ThreatLabZ
Storie di successo dei clienti
Carriere
Partner
Supporto
Contattaci
1-408-533-0288
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal | Admin
admin.zscloud.net
Zscaler Private Access Cloud Portal One | Admin
Portale di Zscaler Private Access Cloud | Amministratore
Home
Scopri il prodottoRichiedi una dimostrazione
Proteggi la forza lavoro

Offri agli utenti un accesso fluido, sicuro e affidabile alle applicazioni e ai dati..

Proteggi il cloud

Sviluppa ed esegui app cloud sicure, abilita la connettività zero trust al cloud e proteggi i carichi di lavoro dal data center al cloud.

Proteggi gli ambienti IoT e OT

Fornisci una connettività zero trust ai dispositivi IoT e OT e un accesso remoto sicuro ai sistemi OT.

Proteggi il B2B

Fornisci ai tuoi partner una connettività zero trust site-to-site e un accesso affidabile alle app B2B.

Zscaler Platform
Perché scegliere Zscaler?
Leadership nell settore dell'AI
SASE di Zscaler
Zscaler SSE
Riconoscimenti degli analisti
Automazione Zero Trust
Storie dei clienti
Ecosistema di partner
Riduci il tuo impatto ambientale

Resoconto di settore

Zscaler: una leader nel Magic Quadrant™ di Gartner® 2025 per il Security Service Edge (SSE)

nvaigation-gartner-report-2025
SASE Zero Trust
Accesso sicuro a Internet (ZIA)
Accesso privato sicuro (ZPA)
Esperienza digitale (ZDX)
Firewall zero trust
Cloud Sandbox
Zero Trust Browser
Zero Trust Branch
SD-WAN zero trust
Segmentazione IoT/OT
Accesso remoto con privilegi
Zscaler Cellular
Sicurezza dell'AI
Gestione delle risorse IA
AI Access Security
AI Red Teaming
Limitazioni dell'AI
Zero Trust Cloud
Secure Ingress and Egress Traffic
Secure East-West Traffic
Microsegmentazione
Zero Trust Gateway
Sicurezza dei dati
DLP per web e e-mail
DLP dell'endpoint
Sicurezza dei dispositivi personali (BYOD)
Multi-Mode CASB
Sicurezza SaaS unificata
DSPM
Microsoft Copilot Data Protection
Operazioni di sicurezza
Risk360
Tecnologia di deception
Asset Exposure Management
Gestione unificata delle vulnerabilità
Ricerca gestita delle minacce
Managed Detection & Response
Data Fabric for Security
CASI D'USO
Zero trust + AI
Business Insights
Sostituire la VPN
Protezione dalle minacce informatiche
Blocca i ransomware
Alternativa alla VDI
Proteggere i dati
Ottimizza le esperienze digitali
Distribuisci i dispositivi personali in modo sicuro
Riduci il rischio informatico
Security Operations
Continuous Threat Exposure Management
Accelerare fusioni, acquisizioni e cessioni
Soluzioni per l'industria e il mercato
Assistenza sanitaria
Servizi finanziari e bancari
Settore manifatturiero
Istruzione
Governo australiano
Governo cinese
Settore pubblico degli Stati Uniti
Governo federale degli Stati Uniti
Amministrazione statale e locale degli Stati Uniti
APJ Mid-Market / Commercial
Partner
Esplora i nostri partner
Diventa un partner
Portale partner
PARTNER TECNOLOGICI
Scopri i partner per la tecnologia
Microsoft
CrowdStrike
AWS
Okta
Rubrik
SAP
Zero trust + AI
Business Insights
Sostituire la VPN
Protezione dalle minacce informatiche
Blocca i ransomware
Alternativa alla VDI
Proteggere i dati
Ottimizza le esperienze digitali
Distribuisci i dispositivi personali in modo sicuro
Riduci il rischio informatico
Security Operations
Continuous Threat Exposure Management
Accelerare fusioni, acquisizioni e cessioni
Assistenza sanitaria
Servizi finanziari e bancari
Settore manifatturiero
Istruzione
Governo australiano
Governo cinese
Settore pubblico degli Stati Uniti
Governo federale degli Stati Uniti
Amministrazione statale e locale degli Stati Uniti
APJ Mid-Market / Commercial
Esplora i nostri partner
Diventa un partner
Portale partner
Scopri i partner per la tecnologia
Microsoft
CrowdStrike
AWS
Okta
Rubrik
SAP
Centro risorse
Libreria delle risorse
Blog
Storie di successo dei clienti
Webinar
Zpedia
Eventi e formazione
Prossimi eventi
Zenith Live
Zscaler Academy
Ricerca e servizi di sicurezza
Analisi di ThreatLabz
Aggiornamenti degli avvisi di sicurezza
Strumenti
Anteprima della sicurezza
Security and Risk Assessment
Divulga una vulnerabilità
Executive Insights App
Calcolatore del ROI della protezione dai ransomware
Community e assistenza
Customer Success Center
Zenith Community
Portale di assistenza Zscaler
Libreria delle risorse
Blog
Storie di successo dei clienti
Webinar
Zpedia
Prossimi eventi
Zenith Live
Zscaler Academy
Analisi di ThreatLabz
Aggiornamenti degli avvisi di sicurezza
Anteprima della sicurezza
Security and Risk Assessment
Divulga una vulnerabilità
Executive Insights App
Calcolatore del ROI della protezione dai ransomware
Customer Success Center
Zenith Community
Portale di assistenza Zscaler
Informazioni su Zscaler

Scopri come tutto è iniziato e le previsioni per il futuro

Partner

Incontra i nostri partner ed esplora gli integratori di sistema e le alleanze tecnologiche

Notizie e annunci

Non perdere gli aggiornamenti sulle ultime novità

Team di leadership

Incontra il nostro team di gestione

Integrazioni con i partner

Esplora le integrazioni con i nostri partner per la tecnologia

Rapporti con gli investitori

Scopri le ultime notizie, le informazioni sulle azioni e i report trimestrali

Carriere

Unisciti alla nostra missione

Conformità

Scopri di più sui nostri rigorosi standard

Centro stampa

Trova tutto ciò di cui hai bisogno per parlare di Zscaler

Culture

Our values, leadership principles, and ways of working

Zenith Ventures

Scopri di più sui nostri rigorosi standard

Environmental, Social and Governance

Scopri il nostro approccio ESG

Home
Scopri il prodottoRichiedi una dimostrazione

Zscaler and APPI

Contents

  1. Introduction
  2. What Is Personal Information Under the APPI?
  3. How Does Zscaler Comply with the APPI?
  4. Helpful Links Regarding the APPI

Introduction

Japan’s general data protection law is the Act on the Protection of Personal Information (“APPI”). The APPI was first enacted in 2003, and significantly amended effective 2017, with further amendments to become effective April 1, 2022. The APPI is a comprehensive, cross-sectoral framework that regulates private businesses using personal information databases. The APPI incorporates the eight basic principles under the Guidelines on the Protection of Privacy and Transborder Flows of Personal Data from the Organisation for Economic Co-operation and Development.

Similar to the GDPR distinction between controllers and processors, the APPI makes a distinction between entities (“business operators,” in APPI terminology) with the authority to control and make decisions about retained personal data (i.e. our customers), and third party service providers that act on behalf of a business operator in processing personal information (i.e. Zscaler).

With respect to cross-border transfers of personal information, the transfer or disclosure of personal data to a third party located outside of Japan requires the data subject's prior consent, unless an exception applies. Exceptions include: (1) the third party is in a country that offers the same level of protection for personal information as Japan, as determined by the Personal Information Protection Commission (the “Commission”) (currently only the European Economic Area and the UK have been so designated), or (2) the third party has established a system to continuously ensure that it undertakes the same level of protective measures required under the APPI. In Zscaler's End User Subscription Agreement, Zscaler commits to the protective measures required by the APPI.

In 2019, the European Commission determined that Japan provides a comparable level of protection of personal data to that in the European Union, thus permitting the free flow of personal data from the European Economic Area to Japan.

The revisions to the APPI that will take effect in April 2022 include expanding data subjects' control over their data, enabling internal big data uses under specific circumstances, and increasing fines for violations.

Zscaler is committed to our customers’ success, including compliance with the APPI, and will assist our customers in satisfying their APPI obligations.

What Is Personal Information Under the APPI?

Personal information under the APPI includes information about a living individual from which the identity of the individual can be ascertained, and includes information that enables identification of the individual by easy reference to, or combination with, other information. 

With the 2017 revision to the APPI, “personal information” includes “personal identifier codes”: characters, numbers, symbols and/or other codes for computer use that represent certain specified personal physical characteristics (such as DNA sequences, facial appearance, finger and palm prints) that are sufficient to identify a specific individual. In addition, identifier numbers such as those on passports, driver's licenses and resident's cards are personal information. 

The revised APPI added a new category of sensitive data that could be used as the basis for discrimination or prejudice, such as medical history, marital status, race, religious beliefs and criminal records. Business operators always need the prior consent of the individual concerned to process such sensitive data.

How Does Zscaler Comply with the APPI?

In its role as a processor of customer data that may be subject to the APPI, Zscaler has several compliance obligations, including the following:

1. Purpose of Use. The APPI requires that a business operator specify the purpose of use of the personal information collected; and once the purpose of use has been identified, the business operator may not make any changes to such purpose that is beyond the scope of the original purpose. Zscaler only uses customer data for the purpose of providing its services and products to the customer.

2. Sharing of Personal Information. With limited exceptions, the APPI does not permit personal information to be disclosed to a third party without the prior consent of the individual. Zscaler does not share customer data with third parties except as disclosed to and permitted by the customer (for example, the sub-processors listed at https://www.zscaler.com/privacy-compliance/subprocessors).

3. Security. The APPI requires that business operators (i) take necessary and appropriate measures to safeguard and protect against unauthorized disclosure of, loss of, or damage to the personal information they process, and (ii) conduct necessary and appropriate supervision over their employees and service providers who process personal data. The Commission has promulgated mandatory and recommended security measures under the APPI. Consistent with the requirements of the APPI and the Commission’s guidance, Zscaler has developed and implemented security policies to protect all personal information against loss, theft, or any unauthorized access, disclosure, copying, use or modification, taking into account the sensitivity of the information and other factors.

4. Data breaches. Zscaler will promptly notify its customers of any data breach involving customer data and provide reasonable assistance to its customers to comply with any legally required notifications, including reports to Japan's Personal Information Protection Commission.

5. Cross-border transfers. As noted above, the APPI imposes restrictions on transfers of personal information outside of Japan. Zscaler satisfies the cross-border transfer requirements of the APPI by the commitments Zscaler makes to protect personal information in its End User Subscription Agreement. Zscaler will take all necessary measures to ensure the continued proper handling of personal information and the provision of information upon the request of data subjects.

6. Rights of data subjects. The APPI gives data subjects the right to require that a business operator disclose the purpose of processing of their personal information, how they can access and correct their personal information, how they can suspend the processing of their personal information, and where they can submit complaints concerning the handling of their personal information. Zscaler assists its customers in fulfilling their obligations to allow data subjects to exercise their rights under the APPI.

7. Audits. The APPI requires business operators that engage third party processors to evaluate the compliance of such third party processors with the APPI through onsite audits, periodic reporting, or other appropriate means. Zscaler will submit to audits or provide reports as necessary to demonstrate Zscaler’s compliance with the APPI.

Helpful Links Regarding the APPI

Japan Personal Information Protection Commission: https://www.ppc.go.jp/en/

Text of the APPI: https://www.jetro.go.jp/ext_images/usa/APPI.pdf 

NOTE: While this site is designed to help organizations understand the APPI in connection with Zscaler's services and products, the information contained herein may not be construed as legal advice and organizations should consult with their own legal counsel with respect to interpreting their unique obligations under Japan’s data protection laws.

Piattaforma Zero Trust
AI Security
Sicurezza dei dati
SecOps
Prodotti e soluzioni
Scopri il prodotto
Settori
Partner
Carbonio
Informazioni su Zscaler
FAQ su Zscaler
Leadership
Carriere
Investitore
Stampa
Responsabilità
Contatti
Prezzi
Red Canary
Community
Analysts
News
Zenith Live
Eventi
Executive Insights App
Attività di ricerca di Threatlabz
Libreria delle risorse
Blog
Webinar
Zpedia
Cyber Academy
Storie di successo dei clienti
Customer Success Center
Contatta l'assistenza
Portale di Assistenza
Avvisi di sicurezza
Divulga una vulnerabilità
Analisi dei rischi per la sicurezza
Conformità
Portale partner
Home

Zscaler è universalmente riconosciuta come leader nel settore dello zero trust. Sfruttando il security cloud più grande del pianeta, Zscaler anticipa le esigenze delle aziende, nonché protegge e semplifica il business delle realtà più affermate del mondo. 

Visita la nostra pagina Facebook(opens in a new tab)Trovaci su LinkedIn(opens in a new tab)Seguici su X(opens in a new tab)Iscriviti al nostro canale Youtube(opens in a new tab)Seguici su Instagram(opens in a new tab)
Mappa del sitoPrivacyLegaleSicurezzaPreferenze sui cookie
© 2026 Zscaler, Inc.

Tutti i diritti riservati. Zscaler™ e gli altri marchi commerciali presenti su zscaler.it/legal/trademarks sono (I) marchi commerciali o marchi di servizio registrati o (II) marchi commerciali o marchi di servizio di Zscaler, Inc. negli Stati Uniti e/o in altri Paesi. Tutti gli altri marchi commerciali sono di proprietà dei rispettivi titolari.