Orange textured background

Japan national law

Japan APPI and browser fingerprinting

How the Act on the Protection of Personal Information treats device fingerprinting, what the 2022 amendments mean for cookie-based identifiers, and when third-party sharing of fingerprint data requires prior consent.

Reviewed

RegionJapan (national)
RegulatorPersonal Information Protection Commission (PPC / 個人情報保護委員会)
Effective30 May 2003 (original); major amendments 1 April 2022 and 1 April 2024
Max penaltyUp to ¥100 million (corporate fine, post-2022 amendments)
Status in-force

How APPI defines personal information and where fingerprinting sits

APPI Article 2 defines 'personal information' (個人情報) as information about a living individual that can identify a specific person by name, date of birth, or other description contained in that information, or that contains a personal identification code. A browser fingerprint (the combined hash of screen dimensions, installed fonts, GPU renderer, audio stack, time zone, and other passive device signals) does not contain a name or date of birth. Standing alone, it does not meet the Article 2 definition of personal information.

That gap was the central motivation for the 2022 amendments. The legislature added Article 2(7) to define 'personally referable information' (個人関連情報): any information relating to a living individual that is neither personal information nor anonymously processed information. The category is explicitly residual. PPC guidance published alongside the 2022 amendments lists cookie identifiers, advertising IDs, and device-fingerprint hashes as archetypal examples of personally referable information.

The practical consequence is a two-tier analysis. A company that collects fingerprints and cannot, on its own, link them to named users is holding personally referable information. A company that can (because it has a login system, purchase history, or any other linking dataset) is holding personal information and the full APPI obligations apply from the moment of collection.

Article 26-2: the personally referable information transfer rule

APPI Article 26-2, introduced by the 2022 amendments, prohibits a business from providing personally referable information to a third party unless the business has confirmed that the receiving third party has obtained prior consent from the data subject to receive such information in the manner that enables re-identification. The confirmation obligation is on the transferring party. The PPC's 2022 Guidelines on the APPI specify that a transferring party must: (1) confirm the existence of the data subject's consent before each transfer; (2) record the confirmation; and (3) retain those records for a prescribed period.

The PPC's 2023 cookie-regulations clarifying guidance applied this analysis directly to web-tracking scenarios. A publisher sharing a fingerprint or cookie ID with a demand-side platform (DSP) or data management platform (DMP) that can re-identify users must either verify that the user has consented to that specific sharing relationship, or stop the transfer. The guidance noted that industry-standard consent management frameworks in Japan had not fully adapted to Article 26-2 at the time of publication.

One nuance worth noting: Article 26-2 applies to 'provision to a third party'. Processing that stays within the same business entity (using a fingerprint for first-party fraud detection without any sharing) does not trigger Article 26-2. It may, however, trigger Article 16 (purpose limitation) and Article 17 (notification of purpose) obligations, discussed below.

Purpose limitation and notification: Articles 16 and 17

Even for fingerprint data that never leaves the collecting entity, APPI imposes purpose discipline. Article 16 requires businesses to use personal information only to the extent necessary to achieve the specified purpose of use. Where the collected data is not yet personal information (because the fingerprint cannot identify anyone in the collector's hands), Article 16 does not apply directly, but PPC guidance treats purpose creep in the personally referable information context as a factor that will inform enforcement scrutiny.

Article 17 requires businesses that collect personal information to notify or publicly announce the purpose of use in advance, or promptly after collection. For fingerprinting deployments that also capture device metadata that tips into personal information (for example, a device identifier combined with a logged-in user's account ID), Article 17 requires that the fingerprinting purpose be stated explicitly in the privacy policy or collection notice. Vague language such as 'we collect information to improve your experience' has been treated by the PPC as insufficient specificity.

Fingerprinting scenarios and APPI treatment

ScenarioData category under APPIKey obligation
Fingerprint held by a publisher with no user login (no re-identification possible)Personally referable informationArticle 26-2 consent required before sharing with any third party that can re-identify
Fingerprint linked to a logged-in account on the same platformPersonal informationFull APPI obligations: purpose notification (Art. 17), purpose limitation (Art. 16), third-party consent (Art. 27)
Fingerprint transferred to an ad network DSP that has a user graphPersonal information at the recipient; personally referable information at the senderSender must confirm recipient has obtained consent before transfer (Art. 26-2)
Fingerprint transferred to an overseas entityPersonal information (if re-identifiable) or personally referable informationCross-border transfer rules under Art. 28 apply once the data is or becomes personal information
First-party fraud detection using fingerprint, no sharingPersonally referable information (if no linking dataset)No Art. 26-2 trigger; purpose should still be disclosed in privacy policy

Third-party provision and consent: Article 27

Where a fingerprint qualifies as personal information in the hands of the transferring party (because the party can link it to an identified user), the third-party provision rules of APPI Article 27 apply directly. Article 27 prohibits providing personal information to a third party without the prior consent of the data subject, subject to limited exceptions: opt-out schemes for certain non-sensitive data, joint-use arrangements with public notice, and a small number of statutory exceptions (court orders, public-interest processing).

The opt-out scheme under Article 27(2) allows businesses to share non-sensitive personal information with third parties if they publicly announce the sharing arrangement and offer an opt-out mechanism. PPC guidance confirms that device fingerprint data, when linked to an identified user, is not categorised as sensitive personal information under Article 2(3), so the opt-out route is technically available. However, the PPC has signalled that fingerprint-based tracking for advertising purposes sits at the edge of where opt-out mechanisms remain acceptable, particularly following the LINE advisory in 2021.

Cross-border transfers: Article 28

APPI Article 28 restricts transfers of personal information to recipients in foreign countries that do not have an equivalent level of personal information protection to Japan. The mechanism has two compliant pathways: the recipient country appears on the PPC's whitelist of countries with adequate protection (currently only the EU under the Japan-EU adequacy arrangement that entered force in January 2019), or the receiving business has implemented contractual measures equivalent to APPI protections.

The Japan-EU adequacy arrangement is the direct product of the 2020 amendments background: Japan and the EU declared mutual adequacy simultaneously, building on the EU's prior adequacy finding for Japan and enabling cross-border flows without additional safeguards in either direction. Outside the EU whitelist, businesses must execute appropriate contracts and confirm the recipient's protective measures, analogous to the EU's standard contractual clauses.

For fingerprinting deployments specifically, the practical implication is that a Japanese business sending fingerprint-linked user data to a US-based ad-tech vendor must implement contractual protections before the transfer. The LINE advisory (2021) is the most cited example: the PPC found that LINE Corporation had allowed engineers at a Chinese affiliate to access message and personal data without adequate transfer safeguards, and issued a formal improvement order. Although the LINE case involved message content rather than fingerprints, the PPC's analysis of what constitutes a 'third-party provision' in the cross-border context applies directly to fingerprint data transfers.

Enforcement reference points

  • PPC advisory to LINE Corporation (March 2021): PPC issued an improvement order after finding that LINE had allowed access to Japanese user data (including personal message content and device-linked identifiers) by staff at a Chinese affiliate without adequate cross-border transfer protections under APPI Article 24 (now re-numbered Article 28 post-2022 amendments). LINE was required to disclose the data flows and implement safeguards.
  • PPC advisory to Rakuten Group (November 2021): PPC issued a guidance notice after finding that Rakuten had shared personal information (including device-level identifiers and purchase histories) across group companies and with third-party ad partners without adequate transparency or consent mechanisms. The advisory specifically cited the need for clear purpose disclosure and user-facing controls for tracking-related data sharing.
  • PPC cookie-regulations clarifying guidance (2023): Although not a formal enforcement action, this guidance document applied the Article 26-2 personally referable information framework to web-based tracking scenarios and put publishers and ad-tech vendors on notice that cookie and fingerprint ID sharing without confirmed consent would be treated as a breach of the 2022 amendments.
  • PPC annual reports (2023, 2024): Flagged a rising volume of reports involving third-party tracking and data brokerage as areas of intensified supervisory focus, signalling that fingerprinting-related enforcement is likely to increase in the medium term.

Japan-EU adequacy and the international context

Japan's adequacy relationship with the EU deserves special mention because it has a direct bearing on fingerprinting compliance for businesses operating across both jurisdictions. Since January 2019, personal data can flow freely between Japan and the EU without additional transfer mechanisms, provided the Japanese business processes the data under APPI-equivalent protections and EU-origin data is handled under the 'supplementary rules' imposed by Japan as a condition of the EU adequacy decision.

For a product team running a fingerprinting SDK, the practical consequence is that a Japanese publisher sharing fingerprint data with an EU-based ad-tech vendor, and vice versa, can do so without SCCs or explicit Article 28 contracts, as long as both ends of the transfer meet their domestic legal obligations. The same does not apply to transfers involving the US, China, South Korea (despite ongoing adequacy discussions), or other jurisdictions not on Japan's adequacy whitelist.

The 2022 amendments also strengthened the penalty regime, raising corporate fines to a maximum of ¥100 million and introducing criminal penalties for representatives who intentionally leak personal information. Prior to the 2022 amendments the corporate fine ceiling was ¥1 million, a figure widely criticised as insufficient deterrence.

What APPI compliance looks like in practice for a fingerprinting deployment

For a first-party site with no third-party data sharing, the minimum APPI-compliant posture for fingerprinting is: state the fingerprinting purpose in your privacy policy in specific terms (Article 17); limit the use of the fingerprint to that stated purpose (Article 16); and maintain records of how the data is used. No prior consent is required simply for collecting a fingerprint on a first-party basis; unlike the EU's ePrivacy Directive, APPI does not impose a device-access consent rule at the collection stage.

The obligation escalates sharply when third-party sharing begins. Before sending a fingerprint to any partner who can re-identify the user, you must confirm that prior consent has been obtained by that partner, and document the confirmation. This confirmation-and-record obligation under Article 26-2 is operationally demanding: it effectively requires a consent signal to accompany each data transfer, or a contractual mechanism that makes the recipient responsible for holding verified consent.

For cross-border transfers to entities outside Japan (other than EU-origin data under the adequacy arrangement), Article 28 requires either a whitelist country or a contract implementing APPI-equivalent protections. Businesses should maintain a data transfer map that tracks every fingerprint-related outbound data flow, the country of the recipient, and the transfer mechanism in use; this is analogous to the ROPA obligation under GDPR but is good practice under APPI even where not formally mandated.

How Benny the Doorman fits into an APPI-aware deployment

Benny collects device fingerprints on behalf of first-party controllers. The fingerprint itself, in the absence of a linking user identity, is personally referable information in the APPI sense. When Benny's hardware ID is associated with a logged-in account in your system, that combined record becomes personal information subject to the full APPI regime.

For Japanese deployments, the integration guidance is: declare fingerprinting as a specific purpose of use in your privacy policy before deployment; where you pass Benny's hardware ID to any downstream vendor that operates a user graph, implement a consent signal confirmation mechanism before each transfer; and map any cross-border transmission of Benny-derived data against your Article 28 transfer inventory. Benny's infrastructure is hosted in Chennai, India. Japanese controllers transferring data there should treat India as a non-whitelist jurisdiction and implement contractual protections, or route data through an EU node where the Japan-EU adequacy arrangement applies.

Frequently asked questions

Is browser fingerprinting illegal under Japan's APPI?

No. Fingerprinting is regulated, not banned. Collecting a fingerprint on a first-party basis without third-party sharing does not, on its own, require prior consent under APPI. The key compliance trigger is third-party sharing with a party that can re-identify the user, which requires confirming prior consent under Article 26-2 of the 2022 amendments.

What is 'personally referable information' and why does it matter for fingerprinting?

Personally referable information (個人関連情報) is a category introduced by APPI's 2022 amendments to cover data that does not identify a person on its own but can be combined with other data to do so. PPC guidance explicitly lists cookie IDs and device fingerprint hashes as examples. The category triggers a specific confirmation obligation before any third-party transfer where the recipient can re-identify the data subject.

When does consent become mandatory under APPI for fingerprinting?

Consent is required in two situations. First, when a fingerprint (as personally referable information) is transferred to a third party that can link it to an identified user: the transferring party must confirm the recipient holds the data subject's prior consent (Article 26-2). Second, when a fingerprint is already personal information in the hands of the transferring party and is being shared with a third party without an applicable opt-out scheme (Article 27).

Does APPI apply to companies based outside Japan that fingerprint Japanese users?

Yes. APPI's territorial reach was explicitly extended by the 2015 amendments to cover foreign businesses that handle personal information of individuals in Japan in connection with the supply of goods or services to Japan. A non-Japanese company running a fingerprinting SDK that processes data about Japanese visitors is within scope. The PPC has referenced this extraterritorial application in its enforcement guidance.

What are the penalties for APPI violations involving fingerprinting?

The 2022 amendments raised corporate fines to a maximum of ¥100 million (approximately USD 650,000 at late-2025 exchange rates) and introduced criminal penalties for individuals who intentionally leak personal information. Before the 2022 amendments the corporate fine ceiling was ¥1 million, which was widely regarded as insufficient deterrent. The PPC can also issue improvement orders and public recommendations, which carry significant reputational consequences.

Can I share fingerprint data with US-based ad-tech vendors under APPI?

Yes, but with safeguards. The US is not on Japan's adequacy whitelist, so transfers of personal information to US recipients require contractual measures under APPI Article 28 that provide protections equivalent to APPI. For personally referable information transfers (where the US recipient can re-identify), you must also confirm the recipient holds prior consent from the data subject under Article 26-2.

How does Japan's APPI relate to GDPR for a business operating in both regions?

Japan and the EU have a mutual adequacy arrangement in force since January 2019, meaning personal data can flow freely between the two without additional transfer mechanisms, provided each side meets its domestic obligations. A business fingerprinting users in both regions must satisfy APPI on the Japan side (including the personally referable information rules) and GDPR plus ePrivacy on the EU side. The adequacy arrangement does not harmonise the consent rules; each jurisdiction's requirements must be met separately.

What did the LINE and Rakuten PPC advisories mean for fingerprinting compliance?

The 2021 PPC advisories to LINE and Rakuten are the most significant enforcement precedents for cross-border data access and third-party sharing. The LINE advisory established that allowing an offshore affiliate to access Japanese user data without adequate transfer safeguards is a violation of APPI's cross-border transfer rules. The Rakuten advisory confirmed that sharing device-level identifiers with ad partners requires clear purpose disclosure and user-facing controls. Both precedents apply directly to fingerprint data flows.

Tooling

Benny the Doorman is built for this compliance posture.

Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.

Last reviewed 2026-06-06