Japan APPI Cross-Border Transfers: What an Overseas Vendor Must Support
Founder & Lead Engineer, RAITHub
A Japanese company can entrust personal data to an offshore developer, but under APPI Article 28 a vendor in a non-designated country such as Bangladesh counts as a third party in a foreign country. The company then needs either informed consent or a vendor that keeps equivalent measures, usually set by contract, and a leak affecting over 1,000 people must be reported to the PPC.
This guide is for founders, CTOs and privacy leads at Japanese companies who are about to hire an overseas development team. RAITHub is a software studio in Dhaka, so we have an interest in the answer; we are the overseas vendor in this picture. We have no office in Japan, and we deliver in English only: no Japanese-language delivery, documentation or support. Points below are drawn from the English translation of the Act on the Protection of Personal Information (APPI) and the Personal Information Protection Commission's (PPC) materials, and linked. This is general information, not legal advice. Confirm every point with your adviser and the PPC before you sign.
Does APPI Article 28 apply when you only entrust data to a vendor?
Yes, for a vendor abroad. This is the point that catches most teams. Inside Japan, entrustment is not a provision to a third party: Article 27(5)(i) excludes cases where a business "entrusts a person with all or part of the handling of personal data within the scope necessary for achieving the purpose of use" (APPI, English translation, consolidated as of 1 April 2023).
Article 28(1), however, opens with "Except cases set forth in the items of paragraph (1) of the preceding Article". It carves out the Article 27(1) exceptions, such as legal obligations, and not the Article 27(5) entrustment exclusion. So an overseas vendor that handles personal data for you is treated as a third party in a foreign country for Article 28 purposes, even though a Japanese vendor doing the same work would not be. Have your adviser confirm this reading against the PPC's guidelines on provision to a third party in a foreign country.
The English text is a translation for reference; the Japanese text is authoritative. The PPC's own laws page links the translation and the Commission rules (PPC, laws and policies).
What are the three ways to send personal data abroad under APPI?
Article 28(1) gives a business three routes, apart from the Article 27(1) exceptions:
- A designated country. Article 28(1) excludes a foreign country "prescribed by Order of the Personal Information Protection Commission as a foreign country that has established a personal information protection system recognized to have equivalent standards to that in Japan". In practice, that list covers the EU and the United Kingdom (DLA Piper, Data Protection Laws of the World: Japan). Bangladesh is not on it, as far as we can verify.
- A recipient with an equivalent-measures system. The Article also excludes a person "that establishes a system that conforms to standards prescribed by Order of the Personal Information Protection Commission as necessary for continuously taking measures equivalent to those" the Act requires. Under the PPC's rules, this is typically met by a contract or other appropriate and reasonable method binding the recipient, or by a recognised international framework such as the APEC Cross-Border Privacy Rules (PPC Enforcement Rules, English; DLA Piper).
- Informed consent. Otherwise, "the businesses must obtain an identifiable person's consent to the effect that the person approves the provision to a third party in a foreign country" (Art. 28(1)). Before asking, Article 28(2) requires you to give the person information about the foreign country's personal information protection system and the measures the recipient takes. The summary of the rules lists the name of the country, its data protection system, and the recipient's measures (DLA Piper).
For a development vendor, the second route is the practical one. Collecting fresh consent from every customer to send their data to Bangladesh is slow, and it does not cover customers who say no.
What does the equivalent-measures route ask of the vendor after signing?
More than a signature. Article 28(3) requires a business relying on this route to "take necessary measures to ensure continuous implementation of the equivalent measures by the third party", and to provide information on those measures to the person on request. As we read the PPC's rules, that means checking periodically that the vendor still applies the measures, watching for foreign laws that could affect them, responding if a problem appears, and stopping the transfer if continued implementation becomes difficult. We could not extract the rules PDF text when checking this post, so confirm the exact list with your adviser.
For the vendor, that turns into three concrete things: answering a periodic questionnaire, keeping evidence of its controls, and telling you promptly if something changes, such as a new sub-processor or a new country of access.
What do Articles 23 and 25 require for an entrusted vendor?
Article 23 requires the business to "take the necessary and appropriate measures for managing the security of personal data including preventing the leaking, loss or damage". Article 25 adds that when it entrusts handling to someone else, it must "exercise the necessary and adequate supervision over the person it entrusts, so as to ensure the secure management of the personal data".
The PPC's general guidelines describe security measures in organisational, human, physical and technical terms, and, where data is handled in a foreign country, expect the business to understand that country's personal information protection system. Treat that last point as something to confirm in the current guidelines. In practice, supervision under Article 25 comes down to choosing the vendor carefully, putting the handling rules in a contract, and checking how the data is actually handled.
The table maps each clause you should expect to the provision it supports.
| Clause | Where it comes from | What to ask the vendor for |
|---|---|---|
| Scope of entrustment | APPI 27(5)(i) | A written list of data categories and purposes, limited to what the build and support need. |
| Equivalent measures | APPI 28(1); PPC rules | A binding commitment to handle the data as the APPI's Chapter IV, Section 2 duties require, so the recipient falls within the equivalent-measures exclusion. |
| Country and access facts | APPI 28(2), 28(3) | Where data is stored, from where it may be accessed, and a description of the vendor's measures you can pass to customers on request. |
| Security control measures | APPI 23 | Access control, encryption, multi-factor sign-in on production, device rules and confidentiality duties on every team member. |
| Supervision and audit | APPI 25, 28(3) | Answers to a periodic questionnaire, evidence of controls, and a right to review them. |
| Change notice | APPI 28(3) | Prompt notice of new sub-processors, new access locations, or local legal changes that could affect the measures. |
| Leak notice to you | APPI 26(1) | Prompt notice of any leak, loss or damage, with the facts you need for your PPC report. |
| Deletion or return | APPI 22 (accuracy and deletion), contract | Deletion or return when the purpose or contract ends, with written confirmation. |
Put the IP assignment and NDA in the same bundle; the offshore IP assignment checklist covers those clauses.
How fast must a data leak be reported to the PPC?
Article 26(1) requires a business to report "leaks, loss or damage and other situations concerning the security of the personal data" that the PPC's rules prescribe as likely to harm individual rights and interests. Those situations are leaks, or likely leaks, of special care-required (sensitive) personal information, of data whose misuse could cause financial damage, of data where a wrongful purpose is suspected, and of data about more than 1,000 people (DLA Piper, breach notification in Japan).
The vendor matters here in a specific way. Article 26(1) says the reporting duty does not apply to an entrusted business that has notified the entrusting business "as prescribed by Order of the Personal Information Protection Commission". In other words, the vendor's job is to tell you quickly and completely; you report.
| Step | Who | What the text says |
|---|---|---|
| Tell you about the leak | Vendor (entrusted business) | Notify the entrusting business as the PPC's rules prescribe, which replaces the vendor's own report (APPI 26(1), proviso) |
| Check the four categories | You | Sensitive data, financial damage risk, suspected wrongful purpose, or more than 1,000 people (PPC rules) |
| Preliminary report to the PPC | You | Promptly after you become aware (PPC rules; confirm the current timing) |
| Final report to the PPC | You | Within 30 days of becoming aware, or 60 days where the leak may involve a wrongful purpose (PPC Enforcement Rules, Art. 8(2)); confirm with your adviser |
| Notify affected people | You | Required under APPI 26(2), unless notification is difficult and alternative measures protect the people affected |
A vendor can make the category check fast by giving you counts and data types on the first call. A small helper in your incident runbook keeps the triage consistent. It is an engineering aid, not a legal decision:
// Triage aid for a suspected leak. Your adviser makes the final call.
type LeakFacts = {
affectedPeople: number
specialCareRequired: boolean // e.g. medical history, criminal record
financialDamageRisk: boolean // e.g. card numbers, bank login data
wrongfulPurposeSuspected: boolean // e.g. unauthorised access, insider theft
}
export function likelyReportableToPpc(f: LeakFacts): boolean {
return (
f.specialCareRequired ||
f.financialDamageRisk ||
f.wrongfulPurposeSuspected ||
f.affectedPeople > 1000
)
}
Answering "which records, and who touched them" needs logs designed for it; designing a SaaS audit log covers what to record.
What happens if a company ignores the PPC?
The PPC can issue guidance, recommendations and orders. Breaking an order is a criminal matter, and a corporation that violates a PPC order can face a fine of up to JPY 100,000,000 (DLA Piper). The larger practical cost is usually the incident itself: investigation, customer notices and lost trust with enterprise buyers.
The law is also moving. The PPC decided a system reform policy under the Act's triennial review on 9 January 2026 (PPC, system reform policy). The resulting amending act passed the Diet on 10 July 2026 and was promulgated on 17 July 2026; the PPC is still drafting the cabinet orders, rules and guidelines that implement it (PPC, 2026 amendment page, in Japanese). Ask your adviser which changes are in force before you rely on the details above.
Can the data stay in Japan while the team works from Dhaka?
Often, yes, and it narrows the problem. Host production in Japan, for example in the AWS Asia Pacific (Tokyo) region, ap-northeast-1 (AWS Regions), and let the team build against synthetic data. This is engineering guidance; whether remote access from Dhaka to a Tokyo-hosted system counts as a provision to a third party in a foreign country in your set-up is a question for your adviser.
- Synthetic data by default. Development and staging run on generated records, never a copy of production.
- No standing production access. Incident access is requested, approved by you, time-limited and logged.
- Tenant isolation in the database. Row-level security keeps one customer's rows away from another's; see the Postgres row-level security guide.
How much working time overlaps between Tokyo and Dhaka, and in what language?
About 6 hours a day, with both sides on a 9:00 to 18:00 day. Tokyo is 3 hours ahead of Dhaka, and neither observes daylight saving, so the shared window is 12:00 to 18:00 Tokyo time all year. Everything else runs on written daily handoffs, and the working week is agreed per client.
Delivery is in English only. Specifications, tickets, documentation, calls and incident reports are all in English. If your product team or your customers need Japanese-language support from the vendor, we are not the right fit for that part.
Why RAITHub for this
- We sign your paper. RAITHub signs DPAs and SCCs, and will sign an entrustment contract setting out the equivalent measures your adviser specifies, then follows your controls. NDA is standard, and the client owns the IP.
- Facts for your Article 28 file. We will describe in writing who can access what, from where, so the information you give customers under Article 28(2) and (3) rests on facts.
- Access control we have shipped. Sundor Skin runs 146 PostgreSQL tables with row-level security, 88 permission codes and 12 staff roles, covered by 530+ tests.
- Six shared hours. A leak question at 14:00 in Tokyo gets a live answer the same afternoon.
- A clear next step. Multi-tenant products run under SaaS development; integration-heavy work under API and backend development.
When you don't need us
- You need Japanese-language delivery. RAITHub works in English only.
- You need an APEC CBPR-certified recipient. RAITHub holds no CBPR, SOC 2 or ISO 27001 certification, so your transfer would rest on the contract.
- You need legal advice. RAITHub has no legal expertise. Have a Japanese data protection lawyer draft the entrustment contract and consent wording.
- You want a developer placed in your team. RAITHub does not offer staff augmentation.
For comparison with nearby regimes, see the Singapore PDPA vendor guide and the Malaysia PDPA processor guide. For the security review enterprise buyers send, see answering a first security questionnaire without SOC 2, and for the wider vendor-risk view, is it safe to hire a Bangladesh software agency.
Sources checked on 1 October 2026: the APPI English translation consolidated as of 1 April 2023, the PPC's English pages, and DLA Piper's Japan summary for points we could not read in the PPC's rules PDF. Article numbers refer to the Act as translated. General information only; confirm with your adviser and the PPC.
If none of those rule us out, book the free 15-minute technical audit. Bring a list of the personal data your product holds, and we will tell you on the call what the team would and would not need to see.
Frequently asked questions
Is entrusting data to an overseas vendor a third-party provision under APPI?
For Article 28 purposes, generally yes. The entrustment exclusion in Article 27(5) is not among the exceptions Article 28(1) carves out, so an overseas vendor counts as a third party in a foreign country. This is general information; confirm with your adviser.
Which countries are designated as equivalent to Japan under APPI?
The PPC's designation covers the EU and the United Kingdom. Bangladesh is not designated, so a transfer there needs consent or a recipient with an equivalent-measures system, usually set up by contract.
What information must be given before asking for consent to a foreign transfer?
Under Article 28(2) and the PPC's rules, the name of the country, its personal information protection system, and the measures the recipient takes to protect the data.
When must a leak be reported to the PPC?
When it involves sensitive data, data whose misuse could cause financial damage, a suspected wrongful purpose, or more than 1,000 people. A preliminary report goes in promptly and a final report follows; confirm current deadlines with your adviser.
Does an entrusted vendor report a leak to the PPC itself?
Not if it notifies the business that entrusted it, as the PPC's rules prescribe. Article 26(1) then puts the report on the entrusting business, so the vendor's contract duty is to notify you promptly and completely.
Can RAITHub work in Japanese?
No. RAITHub delivers in English only, including documentation, tickets and incident reports. It offers about 6 shared working hours a day with Tokyo, plus written daily handoffs.
Related posts
Ready to discuss your project?
Book a free 15-minute technical audit with our engineering team.