Act on the Protection of Personal Information, breach notification
Act No. 57 of 2003, as amended by Act No. 37 of 2021, Art. 26
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 April 2022.
A breach notification rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app that suffers a leak, loss, or damage of personal data belonging to a person in Japan must report the incident to the Personal Information Protection Commission where it is likely to harm the data subject's rights and interests, following PPC-prescribed procedure and timing.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Art. 26(1) requires a business to report to the Personal Information Protection Commission any leak, loss, or damage of personal data that PPC order identifies as likely to harm individual rights and interests, following PPC-set procedure and timing; no duplicate report is needed where an entrusting business has already been notified. The administrative-entity mirror duty sits at Art. 68.
The PPC's own order or rules set the specific report-timing thresholds and the individual-notification trigger; the Art. 26 duty is summarised without that procedural detail.
When LexLint raises it
processes_biometricsprocesses_voicecrawls_web
Read the law
official statute text, Japanese Law Translation portal
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.