Jurisdiction
Japan
- Source
- Editorial review of primary sources — not yet re-anchored
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01Framework
Japan regulates personal data under the Act on the Protection of Personal Information, enforced by the Personal Information Protection Commission. A further amending act was promulgated on 17 July 2026 and will commence on a date fixed by Cabinet Order, so the law is in a known state of change. AI is governed by promotion and guidance rather than prohibition: the AI Promotion Act of 2025 sets national policy and creates an AI Strategy Headquarters without imposing penalties on deployers, and the MIC and METI AI Guidelines for Business, now at version 1.2, carry the practical expectations.
- Region
- North Asia
- ISO code
- JP
- Privacy framework
- Act on the Protection of Personal Information (個人情報の保護に関する法律, Act No. 57 of 2003). Requires the purpose of use to be specified and adhered to, restricts acquisition and third-party provision, sets security control measures, and imposes duties when personal data is entrusted to a contractor — which is what using a model provider usually is. Transfers to a third party in a foreign country are subject to their own regime, with an information duty to the individual. The e-Gov entry currently shows unenforced provisions pending, so check which version applies before relying on an article number.
- AI-specific rules
- No prohibition-style AI statute. The Act on Promotion of Research, Development and Utilization of AI-Related Technologies (Act No. 53 of 2025) was promulgated on 4 June 2025 and came fully into force on 1 September 2025; it establishes an AI Strategy Headquarters and directs national policy, and does not create deployer offences. The operative expectations sit in the AI Guidelines for Business, published jointly by the Ministry of Internal Affairs and Communications and METI and updated to version 1.2 on 31 March 2026. The Personal Information Protection Commission issued a cautionary notice on the use of generative AI services in June 2023, addressed both to businesses generally and, separately, to OpenAI.
- Last reviewed
- 20 Aug 2026
- Status
- published
Cross-border transfer
The APPI treats provision of personal data to a third party in a foreign country as its own category, with an information duty to the individual about the destination country and the recipient’s protection measures. Where a country has been recognised as having an equivalent standard, or where the recipient has put in place measures meeting the Commission’s standards, the analysis differs. Because sending a prompt to an overseas model provider is normally both entrusted processing and a cross-border provision, the two questions have to be answered separately: what the entrustment requires by way of supervision, and what the cross-border route requires by way of information and safeguards.
Regulators
Primary sources
- Legislation個人情報の保護に関する法律 — e-Gov 法令検索
- Legislation人工知能関連技術の研究開発及び活用の推進に関する法律 — e-Gov 法令検索
- Regulator page個人情報保護委員会 — 令和8年 改正個人情報保護法について
- Regulator guidance個人情報保護委員会 — 生成AIサービスの利用に関する注意喚起等について
- StandardAI事業者ガイドライン(第1.2版)— 経済産業省
- Regulator page内閣府 — AI法(人工知能関連技術の研究開発及び活用の推進に関する法律)
- Regulator pagePersonal Information Protection Commission — English site
02Regulations and guidance
| Instrument | Status |
|---|---|
| AI Guidelines for BusinessJoint guidance from the Ministry of Internal Affairs and Communications and METI for businesses developing, providing or using AI. Version 1.2 is the current edition, superseding 1.0, 1.01 and 1.1. Non-binding, but it is the reference point Japanese counterparties and procurement teams use when asking how an AI deployment is governed. | In force |
| AI Promotion ActA promotion statute. Defines AI-related technologies, sets national and local government responsibilities, and establishes an AI Strategy Headquarters chaired by the Prime Minister. It contains no penalties and imposes no direct obligations on a company deploying AI; its effect on a deployment is indirect, through the policy and guidance it drives. | In force |
| APPIJapan’s personal information statute. Specifies the purpose of use and holds processing to it, restricts acquisition and third-party provision, requires security control measures, and imposes supervision duties when handling is entrusted to a contractor. Cross-border provision has its own regime with an information duty. The e-Gov entry marks provisions that are promulgated but not yet in force. | Partly in force |
| APPI 2026 AmendmentAmending act promulgated on 17 July 2026. Its main body commences on a date to be fixed by Cabinet Order within two years of promulgation, with earlier tranches for some provisions. The Commission has published an implementation programme and is still preparing the orders, rules and guidelines beneath it. | Adopted, not yet applicable |
| PPC Generative AI NoticeCommission notice on generative AI. Tells businesses to confirm that entering a prompt containing personal information stays within the necessary scope of the specified purpose of use, and records that a separate cautionary notice was issued to the developers of ChatGPT. | In force |
03Common enterprise issues
Data processing agreement
Entrusting processing carries a supervision duty
Using a model provider is usually entrustment. The APPI expects necessary and appropriate supervision of the contractor, which means contract terms plus evidence that you actually check — not a signature and a filing cabinet.
Transparency
The purpose of use has to cover the AI feature
A purpose-of-use statement written for a document management system rarely covers indexing that content for a generative assistant. Extending the purpose is a specific step with its own notification consequences.
Prompt leakage
The PPC has already spoken about prompts
The June 2023 cautionary notice tells businesses to confirm that entering personal information in a prompt stays within the specified purpose of use. It is the clearest statement of what the regulator expects from staff usage.
Personal data
The Act is mid-amendment
Act No. 56 of 2026 was promulgated on 17 July 2026 with staged commencement, and new concepts including specified biometric identifiers appear in it. Design decisions with a multi-year life should account for it.
04Vendor restrictions
Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.
No vendor restriction has been recorded for this jurisdiction.
05Stacks with notes for this jurisdiction
No published stack carries a compliance note for this jurisdiction yet.
06Evidence
Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.
No sources were recorded for this answer. Nothing on this page should be treated as verified.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.