervision, and concluding an agreement is one means of achieving it. So the question to ask is not whether you have signed an agreement, but whether what you are actually doing amounts to necessary and appropriate supervision.
What To Do1. After considering factors (1)-(4) above, consider fulfilling your duty of supervision through the following three measures as necessary and appropriate measures. (1) Selecting an appropriate provider. (2) Concluding an outsourcing agreement. (3) Monitoring how the provider handles the personal data. 2. Where the personal data is sensitive, it is regarded as desirable to include five items in the agreement. (1) A clear statement of the responsibilities of the entrusting party and of the provider. (2) The specific content of the security control measures. (3) The conditions for subcontracting, that is, whether the provider may pass the work on to another company and on what terms. (4) The return and deletion of the data after the outsourcing ends. (5) Reporting on the state of handling, and how you audit it. 3. Check compliance with the cross-border provision requirements and supervision of the service provider separately. Neither can substitute for the other. Signing an outsourcing agreement with the provider does not mean you have met the cross-border provision requirements. Obtaining prior consent from the individuals does not mean that you have fulfilled your supervision obligations.