Guides compliance with Japan's Act on the Protection of Personal Information (APPI, 2022 amendments).

Apache-2.0Auto-check passedMarketing & SEO

Install Japan Appi

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill japan-appi -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills japan-appi --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/japan-appi .claude/skills/japan-appi && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
japan-appi
GitHub stars
301
Token cost
~2.9k tokens
SKILL.md length
1,300 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides compliance with Japan's Act on the Protection of Personal Information (APPI, 2022 amendments).

  • Works in 5 steps: Delete information that can identify a… → Delete or replace Individual Number (My… → Delete personal identification codes → …
  • Tasks that involve Paid advertising
  • SKILL.md covers Overview, Key Categories of Information, Cross-Border Transfer (Art.… and Individual Rights (2022…, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Japan Appi is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides compliance with Japan's Act on the Protection of Personal Information (APPI, 2022 amendments). Covers individual rights expansion, cross-border transfer restrictions including pre-transfer information requirements, PPC enforcement, and pseudonymised and anonymously processed information. Keywords: APPI, Japan data protection, PPC, cross-border transfer, pseudonymised information, individual rights.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Marketing & SEO, covering Paid advertising and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Paid advertising
  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the japan-appi skill to guide compliance with Japan's Act on the Protection of Personal Information (APPI, 2022 amendments)”
  • “/japan-appi”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Delete information that can identify a specific individual through description alone (e.g., unique identifiers)
  2. Delete or replace Individual Number (My Number) and other specified identifiers
  3. Delete personal identification codes
  4. Delete information that may cause property damage if misused (e.g., credit card numbers)
  5. Take into account the characteristics of the personal information database

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Japan Appi loads about 2.9k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 1,300 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,300 words, ~2,920 tokens.

Download SKILL.mdSave it as .claude/skills/japan-appi/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
japan-appi
description
Guides compliance with Japan's Act on the Protection of Personal Information (APPI, 2022 amendments). Covers individual rights expansion, cross-border transfer restrictions including pre-transfer information requirements, PPC enforcement, and pseudonymised and anonymously processed information. Keywords: APPI, Japan data protection, PPC, cross-border transfer, pseudonymised information, individual rights.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
global-privacy-regulations
metadata.tags
appi, japan-data-protection, ppc-enforcement, cross-border-transfer, pseudonymised-data

Japan APPI Compliance (2022 Amendments)

Overview

The Act on the Protection of Personal Information (APPI, 個人情報の保護に関する法律) was originally enacted in 2003, substantially reformed in 2015 (effective May 2017), and further amended in 2020 (effective 1 April 2022). The 2022 amendments significantly strengthened individual rights, tightened cross-border transfer requirements, expanded the scope of anonymously processed information, and introduced the concept of pseudonymously processed information.

The Personal Information Protection Commission (PPC, 個人情報保護委員会) is the independent supervisory authority with rulemaking, enforcement, and international cooperation functions.

Japan received an EU adequacy decision on 23 January 2019, enabling free flow of personal data between the EU/EEA and Japan under supplementary rules adopted by the PPC.

Key Categories of Information

CategoryAPPI DefinitionProcessing Framework
Personal Information (個人情報)Information relating to a living individual that can identify the individual (Art. 2(1))Full APPI obligations apply
Personal Data (個人データ)Personal information forming part of a personal information database (Art. 16(1))Additional obligations: accuracy, security, third-party provision rules
Retained Personal Data (保有個人データ)Personal data that the business operator has authority to disclose, correct, or delete (Art. 16(4))Subject to individual rights requests
Special Care-Required Personal Information (要配慮個人情報)Race, creed, social status, medical history, criminal record, crime victimisation, disability, and other categories prescribed by Cabinet Order (Art. 2(3))Consent required for collection (Art. 20(2))
Pseudonymously Processed Information (仮名加工情報)Personal information processed to prevent identification without additional information (Art. 2(5)) — introduced 2022Relaxed obligations: internal use only; no individual rights; no third-party provision
Anonymously Processed Information (匿名加工情報)Information derived from personal information that cannot identify individuals and cannot be restored (Art. 2(6))May be provided to third parties with proper disclosure; no individual consent required

Cross-Border Transfer (Art. 28, 2022 Amendments)

Pre-Transfer Information Requirement

The 2022 amendments introduced a significant new requirement: before obtaining consent for cross-border transfer, the business operator must provide the individual with information regarding the personal information protection system of the destination country.

Transfer Mechanisms
MechanismAPPI ArticleRequirements
Consent with pre-transfer informationArt. 28(1)Consent after providing: (1) name of destination country, (2) personal information protection system of that country, (3) measures taken by the recipient for PI protection
Adequate countryArt. 28(1) exceptionTransfer to a country recognised by the PPC as having equivalent protection (EU/EEA and UK recognised)
Recipient with equivalent measuresArt. 28(1) exceptionTransfer to a recipient that has established a system conforming to APPI standards, verified by: (a) contract with the recipient, or (b) recipient is part of a corporate group with equivalent internal rules
Article 27 basesArt. 28(2)Transfer necessary for life protection, public hygiene, or cooperation with government agencies
PPC-Recognised Adequate Countries/Regions

As of March 2026: EU/EEA member states, United Kingdom (under supplementary rules)

Pre-Transfer Information Content (PPC Guidelines)
Information ElementDetail
Destination country nameSpecific country or countries to which data may be transferred
PI protection systemWhether the destination has a comprehensive PI protection law; key features and limitations
Enforcement mechanismWhether an independent enforcement authority exists
Individual rightsWhether individuals have enforceable rights in the destination
Recipient's protection measuresSpecific measures the recipient has implemented (encryption, access control, contractual obligations)
Zenith Global Enterprises Cross-Border Transfer Register
Transfer IDFlowDestinationMechanismPre-Transfer Info ProvidedStatus
CBT-JP-001Customer data → EU HQGermany (EU)Adequate country (PPC recognition)N/A (adequacy exemption)Active
CBT-JP-002Employee data → Regional HRSingaporeConsent with pre-transfer infoYes — Singapore PDPA briefing providedActive
CBT-JP-003Logistics data → APACThailandConsent with pre-transfer infoYes — Thailand PDPA briefing providedActive
CBT-JP-004Payment data → TreasuryUKAdequate country (PPC recognition)N/A (adequacy exemption)Active

Individual Rights (2022 Expansion)

Expanded Rights Under 2022 Amendments
RightArticle2022 Enhancement
DisclosureArt. 33Expanded to include electronic format disclosure; individual may specify format (electromagnetic record)
Correction, addition, deletionArt. 34Unchanged
Cessation of use and erasureArt. 35(1)Expanded triggers: (1) purpose achieved, (2) data no longer needed, (3) security incident occurred, (4) rights or legitimate interests likely to be harmed
Cessation of third-party provisionArt. 35(3)Expanded to match cessation of use triggers
Disclosure of third-party provision recordsArt. 33(5)New right: individuals may request disclosure of records of third-party data provisions
Explanation of processingArt. 32(2)New: business operator must explain the basis for decisions regarding retained personal data
Retained Personal Data Definition Change

Prior to the 2022 amendments, data scheduled for deletion within 6 months was excluded from retained personal data. The 2022 amendments removed this 6-month exception, meaning all personal data in a personal information database is now subject to individual rights requests regardless of planned retention period.

Response Deadlines

The APPI does not prescribe a specific day count, but the PPC Guidelines require response "without delay" (遅滞なく). The PPC has indicated that 1-2 weeks is expected for straightforward requests, with up to 2 months for complex cases with notification to the individual.

Show full SKILL.md (500 more words)Show less

Pseudonymously Processed Information (2022 Introduction)

Purpose and Benefits

Pseudonymously processed information allows business operators to process personal data for internal purposes (analytics, research, product development) with relaxed obligations:

FeaturePersonal DataPseudonymously Processed
Purpose limitationStrict — specific purpose requiredRelaxed — may be used for purposes beyond original collection purpose (internal only)
Individual rightsFull rights applyNo individual rights requests
Accuracy obligationMust keep accurateNo accuracy obligation
Third-party provisionConsent or exception requiredProhibited — internal use only
Notification of purposeRequiredMust publicly announce the purpose
Security measuresRequiredRequired — including separation of additional information
Processing Standards (Art. 41)
  1. Delete information that can identify a specific individual through description alone (e.g., unique identifiers)
  2. Delete or replace Individual Number (My Number) and other specified identifiers
  3. Delete personal identification codes
  4. Delete information that may cause property damage if misused (e.g., credit card numbers)
  5. Take into account the characteristics of the personal information database
Zenith Global Enterprises Pseudonymisation Register
Data SetPurposeMethodAdditional Info SeparatedAnnual Review
Customer shipping analyticsRoute optimisation researchTokenisation + generalisationYes — key table in separate secured environmentMarch 2027
Employee performance trendsWorkforce planningAggregation to department levelYes — name mapping in HR vaultJune 2026

PPC Enforcement

Administrative Actions
Action TypeDetail
Guidance (指導)Non-binding recommendations for compliance improvement
Recommendations (勧告)Art. 148: Formal recommendation to take specific measures; most common enforcement tool
Orders (命令)Art. 148: Legally binding order to comply; failure constitutes criminal offence
Emergency orders (緊急命令)Art. 148(3): Immediate compliance order in urgent cases
Criminal Penalties (2022 Enhancement)
ViolationPenalty
Violation of a PPC orderImprisonment up to 1 year or fine up to JPY 1 million
Providing personal information for wrongful purposesImprisonment up to 1 year or fine up to JPY 500,000
Corporate penalty for order violationFine up to JPY 100 million (increased from JPY 50 million by 2022 amendments)
False reporting to PPCFine up to JPY 500,000
Notable PPC Enforcement

Recruit Career (2019):

  • PPC recommendation regarding the Rikunabi DMP service that scored job applicants' likelihood of declining employment offers
  • Used browsing data to predict job candidate behaviour without adequate consent
  • Significance: Led to increased scrutiny of profiling and automated decision-making

LINE Corporation (2021):

  • PPC guidance following disclosure that personal data of Japanese users was accessible from China-based subsidiaries
  • Required enhanced cross-border transfer controls and transparency
  • Significance: Contributed to the tightening of cross-border transfer rules in the 2022 amendments

Compliance Programme

ComponentDetail
Privacy Manager (Japan)Tanaka Yuki, Chief Compliance Officer — Tokyo office
PPC registrationBusiness operator registered with the PPC
Privacy policyPublished at zenithglobal.co.jp/privacy in Japanese
Consent frameworkOpt-in for special care-required info; pre-transfer information for cross-border
Individual rightsDisclosure in electronic format; expanded cessation rights per 2022 amendments
Pseudonymisation programmeInternal analytics using pseudonymously processed information
Third-party provision recordsMaintained per Art. 29-30; subject to individual disclosure requests
Cross-border safeguardsPPC adequacy for EU/UK; consent with pre-transfer info for other destinations
Annual trainingAPPI compliance training for all Japan employees

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/japan-appi of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Japan Appi next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Japan Appi compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Japan Appi this skillmukul975/Privacy-Data-Protection-Skills301—~2.9kAutomated safety check: PassApache-2.0
Ad Conversion Tracking Setupminhnv0807/ai-business-skills609—~3.7kAutomated safety check: PassMIT
Analyticsericrisco/rsc-harness190—~2.8kAutomated safety check: PassMIT
Product Marketing Context Globalminhnv0807/ai-business-skills609—~2.1kAutomated safety check: PassMIT
Ad CreativeLeoYeAI/openclaw-marketing-skills1k8 repos~3.4kAutomated safety check: PassCustom licence
Blog GoogleAgriciDaniel/claude-blog2.3k1 repos~3.3kAutomated safety check: NotesMIT

Similar skills

  • Ad Conversion Tracking Setup

    minhnv0807/ai-business-skills

    Sets up and verifies conversion tracking before ad spend: Meta Pixel and CAPI, Google Ads, GA4, TikTok, server-side GTM, consent mode, UTMs and a pre-launch checklist.

    609 GitHub stars~3.7k tokensUpdated 29 days ago
    Marketing & SEOAuto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    190 GitHub stars~2.8k tokensUpdated today
    Marketing & SEOAuto-check passed
  • Product Marketing Context Global

    minhnv0807/ai-business-skills

    A skill your agent uses when starting work on a new product, client, or market — this skill creates the file .agents/product-marketing-context-global.md that 60+ other global skills read before they…

    609 GitHub stars~2.1k tokensUpdated 29 days ago
    Marketing & SEOAuto-check passed
  • Ad Creative

    LeoYeAI/openclaw-marketing-skills

    When the user wants to generate, iterate, or scale ad creative — headlines, descriptions, primary text, or full ad variations — for any paid advertising platform.

    1k GitHub starsUsed in 8 repos~3.4k tokens
    Marketing & SEOAuto-check passed
  • Blog Google

    AgriciDaniel/claude-blog

    Google API integration for blog performance: PageSpeed Insights, CrUX Core Web Vitals with 25-week history, Search Console performance, URL Inspection, Indexing API, GA4 organic traffic, NLP entity…

    2.3k GitHub starsUsed in 1 repo~3.3k tokens
    Marketing & SEOAuto-check: notes
  • Ad Account Auditor

    aaron-he-zhu/aaron-marketing-skills

    A skill your agent uses when auditing a paid ad account for incremental contribution, wasted spend, or measurement integrity before scaling; runs a typed 20-item ROAS profile with verified vetoes…

    2.9k GitHub starsUsed in 2 repos~2.2k tokens
    Marketing & SEOAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Japan Appi

What does Japan Appi do?

Guides compliance with Japan's Act on the Protection of Personal Information (APPI, 2022 amendments). Japan Appi is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides compliance with Japan's Act on the Protection of Personal Information (APPI, 2022 amendments).

When should I use Japan Appi?

Japan Appi fits situations like: tasks that involve Paid advertising; tasks that involve Privacy and GDPR.

How do I install Japan Appi in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill japan-appi -a claude-code`. Or copy the skill folder (skills/privacy/japan-appi in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/japan-appi in your project. Claude Code loads it when a task matches its description.

How do I install Japan Appi in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill japan-appi -a codex`. Or copy the skill folder (skills/privacy/japan-appi in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/japan-appi in your project. Codex loads it when a task matches its description.

Can I use Japan Appi in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill japan-appi -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/japan-appi, .gemini/skills/japan-appi, .github/skills/japan-appi and .opencode/skills/japan-appi in your project.

What does Japan Appi need to run?

Going by SKILL.md and its folder, Japan Appi needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Japan Appi access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Japan Appi safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Japan Appi use?

Japan Appi is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Japan Appi use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Japan Appi?

Skills that share tags, products or a category with Japan Appi: Ad Conversion Tracking Setup (minhnv0807/ai-business-skills, 609 stars), Analytics (ericrisco/rsc-harness, 190 stars), Product Marketing Context Global (minhnv0807/ai-business-skills, 609 stars) and Ad Creative (LeoYeAI/openclaw-marketing-skills, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Japan Appi?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.