The Amended Act on the Protection of Personal Information: Where Things Stand After Promulgation and What Companies Should Prepare
Hello, I'm Noriaki Asato, Representative Attorney at LegalAgent.
Some legal staff may not be able to recall right away when their company last revised its privacy policy. There are cases where a company keeps using the text from the launch of its service, and even as the number of service providers grows and overseas cloud services are introduced, only the policy text remains stuck in the business reality of the past. For such companies, responding to the amended Act on the Protection of Personal Information (APPI) promulgated in July 2026 leads to a review that goes beyond simply revising the wording of their terms.
Enactment, Promulgation and Effective Date of the Amended Act
The APPI contains a provision calling for a review every three years, and the Personal Information Protection Commission published its "Policy on System Reform" on January 9, 2026. In response, the "Bill for Partial Amendment of the Act on the Protection of Personal Information, etc." was approved by the Cabinet on April 7, 2026 and submitted to the 221st session of the Diet.
According to the bill information of both houses of the Diet, the bill was passed by a special committee of the House of Representatives on May 21, 2026, passed at the plenary session on May 26 and sent to the House of Councillors. In the House of Councillors, it was referred on June 12 to the Special Committee on the Formation of a Digital Society and the Utilization of Artificial Intelligence, etc., passed by that committee on July 8, and passed and enacted at the plenary session on July 10. The amended Act was promulgated on July 17, 2026 as Act No. 56. Accordingly, the amendments should be treated not as a bill under deliberation but as a law that has already been promulgated.
On the other hand, the effective date has not yet been fixed. With the exception of certain provisions, the amended Act is to take effect on a date specified by Cabinet Order within a period not exceeding two years from the date of promulgation. Read literally, it will take effect by July 16, 2028 at the latest, but as of the time of writing (September 20, 2026), no Cabinet Order setting the specific date has been confirmed. In addition to the Cabinet Order, amendments to Commission rules and guidelines are expected to be issued in sequence, and if internal materials clearly state the current position as "promulgated, effective date not yet determined," the premise will not be misunderstood even when the person in charge changes.
The Administrative Surcharge System and Increased Penalties
A major pillar of this amendment is the creation of an administrative surcharge system. According to the House of Councillors' summary of the bill, a system has been established under which the Personal Information Protection Commission orders a business operator handling personal information that has obtained a financial benefit through unlawful handling of personal information or similar conduct to pay a surcharge. At the same time, the statutory penalties for business operators that improperly provide personal information databases and the like have been increased.
The previous law also provided administrative measures such as guidance, recommendations and orders, but these were intended to prompt correction of a state of violation and were not a framework for clawing back the economic benefit unjustly obtained. Once the surcharge system takes effect, a new means will be added for removing unjust gains from violations.
In practical terms, legal violations will no longer be merely "problems that can be fixed after being pointed out." Companies whose checks on service providers have become a mere formality, or which have neglected to keep records of provision to third parties, would be wise to review their current situation early, without waiting for the effective date.
Rules on Biometric Information, Information on Minors and Contactable Information
The amended Act contains substantive revisions beyond the surcharge. According to the House of Councillors' summary of the bill, for specified biometric personal information, which includes information relating to the characteristics of part of the body, provisions have been established allowing the individual to request suspension of use and the like even without unlawful handling. Provisions have also been put in place on notifying the individual's legal representative and similar measures when handling personal information and the like of persons under 16 years of age, and for contactable personal-related information, which includes descriptions and the like that can be used to contact a specific individual, inappropriate use and improper acquisition are prohibited. For cases such as providing personal information to a third party that prepares statistics and the like, a treatment has been introduced under which the individual's consent is not required if the content of the statistics preparation and the like is made public.
That said, some aspects of the specific scope of each provision remain to be worked out in future Cabinet Orders, Commission rules and guidelines. At this point, it is prudent to avoid reaching definitive interpretations of the provisions. Even so, for companies operating services that handle biometric information such as facial recognition, fingerprints and voiceprints, businesses that anticipate users under 16, and businesses that collect contact details and use them for sales and advertising, it is worth checking whether their current privacy policies and consent screens accurately describe what actually happens. These types of information required care even under the law before the amendment, and they are areas that should be given high priority for review without waiting for the effective date to be fixed.
Advance Review Based on the Current Provisions
Even without waiting for the effective date to be fixed, there are several items that can be checked right now against the provisions of the APPI currently in force.
Article 17 requires the purpose of use to be specified, and Article 18 restricts handling beyond the scope necessary to achieve the specified purpose of use. Whether the purposes of use stated in the policy are consistent with the data processing in day-to-day operations is a matter that should be reviewed without waiting for the amended provisions to take effect. If a company sends data for ad delivery or to external AI services while its policy contains only a broad description such as "to provide the service," it may be carrying risk even under the current rules.
In addition, Article 21 provides that when personal information is obtained directly from the individual in writing or the like, the purpose of use must be clearly indicated in advance. Whether this indication is properly reflected in a form visible to users on each screen for membership registration, inquiries and requests for materials is also subject to review.
Furthermore, the restrictions on provision to third parties under Article 27 and the restrictions on provision to third parties located in foreign countries under Article 28 also require review. The more a company outsources and uses overseas SaaS and cloud services, the more likely it is that the classification of whether a data linkage constitutes entrustment, or instead provision to a third party or a cross-border transfer, becomes blurred. If you proceed only with responding to the amended provisions without sorting this out, the foundation may be shaken.
Internal Preparations That Can Be Started Early
Even at this stage, when the effective date has not been fixed, I think it is beneficial to get a head start on the following four points:
- Reviewing internal rules: checking whether the descriptions of personal information handling procedures, criteria for selecting service providers and security control measures match current practice
- Taking stock of outsourcing contracts: confirming whether the contracts include notification obligations in the event of a data breach, conditions for consenting to subcontracting and clauses on cooperation with audits
- Clarifying the data breach response flow: setting out as a procedure the division of roles and deadlines from discovery of an incident through internal reporting and fact-finding to reporting to the Commission
- Rechecking consent screens: considering whether purposes of use are too abstract and whether consent screens need to be designed to account for biometric information and information on minors
These tasks are of a nature such that it is difficult to secure enough time to respond if you start only after the Cabinet Order setting the effective date is promulgated. In particular, reviewing outsourcing contracts involves discussions with counterparties, so it is realistic to identify the relevant contracts now.
Once the surcharge system takes effect, the risk of a state in which internal rules have become hollow and diverge from reality will be heavier than at the stage where the response is limited to guidance and recommendations. Rather than simply waiting for the Cabinet Order to be promulgated, if you complete a review based on the current provisions, you can respond calmly whenever the effective date is set.