Yes, if your contract lets any party outside Japan access personal data of Japan-resident individuals, whether as a SaaS vendor, an intercompany affiliate, or an outsourced processor. Article 28 (第28条) of the Act on the Protection of Personal Information (個人情報保護法, APPI) restricts that transfer to three lawful bases, and since July 2026 a new administrative fine regime makes getting the clause wrong a direct financial exposure rather than a theoretical one.
What Is Article 28 of APPI and Why Does It Matter to a Commercial Contract?
Article 28 restricts any transfer of personal data to a third party located outside Japan, and a commercial contract is very often the mechanism that either creates or authorizes that transfer. The Act on the Protection of Personal Information (個人情報保護法), most recently substantially amended in 2020 with that amendment fully effective April 1, 2022, treats a foreign affiliate's server access, a foreign SaaS vendor's hosting, or an offshore support team's ticket queue as a transfer to a third party outside Japan the moment personal data of a Japan resident becomes accessible there.
The regulator is the Personal Information Protection Commission (個人情報保護委員会, PPC). Since the 2022 amendment, PPC guidelines require the transferring organization to document, for every cross-border transfer, which of the three Article 28 bases it relies on, and to prepare an information-provision document that data subjects can request. If your contract does not name a basis, your compliance file has nothing to point to when a data subject or the PPC asks which one applies.
When Does Article 28 Actually Apply to My Contract?
Article 28 applies whenever personal data of a Japan resident becomes accessible to a party physically located outside Japan, regardless of whether that party is a vendor, an affiliate, or a subcontractor. It does not apply to purely domestic processing, and it does not turn on nationality, only on the location of the recipient at the moment of access.
This catches structures that founders and legal teams often assume are internal and therefore exempt. A foreign parent's engineering team pulling customer records from a Japan subsidiary's database for maintenance is a cross-border transfer. A SaaS vendor headquartered outside Japan whose support staff can view ticket contents containing Japan-resident personal data is a cross-border transfer. An intercompany services agreement that lets a regional hub process HR data for a Japan entity is a cross-border transfer. The 2024 enforcement matter below shows the Personal Information Protection Commission treating exactly this pattern, that it is just internal group access, as insufficient on its own to avoid Article 28.
What Are the Three Lawful Bases for a Cross-Border Transfer Under Article 28?
A cross-border transfer is lawful only if it rests on informed consent, a PPC adequacy designation, or a contractual equivalent-protection commitment, and a contract drafter needs to pick one deliberately rather than default to silence. The three bases are:
(a) Consent. The data subject gives informed consent after being told about the destination country's data-protection framework and the recipient's data-handling practices. This basis is workable for a defined, disclosed data flow but becomes unwieldy for ongoing intercompany or SaaS access, since consent typically needs to be current and specific rather than a one-time boilerplate acknowledgment.
(b) Adequacy designation. The destination country has been designated by the PPC as maintaining an equivalent level of protection. The EU and EEA have held this mutual designation since January 2019, and as of mid-2026 no other jurisdiction holds a PPC adequacy designation, so a US, UK, Singapore, or Hong Kong recipient cannot rely on this basis regardless of that jurisdiction's own privacy law.
(c) Contractual equivalent-protection measures. The recipient has agreed by contract or another binding arrangement to implement measures equivalent to APPI's protections, and the transferring company has taken the necessary steps to confirm those measures are actually followed. For most foreign vendor and intercompany structures, this is the only realistic basis, which is exactly why the clause needs to be drafted with care rather than copied from a generic data processing addendum.
Key points:
(a) If your counterparty or affiliate sits outside Japan and touches personal data of Japan residents, Article 28 applies regardless of how the relationship is labeled internally: service agreement, intercompany cost-sharing, or SaaS subscription. (b) The contractual basis at (c) above is the practical default for non-EU/EEA recipients, but it requires actual monitoring of whether the recipient follows the equivalent measures, not just a signed clause. (c) A contract silent on Article 28 does not avoid the obligation; it just leaves the transferring party unable to point to a lawful basis when the PPC or a data subject asks which one applies.
Why Does the 2026 APPI Fine Regime Change the Calculus?
Japan's first administrative fine (課徴金) regime for APPI violations, promulgated July 17, 2026, replaces what was previously a criminal-only enforcement path with a civil fine calculated on the profit gained from the unlawful use or provision of personal data. Before this promulgation, a defective cross-border transfer clause was a compliance gap with mostly reputational and criminal-referral risk, and criminal enforcement of this type was rare in practice. That asymmetry is gone.
The new fine applies to operators handling 1,000 or more individuals' data, among other triggers, carries a 1.5x multiplier for repeat violations within 10 years, and offers a 50% reduction for self-reporting. Because the fine is profit-based rather than a fixed penalty, a company with meaningful revenue tied to the data flow in question now faces a fine mechanism scaled to that revenue, not a flat administrative penalty. Enforcement is expected to phase in within roughly two years of promulgation, by approximately 2028, which gives contracting parties a real but finite window to correct legacy agreements before the exposure becomes live.
The Personal Information Protection Commission's 2024 administrative guidance against a major Japan-based messaging platform operator, issued before this fine regime existed, shows how the PPC actually applies Article 28 in a group-affiliate context. The PPC found that an overseas group affiliate's access to Japan-resident users' personal data for system maintenance was a cross-border third-party transfer requiring Article 28 compliance, and that the outsourcing exception did not apply because the affiliate's access exceeded ordinary maintenance scope and was not governed by contractual oversight measures equivalent to APPI obligations. The PPC ordered a review of the transfer governance framework, required equivalent-protection measures for continuing overseas access, and required appointment of a senior officer responsible for personal information protection. Read against the 2026 fine regime, the same fact pattern today carries administrative fine exposure on top of the governance remediation the PPC already ordered in 2024.
How Should I Draft the Clause in Practice?
Draft the clause to name the specific Article 28 basis relied on, describe the actual data flow, and impose a monitoring obligation, not a bare representation that the recipient will comply with applicable data protection law. A clause that only recites APPI's existence without naming basis (a), (b), or (c) gives the transferring party nothing to show a regulator, and PPC guidance since 2022 explicitly expects that documentation to exist per transfer.
This clause sits alongside the other standard items a Japan-facing commercial contract should carry, the same way the anti-social forces clause has become a market-convention fixture in Japan contracting regardless of deal size. Governing law choice also interacts with the transfer clause: a contract that selects Japan law over Hong Kong law as the governing framework should not assume that choice alone satisfies Article 28's equivalent-protection requirement, since the two questions, which law governs the contract and what basis authorizes the data transfer, are legally distinct. If the contract will be executed electronically rather than on paper, confirm the execution method carries the same enforceability as a wet-ink signature before relying on it for a clause with this much downstream exposure. Contract review that checks Article 28 basis selection against the actual data flow, rather than against a template clause, is exactly the kind of gap a Japan legal and contract review engagement is built to catch before a regulator does.
Frequently Asked Questions
Does an intercompany services agreement between a Japan subsidiary and its foreign parent need an APPI transfer clause?
Yes, if the foreign parent's staff can access personal data of Japan-resident employees, customers, or users as part of the services. Article 28 applies to any recipient located outside Japan regardless of corporate affiliation, so the parent-subsidiary relationship does not create an exemption on its own, and the 2024 PPC enforcement matter against a group affiliate confirms the PPC applies this standard in practice.
Can we rely on the EU adequacy designation if our vendor is US-based?
No. The EU and EEA are the only jurisdictions currently holding a PPC adequacy designation as of mid-2026, so a US, UK, Singapore, or Hong Kong recipient cannot use the adequacy basis regardless of that vendor's own certifications or its EU operations. A US-based vendor needs either informed consent for the specific transfer or a contractual equivalent-protection commitment under Article 28's third basis.
Does the new 2026 fine regime apply retroactively to contracts already signed?
The fine regime was promulgated July 17, 2026 and enforcement is expected to phase in over roughly two years, so the immediate priority is reviewing and correcting existing agreements before that window closes rather than assuming a signed date shields the arrangement. The fine is calculated on profit from the unlawful transfer, so an ongoing data flow under an old contract remains exposed for as long as the flow continues without a documented Article 28 basis.
Conclusion
Article 28 applies the moment personal data of a Japan resident becomes accessible outside Japan, and silence in the contract is not a safe default. The 2026 administrative fine regime turns what used to be a rarely enforced criminal risk into a profit-scaled civil exposure with a defined phase-in horizon, which makes now the practical deadline for reviewing which of the three lawful bases each cross-border data flow actually rests on.
This article is informational only and does not constitute legal, tax, or regulatory advice. Consult a qualified advisor before acting on the content. Last updated: August 2026.
