Japan Market Entry
Do Overseas Sellers Need a Japan-Specific Data-Handling Process Under the APPI?
Bottom line: if you sell to people in Japan, Japan's Act on the Protection of Personal Information reaches you — Article 171 says so explicitly, there is no small-seller exemption, and since 2020 the regulator can demand reports from and issue orders to businesses with no Japanese entity at all. But "the Act applies" is not the same as "you need a separate Japanese compliance programme." The obligations that actually bite an overseas seller are narrower and more specific than a GDPR-style overhaul, and three of them — cross-border transfer, the country-disclosure duty, and the breach clock — are where brands with an otherwise tidy privacy programme get caught. This is a summary from an operations firm, not legal advice.
By Chen Kuan, LAUNOVA
Published
Chen Kuan writes for LAUNOVA about Japan ecommerce market entry and operations across Rakuten Ichiba, Amazon Japan, Yahoo! Shopping, and Shopify. Full company profile →
Most overseas brands selling into Japan meet Japanese privacy law twice, and usually in the wrong order. The first meeting is a Japanese partner asking them to sign an entrustment agreement they did not expect. The second is someone in legal asking, months later, whether the company was ever supposed to have a Japan-specific process at all — and finding that the honest answer is not in any of the market-entry material they have read.
This article answers that second question. It is deliberately scoped to the brand's own baseline duties when it holds Japanese consumers' personal information directly — the Shopify store operated from a head office in Los Angeles or Munich, the customer-service inbox handled in English by a team that has never been to Japan, the CRM sitting on infrastructure in Virginia. We have covered the other scenario separately: what happens to customer data when you change Japanese agencies, and the supervision duty that comes with entrusting the work, is the subject of our guide to switching a Japan EC agency. That article is about the delegated relationship. This one is about what you owe whether or not anyone is delegated anything.
One boundary first, and it is not boilerplate: we run e-commerce operations, not legal practice, and nothing here is legal advice. What follows is a plain-language summary of published statutory text and regulator guidance, written to help you decide whether this needs a lawyer's time — not to substitute for one.
The Short Answer: Article 171 Reaches You
Japan's Act on the Protection of Personal Information — the APPI — contains an explicit extraterritoriality provision. Article 171 extends the Act to a personal information handling business operator located in a foreign country that handles, abroad, personal information about people in Japan acquired in connection with supplying goods or services to people in Japan.
The Personal Information Protection Commission — the independent regulator that administers the Act, referred to below as the Commission — states this in its own published FAQ. The example it works through is a foreign business processing Japanese users' data under contract for a Japan-facing app: because the processing relates to supplying goods or services to people in Japan, the Act applies, and the foreign operator is obliged to handle the data in accordance with the Act's provisions.
A cross-border storefront selling to Japanese addresses fits that description without needing a creative reading: you take names, addresses, phone numbers and order histories from people in Japan, in connection with selling them things. The Act's provisions attach whether those records sit in Shopify, a marketplace seller account, or a spreadsheet.
What changed in 2020 is the part that turns this from a theoretical obligation into a practical one. The 2020 amendment brought foreign operators inside the Commission's enforcement machinery: they became subject to demands for reports, to on-site inspection, and to orders, with the Commission able to publish the fact of non-compliance. Before that amendment, a foreign operator was formally in scope but largely beyond reach. That gap is closed.
There Is No Small-Seller Exemption
The most common misconception we hear from brands at this stage is a volume one: surely a few hundred Japanese customers is below whatever threshold Japan sets. Japan did have such a threshold — an exemption for operators handling personal information on 5,000 or fewer individuals — and it was removed when the 2015 amendment took full effect on 30 May 2017. Since then, anyone using a personal information database in the course of business is a personal information handling business operator, whatever the size of the business, including sole proprietors and non-profit organisations.
This threshold removal is well established in Japanese legal practice, though the Commission does not restate it on a current guidance page. Either way, there is no volume tier that lets a small overseas brand skip what follows.
Where Overseas Sellers Actually Get Caught: Article 28
Here is the provision that catches brands whose home-market privacy programme is otherwise in good order. Two APPI rules govern giving personal data to someone else:
- Article 27 restricts providing personal data to a third party in general — as a rule, you need the individual's prior consent.
- Article 28 restricts providing personal data to a third party located in a foreign country, and it is stricter.
Under Article 28, providing personal data to a third party abroad requires the individual's prior consent unless the recipient is in a country the Commission has designated as having a data protection regime of equivalent standard, or the recipient has established a system meeting the standards set in the Commission's rules for taking appropriate measures on a continuing basis.
Two details make this bite for an overseas seller.
First, the designated-country list is short. Only the EU and the United Kingdom are designated. That designation traces back to the mutual adequacy arrangement Japan and the EU concluded, and the Commission reviewed it in March 2023 and found maintaining it appropriate. The United States is not designated. Neither is anywhere else. If your data lands with a recipient in the US, Singapore or Australia, the designated-country route is simply unavailable to you and you are on one of the other two.
Second, entrusting work to a contractor does not get you out of Article 28 when the contractor is abroad. This is the counter-intuitive part, and the Commission has published a dedicated FAQ on exactly it. Under Japanese law, entrusting the handling of personal data to a contractor is not third-party provision for Article 27 purposes — a genuinely useful carve-out domestically. But that carve-out does not extend to Article 28. Where the entrusted contractor is located in a foreign country, Article 28's requirement still applies. A brand that reasoned "our processors are processors, not third parties, so the cross-border rule is not our problem" has reasoned from the domestic rule and skipped the one that actually governs.
If you take the consent route, the consent is not a checkbox saying "we may transfer your data overseas." The Commission's rules require you to provide the individual, in advance, with three specific things: the name of the destination country; information about that country's personal information protection regime, obtained by appropriate and reasonable means; and the protective measures the recipient takes. The stated purpose is that the individual can reasonably anticipate the risk of the transfer. A generic consent line does not do that.
If you take the third route — the recipient has a system meeting the Commission's standards — Article 28 then imposes a continuing duty: periodically confirm that the recipient is actually implementing the measures and check for foreign laws that would obstruct them, take action if implementation lapses, suspend the transfer if continued compliance becomes impossible, and provide the individual with information about how and how often you check, on request.
The Obligation Nobody Reads About: Naming the Country
Alongside the transfer rules sits a security-control duty that is easy to miss and unusually visible when you get it wrong, because it shows up in your published privacy policy.
The Act requires appropriate security control measures over personal data. The Commission's guidance treats grasping the external environment — understanding the data protection regime of any foreign country where the data is actually handled — as one of those measures. In its published FAQ on foreign cloud services, the Commission puts it in operational terms: you need to make clear the name of the foreign country where the cloud provider is located and the name of the foreign country where the servers storing the personal data sit, and to place the content of the measures you took, having understood that country's regime, in a state the individual can know. That last phrase links back to Article 32, which requires certain matters about your retained personal data to be knowable to the individual.
The Commission also addresses the case where you genuinely cannot pin down the server location: disclose why the country cannot be specified, plus reference information useful to the individual, such as the candidate countries where the server may sit.
For an overseas seller, the practical translation is blunt. A Japanese-language privacy notice that says nothing about where the data goes is not just thin — it is missing a specific disclosure the regulator has described in concrete terms. And unlike most of the Act, this one is checkable by anyone who opens your page.
Selling into Japan from a head office abroad and unsure what your Japan-side workflow is actually doing with customer data? We map who touches what across your storefront, fulfilment and customer contact, so your lawyer has a real picture to work from.
Talk to Us About Japan OperationsThe Breach Clock Starts on Discovery, Not on Understanding
The 2020 amendment made breach reporting mandatory rather than a matter of guidance. Under Article 26, reporting to the Commission is required where a leak, loss or damage falls into one of four categories:
- It involves sensitive personal information — the category Japanese law calls 要配慮個人情報, covering matters such as race, creed, medical history and criminal record.
- It involves data whose misuse could cause financial harm — payment card numbers, credentials for payment services.
- It was caused by an intentional act — unauthorised access, ransomware, theft, or misconduct by someone inside the business acting with wrongful intent.
- It affects more than 1,000 individuals.
The Commission's published guidance sets the deadlines from the day the incident is discovered: a preliminary report within approximately three to five days, and a final report within 30 days — extended to 60 days where the cause was an intentional act. The Act also requires notification to the affected individuals.
Read those numbers against how a cross-border operation actually finds out about a breach. A payment-data incident at a Japan-side vendor surfaces first in Japanese, to whoever is closest to the platform or the warehouse — not to the head-office security team. If the escalation path from that person to whoever files has never been written down, the three-to-five-day preliminary window goes on working out who owns the problem.
This is the one obligation in this article that is an operations problem before it is a legal one. The fix is not a policy document; it is a named path, agreed in advance, from every Japan-side party who might see an incident first — agency, 3PL, marketplace account manager — to the person who files. If you are structuring or restructuring that side of the business, our comparison of Japan 3PL and cross-border fulfilment covers who ends up holding customer data under each model, which is the map you need before you can draw the escalation path.
Your Ad Pixels Have Their Own Rule
One more provision catches e-commerce specifically. Article 31 governs what Japanese law calls 個人関連情報 — personal-related information, the category that covers things like browsing history collected against a cookie or device identifier, which is not personal data in your hands because you cannot identify anyone from it.
The rule is about what happens at the other end. Where it is anticipated that the recipient will acquire that information as personal data — because the recipient can match it to an identified individual — the provider must confirm that the individual's consent to that acquisition has been obtained. The Commission's guidance gives website browsing history collected via cookies and other terminal identifiers as an example, and lets the provider confirm consent by accepting the recipient's declaration or written undertaking, checking the recipient's consent records, or obtaining the consent on the recipient's behalf.
If you run remarketing or conversion tracking that hands identifiers to a Japanese ad platform which then matches them to logged-in accounts, that is the fact pattern this provision was written for. It is worth putting on the list you take to your adviser rather than treating tracking as a separate, purely marketing question.
What Enforcement Actually Looks Like
Japanese enforcement is escalatory rather than immediately punitive, and it is worth knowing the sequence because it changes how much of this is a genuine risk versus a compliance-team talking point.
The Commission's own FAQ sets out the ladder: guidance and advice under Article 147, then recommendations and orders under Article 148. Criminal penalties attach at the far end. Failure to comply with an order carries up to one year's imprisonment or a fine of up to ¥1,000,000 under Article 178. Improper provision or misappropriation of a personal information database carries up to one year's imprisonment or a fine of up to ¥500,000 under Article 179. Failure to comply with a reporting demand or inspection carries a fine of up to ¥500,000 under Article 182. And under the Act's dual-liability provision, a corporation whose representative or employee commits the Article 178 or 179 offences in the course of business faces a fine of up to ¥100,000,000. The Commission may also publish the fact of non-compliance.
Two things follow. The realistic first contact for a mid-sized overseas seller is guidance, not a raid — but the 2020 amendment means it can now reach a company with no Japanese entity, and the publication power means reputational cost can land well before any fine does.
What the July 2026 Amendment Changes
A significant amendment to the Act was promulgated on 17 July 2026, as confirmed on the Commission's own page for it. The Commission has published a roadmap toward implementation and states that it will now work through the necessary cabinet orders, rules and guidelines.
On timing, be careful with what you read elsewhere. Article 1 of the amendment's supplementary provisions — in the statutory text the Commission publishes on its own amendment page — provides that the Act takes effect on a date fixed by cabinet order, no later than two years from promulgation. No specific commencement date has been fixed. Some outlets have circulated specific dates; the two-year outer limit is the part that is safe to plan against.
The substance, per that commentary, is the largest revision in roughly two decades. The items most relevant to a consumer-facing overseas seller are the introduction of an administrative surcharge system — an order to pay an amount corresponding to gains obtained through violation, with a reduction and exemption scheme, alongside the existing criminal penalties; strengthened protection for the personal information of children under 16, with guardian consent and reinforced suspension rights; new treatment of facial-feature and other biometric data; relaxations around statistical and research use; a narrowing of when individual notification is required after a leak where the risk to rights and interests is low; and more flexible recommendation and order powers for the Commission.
Nothing in that list requires action from an overseas seller this quarter. It does change the medium-term shape of the risk: a surcharge regime moves Japanese enforcement from "criminal penalties nobody expects to see" toward something closer to the economic-penalty model brands already plan around in Europe. If you are building a Japan data process now, build it knowing that is coming.
So Do You Need a Japan-Specific Process?
Not necessarily a separate programme. But you cannot answer the question by asking whether your GDPR work covers it, because the two regimes diverge exactly where the risk sits for you. Four questions decide it:
- Where does Japanese customer data physically sit, and who else touches it? If any of them is outside Japan and outside the EU or UK, Article 28 is live and the designated-country route is closed. If any of them is a contractor rather than a third party, you have read above why that does not help.
- Does your Japanese-language privacy notice name the countries where the data is handled? If not, the country-disclosure duty is unmet, and it is the one an outsider can check.
- Is there a written escalation path from every Japan-side party to whoever files a breach report? If not, the three-to-five-day preliminary window is a problem waiting for a trigger.
- Do you know what your tracking hands to Japanese ad platforms? If not, Article 31 is an open question rather than a settled one.
A brand that can answer all four cleanly probably needs a documented process rather than a new compliance function. A brand that cannot answer the first two should get a Japanese lawyer or data protection adviser onto it before the next campaign, not after. And a brand still deciding how to structure its Japan presence at all should factor this in early — the choice between selling cross-border into Japan and operating a local storefront changes who holds the data and therefore how much of the above lands on you directly.
Where we fit is narrow, and we want to be exact about it. We run Japanese storefronts and marketplace operations for overseas brands across Rakuten, Amazon Japan, Yahoo! Shopping and Shopify. Engaging us does not make a brand APPI-compliant. The Act's obligations attach to you as the brand, and the compliance judgement belongs to you and to a qualified Japanese lawyer or data protection adviser. What an operations partner can do is make the picture legible — who touches which data, at which step, in which country — so the legal work is done against reality rather than an org chart, and so the escalation path in question three has names in it. If that mapping is what is missing, tell us how you sell into Japan today and who handles the Japan-side work. Scope and pricing are quoted against the work rather than published as a rate card.
Related articles
Switching Your Japan EC Agency
The delegated side of the same law — your Article 25 supervision duty over a contractor, and what happens to customer data at handover.
Japan 3PL vs Cross-Border Fulfilment
Which fulfilment model puts customer records in whose hands — the map you need before drawing a breach escalation path.
Where an Agency's Job Stops at Customs
Another boundary question overseas sellers discover late: which obligations an operations partner can and cannot absorb.
Sources
- • Primary, regulator: Personal Information Protection Commission FAQ Q11-4 (ppc.go.jp/all_faq_index/faq1-q11-4/) — extraterritorial application under Article 171 to a foreign operator handling personal data of people in Japan in connection with the supply of goods or services to people in Japan. Retrieved August 2026.
- • Primary, regulator: Personal Information Protection Commission FAQ Q12-1 (ppc.go.jp/all_faq_index/faq1-q12-1/) — entrustment is not third-party provision under Article 27, but Article 28(1) still applies where the entrusted party is located in a foreign country. Retrieved August 2026.
- • Primary, regulator: Personal Information Protection Commission, Guidelines on Provision to a Third Party in a Foreign Country (ppc.go.jp/personalinfo/legal/guidelines_offshore/) — the three items that must be provided before obtaining consent under Article 28(2) and Rules Article 17(2): destination country name, information on that country's personal information protection regime obtained by appropriate and reasonable means, and the measures taken by the recipient; and the continuing confirmation, remediation, suspension and on-request disclosure duties under Article 28(3). Retrieved August 2026.
- • Primary, regulator: Personal Information Protection Commission, cross-border data transfer with the EU and the UK (ppc.go.jp/enforcement/cooperation/cooperation/sougoninshou/) and the Commission Secretariat's review report of 22 March 2023 (ppc.go.jp/files/pdf/20230322_review_report.pdf) — the EU and the UK are the countries designated under Article 28(1); the Commission assessed maintaining both designations as appropriate. Designation instrument cited in the review as Personal Information Protection Commission Public Notice No. 1 of 2019. Retrieved August 2026.
- • Primary, regulator: Personal Information Protection Commission FAQ Q10-25 (ppc.go.jp/all_faq_index/faq1-q10-25/) — grasping the external environment as a security control measure; the operator must make clear the name of the foreign country where the cloud provider is located and where the servers storing personal data are located, and place the content of the measures taken, having understood that country's regime, in a state the individual can know; where the server country cannot be specified, disclose the reason and reference information such as candidate countries. Retrieved August 2026.
- • Primary, regulator: Personal Information Protection Commission, guidance on responding to leaks (ppc.go.jp/personalinfo/legal/leakAction/) — the four reportable categories (sensitive personal information; data whose misuse could cause financial harm; leaks caused by an intentional act; leaks affecting more than 1,000 individuals); preliminary report within approximately three to five days of discovery; final report within 30 days of discovery, or 60 days where the cause was an intentional act; duty to notify affected individuals. Retrieved August 2026.
- • Primary, regulator: Personal Information Protection Commission FAQ Q11-1 (ppc.go.jp/all_faq_index/faq1-q11-1/) — guidance and advice under Article 147, recommendations and orders under Article 148; Article 178 (order violation: up to one year's imprisonment or a fine up to ¥1,000,000), Article 179 (improper provision or misappropriation of a personal information database: up to one year's imprisonment or a fine up to ¥500,000), Article 182 (failure to comply with a reporting demand or inspection: fine up to ¥500,000); dual-liability fine of up to ¥100,000,000 for a corporation in respect of the Article 178 and 179 offences. Retrieved August 2026.
- • Primary, regulator: Personal Information Protection Commission page on the 2026 amendment (ppc.go.jp/personalinfo/legal/r8kaiseihogohou/) — the Act partially amending the Act on the Protection of Personal Information and related acts was promulgated on 17 July 2026; a preparation period is provided and the Commission has published a roadmap toward smooth implementation, with cabinet orders, rules and guidelines to follow. The Commission page does not state the law number or specific commencement dates. The statutory text (ppc.go.jp/files/pdf/260717_houritsu.pdf) confirms in Article 1 of the supplementary provisions that the Act takes effect on a date fixed by cabinet order, no later than two years from promulgation; the same text also covers the administrative surcharge payment order, protection of those under sixteen, specified biometric identification data, and the statistical-use exception. Retrieved August 2026.
- • Secondary, legal commentary: BUSINESS LAWYERS, explanation of the 2026 amendment (businesslawyers.jp/articles/1521) — an overview of the twelve principal amendment items, including the surcharge system, protection of the personal information of children under 16, treatment of facial-feature data, relaxations for statistical use, narrowing of individual notification after low-risk leaks, and more flexible recommendation and order powers. The substance of the amendment items is taken from this secondary source and was not confirmed against the official gazette or a Commission publication.
- • Secondary, legal commentary: Japanese legal-practice commentary on the abolition of the 5,000-record threshold with the 2015 amendment taking full effect on 30 May 2017, after which any operator using a personal information database in the course of business is a personal information handling business operator regardless of size. Not confirmed against a Commission page.
- • Secondary, legal commentary: Japanese legal-practice commentary on the 2020 amendment's extension of the Commission's reporting demands, on-site inspection and orders to foreign business operators, and on the publication power for non-compliance with an order. Presented here as the direction of the amendment; the specific enforcement provisions were not read in the statutory text.
- • Secondary, guideline commentary: Commentary on the Article 31 personal-related information rule and the Commission's guidelines on confirmation and record-keeping for third-party provision (ppc.go.jp/personalinfo/legal/guidelines_thirdparty/) — browsing history collected via cookies and other terminal identifiers as an example of personal-related information; permitted methods for the provider to confirm that the recipient has obtained consent. Article number and mechanism confirmed against the guideline page; the illustrative examples are taken from commentary summarising the guidelines.
- • Not legal advice: LAUNOVA is an e-commerce operations firm, not a law firm or a certified data protection adviser. Nothing in this article is legal advice, no attorney-client relationship arises from reading it, and engaging LAUNOVA does not make a brand compliant with the Act. Obligations under the Act attach to the brand as the personal information handling business operator. Compliance questions should go to a Japanese lawyer or a qualified data protection adviser.