Every time a guest checks into one of our properties, we log their details in our guest ledger and verify who they are. For foreign guests without a Japan address, that means recording their nationality and passport number and keeping a copy of the passport itself. Multiply that by however many bookings a month, across however many properties, and you’re sitting on a pile of personal data that most small operators never think about as a compliance problem — until something goes wrong.

TL;DR

  • Japan’s Act on the Protection of Personal Information (個人情報保護法, “APPI”) applies to essentially every business handling personal data, regardless of size — the old exemption for operators handling 5,000 or fewer records over the previous six months was removed in 2017.
  • If you keep a guest ledger and verify guest identity (required under minpaku/ryokan rules, with passport number, presentation, and a copy required for foreign nationals without a Japan address), you are a 個人情報取扱事業者 (personal information handler) and must specify and stick to a stated purpose of use.
  • You’re expected to take “safety management measures” (安全管理措置) — technical, organizational, and physical — to protect that data, not just collect it and hope for the best.
  • Since the 2020 APPI amendment (effective April 1, 2022), certain data breaches — involving special-care-required personal information, possible financial harm, suspected improper purpose, or more than 1,000 affected individuals — carry a mandatory reporting obligation to the Personal Information Protection Commission (PPC) and a notification obligation to affected guests.
  • Practical fixes are cheap: clearly disclosed purposes of use (a privacy policy is the easiest way to do this), access limits, encrypted storage, and a retention/deletion schedule cover most of what small operators need.

What Is the APPI and Why Does It Apply to My Guesthouse?

The APPI is Japan’s general data protection law, and it applies to your guesthouse the moment you collect a guest’s name, ID document, or contact details. There’s a common misconception among small operators that data protection law is a “big company” problem — something for banks and tech platforms, not a two-property Airbnb operation. That was true before 2017, when businesses handling 5,000 or fewer records over the previous six months were exempt. That exemption is gone. If you’re verifying guest ID (which minpaku and ryokan business law require you to do), you’re handling personal information, full stop, and the APPI applies to you the same as it applies to a hotel chain.

What Guest Data Are You Actually Collecting?

Most operators are collecting more than they realize. For every guest, that’s full name, nationality, and contact email and phone — all guests go on your lodging register, and their identity is checked at check-in. For foreign nationals without an address in Japan, minpaku and ryokan business rules specifically require you to also record their passport number, have them present the passport, and keep a copy of it. Whether you additionally scan a driver’s license or other ID for domestic guests is generally a matter of your own operator policy or local ordinance, not a blanket national requirement. On top of that, you’ll typically have booking details, payment status, payout records, or any payment data your OTA/PMS/payment processor actually makes available. Each of these needs a stated purpose — under the APPI you’re required to specify what you’re using the data for (利用目的の特定) and not use it beyond that purpose without new consent. In practice this means: ID verification and legal record-keeping is a fine stated purpose; quietly adding guests to a marketing email list because you already have their address is not, unless you disclosed that upfront.

What Are the Practical Storage and Retention Requirements?

The law requires “safety management measures” appropriate to the sensitivity of the data, not a specific technical checklist. That’s actually the tricky part — there’s no single certified standard to follow, just an expectation that you’ve taken reasonable steps: encrypting stored ID scans, restricting who on your team can access them (a cleaner doesn’t need to see a passport photo), and not emailing ID copies around in plaintext between staff. On retention, minpaku and ryokan business rules require keeping the guest ledger for three years from its creation. For foreign guests without a Japan address, that includes keeping the passport copy together with the ledger for that same three-year period — this one you don’t get to delete early. The APPI’s general principle is to not hold data longer than necessary for its stated purpose, so beyond what the ledger requirement and any other law, ordinance, or contract actually demands, delete optional or non-required ID images (for example a domestic guest’s driver’s license scan, if nothing requires you to keep it) once verification is complete.

What Happens If You Get This Wrong?

A mishandled guest data incident now carries a real reporting obligation, not just reputational risk. Since April 1, 2022, under the 2020 APPI amendment, a leak, loss, or damage of personal data — or a suspected incident — must be reported to the Personal Information Protection Commission (PPC), and affected individuals must be notified, if it involves special-care-required personal information (要配慮個人情報), a risk of financial harm, suspected improper purpose, or more than 1,000 affected individuals. This isn’t hypothetical for hospitality operators: a poorly secured shared drive full of scanned passports, or a compromised property management account, is exactly the kind of exposure regulators had in mind.

How Should Small Operators Handle This Without a Compliance Team?

You don’t need a legal department — you need a handful of concrete habits, applied consistently. At BenStay, our practical baseline across properties is: a written, published privacy policy stating what we collect and why; ID scans stored in an access-controlled system rather than shared folders or email threads; a defined retention window tied to the legal ledger requirement, with a deletion step afterward; and limiting who on the team — cleaners, co-hosts, contractors — ever sees a guest’s raw ID document versus just their booking details. For any outsourced cleaners, co-hosts, or vendors who need this data, we treat it as entrustment: the handling instructions go in writing or in the contract, we confirm they have reasonable safety controls, and we don’t hand over a passport scan unless there’s a real reason to. None of this is expensive or complicated. It’s mostly about not letting convenience (forwarding a passport photo in a group chat because it’s easy) become your default process.

FAQ

Q: Do I need a formal privacy policy on my booking site or listing?

Not strictly — the APPI’s actual requirement is that you specify your purposes of use and notify or publicly announce them, and when you collect data directly through something like a booking form, you show the purpose before you collect it. A standalone privacy policy isn’t legally mandatory, but it’s usually the cleanest way to satisfy that disclosure requirement, so most operators use one anyway.

Q: Does sharing guest data with my OTA or cleaning staff count as a violation?

Not automatically — providing data to an OTA as part of the booking transaction, or giving a cleaner the information they actually need, is generally fine. But if you’re handing data to outsourced cleaners, co-hosts, or vendors, treat that as entrustment (委託): only share what’s within the necessary scope, put the handling instructions in writing or your contract, and confirm they have reasonable safety controls in place. Sharing outside that necessary scope — or with a party who isn’t really acting as your contractor — may need the guest’s consent or another APPI exception, and a cleaner doesn’t need a passport scan.

Q: How long do I actually need to keep guest ID copies?

It depends on your license category and local ordinance for anything beyond the baseline, but the baseline itself is fixed: keep the guest ledger for three years from its creation, and for foreign guests without a Japan address, keep their passport copy together with the ledger for that same three years. Beyond that, delete optional ID images (for example a domestic guest’s driver’s license scan) once verification is complete, unless some other law, ordinance, contract, or documented purpose requires you to keep them.


This post is for informational purposes only and does not constitute legal or tax advice. Please consult a qualified professional for your specific situation.