Every week, Japanese companies publish notices headed お詫びとお知らせ ("apology and notice") saying that personal data "may have leaked". Behind each one is a legal duty to report to Japan's privacy regulator, the Personal Information Protection Commission (PPC), on a fixed timetable. This explainer sets out how that duty works under the Act on the Protection of Personal Information (APPI), what changes with the law amended in July 2026, and why Japanese breach notices read the way they do.

Key takeaways

  • A company must report a breach to the PPC if it involves sensitive data, data that could cause financial harm, an attack or other wrongdoing, or more than 1,000 people. A breach that may have happened counts too.
  • The first report is due "promptly", which the PPC's guidelines put at about 3 to 5 days. A full report follows within 30 days, or 60 days when the cause may be an attack or other wrongdoing.
  • When a contractor is breached, both the contractor and its client are responsible. That is why one incident can produce notices from many companies and local governments.
  • Companies must also tell the people affected, but only "promptly according to the situation". Publishing a notice is recommended, not required.
  • The rules apply to foreign companies that handle the personal data of people in Japan when supplying goods or services to them.
  • A July 2026 amendment will ease some reporting and notification duties and introduces administrative fines, though not for breaches caused by attacks. Most of it takes effect by 2028.

The rules at a glance#

Businesses and other private-sector organizations Government bodies
Report to The PPC, or the ministry in charge for some sectors The PPC
When reporting is required Sensitive data; risk of financial harm; possible wrongdoing such as an attack; more than 1,000 people Similar triggers; more than 100 people
Preliminary report "Promptly", about 3–5 days after the company knew Same
Final report Within 30 days; 60 days if wrongdoing such as an attack may be involved Same
Tell the people affected Yes, "promptly according to the situation" Yes
Public announcement Recommended, not required Recommended

National universities, and public universities and hospitals run by independent administrative agencies, follow the private-sector rules for breach reporting, even though they are publicly owned.

When a breach must be reported#

Article 26 of the APPI requires a report when a breach is "likely to seriously harm the rights and interests of individuals". The PPC's rules define that as any of four situations, each covering a leak, loss or damage of personal data that has occurred or may have occurred:

  1. Sensitive personal information (要配慮個人情報) is involved, such as medical records, health check results or criminal records. A hospital losing a USB stick with patient data is the PPC's own example.
  2. The data could cause financial harm if misused, such as credit card numbers, or the login IDs and passwords of services that can make payments or transfers. The last four digits of a card and its expiry date alone do not qualify.
  3. The breach may have been caused with an improper purpose. This covers cyberattacks, theft and insiders taking data, and includes data a company was in the middle of collecting, such as card details typed into a tampered web form.
  4. More than 1,000 people are affected. A breach that starts small becomes reportable the moment the count passes 1,000.

Data protected by strong encryption does not need to be reported. Ransomware that encrypts data beyond recovery counts as damage to the data, unless a copy exists elsewhere, and as a leak if the attackers also took it.

Government bodies, from ministries to local governments, follow similar triggers with a lower threshold of 100 people. Breaches involving My Number, Japan's national ID number, are reported under a separate set of triggers, which also uses 100 people as the threshold.

"May have" is enough#

The word that appears in almost every Japanese breach notice is おそれ (osore), "risk" or "possibility". The law requires a report when a breach may have occurred, judged on what the company knows at the time. For cyberattacks, the PPC's guidelines list signs that are enough to trigger a report even without proof that data left:

  • Traces of data being exfiltrated from a server holding personal data, or from a device with access to it
  • Infection with malware known to steal information
  • Traffic to a known command-and-control server
  • A web page altered to capture what users type into it
  • A credible warning from a public body, security vendor or expert

This is why notices so often say data "may have been viewed or taken" (閲覧・取得された可能性). It is the legal threshold for reporting, and it is reported before the investigation can say more.

The deadlines#

Report Deadline What it contains
Preliminary (速報) "Promptly". The PPC's guide is about 3 to 5 days Whatever the company knows at that point
Final (確報) 30 days, or 60 days if the breach may involve an improper purpose such as an attack All nine required items. Anything still unknown is added later

The clock starts when any department of the company becomes aware of the breach, not when management is told. For the final report, that day counts as day one and weekends and holidays count. If the last day falls on a day government offices are closed, the deadline moves to the next working day.

Both reports cover the same nine items: an overview, the types of data, the number of people, the cause, any secondary harm, what has been done for the people affected, whether the breach has been made public, measures to prevent a recurrence, and anything else relevant. Reports are filed through the PPC's online form. In some sectors, such as finance, the PPC has delegated this to the ministry in charge, and companies report there instead, on the same deadlines. For ransomware and other cyberattacks, companies can use a common form shared across government agencies, so that one set of facts can serve several reports.

Contractors: why one breach produces many notices#

When a company hands personal data to a contractor, such as a cloud service, call center or delivery company, both are treated as handling the data. If the contractor is breached, both are obliged to report, and they may file a joint report. The contractor is released from its own duty if it promptly tells the client, which then reports.

That rule explains a pattern that runs through Japan's 2026 breaches:

  • When attackers broke into the i-ask FAQ system, each client, including Daiwa Securities and Citizen, published its own notice.
  • After the IDCF Cloud ransomware attack, JR East, View Card and JR Kyushu disclosed possible leaks from an email delivery service hosted there.
  • Sagawa Express says it will file reports jointly with the shippers whose parcels it carried, and shippers such as the city of Yokosuka have started warning their own customers.

For readers, it means a notice about the same incident may come from a company they have never heard of, or from one they forgot they used.

Telling the people affected#

When a breach must be reported, the company must also notify the individuals affected. The law asks for this "promptly according to the situation", which gives companies some room. The PPC's examples of when immediate notice is not required include cases where leaked data has been posted online and has not yet been taken down, so that notifying people could spread it further, and cases where so little is known that people could not act on a notice.

The notice must cover the overview, the types of data, the cause, any secondary harm, and anything that helps people protect themselves. It can be sent by letter, email or similar means, with no fixed format. If a company cannot reach people, for example because it has no contact details or they are out of date, it may instead publish the breach or set up a public inquiry line so that people can check whether they are affected.

Why companies publish notices at all#

The APPI does not require a public announcement. The PPC's guidelines say it is "desirable" to publish the facts and prevention measures, to limit secondary harm and help others avoid similar incidents. In practice, most large breaches are published, partly because publication is an accepted substitute when people cannot be reached individually. Times Car is an example: it asked former members to contact it through a form because their registered details may no longer be valid. Listed companies may also need to disclose a breach to investors through the Tokyo Stock Exchange's TDnet system if it could affect their business.

Other reports that may be required#

The PPC report is not the only one. Depending on the organization and the incident:

  • Critical infrastructure operators designated under Japan's active cyber defense law must report certain cyber incidents affecting key systems "promptly" from October 1, 2026.
  • Police: reporting a crime is not required by the APPI, but the PPC encourages companies hit by unauthorized access to contact the police and the IPA.
  • Sector regulators may require their own reports, for example in finance and telecommunications.
  • Holders of the Privacy Mark certification must report incidents to JIPDEC, which runs the scheme.

What happens if a company does not report#

The PPC can give guidance, issue recommendations and, if those are not followed or the case is urgent, issue orders. Violating an order is a crime, punishable by up to one year in prison or a ¥1 million fine, and companies can be fined up to ¥100 million. There are no fines for a late or missing breach report as such, and Japan has had no administrative fines for privacy violations until now.

What the 2026 amendment changes#

The Diet passed an amendment to the APPI on July 10, 2026, and it was promulgated on July 17. It takes effect in stages, mostly within two years of promulgation. The PPC is now drafting the detailed rules. For breaches, the PPC's overview says it will:

  • Ease notification to individuals where the lack of a notice is unlikely to harm them, for example when only internal IDs that mean nothing on their own have leaked. Companies would use alternative measures instead.
  • Allow some companies to skip the preliminary report within a certain range, if a third party such as an accredited privacy organization has checked their systems and procedures.
  • Allow final reports to be grouped for breaches affecting a single person, such as a letter sent to the wrong address.
  • Make unlawful provision of data to third parties a reportable event.
  • Set up a single reporting window under the National Cybersecurity Office for cyberattack reports filed on the common form, in step with the active cyber defense law.

The amendment also introduces Japan's first administrative fines (課徴金) for privacy violations, equal to the gains made from the violation. They are aimed at improper use, improper collection and unlawful sharing of personal data at scale, such as selling data, involving more than 1,000 people. In our reading of the PPC's overview, they do not apply to companies whose data is stolen in an attack. For breached companies, the main consequences remain the PPC's guidance and orders, and any claims from the people affected.

The numbers#

The PPC handled 17,139 breach reports from businesses in fiscal 2025 (April 2025 to March 2026), down about 10% from a record 19,056 the year before, according to its annual report as covered by Japanese media. Government bodies filed 2,278. Most reports involve human error, such as misdirected mail and lost documents, and many involve sensitive medical data.

The trend has turned up again. In the first quarter of fiscal 2026 (April to June 2026), the PPC processed 6,101 reports in total, more than in any of the four quarters of fiscal 2025. Of the reports from businesses:

Trigger Q1 FY2025 Q1 FY2026
Sensitive data 3,099 3,196
Risk of financial harm 991 1,093
Possible wrongdoing, including attacks 1,136 1,450
More than 1,000 people 310 246

Some reports meet more than one trigger, and a client and its contractor may both report the same incident. These figures predate the wave of large breaches disclosed from September 2026, which we track in our list of the largest breaches and our ransomware tracker. The PPC's response to that wave is covered in our article on its warning to companies.

What this means for readers#

  • If you run or advise a business that serves people in Japan, including from abroad, the APPI's reporting duty applies to you. Plan for a preliminary report within days, and know which of your contractors hold your customers' data.
  • If you use a contractor in Japan, make sure your contract requires it to tell you about a breach quickly. Its report to you starts your own clock.
  • If you receive a Japanese breach notice, "may have leaked" usually means the company could not rule it out, not that it has confirmed a leak. Notices can also come from a company that only held your data on behalf of another.
  • If your data was involved but you have not heard anything, check the company's website or inquiry line. Notification can lag, and publication may be the only notice for people the company cannot reach.

Japanese terms at a glance#

Japanese Reading Meaning
個人情報保護委員会 Kojin Jōhō Hogo Iinkai Personal Information Protection Commission (PPC)
漏えい等報告 rōei-tō hōkoku Breach report to the PPC
速報 / 確報 sokuhō / kakuhō Preliminary report / final report
報告対象事態 hōkoku taishō jitai Situation that must be reported
要配慮個人情報 yōhairyo kojin jōhō Sensitive personal information
おそれ osore Possibility, risk (as in "may have leaked")
本人への通知 honnin e no tsūchi Notifying the individuals affected
委託元 / 委託先 itakumoto / itakusaki Client / contractor (for data handling)
公表 kōhyō Public announcement
課徴金 kachōkin Administrative fine