The sooner or the later, I guess the Japanese privacy mark certifications (Pマーク)would be replaced with ISO27701 extension to ISMS one for many entities not to compromise GDPR. Conformity to ISMS extension would be relevant to ISMAP政府情報システムのためのクラウドセキュリティ評価制度 for cloud service providers process PII. A credit card number would be Personally Identifiable Information(PII). ISO27701, ISO27017, and ISO27018 are partially relevant to PCI DSS.