LEGAL UPDATE | NO. 2 | SEPTEMBER 2026
[SAKURA Law Office | Legal Update by Managing Partner Kenshiro Michishita]
SAKURA Law Office
Managing Partner Kenshiro Michishita
Tokyo, Japan | September 24, 2026
Executive Summary
Japanese law does not impose a blanket prohibition on entering customer information or other personal information into ChatGPT or another generative AI service. The legal analysis depends on the nature of the information, whether it constitutes “personal information” or “personal data” under Japan’s Act on the Protection of Personal Information (APPI), the stated purpose of use, the role and contractual position of the AI provider, whether the data may be used for model training or other independent purposes, whether data is transferred to a recipient outside Japan, and whether appropriate security and governance measures are in place. For corporate users, the correct unit of analysis is therefore not the product name alone, but the specific use case, subscription plan, configuration, contractual terms and data flow.
SAKURA Law Office has published the second installment of the Legal Update series by Managing Partner Kenshiro Michishita, entitled “Can Companies Enter Customer and Personal Information into ChatGPT? — Generative AI and Japan’s APPI (2026).”
As the use of generative AI becomes part of ordinary corporate operations, one of the questions most frequently raised in practice is whether a company may enter customer names, emails, contracts, inquiry histories, employee data or other information concerning individuals into ChatGPT or another generative AI service.
Neither of the two simplest answers — “personal information must never be entered into generative AI” or “enterprise AI is always safe” — is legally accurate. Japan’s APPI applies different rules depending on the nature of the information, the purpose for which it was obtained, whether the information constitutes personal data, how the external service provider handles it, whether the relationship is properly characterized as outsourcing, whether data is transferred to a foreign recipient, and what security measures are implemented.
Generative AI raises particular issues because information entered in a prompt may be processed solely to generate a response, retained for a period of time, used for abuse monitoring or quality control, made available to subprocessors, or, depending on the service and settings, used for model training or service improvement. Those differences can materially affect the legal analysis.
This Legal Update explains the principal issues under the APPI and related guidance as of September 24, 2026, including guidance issued by Japan’s Personal Information Protection Commission (PPC) regarding generative AI services and the amendments to the APPI enacted in July 2026.
1. There Is No Single Answer to the Question “Can We Enter Personal Information into ChatGPT?”
The analysis should begin by separating three questions: what information will be entered, why the company wishes to use it, and what the AI service provider will do with it.
For example, a company may use an enterprise AI environment to summarize an incoming customer inquiry where the contract provides that submitted data will not be used to train the provider’s general-purpose models and will be processed only to provide the contracted service. That situation is materially different from an employee copying the same customer email into a personal consumer account where the provider may use submitted content for broader service-improvement purposes.
Accordingly, companies should avoid making decisions solely at the product level — for example, “ChatGPT is permitted” or “ChatGPT is prohibited.” The more appropriate approach is to assess the intended use case, the categories of information involved, the applicable subscription plan, technical settings, data retention, training use, subprocessors, cross-border processing, access rights and human review.
It is equally unsafe to assume that a single fact resolves the issue. An enterprise subscription does not by itself establish legal compliance; turning off model training does not resolve every APPI issue; and deleting a person’s name does not necessarily mean that the information has ceased to be personal information.
2. The Distinction Between “Personal Information” and “Personal Data” Under the APPI
Under the APPI, “personal information” and “personal data” are related but distinct legal concepts. That distinction matters when generative AI is used in corporate operations.
Broadly speaking, “personal information” means information relating to a living individual that can identify a specific person by name, date of birth or other description, including information containing an individual identification code. Information may also qualify where it can be readily cross-referenced with other information to identify a specific individual.
“Personal data,” by contrast, refers to personal information that forms part of a “personal information database, etc.” Information extracted from a customer-management system, employee database, applicant-tracking system or similar organized database will often constitute personal data.
This distinction is important because additional APPI requirements apply to personal data, including rules governing third-party provision, supervision of processors, security control measures and transfers to foreign third parties.
The correct question is therefore not merely whether a prompt contains a person’s name. Companies should also consider where the information came from and how it is organized and managed within the company.
3. The First Legal Question: Is the AI Use Within the Stated Purpose of Use?
Under the APPI, a business handling personal information must specify the purpose of use as clearly as possible and, as a general rule, may not handle personal information beyond the scope necessary to achieve that specified purpose without obtaining the individual’s consent.
The PPC has specifically cautioned businesses using generative AI to confirm that entering personal information into a generative AI service falls within the scope necessary to achieve the purpose for which the information was obtained.
For example, if a company has collected customer information for the purpose of responding to customer inquiries, using an approved AI environment to summarize the inquiry or draft a proposed response may be capable of falling within that purpose, depending on the facts. By contrast, using the same customer information to train an unrelated internal model or to conduct a separate marketing analysis may require a different assessment.
An abstract statement such as “for improving operational efficiency” should not be assumed automatically to cover every form of AI processing. PPC guidance expects the purpose of use to be specific enough that the individual can reasonably understand and anticipate how the information will be used in the relevant business context.
Companies deploying generative AI on a broader scale should therefore review whether their privacy notices and internal purpose-of-use descriptions remain aligned with the actual AI use cases being introduced.
4. Does Sending Personal Data to an AI Provider Constitute a Third-Party Provision?
Where personal data is entered into an external AI service, the company must consider how the transfer is characterized under the APPI.
As a general rule, the APPI restricts the provision of personal data to a third party without the individual’s prior consent. However, where personal data is provided to an external service provider as part of an outsourcing arrangement that is necessary to achieve the company’s purpose of use, the service provider is not treated as a “third party” for the purposes of the ordinary domestic third-party provision rules, provided the arrangement falls within the statutory outsourcing framework.
An AI provider may therefore be treated as an entrusted service provider where it processes the data only within the scope of the outsourced service and does not independently use the data outside that scope. The analysis depends on the contract and the actual service design.
Companies should not assume that the use of an AI service is automatically an outsourcing arrangement. The provider’s rights over prompts, uploaded files, metadata and outputs must be examined, together with its rights to retain, analyze, improve, train on or otherwise use the submitted information.
5. If the Arrangement Is Outsourcing, the AI Provider Must Be Properly Supervised
Where a company entrusts the handling of personal data to an AI provider, the company remains responsible for taking necessary and appropriate measures to supervise the entrusted party.
In practice, this may involve reviewing the provider before engagement, contractual security obligations, restrictions on subprocessors, permitted purposes of use, access controls, retention periods, deletion obligations, incident notification, audit rights or other mechanisms for confirming how the data is handled.
Generative AI services can create particular challenges because subprocessors may be numerous, processing may occur in multiple jurisdictions and service specifications may change over time. Oversight should therefore not necessarily end when the initial agreement is signed.
The entrusted party may handle personal data only within the scope of the entrusted work. A provider cannot rely on the outsourcing characterization to pursue an unrelated independent business purpose. At the same time, PPC guidance recognizes that certain technical improvement activities may, depending on the facts, remain within the scope of the entrusted work where they are necessary to achieve the entrusting company’s purpose. The correct distinction is therefore between processing that remains within the entrusted purpose and independent use outside that purpose.
6. Model Training and Service Improvement Require Particular Attention
One of the most important generative-AI-specific issues is whether information submitted by the corporate user may be used for purposes other than generating the requested response.
The PPC has stated that, where a business enters personal data into a generative AI service without the individual’s consent and the data is handled for a purpose other than producing the requested output, the use may violate the APPI. The PPC therefore recommends confirming that the provider does not use the personal data for machine learning or other purposes beyond the relevant response generation.
Accordingly, where personal data may be submitted, companies should determine whether model-training use can be disabled, whether enterprise and consumer plans have different data terms, whether opt-out settings operate at the user or organization level, and whether API usage is subject to different conditions from the ordinary user interface.
Even where a provider states that customer data is not used to train its general models, the company should still understand what processing remains possible for purposes such as service delivery, security, fraud prevention, abuse monitoring, debugging, quality assurance or other operational functions. The legal assessment should be based on the actual contractual rights and processing activities, not on a marketing label alone.
7. Foreign AI Services: Cross-Border Transfer Rules Must Be Considered Separately
Many leading generative AI services are provided by companies outside Japan, and personal data may be processed or accessed outside Japan. Where personal data is provided to a “third party in a foreign country” within the meaning of Article 28 of the APPI, additional requirements apply.
Importantly, the foreign-transfer rules can apply even where the foreign recipient is an outsourced processor. Unless an exception applies, a company providing personal data to a foreign third party generally must obtain the individual’s consent to the foreign transfer after providing the information required by law.
Exceptions and alternative structures may be available, including where the recipient is located in a jurisdiction recognized as providing an equivalent level of protection or where the recipient has established a system that continuously implements measures equivalent to those required under the APPI. The applicable structure should be confirmed for the particular provider and arrangement.
Cross-border analysis should also address security-control obligations. Companies may need to understand the legal environment of the foreign country in which an entrusted party or subprocessor handles personal data and reflect that assessment in their security measures.
For global AI services, the corporate headquarters of the provider, the location of relevant subprocessors, the physical server location and the locations from which personnel may access the data may not be identical. Companies should therefore examine the actual data flow rather than relying solely on the provider’s place of incorporation.
8. Ordinary Cloud Storage and Generative AI Should Not Be Treated as the Same Thing
PPC guidance recognizes that, in certain cloud arrangements, storing personal data on infrastructure operated by an external provider may not constitute a “provision” of personal data if the provider is contractually and technically prevented from handling the stored personal data.
That concept should not be applied mechanically to generative AI. A generative AI service ordinarily processes the contents of a prompt or uploaded file in order to generate a response. It is therefore fundamentally different from a storage provider that is unable to access or handle the underlying data.
Accordingly, a company should not conclude that an AI service falls outside the provision rules merely because it is “a cloud service.” The relevant questions are whether the provider actually handles the information, for what purposes it does so, and what rights it has under the contract and technical architecture.
9. Security Control Measures Remain Essential When Personal Data Is Used with AI
Even where the company has resolved the third-party provision and outsourcing issues, the APPI’s security requirements remain relevant.
Companies should determine who may use which AI services, whether personal consumer accounts are permitted, what authentication is required for enterprise accounts, whether prompt and output logs are available, how former employees lose access, whether sensitive files can be uploaded, and whether technical controls should limit access to unapproved AI services.
Shadow AI — the use of unapproved public AI services by employees — is a particularly important risk. A company may believe that it has not formally adopted generative AI while personal data is already being submitted to external services through employees’ personal accounts.
Effective governance therefore ordinarily requires more than a written prohibition. Approved-tool policies, employee training, identity and access management, technical controls, logging and an incident-reporting process should be designed together.
10. Sensitive Personal Information, My Number and Other High-Risk Data
Information such as medical history, health examination results, disabilities and criminal history may constitute “special care-required personal information” under the APPI and should be handled with particular caution. Healthcare, HR, insurance, recruitment and employment use cases may involve such information even where the business user does not initially recognize it as sensitive.
Japan’s My Number regime is subject to separate and strict statutory restrictions on use and provision. In ordinary corporate generative-AI use, there will rarely be a legitimate need to enter My Number information into a general-purpose AI service. As a practical governance matter, companies should generally treat such information as prohibited input unless a highly specific and legally validated use case exists.
For high-risk data, the question should not be limited to whether the provider promises not to use the information for model training. The company should first ask whether the AI use is necessary at all, whether the processing can occur in a more restricted environment, and whether masking, redaction or minimization can reduce the amount of personal information involved.
11. Removing a Name Does Not Necessarily Remove the Information from the APPI
It is common to assume that information stops being personal information once a person’s name has been deleted. That assumption can be wrong.
If a person can still be readily identified from a combination of department, position, age, address, transaction history, matter description or other information, the information may continue to qualify as personal information even without the person’s name.
Likewise, replacing a name with “Employee A” or “Customer X” does not automatically create “pseudonymously processed information” under the APPI. That statutory category has specific processing and handling requirements.
Where information is modified before being submitted to an AI service, companies should assess re-identification risk, matter-specific details and the possibility of ready cross-referencing with other data. As a practical rule, the prompt should contain only the information genuinely necessary for the AI task.
12. The Output of Generative AI Can Also Create Data Protection and Related Legal Risk
Data protection risk is not limited to what the company enters into the AI system. The output can itself create legal problems.
The PPC has cautioned that generative AI responses may contain inaccurate personal information. An AI system may generate false biographical details, employment history, criminal allegations, health information or other statements concerning customers, employees, job candidates or business contacts.
If such output is then used in recruitment, HR decisions, transaction screening, internal circulation or public statements, issues may arise not only under the APPI but also in relation to defamation, privacy, employment law and other legal duties.
For important decisions concerning identifiable individuals, generative AI should not be treated as a substitute for primary-source verification. Human review remains essential.
13. The 2026 APPI Amendments and AI Development
On July 10, 2026, amendments to the APPI and related legislation were enacted by the Japanese Diet and were promulgated on July 17, 2026. Except for certain provisions, the amendments are scheduled to take effect on a date to be specified by Cabinet Order within two years after promulgation. As of September 24, 2026, the principal amendments are therefore not yet in force.
The amendments include measures intended to facilitate appropriate data utilization. In particular, they establish a framework under which, subject to statutory safeguards, consent requirements may be relaxed for certain acquisition or third-party provision of personal information or personal data where the information is used only to create statistical information or similar outputs in which the relationship to specific individuals is excluded. Government materials expressly contemplate that certain forms of AI development may fall within the concept of creating such statistical information or similar outputs.
This does not create a general rule that personal data may be freely used for AI development. The framework is subject to conditions intended to ensure that the data is used only for the specified statistical or similar purpose, including disclosure requirements, agreements between data providers and recipients in third-party provision scenarios, and restrictions on purpose-exceeding use and onward provision. Further details are being developed through Cabinet Orders, PPC rules and guidance.
Companies should therefore not rely on the 2026 amendment today as a basis for disregarding current consent, third-party provision or other APPI requirements. Current AI deployments should be assessed under the law presently in force, while future compliance programs should also prepare for the amended regime.
14. A Practical Decision Sequence Before Entering Personal Information into Generative AI
For corporate use, it is helpful to apply a consistent decision sequence rather than resolving each question ad hoc.
First, determine whether the information to be entered contains personal information and whether it constitutes personal data. Second, confirm that the proposed AI use falls within the purpose of use applicable to the information. Third, identify how the AI provider will handle the data and determine whether the relationship can properly be structured as outsourcing or whether third-party provision rules must be addressed. Fourth, consider Article 28 and the relevant foreign legal environment where the provider, processor or subprocessor is located outside Japan. Fifth, review contractual and technical safeguards, including training use, retention, deletion, access controls, subprocessors, logging and incident response.
After that analysis, ask one further question: does the AI system actually need the personal data at all? In many cases, the business purpose can be achieved by removing names, reducing detail or using appropriately masked information.
Good AI governance is not about entering every category of information that the law might theoretically permit. It is about using the minimum information necessary to achieve the legitimate business purpose.
15. An Internal AI Policy Should Say More Than “Do Not Enter Personal Information”
A single sentence prohibiting personal information is usually not enough for an operational corporate AI policy. Employees will still need to know whether a customer name can be removed, whether an enterprise AI environment changes the answer, whether contracts may be uploaded and when legal or privacy review is required.
An effective policy should identify approved AI services and plans, classify information categories, and state which categories may be processed in which environments. Public information, ordinary internal information, personal information, special care-required personal information, trade secrets and third-party confidential information should not necessarily be governed by the same rule.
AI environments approved to process personal data should undergo prior review of training use, administrator controls, logging, retention, foreign processing, subprocessors and access rights. Higher-risk use cases may require approval by legal, privacy, security or management functions.
Where AI output concerning an individual will be used externally or for recruitment, employment, credit or other decisions materially affecting an individual’s rights or interests, the policy should also require meaningful human verification and approval.
16. What to Do if Personal Data Is Accidentally Entered into an Unapproved AI Service
An accidental submission of personal data to an unapproved AI service should not automatically be labeled a reportable data breach before the facts are understood. It should, however, be treated as a potential incident and investigated promptly.
The company should identify when the incident occurred, who entered the information, the AI service and account or subscription used, the exact data submitted, the number of affected individuals, whether special care-required personal information was involved, and whether the provider may retain, train on, share or process the information outside Japan.
Where possible, the company should consider deleting the conversation or uploaded file, requesting deletion from the provider, changing relevant settings, disabling credentials or API keys and preserving logs necessary for the investigation.
The company should then assess whether notification to the PPC or affected individuals is required under the APPI’s breach-reporting regime, whether contractual notification duties apply, and what remedial measures are necessary.
In AI-related incidents, speed matters. Employees should therefore be encouraged to report accidental submissions immediately rather than conceal them out of fear of discipline.
17. Frequently Asked Questions
Q1. Is it illegal to enter a customer’s name into ChatGPT?
Not necessarily. The analysis depends on whether the information is personal information or personal data, whether the use is within the stated purpose of use, how the provider handles the information, whether the arrangement constitutes outsourcing or third-party provision, whether data is transferred abroad, and what security measures are in place. If the customer’s identity is not needed, minimizing or appropriately masking the information is generally preferable.
Q2. Is it safe to enter personal data if we use an enterprise version of ChatGPT or another AI service?
An enterprise plan can materially improve the risk profile, but it does not by itself determine APPI compliance. The company should review the specific contractual terms, training use, retention, subprocessors, foreign processing, administrator functions, access controls and other settings applicable to the actual service plan.
Q3. If we replace the person’s name with “Person A,” is the information no longer personal information?
Not necessarily. If the individual can still be readily identified from other details or by cross-referencing information available to the company, the information may remain personal information. A simple substitution also does not automatically create statutory pseudonymously processed information.
Q4. Can we upload a contract to a generative AI service for review?
The analysis should cover more than personal information. Contracts may contain trade secrets, M&A information, third-party confidential information or other sensitive content. The company should confirm the AI provider’s data terms and the relevant confidentiality obligations and consider redaction or masking where appropriate.
Q5. Is turning off model training sufficient?
No. Disabling general model training is important, but separate issues remain, including purpose of use, response-generation processing, retention, abuse monitoring, subprocessors, foreign transfers, security measures and processor supervision.
Q6. Does using an overseas AI service automatically constitute a foreign third-party transfer?
Not in every case. The answer depends on whether the foreign provider handles the personal data, the legal relationship between the parties, whether an Article 28 exception applies and the actual data flow. The contract and technical architecture should be reviewed.
Q7. Did the 2026 APPI amendments make personal data freely available for AI training without consent?
No. The amendments create a conditional framework for certain statistical or similar uses and may cover certain types of AI development, but they do not establish an unrestricted AI-training exception. Moreover, the principal amendments are not yet in force as of September 24, 2026.
18. The SAKURA Law Office Perspective on Generative AI and Data Protection
In practice, the question “Can we enter personal information into ChatGPT?” should not be answered in isolation.
The more useful analysis maps the entire data flow: what information the company holds, why it was collected, which AI service will receive it, under what contract and configuration, how the provider and its subprocessors will process it, where that processing occurs, and how the output will ultimately be used.
Legal permissibility and prudent corporate risk appetite are also not always identical. A processing activity may be legally possible under certain conditions but still be inappropriate because of customer expectations, contractual confidentiality, sector regulation, cybersecurity exposure or reputational risk.
Conversely, a blanket prohibition on all enterprise AI use is not always the safest solution. If employees are denied a workable approved environment, they may turn to unmanaged shadow AI. Effective governance therefore requires proportionate controls rather than reflexive prohibition or unrestricted adoption.
The objective is to design an AI environment that reflects the sensitivity of the information, the purpose of use, the contractual protections, technical safeguards and potential impact on individuals.
19. About the Kenshiro Michishita Legal Update Series
SAKURA Law Office will continue to publish the Legal Update series on the profile page of Managing Partner Kenshiro Michishita, addressing legal developments and practical issues of significance to companies and business leaders.
The first Legal Update addressed the broader legal risks of corporate generative AI use and the design of AI governance frameworks in Japan. This second installment focuses on one of the most important issues within that framework: the handling of personal information and personal data under the APPI.
Future Legal Updates are expected to address generative AI and copyright, confidential information and trade secrets, AI service agreements, internal AI policies, AI agents, M&A, cross-border transactions, Web3 and digital assets, crisis management, corporate misconduct and information governance.
The series is intended not merely to summarize statutes, but to identify the legal questions that companies, management teams and in-house counsel should address in real-world decision-making.
20. How SAKURA Law Office Can Assist with Generative AI and Data Protection
SAKURA Law Office advises companies on legal and governance issues arising from the use of ChatGPT and other generative AI systems involving personal information and personal data.
Our work may include determining whether customer or employee information can be processed in a proposed AI use case; reviewing the contractual terms and data flow of an AI service; assessing enterprise AI or API deployments; reviewing data processing agreements and related contracts; analyzing cross-border transfers and overseas processing; drafting or revising internal AI policies, privacy policies and data-governance rules; responding to accidental submissions of personal data; and reviewing the legality of AI-enabled products and services under the APPI and other applicable laws.
Companies are welcome to consult us before a final AI platform or implementation model has been selected. By examining the proposed use case, categories of information, candidate services and internal governance structure, we can help identify the legal, contractual and operational measures that should be addressed before deployment.
Generative AI / Data Protection Legal Inquiries
For advice concerning generative AI deployment, personal information and personal data, AI service agreements, cross-border transfers, internal AI policies, privacy policies, AI-related incidents or other AI / IT legal matters, please contact SAKURA Law Office.
Corporate clients may consult us not only after an issue has arisen, but also regarding pre-deployment legal reviews, data-flow assessments, contractual structuring and ongoing AI governance.
SAKURA Law Office
Managing Partner: Kenshiro Michishita
4F, Ark Hills South Tower, 1-4-5 Roppongi, Minato-ku, Tokyo 106-0032, Japan
TEL: +81-3-6910-0692
SAKURA Law Office – English Website
Principal Japanese Sources
— Personal Information Protection Commission – Notice Concerning the Use of Generative AI Services
— Personal Information Protection Commission – APPI Guidelines (General Rules)
— Personal Information Protection Commission – APPI Guidelines Q&A
— Personal Information Protection Commission – 2026 APPI Amendments
— Personal Information Protection Commission – Promulgation of the 2026 Amendment Act (July 17, 2026)
— Ministry of Economy, Trade and Industry – Checklist for Contracts Concerning AI Use and Development
— e-Gov Laws – Act on the Protection of Personal Information
Disclaimer
This article provides general legal information based on laws, PPC guidance and other public materials available as of September 24, 2026. It does not constitute legal advice or a legal conclusion concerning any specific matter. The contractual terms, technical specifications, retention practices, training practices and processing locations of generative AI services may change over time. In addition, the principal provisions of the 2026 amendments to the APPI are not yet in force. Specific matters should be assessed in light of the latest applicable law and guidance, the relevant service terms and technical architecture, and the individual facts.
Written and supervised by SAKURA Law Office, Managing Partner Kenshiro Michishita