Law note · Japan

Act on the Protection of Personal Information, breach notification

cite Act No. 57 of 2003, as amended by Act No. 37 of 2021, Art. 26 stage IN FORCE in force since 2022-04-01 kind Breach notification binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that suffers a leak, loss, or damage of personal data belonging to a person in Japan must report the incident to the Personal Information Protection Commission where it is likely to harm the data subject's rights and interests, following PPC-prescribed procedure and timing.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web

What we found

Art. 26(1) requires a business to report to the Personal Information Protection Commission any leak, loss, or damage of personal data that PPC order identifies as likely to harm individual rights and interests, following PPC-set procedure and timing; no duplicate report is needed where an entrusting business has already been notified. The administrative-entity mirror duty sits at Art. 68.

The PPC's own order or rules setting the specific report-timing thresholds and the individual-notification trigger were not independently read this pass, so this document records only the Art. 26 duty itself, not its procedural detail.

← Back to the example  ·  Lint your app →