Japan's cabinet approved an amendment to its Act on the Protection of Personal Information on April 9, loosening the rules around using personal data to train AI models. The change removes mandatory opt-in consent for data that poses "little risk" to individuals' rights, and broadens access to health records and facial recognition data for AI development. Administrative fines for privacy violations, Japan's first such regime, come into effect at the same time.

The practical effect is significant. Previously, Japanese companies building AI had to navigate consent requirements that made large-scale data collection for training purposes difficult. Under the revised law, that friction is substantially reduced for data classified as low-risk, a category broad enough to cover much of the text, behavioral, and commercial data that AI developers typically want.

Health data gets its own carve-out. It can now be used for AI development if the project "improves public health," a phrase broad enough to include a wide range of medical and pharmaceutical applications. Facial recognition data is also available to developers without mandatory opt-out, though companies must explain how they handle it.

The fines regime is new ground for Japan. Companies that improperly handle data affecting 1,000 or more individuals can face administrative penalties calculated as a proportion of profits from the violation. Whether enforcement will match the law's ambition remains to be seen, but the legal mechanism now exists.

The Digital Watch Observatory notes that the amendment positions Japan as the most AI-training-friendly jurisdiction among major economies, ahead of the EU, which applies stricter consent requirements under GDPR, and the United States, which has no comprehensive federal privacy law and therefore no uniform rules to relax.

What it means for AI development

The APPI change matters beyond Japan's borders because several large AI labs have significant operations or partnerships in the country. Sony, SoftBank, NTT, and Toyota have all made AI investments that this law now supports more directly. International companies training models that include Japanese-language data or Japanese user interactions also benefit.

The broader regulatory picture is moving in two directions at once. The EU tightened its rules substantially with the AI Act; Japan loosened them. The United States remains fragmented, with individual states passing legislation in opposite directions, as New York's RAISE Act and the White House's preemption push illustrate. For companies deciding where to anchor their AI data operations, that divergence is starting to matter.

Sources

  1. i. dig.watch

Commentarii · 0

Add · a · Comment