日本語 Get in touch
All articles

Compliance

7 compliance checks before you launch an app or web service in Japan

The final confirmation screen for subscriptions, consent records for marketing email, the external transmission rules, the new under 16 rules, Google Fonts and session replay. Seven items that are small fixes before launch and expensive ones after, with the primary source for each

Published 6 min read

When a company launches a new app or web service, the legal side usually comes last. People think about trademarks and terms of service. The things that actually cause trouble are much plainer. What sits next to the subscribe button. Which list got the launch email. Which outside services receive data from the page behind the scenes.

None of those look like legal questions. They look like the normal way of building something, and that is why they get missed.

These are the seven items we check before every launch, with the primary source behind each one. We build products; we are not lawyers. This is a checklist for getting the obvious things done without gaps. If your service handles medical or financial data, or many children use it, talk to a specialist at least once.

1. Put six items on the final confirmation screen for subscriptions

Since the amended Act on Specified Commercial Transactions took effect on June 1, 2022, the "final confirmation screen" of an online sale has required content (Article 12-6). If your own site takes subscription or recurring orders, the screen right before the confirm button must show:

  • quantity (for recurring plans, what each delivery or period includes and how many, or that it continues indefinitely)
  • price (not only the first payment, but later payments and the total)
  • when and how payment is taken
  • when the product or service is provided
  • the application period, if a campaign has a deadline
  • how to cancel, and on what terms

The Consumer Affairs Agency's guidelines name a big first month price with small later prices as a clear problem. When a customer signs up because of a misleading display, they can rescind the order, and the business faces penalties.

From a design point of view, a link to the terms does not solve this. The information goes right beside the button, where the eye already is. Make canceling as easy as signing up, and keep a record of what the screen said, the price, the time and the account, so you can answer questions later.

The sales pages also need the "Specified Commercial Transactions Act disclosure" (business name, address, phone number and so on). Most companies have one. It gets forgotten when a new service launches on its own domain.

Japan's Act on Specified Electronic Mail is opt in by default: you may only send marketing email to people who agreed in advance. A launch announcement to your waitlist is marketing email, so the signup form needs a consent line for it.

The MIC and Consumer Affairs Agency guidelines come down to three points.

  • Keep a record that proves consent (for at least one month after the last message).
  • Show the sender's name, address and a contact for complaints and questions in the message.
  • Show where to send an opt out (an email address or URL), with a note right before or after it saying the reader can opt out.

The emails people miss are the ones sent outside the main tool: a drip sequence built in another app, a follow up to launch day signups, an announcement BCC'd to a few hundred people from someone's own inbox. The same rules apply to every one of them.

If you send more than 5,000 messages a day to Gmail addresses, Google's sender guidelines also require one click unsubscribe headers (List-Unsubscribe) and processing within two days. Most sending services add them automatically, but check once.

3. Check whether the external transmission rules apply

Since June 16, 2023, the external transmission rules in the amended Telecommunications Business Act have been in force. When a covered service makes the user's device send information to an outside company, it must notify or publish what is sent, the name of the recipient and the purpose, in a form users can understand.

Coverage follows the list in MIC's FAQ: SNS, messaging, search, news and information delivery and similar services. Pages that only introduce a company's own products are excluded. So a corporate site is often outside the rules while the new app itself may be inside them.

If you are covered, list everything that talks to an outside server: analytics, ad tags, chat, even font delivery. The longer that list, the more you have to publish and explain. Moving fonts to your own domain, the next item, makes it shorter.

4. Serve fonts from your own domain

When a page loads Google Fonts from fonts.googleapis.com, the visitor's browser connects to Google and hands over its IP address the moment the page opens, before any consent banner. In January 2022 the Munich Regional Court ruled that this breached the GDPR without consent and awarded the visitor €100. A wave of demand letters on the same grounds followed in Germany.

Even a service aimed at Japanese users gets visitors from Europe. The fix takes about ten minutes: download the .woff2 files, host them on your own domain and load them with @font-face in your CSS. The app is often clean while campaign pages, landing pages and blog templates still load fonts from outside. Open the live pages with the network tab in developer tools and confirm nothing goes to fonts.googleapis.com or use.typekit.net.

Session replay tools such as Microsoft Clarity, Hotjar, FullStory and LogRocket record clicks, scrolling and, depending on the settings, what people type. Under the APPI you need to specify and publish what you collect and why in your privacy policy. In the US these tools are the subject of ongoing class actions under California's wiretapping law (CIPA), on the theory that they intercept a conversation without consent.

Our default is off. If you truly need it to improve a funnel, enable it only after consent, mask every input by default and remove password, payment and health fields from recording entirely. Clarity uses the data-clarity-mask attribute and Hotjar uses data-hj-suppress. Then sign up yourself, watch the recording and confirm you cannot read what you typed.

Chat widgets need the same check. Some products can show your staff what a visitor is typing before they press send. Turn that off.

6. Ask for age before collecting personal information

Today's APPI sets no age for children. The Personal Information Protection Commission's Q&A says that, generally, children aged 12 to 15 and under are considered to need a legal representative's consent.

That is changing. The 2026 amendment to the APPI, promulgated on July 17, 2026, sets the line at under 16. Consent and notices go to the legal representative, and under 16s get an easier right to have their data use stopped. It takes effect on a date set by cabinet order within two years of promulgation.

A service you launch now will still be running when it does. Put a birth year or an "I am 16 or older" check on the signup screen, before the email field. If someone is under the age, stop the signup or move them to a parental consent flow. Say plainly in your terms and privacy policy that the service is not for children. If you have US users, COPPA applies to children under 13 as well.

7. Put the privacy policy and terms inside the app too

Apple's App Review Guidelines require a privacy policy link in both App Store Connect and the app itself. Google Play asks for the same. The policy covers what you collect, who you share it with (including analytics and ad SDKs) and how users can ask for deletion.

On iOS, if you combine data from your app with data from other companies' apps or websites for advertising, you need App Tracking Transparency permission first, and you cannot make features depend on a yes. Many ad measurement SDKs track by default, so check their settings before you submit for review.

Half a day before launch

Put side by side, every item is small: six lines on a confirmation screen, a consent line on a form, an email footer, a list of outside connections, a folder of fonts, a script switched off, an age question and two links. Half a day to a day of work.

Users almost never notice any of it. The moment they notice is after something has gone wrong, and doing this before launch means that moment never comes.

Sources

  1. Consumer Affairs Agency, Guidelines on displays at the application stage of mail order sales (Act on Specified Commercial Transactions, Article 12-6, final confirmation screen)
  2. MIC and Consumer Affairs Agency, Guidelines on sending specified electronic mail
  3. MIC, External transmission rules FAQ (Telecommunications Business Act, in force since 2023-06-16)
  4. Personal Information Protection Commission, Q&A 1-62 (age at which a legal representative's consent is needed)
  5. Personal Information Protection Commission, 2026 amendment to the APPI (promulgated 2026-07-17)
  6. Google, Email sender guidelines FAQ (senders of 5,000+ messages a day, one click unsubscribe)
  7. Apple, App Review Guidelines 5.1.1 and 5.1.2 (privacy policy and App Tracking Transparency)

Recognize the problem

Brand, video, websites and ads, made and run by one team. Tell us where things stand.

Get in touch