Hello, this is Ryuta Hamamoto from TIMEWELL.
"If we send personal data to an LLM hosted overseas, that's a cross-border transfer, isn't it?" Our own legal team asks me this. So do clients' IT departments. My answer is usually some version of "it isn't that simple," which is an unsatisfying thing to say out loud. But open the statute and the regulator's own documents, and that is where you land.
Here is the part that surprises people. Japan's Personal Information Protection Commission (個人情報保護委員会) published an alert on the use of generative AI services on 2 June 2023. The words "Article 28", "a third party in a foreign country" and "cross-border" do not appear anywhere in it1. The Commission has not been silent on generative AI as such. On this particular question, though, I cannot find a published document in which it applies Article 28 to generative AI, as of September 2026.
Which leaves us to assemble the answer from the general rules ourselves.
So this piece reads Article 28 of the Act on the Protection of Personal Information (個人情報保護法第28条), Articles 16, 17 and 18 of the Enforcement Rules (個人情報の保護に関する法律施行規則), the Commission's Guidelines and its Q&A, going to the original text of each and asking where the lines have actually been drawn. If you would rather first get a read on where your own organisation stands today, start with the free AI readiness check.
Two things to flag before we start. English renderings of the statute and of the Commission's documents in this article are my own translations of the Japanese originals, not official translations, and the Japanese text governs. And wherever I apply these rules to LLM APIs, that is my reading rather than the Commission's. I will say so again at the points where it matters most.
Why "send it to an AI and Article 28 kicks in" does not hold
Let me undo the common misconception first. Article 28 is not a provision about AI. It is a general rule setting out the procedure for providing personal data to a third party in a foreign country. The phrase "generative AI" appears nowhere in it.
The Commission does not fill that gap either. As I said, the alert of 2 June 2023 contains none of the vocabulary of Article 281. What about the Guidelines? The version now in force was partially amended in December 20252, and it carries no passage applying generative AI to Article 28. The most recent Q&A, updated 1 July 2025, is the same3. As things stand, I cannot find any document in which the Commission has stated a view on Article 28 as applied to generative AI.
That fact carries real weight in practice, because it takes away the sentence "the Commission says so." What remains available is the existing test written for cloud services in general, and the step of applying that test to an LLM API is each company's own interpretation. Including mine. The application I set out below is my reading of the statute and the official documents. Please do not receive it as a settled answer.
There is a second thing worth straightening out, which is how the question is framed. "Is an LLM API covered by Article 28" is really two questions stacked on top of each other. First, has there been a provision of personal data to a third party at all? Second, if there has, on what basis do you proceed? Plenty of teams skip the first and go straight to drafting consent language. That order is backwards. Depending on how the first question resolves, an entire workstream may vanish. Or you may believe it has vanished when it has not.
Struggling with AI adoption?
We have prepared materials covering ZEROCK case studies and implementation methods.
What Article 28(1) actually says
Time to read the text. It runs long, but the parentheticals are the substance rather than the packaging, so I am quoting it in full. The English below is my own rendering of the Japanese, following the original word order as closely as English allows4.
A personal information handling business operator shall, in cases where it provides personal data to a third party in a foreign country (meaning a country or region outside the territory of Japan; the same applies hereinafter in this Article and in Article 31, paragraph 1, item (ii)) (excluding those prescribed by rules of the Personal Information Protection Commission as foreign countries having a personal information protection system recognised to be at a level equivalent to that of Japan in terms of protecting the rights and interests of individuals; the same applies hereinafter in this Article and in that item), that third party being one other than a person who has established a system conforming to the standards prescribed by rules of the Personal Information Protection Commission as necessary for continuously taking measures equivalent to those which a personal information handling business operator is required to take under the provisions of this Section with respect to the handling of personal data (such measures being referred to as "equivalent measures" in paragraph 3) (the same applies hereinafter in this paragraph, in the following paragraph and in that item), obtain in advance the consent of the individual to the effect that the individual approves the provision to a third party in a foreign country, except in the cases listed in each item of paragraph 1 of the preceding Article. In this case, the provisions of the preceding Article do not apply.
The reason it reads badly becomes obvious quickly. Two carve-outs sit embedded inside the sentence as parentheticals. The first removes, from the word "foreign country", those countries whose protection regime is at a level equivalent to Japan's. The second removes, from the word "third party", anyone who has established a conforming system. Fall inside the first and your counterparty's country is no longer a "foreign country" for these purposes. Fall inside the second and your counterparty is no longer a "third party". Either way Article 28(1) simply does not apply, and the Guidelines set out that structure explicitly5.
What falls away, though, is Article 28 and nothing more. The Guidelines say that even in these cases you still have to proceed by one of the routes under Article 27: the consent of the individual, one of the cases listed in the items of Article 27(1), opt-out, or provision by way of entrustment, business succession or joint use5. Escaping Article 28 is not the same as being free of obligations. Miss that, and the only conclusion that travels around the company is "we don't need cross-border consent."
One more caveat belongs with any quotation of this text. The Act partially amending the Act on the Protection of Personal Information and related acts (Act No. 56 of 2026) was promulgated on 17 July 2026, and its new-and-old comparison table shows the internal cross-reference wording of Article 28(1) being revised6. The change is housekeeping. Wording along the lines of "the same applies hereinafter in this Article and in Article 31, paragraph 1, item (ii)" becomes "the same applies hereinafter". Paragraphs 2 and 3 are marked "2 and 3 (omitted)" and are not amended. The substance of the rules is not changing. Under Article 1 of the supplementary provisions the amendment comes into force on a date to be fixed by cabinet order within two years from the date of promulgation, and as of September 2026 it has not come into force. If you are pasting the article text into an internal memo, I would add that sentence.
Only the EU and the UK are on the equivalent-level list
The countries removed by the first parenthetical are named plainly in the Guidelines. The EU and the UK7. "EU" here means the countries specified in Personal Information Protection Commission Public Notice No. 1 of 2019, which does not include the UK; the UK is designated separately. The Guidelines also record the background, which is that the designation was made alongside the European Commission's adequacy decision for Japan, in order to facilitate the smooth mutual transfer of personal data between Japan and the EU.
In practice this route is close to unusable here, because the major LLM providers are not headquartered in the EU or the UK. Remembering that the list has two entries on it is about the right level of attention to give it.
The conforming system is one of two options, and there is nothing to file
The second parenthetical, the conforming system, looks like it opens up a range of choices. Article 16 of the Enforcement Rules provides exactly two8. Item 1 is that, between the provider and the recipient, the implementation of measures in line with the purpose of the provisions of Chapter IV, Section 2 of the Act is ensured by an appropriate and reasonable method with respect to the recipient's handling of the personal data concerned. Item 2 is that the recipient has obtained a certification under an international framework concerning the handling of personal information.
On what counts as an "appropriate and reasonable method" under item 1, the Guidelines give contracts, confirmation documents and memoranda in the case of entrustment, and internal rules or privacy policies in the case of transfers within the same corporate group9. For item 2, they state that holding certification under the APEC CBPR system or the Global CBPR system qualifies9.
There is a sentence at the head of Chapter 4 of the same Guidelines that gets missed a lot. No prior notification or similar filing with the Personal Information Protection Commission is required in respect of having established the necessary system9. This does not appear in the text of Rule 16, so the accurate citation for it is the Guidelines. And because nothing is filed, whether your arrangement is adequate remains entirely your own accountability to demonstrate.
The dividing line is whether the recipient is to handle the data
Back to the first of the two stacked questions, which is whether there has been a provision at all. Q7-53 of the Q&A is where this lives10. On whether use of a cloud service amounts to third-party provision or entrustment, the Commission writes:
The criterion is not whether the stored electronic data contains personal data, but whether the business operator providing the cloud service is to handle the personal data.
The test does not look at the contents of the data. It looks at whether the recipient is to handle it. Where the recipient is not to handle it, the answer states that no personal data has been provided, the consent of the individual is unnecessary, and because there is no entrustment either, no supervisory duty arises under Article 25 of the Act. And "a case where the recipient is not to handle it" is described as covering situations such as where contractual terms provide that the external operator will not handle the personal data stored on the server, and access control is appropriately implemented.
Q12-3 carries this over to Article 2811. Even where personal data is stored on a server that a foreign operator has installed, manages and operates in a foreign country, if the operator running that server is not to handle the personal data stored on it, there is no provision to a third party in a foreign country. Storing data on a server that you yourself install, manage and operate in a foreign country is likewise outside the provision. So the cloud carve-out is properly connected through to the Article 28 side as well.
From here on this is my interpretation. Apply that test to LLM API use and the whole argument narrows to a single question, which is whether the provider is to handle the prompts you submit. If the contractual terms provide that inputs will not be used for training, will not be retained, and will not be viewed by employees, and actual access controls sit behind those terms, then you are fairly close to the structure Q7-53 describes. If human review is reserved, or the design retains inputs for abuse detection in a way that staff may view them, "not handling" becomes a hard argument to make. What matters here is that none of this is a doctrine peculiar to generative AI. It is the work of reading a contract and reading your access controls.
Whether the server sits in Japan does not decide it
"We picked the Tokyo region, so we're fine." I have heard that explanation a great many times. Q12-4 answers it head on12. Where the foreign operator running the server concerned handles the personal data stored on that server, this constitutes a provision to a third party in a foreign country even in a case where the server is located in Japan. That is the principle.
The same answer carries a proviso, and any summary that drops it is wrong. It does not fall within the provision where the foreign operator running the server handles the personal data stored on that server within Japan, and is recognised as using a personal information database, etc. for its business in Japan. The cross-reference given is section 2-2 of the Guidelines.
Section 2-2 says that whether someone is "a third party in a foreign country" is judged by legal personality in the first place13. A Japanese company providing data to a local subsidiary that has acquired foreign legal personality is covered; movement within the same legal person, such as to a local office or branch, is not. And a foreign corporation is not covered where it is recognised as using a personal information database, etc. for its business in Japan, such as where it has established an office in Japan or carries out business activities in Japan. The related Q12-5 adds that whether it is so recognised is judged individually taking into account the actual state of its business in Japan, so merely having a liaison office in Japan does not by itself immediately place it outside the provision14.
Put together, three things decide it. The counterparty's legal personality, the actual state of its handling of the data in Japan, and whether it is to handle the data at all. The latitude and longitude of the server is none of the three. On the separate question of whether the government where your data sits can reach for it, I went through the texts in which government can reach your data abroad.
The consent route starts by filling in the three items in Rule 17
Suppose you conclude that a provision has taken place. Consent from the individual is the first thing most people reach for. But Article 28 does not treat consent as the end of the matter. Paragraph 2 requires that, where you intend to obtain that consent, you must provide in advance information on the personal information protection system of the foreign country concerned, information on the measures the third party takes for the protection of personal information, and other information that would serve as a reference to the individual, with the content of all this delegated to Commission rules4.
Article 17(2) of the Enforcement Rules, the provision that catches that delegation, sets out an exhaustive list of three15. The name of the foreign country concerned. Information on that foreign country's personal information protection system, obtained by an appropriate and reasonable method. Information on the measures the third party concerned takes for the protection of personal information.
Item 2 is the heavy one. The Guidelines say the system information has to be information from which the individual can reasonably recognise the essential differences between the regime of the foreign country where the recipient is located and Japan's Act, and then give four perspectives16. The presence or absence of a system. The existence of information capable of serving as an indicator of the system. The absence of an operator obligation or an individual's right corresponding to the eight principles of the OECD Privacy Guidelines. And the existence of other systems that may have a material impact on the rights and interests of the individual. Two examples are given for the fourth: a system enabling broad information collection by the government in respect of personal information held by operators, and a system imposing a domestic storage obligation on personal information under which there is a risk of being unable to respond to a request for erasure from the individual. A limit is attached as well, in that only systems applicable to the recipient third party are in scope; systems that do not apply to it are not included.
For anyone worried about US state law, the treatment sits in section 5-2(1) of the same Guidelines. It is not in the body text, though. It appears in a footnote, note 2, which says that showing the name of the foreign country suffices and that showing the name of the state and so on is not required, and then adds that where state law is the principal regulation and information about state law would contribute to improving the individual's predictability, it is desirable to indicate the state and provide information on the state-level system as well16. Desirable, not obligatory. That distinction is worth carrying accurately.
The escape routes for when you cannot write these things are built into the Rules in advance. Where the country cannot be identified, Rule 17(3) applies, and in place of the country name and system information you provide the fact that it cannot be identified together with the reason, plus, where there is information that would instead serve as a reference to the individual, that information. Where the information on the measures taken by the recipient cannot be provided, Rule 17(4) applies as a separate track, allowing this to be replaced by that fact and the reason for it15. The two examples the Guidelines give are a clinical trial in which it has not been settled which country's regulatory authority the approval application will ultimately go to, and reinsurance in which it has not been settled which reinsurer will ultimately take the risk17.
One thought from the platform side. If you want to reduce this burden, checking first whether you can build in a way that never sends personal data outside is often quicker than working the paperwork. That is a large part of why we hold to domestic-region architecture in ZEROCK. My honest sense is that there is usually work left on the table before anyone needs to start polishing consent language.
The conforming-system route comes with homework after the handover
There are situations where going out to collect consent is not realistic, and that is where the conforming system gets chosen. The entrance is light on this road, and the exit is long. Article 28(3) provides that where you have made the provision on the basis of a conforming system, you must take the measures necessary to ensure the continued implementation of the equivalent measures, and must provide information on those measures at the request of the individual4.
Article 18(1) of the Enforcement Rules spells out two such measures18. The first is to confirm periodically, by an appropriate and reasonable method, the implementation status of the equivalent measures by the recipient, together with the presence and content of any system in the foreign country concerned that may affect their implementation. The second is that where an impediment to the implementation of the equivalent measures arises, you take necessary and appropriate measures, and where ensuring their continued implementation becomes difficult, you stop providing personal data to that third party. Keep an eye on the other country's regime on a recurring basis, in other words, as a matter of legal requirement. That one seems less widely known than it should be.
The information you hand over when an individual asks for it is listed in Rule 18(3), which sets out seven items18. The method by which the system was established. An outline of the equivalent measures. The frequency and method of confirmation. The name of the foreign country concerned. The presence and outline of any system in that foreign country that may affect implementation of the equivalent measures. The presence and outline of any impediment. And an outline of the measures taken in relation to that impediment. The rule is to provide these without delay; where doing so risks causing serious impediment to the proper implementation of your business you may withhold all or part of them, but you then have to notify the individual to that effect without delay under paragraph 4, and endeavour to explain the reason under paragraph 5.
This is where a proviso placed in the Guidelines starts to matter. After explaining that Article 28(3) clarifies the provider's responsibility to continue ensuring proper handling in cases where the provision was made on the basis of a conforming system, the Guidelines go on to say this. In light of the purpose of the system, where personal data has been provided to a third party in a foreign country on the basis of the consent of the individual, the measures under Article 28(3) are not required, even in a case where that third party is recognised as having established a conforming system19.
The two roads therefore differ only in where they put the load. Go by consent and the Article 28(3) homework does not follow you home. You explain everything at the entrance, and in exchange you are released from the periodic confirmation and from keeping the seven-item disclosure ready. Go by the conforming system and the entrance is handled in a contract, but an operational duty to keep watching the counterparty country's regime begins on the day you sign. Which one is lighter comes down to how often you provide the data and whether you have any direct contact with the individual. A business where collecting consent once a year is enough leans the first way; the back end of a B2B flow with no direct contact leans the second. That is my instinct on it, at least.
Falling outside Article 28 does not clear everything
The last point is the one I see missed most often. Say you have landed inside the cloud carve-out of Q7-53 and Q12-3. You are not finished. Q10-25 addresses this squarely20.
Where you use a cloud service provided by a third party in a foreign country and the providing operator is not to handle the personal data, there is no third-party provision. So far, identical to what we covered above. Then the answer continues. In this case the personal information handling business operator will be handling personal data in a foreign country, so it must take security control measures after ascertaining the personal information protection system and related matters of that foreign country. And one more sentence follows. The same applies in cases where the personal data is stored on a server located in Japan.
Q10-25 goes a step further still. As the "measures taken for the security control of retained personal data" under Article 32(1)(iv) of the Act and Article 10(i) of the Cabinet Order, you must make clear the name of the foreign country where the cloud service provider is located and the name of the foreign country where the server storing the personal data is located, and place the content of the measures you have taken after ascertaining that country's system in a state where the individual can know it. A substitute is provided for cases where the country in which the server is located cannot be identified: in place of the country name, you put the fact that it cannot be identified, the reason, and information that would serve as a reference to the individual. Q12-3 noted the same thing in its own context, adding that care is needed because the security control measures under Article 23 of the Act and the publication under Article 32(1)(iv) remain in place11.
This is the part that bites hardest in day-to-day work. Even where you have avoided needing consent under Article 28, understanding the external environment and publishing what you found remain. A domestic server does not get you out of it either. A company that claims the cloud carve-out while never once updating its privacy policy may well have a hole open somewhere other than where it is looking. On which models are actually available in which region, which is the precondition for all of this, I wrote up what the providers' own documentation says in can you actually run an LLM inside Japan.
As for the order to work in, here is how I think about it. Open the contract first and check whether the recipient is to handle the personal data. Next, the counterparty's legal personality and the actual state of its handling of the data in Japan. If you can conclude at that point that no provision has taken place, the thing you go and fix is not your consent wording but the external-environment description in your privacy policy. If a provision has taken place, compare consent against the conforming system by weighing the burden at the entrance against the burden at the exit, and pick the one that fits how you actually operate. Do it in the reverse order and you start with the heaviest piece of work, the consent design, and leave the most easily missed piece, the publication, sitting untouched until the end.
One closing caveat. This article is an organised reading of the statute, the Guidelines and the Q&A in their original text, and it is not legal advice. The parts where the rules are applied to LLM APIs contain my own interpretation. Final decisions on any specific matter should be taken together with your own legal department and outside counsel.
Designing where the line falls between what stays inside Japan and what goes beyond it is the work we do on enterprise AI platforms in ZEROCK. If you want to take stock of your own architecture against the actual text, get in touch.
Footnotes
-
Personal Information Protection Commission of Japan, "Alert and related matters concerning the use of generative AI services" (生成AIサービスの利用に関する注意喚起等について), 2 June 2023. The absence from that document of the terms rendered in this article as "Article 28", "a third party in a foreign country" and "cross-border" reflects a check of the published material as at 6 September 2026. https://www.ppc.go.jp/news/press/2023/230602kouhou/ ↩ ↩2
-
Personal Information Protection Commission of Japan, "Guidelines on the Act on the Protection of Personal Information (Volume on Provision to a Third Party in a Foreign Country)" (個人情報の保護に関する法律についてのガイドライン(外国にある第三者への提供編)), November 2016, partially amended December 2025. This article references that current version, not an earlier one. https://www.ppc.go.jp/personalinfo/legal/guidelines_offshore/ / PDF https://www.ppc.go.jp/files/pdf/251212_guidelines02.pdf ↩
-
Personal Information Protection Commission of Japan, "Q&A on the Guidelines on the Act on the Protection of Personal Information" (「個人情報の保護に関する法律についてのガイドライン」に関するQ&A), 16 February 2017, updated 1 July 2025. This is the most recent version as at 6 September 2026. https://www.ppc.go.jp/files/pdf/250701_APPI_QA.pdf ↩
-
Act on the Protection of Personal Information (Act No. 57 of 2003), Article 28, paragraphs 1 to 3. Article text from the e-Gov legislative database. English renderings in this article are the author's translations of the Japanese original and are not official translations. https://laws.e-gov.go.jp/law/415AC0000000057 ↩ ↩2 ↩3
-
Guidelines cited above (Volume on Provision to a Third Party in a Foreign Country), chapter 2 (general provisions). The points that a country with an equivalent-level regime does not fall within "foreign country" under Article 28(1), that a person having established a conforming system does not fall within "third party" under the same paragraph, and that even in these cases the provision must proceed by one of (a) the consent of the individual, (b) a case listed in the items of Article 27(1), (c) opt-out, or (d) entrustment, business succession or joint use, are all from that chapter. https://www.ppc.go.jp/files/pdf/251212_guidelines02.pdf ↩ ↩2
-
Personal Information Protection Commission of Japan, new-and-old comparison table for the Act partially amending the Act on the Protection of Personal Information and related acts (Act No. 56 of 2026), promulgated 17 July 2026. The revision of the internal cross-reference wording in Article 28(1), the marking of paragraphs 2 and 3 as "2 and 3 (omitted)" without amendment, and the entry into force under Article 1 of the supplementary provisions on a date to be fixed by cabinet order within two years from the date of promulgation, are all from that table. No cabinet order fixing the date of entry into force could be confirmed as at 6 September 2026. https://www.ppc.go.jp/files/pdf/260717_sinkyutaisyohyo.pdf ↩
-
Guidelines cited above (Volume on Provision to a Third Party in a Foreign Country), chapter 3. The identification of the EU and the UK as foreign countries having an equivalent-level regime, the point that "EU" here means the countries specified in "Foreign countries and other jurisdictions having a personal information protection system recognised to be at a level equivalent to that of Japan in terms of protecting the rights and interests of individuals" (Personal Information Protection Commission Public Notice No. 1 of 2019) and does not include the UK, and the background to the designation, are all from that chapter. https://www.ppc.go.jp/files/pdf/251212_guidelines02.pdf ↩
-
Enforcement Rules of the Act on the Protection of Personal Information (Personal Information Protection Commission Rules No. 3 of 2016), Article 16. https://laws.e-gov.go.jp/law/428M60020000003 ↩
-
Guidelines cited above (Volume on Provision to a Third Party in a Foreign Country), chapter 4 (chapeau), 4-1 and 4-3. The point that no prior notification or similar filing is required appears in the chapeau of that chapter and is not provided for in the text of Article 16 of the Enforcement Rules. https://www.ppc.go.jp/files/pdf/251212_guidelines02.pdf ↩ ↩2 ↩3
-
Q&A cited above, Q7-53 and A7-53. The criterion, the points that where the recipient is not to handle the data the consent of the individual and supervision under Article 25 of the Act are unnecessary, and the description of contractual terms and access control, are all from that answer. The same answer also states expressly that Q12-3 should be consulted on the relationship with Article 28. https://www.ppc.go.jp/all_faq_index/faq1-q7-53/ / PDF https://www.ppc.go.jp/files/pdf/250701_APPI_QA.pdf ↩
-
Q&A cited above, Q12-3 and A12-3 (updated September 2021). The points that storage on a server one installs, manages and operates oneself in a foreign country is outside the provision, that a case where the foreign operator is not to handle the data is outside the provision, and that care is needed regarding the security control measures under Article 23 of the Act and the publication under Article 32(1)(iv) of the Act and Article 10(i) of the Cabinet Order, are all from that answer. https://www.ppc.go.jp/files/pdf/250701_APPI_QA.pdf ↩ ↩2
-
Q&A cited above, Q12-4 and A12-4 (updated September 2021). Both the principle and the proviso appear in that answer. https://www.ppc.go.jp/files/pdf/250701_APPI_QA.pdf ↩
-
Guidelines cited above (Volume on Provision to a Third Party in a Foreign Country), section 2-2. Judgment by legal personality, the distinction between a local subsidiary and an office or branch within the same legal person, and the point that a foreign corporation recognised as using a personal information database, etc. for its business in Japan falls outside the provision, are all from that section. https://www.ppc.go.jp/files/pdf/251212_guidelines02.pdf ↩
-
Q&A cited above, Q12-5 and A12-5 (updated September 2021). https://www.ppc.go.jp/files/pdf/250701_APPI_QA.pdf ↩
-
Enforcement Rules cited above, Article 17, paragraphs 1 to 4. The method of provision, the three items to be provided, the substitute where the foreign country cannot be identified, and the substitute where the information on the recipient's measures cannot be provided, are each from the respective paragraph of that Article. https://laws.e-gov.go.jp/law/428M60020000003 ↩ ↩2
-
Guidelines cited above (Volume on Provision to a Third Party in a Foreign Country), section 5-2. The requirement that the information allow the individual reasonably to recognise the essential differences, the four perspectives (a) to (d), the two examples under (d), and the point that regimes not applicable to the recipient are not included, are all from the body of that section. The passage on the names of states and the like is footnote 2 within section 5-2(1) and is not body text. https://www.ppc.go.jp/files/pdf/251212_guidelines02.pdf ↩ ↩2
-
Guidelines cited above (Volume on Provision to a Third Party in a Foreign Country), sections 5-3-1 and 5-3-2. The clinical trial example where the regulatory authority for the approval application is undetermined, and the reinsurance example where the reinsurer is undetermined, are from the [Example] entries in those respective sections. https://www.ppc.go.jp/files/pdf/251212_guidelines02.pdf ↩
-
Enforcement Rules cited above, Article 18, paragraph 1 and paragraphs 3 to 5. The two measures of periodic confirmation and suspension of provision, the seven items to be provided at the request of the individual, and the withholding, notification and explanation of reasons where there is serious impediment, are each from the respective paragraph of that Article. https://laws.e-gov.go.jp/law/428M60020000003 ↩ ↩2
-
Guidelines cited above (Volume on Provision to a Third Party in a Foreign Country), chapter 6. The purpose of Article 28(3) and the point that the measures under that paragraph are not required where the provision was made on the basis of the consent of the individual are from that chapter. https://www.ppc.go.jp/files/pdf/251212_guidelines02.pdf ↩
-
Q&A cited above, Q10-25 and A10-25 (added September 2021). The need to take security control measures after ascertaining the foreign country's regime, the point that the same applies where the server is located in Japan, the need to make clear the name of the country where the providing operator is located and the name of the country where the server is located and to place the measures in a state where the individual can know them, and the substitute where the country in which the server is located cannot be identified, are all from that answer. https://www.ppc.go.jp/files/pdf/250701_APPI_QA.pdf ↩

![Making Sense of Japan's 2026 APPI Amendment | Easier AI Training Data, a New Surcharge Regime, and Children's Personal Information [Hamamoto Explains]](/images/columns/personal-information-protection-law-2026-amendment/cover.png)




