Regulation and standard

What does Japan's APPI require for employee supervision and training?

Short answer

Japan's Act on the Protection of Personal Information (APPI) requires every business handling personal information to take necessary and appropriate security control measures (Article 23) and to supervise employees who handle personal data (Article 24). The Personal Information Protection Commission's General Rules Guidelines make employee education a mandatory human security control measure: staff must be made fully aware of proper handling of personal data and given appropriate education, with periodic training as the illustrated method.

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
12 min
Jurisdiction
Japan (national)
Regulator
Personal Information Protection Commission (PPC)

Key takeaways

  • APPI Article 23 requires security control measures and Article 24 requires necessary and appropriate supervision of employees who handle personal data. These article numbers apply after the 2021 amendment renumbered the Act.
  • The PPC General Rules Guidelines list employee education (jūgyōsha no kyōiku) as a human security control measure that businesses must take, with periodic training on handling rules as the example method.
  • "Employee" is broad: it covers regular, contract, part time and dispatched workers and also directors, executive officers and auditors.
  • The Guidelines say it is desirable to scale the content and frequency of education to risk, based on the size of the business and the nature and volume of personal data handled.
  • An amending Act was promulgated on July 17, 2026. It mostly takes effect within two years of promulgation, with the penalty changes applying six months after promulgation. It does not change the Article 23 and 24 duties, but it adds administrative surcharges and tougher penalties that raise the stakes of weak controls.

What do the PPC Guidelines require for employee education?

The PPC Guidelines require businesses to make employees fully aware of the proper handling of personal data and to give them appropriate education. Section 10 of the General Rules Guidelines (an appendix setting out the security control measures to be taken) groups those measures into a basic policy, handling rules, organizational, human, physical and technical measures, and understanding the external environment. Under section 10-4, human security control measures (jinteki anzen kanri sochi), the measure that businesses must take is employee education: staff must be made thoroughly aware of the proper handling of personal data and given appropriate education.

The Guidelines then give two example methods, which apply equally to small and medium sized businesses: holding periodic training (teikiteki na kenshū) for employees on points to note when handling personal data, and including confidentiality obligations for personal data in the work rules (shūgyō kisoku) or similar documents. Methods are illustrations, so a business may choose other methods that achieve the same result, but the requirement to educate is not optional.

Section 3-4-3 of the Guidelines, on supervision of employees under Article 24, adds a risk based expectation. Considering the harm individuals would suffer from a leak, the size and nature of the business and the nature and volume of personal data handled, it is desirable to strengthen the content and frequency of education and training for employees who handle personal data. The same section lists failures that count as inadequate supervision, including not checking whether employees follow the handling rules, and leaving repeated removal of laptops or media containing personal data unaddressed until a loss occurs.

Where training sits in the APPI framework, as at September 2026
SourceWhat it saysStatus
APPI Article 23Take necessary and appropriate security control measures for personal dataBinding duty in the Act
APPI Article 24Exercise necessary and adequate supervision over employees who handle personal dataBinding duty in the Act
General Rules Guidelines, section 10-4Make employees fully aware of proper handling and give appropriate educationWritten as a "must": failure may be judged a violation
Section 10-4 example methodsPeriodic training on handling points; confidentiality in work rulesIllustrations: other effective methods may be used
Section 3-4-3Scale content and frequency of education to riskWritten as "desirable"

Who counts as an employee for APPI supervision?

An employee (jūgyōsha) is anyone within the organization who works under its direct or indirect direction and supervision, not only people with an employment contract. The Guidelines list regular, contract, fixed term re-hired, part time and casual employees, and also directors, executive officers, board members, statutory auditors and dispatched (temporary agency) workers. A training plan that covers only permanent staff therefore misses people the PPC expects to be supervised.

Contractors are handled differently. Where a business entrusts the handling of personal data to another company, Article 25 requires supervision of that company, including selecting a contractor whose security measures are at least equivalent to what the Guidelines require. In practice, contract terms often require the contractor to train its own staff, and the business checks that this happens.

Do small businesses have a lighter training duty?

No. Small and medium sized businesses must still take the security control measures in Article 23, including employee education, but the Guidelines offer simpler example methods for some measures. A "small and medium sized business" in the Guidelines means one with 100 or fewer employees, excluding businesses that handle personal data about more than 5,000 individuals on any day in the previous six months and businesses that handle personal data as a contractor. For the education measure specifically, the example methods for small businesses are the same as for everyone else: periodic training and confidentiality in the work rules.

How does leak reporting affect training content?

Training must prepare staff to escalate suspected leaks quickly, because Article 26 makes reporting to the PPC mandatory for certain incidents. Since the 2020 amendment took full effect on April 1, 2022, businesses must report to the PPC and notify affected individuals when a leak, loss or damage of personal data falls into a reportable category. Under PPC Rules Article 7, reportable situations include leaks involving sensitive (special care required) personal information, leaks likely to cause financial damage, leaks that may have been committed for a wrongful purpose, and leaks affecting more than 1,000 individuals.

The clock is short. The Guidelines give roughly three to five days from the time any department of the business becomes aware of the situation as the benchmark for a prompt preliminary report, and require a final report within 30 days (60 days where the leak may result from an act done for a wrongful purpose, such as unauthorized access). Because the clock starts when any department knows, front line staff must know what to report, to whom, and how fast. The Guidelines also expect a reporting line from employees to responsible persons to be set up in advance as an organizational measure.

What happens if training and supervision fall short?

The PPC can request reports and conduct on-site inspections (Article 146), and can issue recommendations and orders for violations of Articles 23 to 26 (Article 148). Breaching a PPC order is a criminal offense punishable by imprisonment of up to one year or a fine of up to 1,000,000 yen (Article 178). An employee or officer who provides or misappropriates a personal information database for wrongful gain faces up to one year's imprisonment or a fine of up to 500,000 yen (Article 179), and the corporation can be fined up to 100 million yen for either offense (Article 184).

The penalties are in transition. The "Act Partially Amending the Act on the Protection of Personal Information and Related Acts" was passed by the Diet on July 10, 2026 and promulgated on July 17, 2026, following the PPC's triennial review (the so-called sannen-goto minaoshi).

According to the PPC's summary of the amending Act, it introduces an administrative surcharge (kachōkin) for serious violations, broadens and raises the criminal penalties for unlawful provision of personal information databases, and relaxes some consent and breach notification rules. It takes effect, in principle, within two years of promulgation, and the PPC is still preparing the Cabinet Order, Rules and Guidelines (PPC page on the 2026 amendment). The summary does not list changes to Articles 23 or 24, so the education duty described here continues.

The penalty changes come sooner: under Article 1 of the Supplementary Provisions of the amending Act they take effect six months after promulgation, in January 2027. From then the insider database offense (renumbered Article 178) also covers provision intended to cause harm and carries up to two years' imprisonment or a fine of up to 1,000,000 yen, a new offense covers acquiring personal information by fraud, violence or unauthorized access, and the corporate liability provision becomes Article 185.

Why the insider offense matters for training

Article 179 (Article 178 once the 2026 penalty changes apply) targets employees and former employees personally. Training that explains this offense, and the corporate fine under Article 184 (to become Article 185), gives staff a concrete reason for the handling rules and gives the business evidence that it warned them.

What should APPI employee training cover?

APPI training should cover the handling rules the business has actually set, not a generic tour of the Act, because the Guidelines tie education to the proper handling of the business's own personal data. The table below is an illustrative mapping from each obligation to a learning outcome and the evidence that would show it was met. Use a training needs analysis to decide which roles need which rows.

Illustrative mapping: APPI obligation to learning outcome to assessment evidence
ObligationLearning outcomeAssessment evidence
Article 23 and the handling rules (section 10-2)Applies the business's handling rules at each stage: acquisition, use, storage, provision, deletion and disposalScenario questions on the business's own rules; supervisor sign off on first handling tasks
Article 24 and education (section 10-4)Explains confidentiality duties in the work rules and the consequences of breaching themSigned acknowledgement of work rules; quiz on confidentiality points
Organizational measures (section 10-3)Recognizes a suspected leak and reports it through the defined line immediatelyTimed incident scenario; records of internal reports
Article 26 leak reportingPrivacy lead can classify a reportable situation and meet the three to five day and 30 day benchmarksTabletop exercise record; post-incident review
Physical and technical measures (sections 10-5, 10-6)Follows rules on carrying media and devices, access control and secure deletionObserved practice checks; access log reviews
Article 25 trustee supervisionProcurement staff check a contractor's security and training before entrusting dataCompleted contractor due diligence checklist
Article 179 and Article 184Understands the personal and corporate penalties for unlawful provision of databasesKnowledge check item; annual attestation

Mapping obligations this way follows the method in how to map training to compliance obligations. It also makes the education measure publicly defensible: businesses must make the security control measures they have taken available to individuals on request, and the PPC's own example of a disclosable human measure is periodic training for employees on points to note when handling personal data.

How do you evidence APPI training to the PPC?

Keep records that show who was educated, on what version of the handling rules, when, and whether they understood it. The Act does not prescribe a record format, but the PPC can request reports and materials under Article 146, and a business investigating a leak will be asked what supervision it exercised. A practical evidence set includes the following.

  1. The handling rules (toriatsukai kitei) and the version in force on each training date.
  2. A roster of everyone treated as an employee under Article 24, including officers and dispatched workers.
  3. Training completion records with dates, content version and assessment results, kept as an audit trail.
  4. Signed confidentiality clauses or work rules acknowledgements, for example through policy attestation.
  5. Records of periodic self checks or audits of how staff actually handle personal data, which the Guidelines list as an organizational measure.
  6. A record of how training frequency and depth were set by risk, supporting the section 3-4-3 expectation.

The same records support audits under other privacy regimes, so multinational organizations can compare this page with GDPR staff training requirements and Australia's Privacy Act training expectations and build one core module with jurisdiction specific inserts.

How does Knowledge Foundry approach this?

Knowledge Foundry models Articles 23 to 26 and the relevant sections of the PPC Guidelines as obligations, links each to the business's own handling rules, and derives learning outcomes and assessment points before any content is written. When the 2026 amendment's Rules and Guidelines are finalized, the affected obligations are flagged so the linked training can be reviewed rather than rebuilt.

Frequently asked questions

Does the APPI say how often employees must be trained?

No. Neither the Act nor the PPC General Rules Guidelines set a fixed frequency. The Guidelines give periodic training as the example method and say it is desirable to increase the content and frequency of education according to risk. Many organizations train at induction and annually, with extra training for roles handling sensitive or large volumes of personal data.

Is APPI training required for businesses with only a few employees?

Yes. There is no small business exemption from Article 23 or Article 24. The Guidelines give simplified methods for some measures to businesses with 100 or fewer employees, but the education measure applies to them too, with the same example methods: periodic training and confidentiality obligations in the work rules.

Do directors and dispatched workers need APPI training?

They fall within the Guidelines' definition of employees, which includes directors, executive officers, statutory auditors and dispatched workers as well as regular and part time staff. If they handle personal data, the business is expected to supervise and educate them.

Does the APPI apply to foreign companies?

It can. The Act applies extraterritorially to foreign businesses that handle personal information of individuals in Japan in connection with supplying goods or services to them. The Guidelines also require businesses that handle personal data in a foreign country to understand that country's data protection system before setting security measures.

Will the 2026 amendment change training requirements?

The PPC's summary of the amending Act promulgated on July 17, 2026 does not list changes to Articles 23 or 24. It adds a surcharge system, heavier penalties and new rules on children's data, facial feature data and contractors. Revised Guidelines are still being prepared, so review training content once they are published.

Sources

  1. Act on the Protection of Personal Information (Act No. 57 of 2003), Japanese text, Digital Agency, e-Gov Laws
  2. Act on the Protection of Personal Information: English translation, Ministry of Justice, Japanese Law Translation
  3. Guidelines for the Act on the Protection of Personal Information (General Rules), revised June 2026, Personal Information Protection Commission
  4. 2026 amendment to the Act on the Protection of Personal Information, Personal Information Protection Commission
  5. About the Act Partially Amending the Act on the Protection of Personal Information and Related Acts (July 2026), Personal Information Protection Commission Secretariat
  6. Act Partially Amending the Act on the Protection of Personal Information and Related Acts (2026), Japanese text, Personal Information Protection Commission
  7. Japanese Law Translation: notice to users, Ministry of Justice

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.