Why Japan shows up on your list
Most small businesses do not set out to enter the Japanese market. They put up a site, take payments in a few currencies, and one day notice orders arriving from Tokyo. That is usually the moment Japan's privacy law becomes your problem, because the law follows the customer rather than the company.
Japan's privacy rules live in the Act on the Protection of Personal Information, which almost everyone calls the APPI. It is enforced by the Personal Information Protection Commission, or PPC, whose English-language site sits at ppc.go.jp. The APPI applies extraterritorially, meaning it can reach a business with no office, staff or servers in Japan. If you handle the personal information of people in Japan in connection with supplying goods or services to them, you are inside its scope.
The APPI is a readable, proportionate law. It asks you to be clear about why you hold data, careful about who you pass it to, and honest when something goes wrong. If you have already done sensible work for the GDPR, you are not starting from zero. But Japan is not a copy of Europe, and the differences are exactly where small businesses go wrong.
Who this applies to
You are in scope if you sell goods or services to people in Japan and handle their personal information as part of that. Personal information here means the ordinary things you already collect: names, email addresses, shipping addresses, phone numbers, order histories, account records, support tickets.
You do not need a Japanese entity, a Japanese bank account or a Japanese-language site. A store that ships to Japan, an app with users in Japan, a consultancy with a few Japanese clients. All of these can be caught. What matters is the connection between the data you handle and what you supply to people there.
If you genuinely do not serve Japan, you can put this aside. If you are not sure, look at your last twelve months of orders or signups. That takes ten minutes and settles the question.
What the APPI asks of you now
These obligations are in force today. None of them depends on the 2026 amendment described in the next section.
Decide your purpose of use, and state it publicly. The APPI is built around the idea that you specify, as concretely as you reasonably can, what you will do with the personal information you collect, and then make that purpose known. "Business purposes" is not a purpose. "To fulfil orders, provide customer support, and send order-related email" is. Once stated, you are expected to stay inside it. Most small businesses have a privacy policy that gestures at this. The work is making it specific and keeping it accurate as your product changes.
Get consent before handing personal data to a third party. Passing personal data to someone outside your business generally requires the individual's consent up front. Japan does also allow an opt-out scheme in some circumstances, where individuals are told and given a way to object rather than asked in advance, but that route is not a shortcut you can quietly adopt. It requires prior notification to the PPC. If you have not filed that notification, opt-out is not available to you, and consent is the path.
Treat cross-border transfers as a separate decision. Sending personal data outside Japan is its own step, not something folded into the general third-party rule. Consent is generally required, and it has to be informed consent: you are expected to give the person information about the data protection regime in the destination country and about the measures the recipient takes to protect personal information. For a small business, this usually means knowing where your CRM, email tool, helpdesk and hosting actually keep data, and being able to say so plainly. That inventory is the hard part. Writing it down afterwards is quick.
Take security control measures. The APPI imposes a duty to take appropriate measures to keep personal data secure, without handing you a checklist. In practice this covers the unglamorous basics: who on your team can see customer data and why, multi-factor authentication on the accounts that matter, encryption where it is available to you, and removing access when someone leaves. A two-person business is not expected to build what a bank builds. It is expected to have thought about it.
Know what to do on the day something leaks. Where a leak falls into the prescribed cases, you owe the PPC a preliminary report promptly and a final report within the period the PPC prescribes, plus notice to the affected individuals. The failure here is rarely unwillingness. It is that nobody knows who makes the call, who writes the report, or where the list of affected customers lives. Decide those three things now.
Understand where cookies actually bite. Japan has no ePrivacy-style cookie law. Consent is not required simply to set a cookie, which is why you see far fewer banners on Japanese sites than on European ones. The APPI's hook is different: Article 31(1) attaches obligations when personally-referable information, such as a cookie ID, is provided to a third party who will link it to an identified individual. So the question is not "do I have a banner" but "am I shipping identifiers to an ad or analytics partner who can tie them back to a named person." If you run retargeting pixels, that deserves a real answer.
What changed in 2026
The APPI is reviewed on a roughly triennial cycle, and the current round has just concluded. The Cabinet approved and submitted the amendment bill to the Diet on 7 April 2026. It passed the Diet on 10 July 2026 and was promulgated on 17 July 2026. It is law.
What it is not yet is in force. Commencement falls within two years of promulgation, on a date to be fixed by Cabinet Order, and that order has not been made. There is no fixed commencement date today, and most provisions are expected to be in effect by 2028. Anyone telling you the new rules bite on a specific day is guessing.
Three changes are worth knowing about at a general level. The first is a consent exemption for using personal data in statistical processing, including in AI and machine-learning development, where the output does not identify individuals. The second concerns children: where the person is a child under 16, notice and consent run to the legal representative, 法定代理人, usually a parent or guardian. Note the shape of that rule, because it is widely misdescribed online as simple parental consent. The third is a set of new transparency obligations for a newly defined category called Specific Biometric Personal Information.
None of this requires action from you this week. It is worth a calendar note, and a look at your assumptions if you have younger users.
Common mistakes
The most common mistake is assuming Japan is Europe with different fonts. Businesses bolt a cookie banner onto their site, feel finished, and never look at the purpose-of-use statement or the cross-border transfer question, which is where their actual exposure sits.
The second is treating adequacy as an exemption. EU-Japan mutual adequacy has been in place since 23 January 2019, with an extension covering the academic and research sector concluded on 18 September 2025. That arrangement smooths data flow between the two regimes. It does not switch off the APPI for your business.
The third is assuming enforcement is toothless. The APPI's enforcement runs through PPC guidance, recommendations and orders, with criminal penalties for breaching an order. It is a quieter escalation ladder than headline fines, but it is a real one.
The fourth is stale documentation. A privacy policy written when you had one product and one email tool stops being true the moment you add a vendor. Accuracy is the obligation, not the existence of the document.
How Dxtra helps
Dxtra generates a privacy program from a questionnaire about how your business actually works: a privacy policy, a cookie notice, consent records, processing records, a public Transparency Center and a way to handle data subject access requests. It covers more than 500 obligations across 140-plus countries, including Japan, and starts at $10 a month. It will not replace a lawyer on a hard question, and it is not meant to.
If you want a starting point that costs nothing, Dxtra's free scan reads your site's public pages in about two minutes with no signup and returns a risk band along with findings mapped to named sources, so you can see which gaps are worth your attention first. It is a diagnostic, not a determination of compliance.
Where to start
Do the smallest true thing first. Check whether you actually serve people in Japan, using your own order or signup data rather than your intentions. If you do, write down every tool that touches customer data and where each one stores it, because both your cross-border transfer answer and your security answer depend on that list.
Then read your privacy policy as a customer would and ask whether the stated purpose of use matches what you really do. Fix it if it does not. After that, decide who makes the call if data leaks, and put that on one page with the PPC's contact route on it.
That is a weekend of work, not a quarter, and it puts you ahead of most businesses your size well before the 2026 amendment comes into force.
This article is general information, not legal advice. Rules change; confirm anything that matters with the Personal Information Protection Commission (ppc.go.jp) or a qualified adviser before you rely on it.
