
Privacy Policy
The Japan Foundation, London (“JF”) is the data controller for the purposes of the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and other applicable data protection laws (“applicable laws”) in connection with the provision of any of the services that the JF provides (“Services”) to users (“Users”) in the United Kingdom and, where applicable, other individuals whose personal data is processed by the JF, and therefore hereby establishes this privacy policy ( “Privacy Policy”) in order to appropriately process the personal data and other data of the Users in accordance with the applicable laws.
1. Processing Personal Data
(1) Definitions
“Personal data” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. This includes, without limitation, names, addresses, dates of birth, telephone numbers, e-mail addresses, and any other information collected in connection with providing the Services.
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
(2) Purpose of use of personal data
The JF will process the Users’ personal data to provide, improve and develop the Services.
In the case of processing the Users’ personal data for purposes other than the above, the JF will notify the Users in advance of such new purposes of use and other matters as required by the applicable laws.
The JF will process the Users’ personal data where it has a lawful basis to do so under the UK GDPR, including, where applicable, the User’s consent, performance of a contract or steps taken at the User’s request, compliance with a legal obligation, the JF’s legitimate interests, or another lawful basis permitted by applicable laws. Where the JF relies on consent, the Users may withdraw such consent at any time. Such withdrawal will not affect the lawfulness of processing based on consent before withdrawal.
The personal data that the Users are to provide is necessary in order for the JF to provide the Services to the Users, and there may be cases in which the Users who have not provided such data will be unable to use the Services.
(3) Retention Period
The JF will not retain personal data for longer than is necessary for the purposes for which it was collected. In accordance with its internal regulations, the JF reviews the necessity of retaining data at regular intervals (typically every five or ten years, depending on the project). Personal data that is deemed no longer necessary will be deleted, while personal data that remains relevant may have its retention period extended.
(4) Transfer
The JF may share the Users’ personal data obtained by its overseas offices including those in London, Paris, Madrid, Rome, Cologne and Budapest with other offices including the headquarters in Japan, and may use trusted third-party services such as Mailchimp (for email and questionnaire distribution), SurveyMonkey or Microsoft Forms (for surveys and questionnaires) to collect and manage data related to its research and communications. We do not sell the Users’ personal information or share it with third parties for their own commercial purposes. All personal data is used solely for the purposes stated at the time of collection. The Users’ rights in relation to their personal data are described in section 1(5) below.
The JF may transfer the Users’ personal data from the United Kingdom to countries outside the United Kingdom, including Japan, where this is necessary for the purposes described in this Privacy Policy. Where the recipient country is covered by UK adequacy regulations, the JF may rely on those regulations for the transfer. The United Kingdom currently has an adequacy decision for Japan. Where there is no applicable UK adequacy decision, the JF will use an appropriate transfer mechanism under the UK GDPR, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another mechanism permitted by applicable laws.
(5) Rights of Users
The Users may:
- request from the JF access to, rectification or erasure of, and restriction of processing of their personal data;
- object to the processing of the Users’ personal data; and
- request data portability, in each case where applicable under the UK GDPR. The JF accepts such Users’ requests at the contact point set forth in “3. Contact” below.
The JF may refuse the Users’ requests, or charge a reasonable fee, where permitted by applicable data protection laws, for example if such requests are manifestly unfounded or excessive.
The Users may lodge a complaint with the UK Information Commissioner’s Office (ICO), the UK supervisory authority for data protection, with regard to the processing of their personal data.
The JF does not currently use any automated decision-making, including profiling, that produces legal effects concerning the Users or similarly significantly affects them. If the JF were to introduce such processing, it would inform the Users in advance and provide appropriate safeguards in accordance with applicable laws.
2. Safety Management Measures
In order to prevent unauthorised access to, or loss, destruction or damage etc. of personal data, the JF will: (i) comprehensively evaluate the risks of personal data breaches, taking into account the nature of the personal data, the degree of sensitivity and harm that could be caused to the Users in the case of a personal data breach; (ii) implement appropriate technical and organisational measures based on the assessed risk; (iii) review such measures on a regular basis; and (iv) constantly strive to improve security.
The JF shall strive to appropriately manage personal data by: (i) restricting the entry of outsiders into the offices which are processing personal data; (ii) conducting educational awareness activities for all officers and employees involved in the protection of personal data; and (iii) placing a manager in charge for each division processing personal data.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of the Users, the JF will notify the UK Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to the rights and freedoms of the Users, the JF will also notify the affected Users without undue delay.
3. Contact
In the event that the Users have any questions or concerns regarding this Privacy Policy or the processing of personal data by the JF or have any requests concerning the exercise of their rights under applicable laws, please contact the JF. The contact information for the JF is as follows:
The Japan Foundation, London
101-111 Kensington High Street, London, W8 5SA
0207-492-6570
LO_info@jpf.go.jp
Last updated: 29 June 2026