Hanko AI›Japanese Law Guide›個人情報保護法第28条

個人情報保護法第28条

Providing Personal Data to Third Parties Located Overseas

外国にある第三者への個人データの提供

Plain-language explanation

Article 28 governs situations where a Japanese business (a "personal information handling business operator") sends personal data to a third party located outside Japan. "Foreign countries" here excludes countries the Personal Information Protection Commission (PPC) has designated as having data protection standards equivalent to Japan's (currently the EU and UK, for example), and it also excludes overseas recipients who have built a system that continuously implements protections equivalent to Japan's requirements ("equivalent measures," as defined by PPC rules).

As a general rule, before transferring personal data to such an overseas third party, the business must obtain the individual's advance, informed consent specifically authorizing the overseas transfer. Getting a signature isn't enough — under Paragraph 2, the business must first give the individual practical information they can use to evaluate the transfer, such as the data protection regime in the destination country and what safeguards the recipient actually has in place.

If instead the recipient has established a certified system for continuously implementing equivalent measures (so individual consent isn't required), the business must, under Paragraph 3, take steps to confirm and maintain that the recipient keeps up those equivalent measures, and must disclose information about those measures to the individual on request. In practice, this article comes up constantly when Japanese companies send customer or employee data to overseas parent/subsidiary companies, cloud service providers, or outsourced call centers, and getting the consent language or the vendor's certification right is a common compliance pain point.

日本語での解説

この条文は、日本の個人情報取扱事業者が個人データを「外国にある第三者」に提供する場合のルールを定めています。ここでいう外国とは、日本と同等水準の個人情報保護制度を持つと個人情報保護委員会規則で認められた国(現状ではEU・英国などが該当)を除く、それ以外のすべての国・地域を指します。また、提供先が日本の法律に相当する保護措置を継続的に講じられる体制(委員会規則が定める基準)を整えている場合も対象外となります。

原則として、こうした外国の第三者にデータを渡す前に、本人から「外国への提供を認める」という明確な同意を得る必要があります。同意を取る際には、単に同意書にサインをもらうだけでなく、提供先の国の個人情報保護制度の内容や、その第三者がどのような保護措置を講じているかなど、本人が判断材料にできる情報を事前に提供しなければなりません(第2項)。

一方、提供先が委員会規則の基準に適合する体制(いわゆる「相当措置」を継続的に実施できる体制)を整備している場合は、個別の同意は不要になりますが、その代わりに事業者は、相当措置が継続的に実施されているかを確認・維持する措置を講じ、本人から求めがあれば、その体制の内容について情報提供する義務を負います(第3項)。実務上は、海外グループ会社やクラウドベンダー、海外のコールセンター委託先などにデータを送る際に、この条文の要件を満たしているかどうかが頻繁に問題となります。

Common scenarios

  • ▸Sending employee or customer data to an overseas parent company or subsidiary for HR or CRM management
  • ▸Using a foreign-based cloud storage or SaaS provider that processes personal data outside Japan
  • ▸Outsourcing customer support or call center operations to a company located overseas
  • ▸Transferring marketing data to an overseas advertising or analytics partner
  • ▸Cross-border M&A due diligence involving transfer of customer databases to a foreign acquirer

Related statutes

  • 個人情報保護法第27条"
  • "個人情報保護法第26条"
  • "個人情報保護法第31条"
  • "個人情報保護法施行規則第17条

Does this affect your contract?

Hanko AI reviews your contracts against 個人情報保護法第28条 and other Japanese statutes in under 60 seconds.

Review your contract free →

Generated by Hanko AI from the official Japanese statute corpus. A general statutory reference for the practising attorney. Confirm the current statute against the facts of your matter.

Providing Personal Data to Third Parties Located Overseas | 個人情報保護法第28条 | Hanko AI | Hanko AI 判断