Overview of Data Protection Laws in Japan
摘要
This chapter explains Japan’s data-privacy framework by tracing the origin, development and transitions of the Act on the Protection of Personal Information (APPI) and the right to privacy. The APPI lies at the core of Japan’s data-privacy architecture, which was enacted in 2003. At that time, the APPI primarily set out obligations for the private sector, with public sector duties governed by separate legislation. However, in 2021, all requirements were consolidated into the APPI. Although the current APPI comprehensively covers both the private and public sectors, the obligations applicable to each remain distinct within the APPI. This chapter subsequently explains the key elements of the APPI, including core concepts, data collection, use, management and provision, breach response, transparency, data subject requests, enforcement powers, and penalties. These APPI requirements are different for the public and private sectors. This chapter also explains APPI-related guidelines, including guidelines for the financial, medical and ICT sectors, as well as related laws and regulations, such as those on direct marketing, cookies and similar technologies, and recruitment. Independently of the APPI legislation, jurisprudence on the right to privacy has also evolved via case law. The right to privacy was first recognised in the 1964 ‘After the Banquet’ case. Privacy-infringement claims have further developed under the theory of tort in the Civil Code, separate from the APPI regime. While its theoretical classification within the legal order remains contested, judicial practice treats the right to privacy as distinct from the APPI, and it occupies a significant place within Japan’s data privacy architecture.