Compliance

Japan’s APPI and the rule written for cookie data.

Japan took an unusual route. Rather than regulating cookies as personal data, the 2020 amendment created a category for data that only becomes identifying in the recipient’s hands, which is precisely what an advertising identifier is.

Law
Act on the Protection of Personal Information
Detected as
APPI
Regulator
Personal Information Protection Commission
Default model
Opt-in

Personally referable information

Whether a cookie ID is personal information depends on the information available to the business, including information it can readily collate to identify an individual. The amended Act also defines "personally referable information" for information relating to a living individual that is not already personal information, pseudonymously processed information or anonymously processed information, and regulates specified transfers of it.

Where a business provides personally referable information to a third party and it is anticipated that the recipient will acquire it as personal information, the provider must confirm in advance that the recipient has obtained the individual’s consent. That is the rule that reaches a data-management platform, an ad network or any partner that will join your identifier to their profile.

Why this maps onto categories cleanly

The obligation attaches to the transfer, not to the storage. A consent model that keeps advertising technologies from loading until the marketing category is granted prevents the transfer from happening in the first place, which is the simplest way to be sure the confirmation duty never arises unmet.

What each region profile resolves to

Region profileResolved modelWhat the visitor sees
Regional defaultsopt-inNothing optional loads until a choice is made
Global strictopt-inNothing optional loads until a choice is made, everywhere
Global balancedopt-inNothing optional loads until a choice is made
EU and UK opt-innoneNo banner

JP is in the engine’s opt-in set, so a Japanese visitor gets a prior-consent experience under Regional defaults, Global strict and Global balanced.

Other APPI duties worth knowing

  • Specify the purpose of use and make it public; changing it beyond a reasonably related scope needs consent
  • Cross-border transfers require consent with prescribed information about the destination, or an adequate framework
  • Breach reporting to the PPC and notification to affected individuals is mandatory for defined categories of leak
  • Individuals have rights to disclosure, correction and cessation of use, exercisable against short-term data as well

A Japanese-language banner is the practical baseline. Add ja to the property translations; the runtime selects it from the visitor’s browser language preferences and falls back to the property default.

This is a product reference, not legal advice

It describes how StrongPrivacy behaves and summarises published law so you can configure the product deliberately. Whether a particular configuration satisfies your obligations is a question for your own counsel, who knows your data flows and your risk position.

Common questions

Are cookies personal information under the APPI?

Sometimes. A cookie identifier can be personal information where the business can identify an individual from it alone or by readily collating other information. If it is not personal information for the provider, it may instead be personally referable information, with a confirmation duty for specified transfers where the recipient is expected to acquire it as personal data.

Does the APPI require a consent banner?

It does not mandate a banner generally. Article 31 requires confirmation that the recipient obtained the individual’s consent in a specified transfer of personally referable information that the recipient is expected to acquire as personal data. A purpose-specific banner may help, but a generic category click does not automatically prove that every statutory information and confirmation requirement was met.

How does StrongPrivacy help with the confirmation duty?

By not letting the transfer start. Under an opt-in model no loader is created for a marketing technology until the category is granted, and every grant is recorded against a configuration version that names the technologies it covered.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.