Skip to content

Japan Overview

Last reviewed: August 2026

This section is a regulatory guide for global enterprise architects and cross-border operations teams who plan to supply cloud services to the Japanese market or operate services using Japanese regions. Japan maintains a de facto entry gate for public-sector cloud procurement in the form of ISMAP (Information system Security Management and Assessment Program), and APPI (Act on the Protection of Personal Information) applies broadly to the handling of personal data. Each system serves purposes similar to other public security certifications (such as the US FedRAMP or Korea’s CSAP) and privacy regulations, but requirements and procedures must be satisfied independently.

The Japanese cloud market is notable for hyperscalers (AWS, Azure, Google Cloud, OCI) competing on a two-region footprint of Tokyo and Osaka, while domestic providers such as Sakura Internet (さくらインターネット) participate in the Government Cloud and are expanding their foothold in the public and financial sectors, which are sensitive to local-region requirements. There is no law that explicitly mandates data localization, but in practice the combination of ISMAP’s procurement-gate nature and APPI’s obligations around cross-border transfers and “understanding the external environment” has a substantial effect on region selection and contract design.

  • ISMAP (Japan Government Cloud Procurement Certification) — covers the program overview, registration process, the distinction between ISMAP and ISMAP-LIU, registration status of hyperscalers and major providers, its gate-like nature that excludes unregistered services from public procurement, and implications for foreign companies and global SaaS entering the market.
  • APPI (Japan’s Act on the Protection of Personal Information) — covers the three routes for cross-border transfer requirements, cross-border mutual adequacy recognition, the impact on cloud region selection, handling of sensitive information such as My Number, and the 2025–2026 triennial review trends.
  • Government Cloud (ガバメントクラウド) — covers the Digital Agency-led shared cloud infrastructure for national and local government, the status of registered CSPs (AWS/Azure/Google Cloud/OCI/Sakura Internet), the dual-gate structure with ISMAP, and the progress of local government system standardization.
  • Japan’s AI Policy and Domestic Model Landscape — covers the AI Act and AI Basic Plan, METI’s GENIAC program, the domestic LLM landscape (NTT tsuzumi, NEC cotomi, PFN PLaMo, and others), the government procurement channel Gennai (源内), and a comparison with Korea’s sovereign FM policy.