Japan's Personal Information Protection Commission recorded 19,417 personal-data-breach notifications in fiscal 2025, the second-highest annual total on record, according to the commission's annual report adopted by the cabinet on 7 July 2026. The figure trails only the previous year's 21,007 and is actually down 7.6 per cent year-on-year. Before that number gets turned into an alarming headline, it is worth being precise about what it counts — because a breach-notification tally is a specific and limited thing.

What the numbers say

The fiscal year, which ended in March 2026, produced a modest overall decline that masks a split between sectors. Notifications from private-sector entities fell to 17,139 from 19,056 the year before. Notifications from government agencies moved the other way, rising to a record 2,278 from 1,951. So the headline total came down, but the public-sector component reached its own high — a divergence worth more attention than the aggregate.

On enforcement, the commission used its most severe measure sparingly. It issued a single administrative order — to a name-list broker found to have supplied names and addresses to members of a fraud group, a case that had already prompted the commission's first-ever emergency order in May 2025. Alongside that, the commission recorded two recommendations and several hundred guidance or advisory measures; the exact count is reported as 649 by Jiji Press, while MLex put the guidance total at 506, a discrepancy worth noting rather than papering over. Either way, the enforcement posture is overwhelmingly advisory, with formal orders reserved for the most serious conduct.

Why a breach count is not a harm count

Here is the part that most coverage skips. A figure of 19,417 is a count of reported notifications, not a count of people harmed, records exposed, or incidents by severity. Under Japan's APPI framework, organisations are required to notify the commission in specified circumstances, including certain breaches involving sensitive information, malicious activity or significant numbers of affected individuals. The number is therefore shaped as much by what the rules require to be reported as by what actually happened. Japan also continued refining elements of its notification framework during 2026, including clarifying circumstances in which strong encryption may reduce reporting obligations.

Two consequences follow. First, a year-on-year decline of 7.6 per cent does not, on its own, mean fewer breaches occurred or that less harm was done; it means fewer notifications met the reporting criteria and were filed. Second, the tally flattens enormously different events onto the same scale. The KDDI incident disclosed during the same period illustrates the point: one very large breach exposing millions of records still contributes only a single notification to the annual total, exactly like a small firm's misdirected email affecting a handful of people. Summed together, these produce a headline number that is genuine and useful for tracking reporting trends, but that says very little on its own about the scale of damage across the year.

What is actually worth watching

Read that way, the more informative signals sit beneath the headline. The record level of public-sector notifications is one; if government agencies are reporting more, that could reflect changes in threat exposure, reporting practices, organisational compliance, or some combination of all three, and it is the trend line to follow. The regulatory direction is another: the commission used its annual report to flag progress toward amending the personal-information protection law, and it is weighing an administrative monetary-penalty system as part of its triennial review — a potentially significant shift for a regime whose enforcement has so far leaned advisory rather than financial. For organisations operating in Japan, that prospective move from guidance to fines is a more consequential development than any single year's notification count.

Key Takeaways

  • Japan's PPC recorded 19,417 breach notifications in FY2025 (ended March 2026), the second-highest on record after FY2024's 21,007, and down 7.6% year-on-year; the report was cabinet-adopted on 7 July 2026.

  • Private-sector notifications fell to 17,139 (from 19,056), while government-agency notifications rose to a record 2,278 (from 1,951).

  • Enforcement stayed mostly advisory: one administrative order (to a name-list broker linked to fraud), two recommendations, and several hundred guidance measures (649 per Jiji; 506 per MLex).

  • A breach-notification count is a reporting-volume metric shaped by notification rules — not a measure of harm, records exposed, or incident severity; a decline can reflect rule changes, not just fewer breaches.

  • The signals worth watching are the record public-sector total and the PPC's move toward APPI amendments and a possible administrative monetary-penalty system.