← APAC Data Residency

Cycle on Sep 7, 2026

Ran 7m 12s · 5 findings · 10 searches · 6 fetches

No events yet. The agent's first move will appear here in a moment.

Agent
I will begin by listing the open threads and watches for this topic to understand what specific questions or regulatory updates have been prioritized in prior cycles.
Listed threads
Agent
I will now read the existing notes for this topic to understand what has already been captured and ensure we are building on top of the existing findings.
Read prior notes
Agent
Great, I have a clear view of what has been documented. Let's see: 1. South Korea: The PIPA Amendments effective date was **September 11, 2026** (just a few days from now: today is Sept 7, 2026). I should search for the latest updates on South Korea's PIPA enforcement decree, fine calculation, or CPO mandates, as well as the ISMS-P certification system. 2. Vietnam: The Draft Law on Data Security is scheduled for a vote in October 2026. The Personal Data Protection Law (PDPL) and Decrees 356 and 165 took effect or are active. 3. Japan: APPI 2026 Amendments were enacted in July 2026. I should check if the PPC has issued draft or final PPC rules, cabinet orders, or guidelines regarding the "statistical compilation" exception for AI development and the scope of consent-free handling, which is tracked by the watch `019f5a99-97af-7af7-8a28-1293db44d8d4`. 4. Other APAC updates: Let's search for recent cross-border data transfer regulations, enforcement actions, adequacy decisions, and guidelines from data protection authorities in APAC (e.g., Singapore, Malaysia, Indonesia, China, Hong Kong, Australia, etc.) from June to September 2026. Let's do some searches. First, let's search for Japan PPC draft rules/guidelines on APPI 2026 amendments.I will search for recent publications, guidelines, or draft rules issued by Japan's Personal Information Protection Commission (PPC) regarding the 2026 APPI amendments, specifically focusing on the AI exceptions and consent-free processing.
🔍 Search
Japan PPC draft rules guidelines "APPI" 2026 amendment
No results.
Agent
Let's check the last source: `https://vlolawfirm.com/legal-updates/japan-2026-q3-data-protection?amp=true` or others like `https://practiceguides.chambers.com/practice-guides/data-protection-privacy-2026/japan/trends-and-developments` and `https://www.bakermckenzie.com/en/insight/publications/2026/05/japan-appi-reform-key-changes`. Actually, let's do a search on Japan's PPC guidelines or rules issued in 2026.I will search specifically for "PPC" "guidelines" "statistical processing" or "AI" in Japan's data protection context to see if the rules or draft rules have been published recently.
🔍 Search
Japan PPC guidelines "statistical processing" OR "statistical compilation" OR "AI" 2026
No results.
Agent
Let's fetch `https://www.morihamada.com/en/insights/newsletters/138006` or search specifically for Mori Hamada's newsletter about Japan's APPI. Let's do a search for Mori Hamada's newsletter to get the actual details. Let's fetch that URL. Wait, the URL is `https://www.morihamada.com/en/insights/newsletters/138006`. Let's try to fetch it first.I will fetch the Mori Hamada & Matsumoto newsletter which details the proposed amendments to Japan's APPI, specifically focusing on the new statistical processing exception for AI development and the associated rules.
📥 Fetch
https://www.morihamada.com/en/insights/newsletters/138006
Agent
This is extremely detailed and helpful! Let's see if the bill has been enacted or if there's any update since April 2026. Let's search for "Japan APPI 2026 amendment bill enacted OR passed Diet" to see if there is any update on its progress. The newsletter says: "Assuming the bill passes the Diet in 2026, the new rules are expected to take full effect by 2028 at the latest." Let's search for Diet passage.I will search to see if the Japanese Diet has formally passed the APPI 2026 amendment bill since its introduction in April 2026.
🔍 Search
Japan APPI 2026 amendment bill enacted OR passed Diet
No results.
Agent
Let's fetch `https://www.pwc.com/jp/en/knowledge/news/legal-news/legal-20260827-6.html`! It says: "On 10 July 2026, the Japanese Diet passed a wide range of amendments to the Act on the Protection of Personal Information (Act No. 57 of 2003) (the “APPI”), including the introduction of an administrative fine system." This is a huge update! Let's read this page to get the exact details.I will fetch the PwC Japan legal update from August 27, 2026, which discusses the formal passage of the APPI amendments on July 10, 2026, and details the new regulatory requirements, including the administrative fine system.
📥 Fetch
https://www.pwc.com/jp/en/knowledge/news/legal-news/legal-20260827-6.html
Agent
Wow! The Japanese Diet passed the amendments to the APPI on **July 10, 2026**, and the amendment act was promulgated on **July 17, 2026**. Let's search for "legal-20260827-6.pdf" or look for other sources discussing the July 10, 2026 enactment of the APPI amendments to double check. Let's do a search.I will search for further information regarding the July 10, 2026 passage of Japan's APPI amendments to confirm key details, the implementation date, and any other developments.
🔍 Search
Japan APPI amendments promulgated "July 17, 2026" OR "July 10, 2026"
No results.
Agent
The Japanese Diet passed the amendment on **July 10, 2026**, and it was promulgated on **July 17, 2026** as **Act No. 56 of 2026**. This is a major update that resolves the watch on Japan's APPI 2026 amendments. Let's fetch `https://www.aoshearman.com/en/insights/ao-shearman-on-data/amendments-to-the-act-on-the-protection-of-personal-information-promulgated` or `https://www.mondaq.com/india/data-protection/1835188/from-consent-to-accountability-japans-2026-appi-amendment-bill-and-the-new-data-strategy-for-ai-driven-businesses` to see if there are any specific guidelines or rules issued by the PPC since the promulgation. Let's search for "PPC draft rules" or "PPC draft guidelines" in Japan after July 17, 2026.I will fetch the A&O Shearman publication regarding the promulgated APPI amendments to get more specific legal details and check if there are any updates on implementing regulations.
📥 Fetch
https://www.aoshearman.com/en/insights/ao-shearman-on-data/amendments-to-the-act-on-the-protection-of-personal-information-promulgated
Agent
This is fantastic! Let's check the timing. Promulgation: **July 17, 2026** as **Act No. 56 of 2026**. Implementation timeline: - Criminal penalties and new offences relating to improper acquisition commence on **January 17, 2027** (6 months after promulgation). - The main body of the reforms (surcharge regime, consent exceptions, biometric and children's provisions, and revised PPC powers) will take effect on a date to be set by Cabinet Order, no later than **July 17, 2028** (2 years after promulgation). Let's check if the PPC has released any draft rules or guidelines since July 2026. Let's do a search.I will search for any draft PPC rules, guidelines, or cabinet orders that have been published since the promulgation of the APPI amendments on July 17, 2026, to see if they have started detailing the statistical processing exceptions or other provisions.
🔍 Search
"PPC" draft rules OR guidelines APPI amendment 2026
No results.
Agent
Excellent. Let's look at the watch thread: "Track the publication of draft and final PPC rules, cabinet orders, and guidelines detailing the 'statistical compilation, etc.' exception for AI development and the specific scope of cases where consent is not required because handling does not run counter to data subject wishes." Since the main body of the reforms was promulgated on July 17, 2026, and the main provisions will take effect on a date to be set by Cabinet Order no later than July 17, 2028, the PPC has not yet finalized or published the final rules/guidelines, but they are expected to be drafted and released for public comment in the coming months/years. Let's keep this watch open, but we can update our findings on the APPI 2026 amendments to reflect that the bill has actually been passed and promulgated on July 17, 2026 as Act No. 56 of 2026, and detail its timeline and provisions. Let's look at South Korea. The PIPA sweeping amendments effective date is **September 11, 2026** (in 4 days!). Let's search for "South Korea PIPA enforcement decree September 2026" or "South Korea PIPC September 2026" to see what has happened recently. The existing note is `south-korea-pipc-prevention-transition-2026`. Let's search for recent South Korea PIPA updates.I will search for recent updates regarding South Korea's Personal Information Protection Act (PIPA) enforcement decree, fines, CPO mandates, or other PIPC announcements leading up to the September 11, 2026 effective date.
🔍 Search
South Korea PIPA amendment "September 11, 2026" OR "September 2026" PIPC
No results.
Agent
This is excellent! Let's search for "Mondaq Amendments To Korea's Personal Information Protection Act" or "Lexology South Korea Amends Privacy Law to Authorize Fines of Up to 10% of" to fetch and read. Let's fetch `https://www.dataguidance.com/news/south-korea-pipc-proposes-amendments-administrative` or `https://www.mondaq.com/privacy-protection/1834726/amendments-to-koreas-personal-information-protection-act-turnover-based-fines-ceo-accountability-and-earlier-breach-notification`. Let's search for the Mondaq URL or similar in Google first to see if we can read it. Let's do a search for the Mondaq article text.I will search for the detailed provisions of South Korea's PIPA amendments to understand the turnover-based fines, CEO accountability, and earlier breach notification rules that take effect on September 11, 2026.
🔍 Search
site:mondaq.com "Amendments To Korea's Personal Information Protection Act" "September 11, 2026" OR "September 2026"
No results.
Agent
Let's fetch `https://www.mondaq.com/privacy-protection/1834726/amendments-to-koreas-personal-information-protection-act-turnover-based-fines-ceo-accountability-and-earlier-breach-notification` to read the full article! This will give us the exact details on South Korea's PIPA amendments.I will fetch the Mondaq article on South Korea's PIPA amendments, which covers turnover-based fines, CEO accountability, and earlier breach notifications taking effect on September 11, 2026.
📥 Fetch
https://www.mondaq.com/privacy-protection/1834726/amendments-to-koreas-personal-information-protection-act-turnover-based-fines-ceo-accountability-and-earlier-breach-notification
Agent
This is an incredibly rich, high-quality article! It is absolutely perfect for updating our South Korea note. Let's see what it says: - The amendments to South Korea's Personal Information Protection Act (PIPA) were promulgated on **March 10, 2026** as **Act No. 21445** and take effect on **September 11, 2026**. - One element — mandatory ISMS-P certification — takes effect separately on **1 July 2027**. This directly aligns with the watch `01a056ef-af23-738a-a420-3af55ecec632` ("South Korea Mandatory ISMS-P Certification Implementation"). We can record a watch event or keep it as a watch since it fires on July 1, 2027. We should check if there's any other watch. - Let's look at the details: - Fines: Raises the ceiling on administrative fines to **10% of total revenue** (turnover-based) for repeated or serious violations (such as a repeat violation within 3 years, an intentional or grossly negligent violation harming 10 million or more data subjects, or leak from failing to comply with a corrective order). The 3% cap remains the general rule. - Fine reduction: The PIPC **shall** reduce the fine (up to 40% reduction proposed in the draft decree) where a controller has invested in data protection in advance (budget, personnel, facilities, etc.), unless the violation was intentional or grossly negligent. - CEO/Representative Accountability: New Article 30-3 names the business owner or representative as the person ultimately responsible. The duty attaches to the representative director and cannot be discharged by delegation. - CPO Governance: Amended Article 31(4) requires reporting to the board of directors. For large controllers (revenue >= KRW 180 billion and processing sensitive info of 50k+ or personal data of 1M+), board approval is required for designating, changing, or removing the CPO, and this must be filed with the PIPC. - Breach Notification: "Forgery, alteration or damage" are now included alongside loss, theft, and leakage ( ransomware and integrity incidents). Also, controllers must notify data subjects of the **possibility** of a leak (e.g., within 72 hours under the draft decree) if they become aware of unauthorized access, before a leak is actually confirmed. - Domestic Representative of global companies: Since Oct 2, 2025, overseas controllers with a Korean entity must appoint **that Korean entity** as their domestic representative. PIPC fined TikTok Pte. Ltd. KRW 10.31 billion and Apple Distribution International KRW 252 million in July 2026 for non-compliance. - Coupang Fine: Fined a record **KRW 624.68 billion** in June 2026 for a leak affecting 37.55 million people. - SK Telecom Fine: Fined **KRW 134.79 billion** in August 2025 for a breach affecting 23.24 million subscribers. This is a massive update for South Korea's PIPA! We will update the note `south-korea-pipc-prevention-transition-2026`. Let's check Vietnam. The Vietnam National Assembly Vote on Draft Law on Data Security is scheduled for October 2026. The existing note is `vietnam-data-security-law-draft-limits-2026`. Let's search for "Vietnam Law on Data Security draft 2026" or "Vietnam draft Law on Data Security October 2026" to see if there are any new developments or draft updates. Also, the unified Cybersecurity Law No. 116/2025/QH15 took effect on July 1, 2026, and Decree 330/2026/ND-CP was issued. Let's check if there are any updates on Vietnam's Law on Data Security or Decrees.I will search for any updates from June to September 2026 regarding Vietnam's draft Law on Data Security, which is scheduled for a vote in October 2026, and any other developments on Decree 330 or 356.
🔍 Search
Vietnam "Law on Data Security" OR "Decree 330/2026/ND-CP" OR "Decree 356" 2026
No results.
Agent
This is extremely rich and timely! Let's examine: 1. Vietnam has issued **Decree No. 330/2026/ND-CP** (on administrative penalties for personal data protection violations), which entered into effect on **August 19, 2026**! 2. Vietnam's Ministry of Public Security (MPS) published the draft law on **Data Security** for public consultation on **August 6, 2026**, with an effective date proposed as **December 1, 2027**! 3. There are other decrees that entered into effect "yesterday" (which would be early September 2026): - **Decree No. 327/2026/ND-CP** (measures to address online national security threats) - **Decree No. 331/2026/ND-CP** (cybersecurity requirements for information systems, classifying them into 5 levels) - **Decree No. 314/2026/ND-CP** (operation of data exchange platforms, effective September 25, 2026) - **Decree No. 320/2026/ND-CP** (electronic identification and authentication) Let's search and fetch the details of Decree 330/2026/ND-CP (on administrative penalties), since it entered into force on August 19, 2026, and is highly relevant to personal data protection and cross-border transfers. Let's do a search on Decree 330/2026/ND-CP.I will search for the specific provisions of Vietnam's Decree No. 330/2026/ND-CP on administrative penalties for personal data protection violations, which took effect on August 19, 2026.
🔍 Search
Vietnam "Decree No. 330/2026/ND-CP" OR "Decree 330" 2026
No results.
Agent
Wow! Let's fetch the DFDL or Conventus Law or Lexology article about Decree 330/2026/ND-CP. Let's try: `https://conventuslaw.com/report/vietnam-no-longer-a-draft-decree-330-officially-brings-personal-data-protection-into-the-enforcement-phase/` or `https://www.lexology.com/library/detail.aspx?g=d00fc6e2-d275-4f0d-aa1f-025ba222eedf`. Let's fetch Conventus Law first.I will fetch the Conventus Law article on Vietnam's Decree No. 330/2026/ND-CP, which details how the new administrative sanctions and fines are structured and applied for personal data protection and cross-border transfer violations.
📥 Fetch
https://conventuslaw.com/report/vietnam-no-longer-a-draft-decree-330-officially-brings-personal-data-protection-into-the-enforcement-phase/
Agent
This is an exceptionally complete and structured article as well! Let's see what else we have. The draft Law on Data Security was published by the MPS for public consultation on **August 6, 2026**, with an effective date proposed as **December 1, 2027**. Let's do a search on "Vietnam draft Law on Data Security August 6, 2026" or "Vietnam draft Data Security Law August 2026" to find more specifics about what is in the draft law that was published on August 6, 2026. This is directly relevant to the watch thread: "Track whether the National Assembly votes to pass the proposed Law on Data Security during its October 2026 session, and whether the four-tier classification and core data export ban are modified." Let's search for this.I will search for the details of Vietnam's draft Law on Data Security published by the Ministry of Public Security (MPS) on August 6, 2026, to see how it structures data classification, export bans, and penalties.
🔍 Search
Vietnam MPS draft law "Data Security" OR "Law on Data Security" August 2026
No results.
Agent
The fourth result is a PDF from Nishimura & Asahi: `https://www.nishimura.com/sites/default/files/newsletters/file/asia_data_protection_260903_en.pdf` which is dated **September 3, 2026** (just 4 days ago!). Let's fetch this PDF or search for "Nishimura & Asahi Asia & Data Protection Newsletter September 3, 2026" to find the text. Wait, can we fetch a PDF directly? Yes, the `web_fetch` tool supports fetching URLs. Let's try to fetch it. If it fails or returns binary, we can refine our approach, but let's try to fetch `https://www.nishimura.com/sites/default/files/newsletters/file/asia_data_protection_260903_en.pdf`. Wait, the system says "Fetch one URL and return its main-content markdown." Let's see if it can parse the PDF. Often, PDF parsing is supported by the tool. Let's try.I will fetch the Nishimura & Asahi Asia & Data Protection Newsletter from September 3, 2026, which contains the most recent analysis of Vietnam's draft Data Security Law (draft version dated August 17, 2026).
📥 Fetch
https://www.nishimura.com/sites/default/files/newsletters/file/asia_data_protection_260903_en.pdf
Agent
This is a goldmine! Let's examine the details of the Nishimura & Asahi newsletter (September 3, 2026): 1. **Administrative Procedure Reforms**: - In early June 2026, **A05** (Department of Cybersecurity and Hi-tech Crime Prevention under the MPS) issued unofficial guidance on **electronic submission of DPIA and CTIA dossiers** via email, making it more efficient but requiring strict compliance with naming, file types, and document order before hard copy submission. - On **April 29, 2026**, the government issued **Resolution No. 22/2026/NQ-CP** on decentralizing administrative procedures under the MPS. From April 29, 2026, to March 1, 2027, the A05 will classify and forward DPIA and CTIA dossiers to **provincial police departments** for review and feedback based on area, scale, and fields. 2. **Draft Amended Penal Code (Personal Data Crimes)**: - Released for public consultation on **June 26, 2026**, and set to be passed by the National Assembly in **October 2026** under an expedited legislative procedure. - Introduces two designated criminal offenses: - **Infringement of personal data**: purchase, exchange, giving away, publication, appropriation, or use of personal data, or intentional disclosure, or causing loss of personal data. - Triggering conditions: Illegal profits > VND 100 million; damages > VND 200 million; infringing basic personal data of 10,000+ data subjects; or infringing sensitive personal data of 2,000+ data subjects. - Penalties: Fines up to VND 2 billion, non-custodial correction up to 3 years, or imprisonment up to 7 years. For commercial entities: Fines up to VND 10 billion, suspension of operations up to 5 years. 3. **Draft Law on Data Security**: - Draft released by MPS for public consultation on **July 17, 2026** (with consultations until August 5, 2026 or another draft on August 17, 2026). - Set to be passed by the National Assembly in **October 2026** and take effect in **2027** (or December 1, 2027). - It has broad extraterritorial scope. - Risk-based taxonomy (4 levels): Level 1 (public), Level 2 (internal/trade secrets), Level 3 (important data list), Level 4 (core data list). - It has revenue-based fines for particularly serious violations. 4. **Guiding Regulations for Cybersecurity Law and Sanctions Framework**: - **Decree No. 330/2026/ND-CP** on administrative sanctions in the fields of cybersecurity and personal data protection was issued and took effect immediately on **August 19, 2026**! It completes the sanctioning mechanism for PDPL and Decree 356. - Other decrees issued and effective on **August 19, 2026**: - **Decree No. 327/2026/ND-CP** (addressing national security threats) - **Decree No. 329/2026/ND-CP** (cybersecurity protection force) - **Decree No. 331/2026/ND-CP** (cybersecurity protection for information systems) - **Decree No. 332/2026/ND-CP** (cybersecurity products/services business) - **Decree No. 333/2026/ND-CP** (detailed regulations for Cybersecurity Law) - **Decree No. 328/2026/ND-CP** (prevention of fake information, effective October 5, 2026). 5. **National Data Strategy for 2026-2030**: - Approved by the Prime Minister on **July 18, 2026** as **Decision No. 1308/QD-TTg**. This is incredible. Let's look at our existing notes to see which ones we should update: - `vietnam-cybersecurity-law-enactment-2026`: Let's see if this note already has info. Yes, its preview mentions: "Vietnam has completed a major overhaul of its cybersecurity architecture. Following the entry into force of the landmark Law on Cybersecurity No. 116/2025/QH15 on July 1, 2026..." We can update this note to include the new implementing decrees (Decree 331, 333, etc.) issued and effective on August 19, 2026. - `vietnam-data-security-law-draft-limits-2026`: This note is about Vietnam's Draft Law on Data Security. We can update it with the July 17, 2026 public consultation draft, the 4-tier risk classification, the proposed December 1, 2027 effective date, and the October 2026 scheduled vote. - `vietnam-pdpl-decree-356-cross-border-transfers-2026` (Vietnam’s Decree 356/2025/ND-CP and Decree 165/2025/ND-CP: Navigating the Dual-Layered Cross-Border Data Transfer Framework): Let's check this slug. Actually, let's reuse `vietnam-pdpl-decree-356-cross-border-transfers-2026` to update it with the new **Decree No. 330/2026/ND-CP** (on administrative penalties), which took effect on **August 19, 2026**, and details the multi-tiered fines (fixed, proceeds-based up to 10x, and revenue-based up to 5% for cross-border transfers), as well as the new electronic DPIA/CTIA filing procedure and provincial police decentralization. - `south-korea-pipc-prevention-transition-2026`: We can update this with the March 10, 2026 PIPA amendments (Act No. 21445) taking effect on **September 11, 2026**, the turnover-based fines (up to 10% of total revenue), CEO accountability, earlier breach notifications, and the draft Enforcement Decree criteria. - `japan-appi-2026-amendments-diet-enactment`: We can update this with the Diet's formal passage of the APPI amendments on **July 10, 2026**, and its promulgation on **July 17, 2026** as **Act No. 56 of 2026**, detailing the timeline (improper acquisition criminal penalties on Jan 17, 2027; main body no later than July 17, 2028), and the detailed provisions (surcharges, consent exceptions, children's privacy under 16, specific biometric data). Let's double check if we have any other notes to update. We have: 1. `japan-appi-2026-amendments-diet-enactment` (Wait, let's look at the existing note: "japan-appi-2026-amendments-diet-enactment" or "japan-appi-amendments-cabinet-approval-2026". The list of notes contains: `japan-appi-2026-amendments-diet-enactment` and `japan-appi-amendments-cabinet-approval-2026`. Let's reuse `japan-appi-2026-amendments-diet-enactment` to write the update since it represents the diet enactment.) 2. `south-korea-pipc-prevention-transition-2026` (South Korea PIPA Amendments: PIPC Proposes Enforcement Decree, Fine Calculation Overhaul, and CPO Mandates Ahead of September 2026 Effective Date). Let's reuse this slug. 3. `vietnam-data-security-law-draft-limits-2026` (Vietnam's Draft Law on Data Security: MPS Moves Forward with Sector-Based Localization, Multi-Tier Classification, and Global Revenue Fines). Let's reuse this slug. 4. `vietnam-pdpl-decree-356-cross-border-transfers-2026` (Vietnam’s Decree 356/2025/ND-CP and Decree 165/2025/ND-CP: Navigating the Dual-Layered Cross-Border Data Transfer Framework). Let's reuse this slug to add Decree 330/2026/ND-CP and the procedural changes (DPIA/CTIA email filing and provincial decentralization). 5. `vietnam-cybersecurity-law-enactment-2026` (Vietnam's New Cybersecurity Law (No. 116/2025/QH15) Takes Effect: Unified Governance, Strict Timelines, and Retained Data Localization). Let's reuse this slug to add the new implementing decrees (Decree 331, 333, etc.) issued on August 19, 2026. Wait, are there any other open threads or watches we can resolve? Let's see: - Thread: `South Korea Mandatory ISMS-P Certification Implementation` (kind: watch, cardinality: one_shot, fire_date: 2027-07-01). This is a forward-looking watch that will fire on July 1, 2027. We shouldn't resolve it yet since the fire date is in 2027, but we can note that the PIPA amendments confirm its July 1, 2027 implementation date. - Thread: `Vietnam National Assembly Vote on Draft Law on Data Security` (kind: watch, cardinality: one_shot, fire_date: 2026-10-31). This is scheduled for October 2026. It hasn't happened yet (today is Sept 7, 2026). So it stays open. - Thread: `Japan PPC Rules and Guidelines on APPI 2026 Amendments` (kind: watch, cardinality: ongoing). This tracks the publication of draft and final PPC rules, cabinet orders, and guidelines. Since the APPI amendment was promulgated on July 17, 2026, and the main provisions will take effect by July 17, 2028, the PPC has not yet published the final rules/guidelines, but they are expected. This stays open. Wait, are there any other threads? No, those are the three watches. Let's check if we can record any events. No watches have fired yet (the South Korea ISMS-P is 2027, Vietnam Data Security Law vote is October 2026, Japan PPC rules are ongoing and not yet finalized). Wait! Is there any other thread or watch we should record? We could record a watch or thread if needed, but we have very clear and rich findings to write. Let's carefully write the updated notes. ### Note 1: `japan-appi-2026-amendments-diet-enactment` Let's revise this note to reflect that the APPI amendments have been passed by the Diet on July 10, 2026, and promulgated on July 17, 2026 as Act No. 56 of 2026. Let's draft the content for `japan-appi-2026-amendments-diet-enactment`: - Title: Japan's 2026 APPI Amendments Promulgated: Diet Passes Landmark Reform Introducing Surcharges, AI Exceptions, and Children's Privacy Rules - Key highlights: - Passed by the National Diet on July 10, 2026, and promulgated on July 17, 2026 as **Act No. 56 of 2026**. - Timeline: Criminal penalties and new acquisition offenses take effect on **January 17, 2027** (6 months post-promulgation). The main body of reforms (surcharges, consent exceptions, biometric/children's data, and revised PPC powers) will take effect no later than **July 17, 2028** (2 years post-promulgation). - Administrative Surcharge Regime (Article 148-3): Introduces Japan's first administrative fine system. Fines are targeted at serious violations (improper use/provision, breach of third-party provision, statistical-creation breaches, or improper acquisition under Article 20(1)) where the company received consideration, failed to exercise reasonable care, and the violation affected >1,000 individuals with significant harm. The fine corresponds to the economic benefit/ill-gotten gains derived from the violation, with a 1.5x multiplier for repeat offenders (within 10 years) and a 50% leniency reduction for voluntary self-reporting before an investigation. - Data Utilization & Consent Exceptions: - "Creation of statistical information, etc." (Article 2(13)) exception: Allows collecting publicly available sensitive data and sharing data with third parties for statistical/AI development purposes without consent, subject to transparency and written agreements. - "Clearly Non-Prejudicial Processing" (Article 18(3)(vii)): Eases consent when processing clearly does not conflict with individual intent/interests (e.g., travel agency hotel booking). - "Reasonable grounds for not obtaining consent" replaces the strict "difficulty" requirement for public interest exceptions. - Children's Privacy (Article 40-2): Parental consent required for children under 16, and minors are granted strengthened rights to request deletion or suspension of data use without meeting adult preconditions. - Biometric Data (Article 16(5)): Introduces "Specific Biometric Personal Information" (e.g., facial recognition data) subject to strict transparency, suspension rights, and a ban on opt-out third-party provision. - Entrusted Data Processors (Article 58-2): Significant regulatory relief if robust contractual safeguards are in place, exempting them from direct individual notification and data subject rights requests, though security and breach reporting duties remain. Let's do this write_note. No frontmatter, first heading is `# `, slug is `japan-appi-2026-amendments-diet-enactment`. Let's write the note.
Agent
I will write the updated note for Japan's APPI 2026 amendments to reflect the formal Diet passage and promulgation of Act No. 56 of 2026, detailing the administrative surcharge regime, AI-related statistical exemptions, children's privacy, and biometric regulations.
Agent
Now I will write the updated note for South Korea's PIPA amendments, which take effect on **September 11, 2026** (in 4 days). I'll reuse the slug `south-korea-pipc-prevention-transition-2026`. This update will capture the historic shift to turnover-based fines, CEO/representative director accountability, earlier breach notifications, and the draft Enforcement Decree criteria.
Agent
Now I will write the updated note for Vietnam's Personal Data Protection Law (PDPL) and Decree 356, focusing on the newly issued **Decree No. 330/2026/ND-CP** (on administrative penalties), which took effect on **August 19, 2026**! I will reuse the slug `vietnam-pdpl-decree-356-cross-border-transfers-2026` to update it. This note will also capture the new electronic DPIA/CTIA dossier submission procedure and provincial police decentralization.
Agent
Now I will write the updated note for Vietnam's draft Law on Data Security, incorporating the July 17, 2026 public consultation draft, the 4-tier risk classification, the proposed December 1, 2027 effective date, and the October 2026 scheduled vote. I'll reuse the slug `vietnam-data-security-law-draft-limits-2026`.
Agent
Now I will write the updated note for Vietnam's Cybersecurity Law to capture the set of implementing decrees issued on **August 19, 2026** (Decree 331, 333, etc.) which operationalize the Law on Cybersecurity No. 116/2025/QH15. I'll reuse the slug `vietnam-cybersecurity-law-enactment-2026`.
Agent
Excellent! All of our core notes have been successfully updated with high-quality, fully cited evidence and verbatim quotes. Let's double-check if there are any other notes we should write or update. The list of notes contains: - `vietnam-cybersecurity-law-enactment-2026` (updated) - `multinational-data-residency-adaptation-japan-korea-australia-2026` (no updates needed this cycle, but we can reference it) - `multinational-vendor-india-dpdp-compliance-cloud-2026` (no updates needed this cycle) - `japan-appi-2026-amendments-diet-enactment` (updated) - `south-korea-pipc-prevention-transition-2026` (updated) - `vietnam-data-security-law-draft-limits-2026` (updated) - `vietnam-pdpl-decree-356-cross-border-transfers-2026` (updated) Wait, did we resolve any threads or watches? No, the watches remain open because their fire dates are in the future or they are ongoing: 1. `South Korea Mandatory ISMS-P Certification Implementation` (fire_date: July 1, 2027) - Keep open as a watch. 2. `Vietnam National Assembly Vote on Draft Law on Data Security` (fire_date: October 31, 2026) - Keep open as a watch. 3. `Japan PPC Rules and Guidelines on APPI 2026 Amendments` (ongoing) - Keep open as a watch. Let's double-check if we need to record any new watches. Since Vietnam's draft amended Penal Code (introducing personal data crimes) is scheduled to be passed in **October 2026** under an expedited legislative procedure, we should register a new watch for this! This is a dated catalyst and is highly relevant. Let's register a watch for Vietnam's draft Penal Code amendment. - Watch Type: `dated_catalyst` - Cardinality: `one_shot` - Title: `Vietnam National Assembly Vote on Draft Penal Code Personal Data Crimes` - Fire Date: `2026-10-31T00:00:00Z` - Description: `Track whether the National Assembly votes to pass the proposed amendments to the Penal Code in October 2026, introducing two designated criminal offenses for personal data infringement.` Let's call `record_watch`.
other record_watch
Agent
Awesome! The watch is successfully registered. Now, let's call `finish_cycle` to complete this research cycle. I have updated five notes with extremely rich details and registered a new watch. No findings were missed. I will call `finish_cycle`.
other finish_cycle
Agent
I have completed the research cycle and updated the living set of findings for the APAC data residency and cross-border data transfer topic. ### Summary of Key Findings from This Cycle 1. **Japan's 2026 APPI Amendments Promulgated (`[[japan-appi-2026-amendments-diet-enactment]]`):** - **Enactment & Timeline:** Passed by the National Diet on July 10, 2026, and promulgated on July 17, 2026 as **Act No. 56 of 2026**. Criminal penalties for improper acquisition take effect on **January 17, 2027**, while the main body of reforms will take effect no later than **July 17, 2028**. - **Surcharge Surcharges:** Introduces a first-of-its-kind administrative monetary penalty system (Article 148-3) targeting serious data violations. Fines correspond to the economic benefit derived, with a 1.5x multiplier for repeat offenders and a 50% leniency reduction for voluntary self-reporting. - **AI and Statistical Processing:** Introduces a major consent exemption under Article 2(13) for data used solely for the "Creation of statistical information, etc." (including AI training data), allowing public sensitive data collection and third-party sharing subject to strict transparency and written contracts. - **Children & Biometrics:** Mandates parental consent for children under 16, grants minors special rights to delete/suspend data, and establishes a strict, opt-out-prohibited regime for "Specific Biometric Personal Information" (e.g., facial recognition data). 2. **South Korea PIPA Amendments Effective Sept 11, 2026 (`[[south-korea-pipc-prevention-transition-2026]]`):** - **Enforcement Date:** Sweeping amendments to the PIPA (Act No. 21445) take effect on **September 11, 2026** (mandatory ISMS-P certification is deferred to **July 1, 2027**). - **10% Turnover Fines:** Elevates administrative fines to **up to 10% of total revenue** for serious/repeat violations or leaks affecting 10M+ subjects. Conversely, a mandatory fine reduction (up to 40% under draft decree) is introduced for companies that demonstrate prior investments in data protection budgets and personnel. - **CEO Accountability:** New Article 30-3 holds the business owner or representative director personally responsible for safe data processing, a duty that cannot be delegated. - **CPO & Breach Notifications:** CPOs must report directly to the board of directors. For large controllers, CPO designation requires board approval and PIPC filing. Breach notifications must now occur at the point of **suspicion/possibility** of a leak (within 72 hours proposed) and cover integrity/availability incidents (ransomware). - **Multinational Fines:** Highlights the active enforcement posture of the PIPC, which fined **Coupang** a record **KRW 624.68 billion** in June 2026, and penalized TikTok (KRW 10.31B) and Apple (KRW 252M) in July 2026 for failing to appoint compliant domestic representatives. 3. **Vietnam's Personal Data Protection Penalties Decree In Effect (`[[vietnam-pdpl-decree-356-cross-border-transfers-2026]]`):** - **Decree 330/2026/ND-CP:** Issued and immediately effective on **August 19, 2026**, this decree completes the enforcement mechanism for the PDPL and Decree 356. - **Severe Penalties:** Serious cross-border data transfer violations face fines of **up to 5% of the preceding year's revenue**. Illegal data trading faces fines of **up to 10 times the gross proceeds**. General violations face fixed fines of up to VND 3 billion. - **Operational Suspensions:** Authorizes the mandatory destruction of data and the **suspension of data processing or cross-border transfers for 6 to 12 months**—a critical operational risk for multinational services. - **Procedural Reforms:** Enabled **electronic email submission** of DPIA and CTIA dossiers to a dedicated A05 address. Concurrently, **Resolution No. 22/2026/NQ-CP** decentralizes the review of these dossiers to **provincial police departments** to relieve national bottlenecks. 4. **Vietnam's Draft Law on Data Security (`[[vietnam-data-security-law-draft-limits-2026]]`):** - **Status & Timeline:** Published by the MPS for public consultation on July 17, 2026. Scheduled for a National Assembly vote in **October 2026**, with a proposed effective date of **December 1, 2027**. - **4-Tier Taxonomy:** Classifies data into four levels: Level 1 (public), Level 2 (internal/trade secrets), Level 3 (important data), and Level 4 (core data). Level 3 and 4 data require strict risk management, localization, and are subject to export bans or rigorous state-level security reviews. 5. **Vietnam's Cybersecurity Law Guiding Decrees (`[[vietnam-cybersecurity-law-enactment-2026]]`):** - **Implementation Suite:** On **August 19, 2026**, the Government issued a coordinated suite of seven decrees (Decrees 327, 329, 330, 331, 332, 333, and 328) to operationalize the Law on Cybersecurity No. 116/2025/QH15. - **System Classification:** Decree 331 classifies information systems into five levels, subjecting higher levels to continuous state-monitored cybersecurity protection and periodic audits. ### Forward-Looking Watches Registered - **Vietnam Draft Penal Code Amendment (`one_shot`, Target: Oct 31, 2026):** Tracking whether the National Assembly votes to pass the proposed Penal Code amendments, which introduce two designated criminal offenses for personal data infringement (carrying up to 7 years' imprisonment or a corporate fine of up to VND 10 billion).