Tailored primarily for counsel and advisors outside Japan, this article outlines key legal issues unique to UGC (user-generated content) platform business, mainly focusing on Japan-specific regulatory matters. It specifically examines a scenario where a foreign strategic buyer directly acquires controlling shares of a privately held Japanese company (“Target”).
The 2020 amendments to the FEFTA (Foreign Exchange and Foreign Trade Act) broadened the scope of “designated business sectors” in the software and information processing fields. Since then, where the applicability of the regime is not entirely clear, prior (occasionally precautionary) notifications to BOJ (Bank of Japan) have increasingly been filed in practice for transactions involving digital businesses including UGC platforms. [FN1] Where prior notification is required, it triggers a standard 30-day waiting period, which may be shortened or extended by the authorities.
Platforms for sharing videos or computer games often enable users to sell their self-made products through online marketplace transactions. Depending on its payment structure, the platform’s collection and transfer of funds between its users may be subject to the Payment Services Act or banking regulations, where a platform company is required to be registered or licensed with FSA (Financial Services Agency). The amendment to the Payment Services Act that came into effect in June 2026 expanded the scope of money transfer regulation for certain cross-border “collection agency services”, where either a payer (e.g. purchaser of content in UGC platform) or a recipient (e.g. creator of content) is located outside Japan.
In order for the Target’s services to be exempted from the regulations of “funds transfer transaction”, the Target should be “indispensably involved in the formation of the contracts” between platform users. Mere processing of payments between users, advertising of goods or matching of customers is insufficient; the Target must actively facilitate contract formation, such as by defining in ToS when sales contracts are formed or specifying eligible goods in the marketplace, and delivering funds to the recipients with their consent in accordance with such contracts. [FN2][FN3]
Separately, where a platform issues paid virtual points or in-app currency whose value is fixed to a statutory currency (e.g. purchasable at one point per one yen) [FN4] even if usable only within the platform, it may trigger the regulations on “prepaid payment instrument”. If (1) the virtual paid points are not limited to use within 6 months and if (2) the “unused balance” exceeds JPY 10,000,000 at the end of March and September every year, notification to a Regional Finance Bureau will be necessary.
Where a service offers private messaging between users [FN5], it will often be regarded as “intermediating other persons’ communications” and therefore require a notification under the Telecommunications Business Act. In addition, many UGC services transmit online identifiers to third parties for purposes such as behavioral advertising and web traffic analytics, which are subject to the “external transmission” rules under the Act and usually need to be disclosed in a cookie policy. In designing and operating such a service, care must also be taken to comply with the statutory secrecy of communications.
Japan's privacy regime differs in several aspects from the data protection laws in some major jurisdictions. For example, Japanese APPI (Act on Protection of Personal Information) requires public disclosure when certain “anonymized” information is created from personal information or provided to third parties. In addition, cookies and other online identifiers are not categorized as personal information itself, as long as they are not associated with a specific person (even if they are associated with a specific device such as smartphones or laptops), but online tracking activities are still regulated through APPI and Japan's Telecommunications Business Act (See above (c)).
When the Target transfers personal data to a third party in a foreign country, it should satisfy any of: informed cross-border transfer consent from the data subject; transfer only to EEA or UK; or appropriate measures including execution of a data processing agreement and data protection system. [FN6]
Depending on the nature and scale of the Target’s business, several other regulatory frameworks may also apply:
In addition to the above regulatory matters, following issues must be examined when assessing the Target’s business model:
Legal due diligence should also verify business continuity, ensuring that the Target can seamlessly continue operating its platform after closing. This includes confirming ownership or valid licenses for the platform software, reviewing software development agreements with external vendors, if any, and identifying any change-of-control restrictions affecting software licenses. [FN10]
Buyers should also ensure that there is no infringement of third parties’ IP rights, such as unauthorized inclusion of third parties’ code, or violation of open-source software licensing policies.
The potential need for a FEFTA prior notification should be identified at an early stage, as the filing and applicable waiting period may affect the transaction timetable and should be appropriately reflected in the closing conditions. Other deficiencies identified through due diligence, such as a missing notification under the Telecommunications Business Act or insufficient ownership of software developed by external vendors, may also warrant pre-closing remediation or specific closing conditions.
While fundamental corporate matters—such as the Target’s ownership structure and shareholder rights—remain standard priorities, buyers must equally focus on these UGC-specific risks. By conducting focused due diligence on these UGC-specific issues from an early stage, M&A buyers can efficiently address operational risks and streamline SPA negotiations for smoother execution.
[FN1] The FEFTA was amended again in June 2026 and is expected to come into force by June 2027. It introduces a regulation on certain indirect investments, ex-post intervention mechanisms and risk mitigation measures. The amendment does not materially affect the analysis above. Even if prior notification is not required, a post-investment report to BOJ will be necessary in many cases.
[FN2] Art.2-2, Item 2, Payment Services Act; Art. 1-3, Para 2, Item 3, Funds Transfer Ordinance; I-2-2-2(3), Funds Transfer Administrative Guidelines
[FN3] Furthermore, if the recipients include individuals who are not engaged in business, which many UGC platforms satisfy, the Target must ensure additional requirements in its ToS and in the actual transaction scheme, such as prevention of duplicate payments to the platform and recipient, and conditional payout structure upon fulfillment of counter-performance. (Article 2-2, Item 1, Payment Services Act; Article 1-2, Items 1 through 3, Funds Transfer Ordinance)
[FN4] If the value of the in-app currency is not fixed to a statutory currency, regulations on crypto assets may be raised as an issue.
[FN5] Open chat services may also become subject to the notification requirement if they have monthly active users of 10 million or more and are designated by MIC (Ministry of Internal Affairs and Communications). As of August 2026, the following giant platforms have been designated: Google LLC, LY Corporation (LINE Yahoo), Meta Platforms, Inc., TikTok Pte. Ltd. and X Corp.
[FN6] Art.28, Para.1, APPI
[FN7] “Act on the Protection of Consumers Who Use Digital Platforms for Shopping”
[FN8] As of August 2026, the following platforms are designated by METI for regulations under the “Act on Improving Transparency and Fairness of Digital Platforms”: Amazon Japan G.K., Rakuten Group, Inc., LY Corporation (LINE Yahoo), eBay Japan G.K., Google LLC, Meta Platforms, Inc., TikTok Pte. Ltd. Likewise, the following platforms are designated by JFTC for regulations under the “Mobile Software Competition Act” (officially known as the “Act on Promotion of Competition for Specified Smartphone Software”) (Newly implemented in December 2025): Apple Inc., iTunes K.K., Google LLC.
[FN9] In addition to the contractual risk of cancellation, the APPI amendment, which was enacted in July 2026 and will take effect no later than July 2028, will require parental involvement such as notification or consent for processing the personal information of children under 16.
[FN10] Even where the Target explains that its software was developed in-house, it is necessary to verify who actually performed the development work. The requirements of the Target’s copyright to the software as a “work made for hire” differ depending on whether the software was developed by its employee engineers or by freelance engineers engaged as independent contractors.
------------------------------------
SPARKLE LEGAL
This document provides general information only and does not constitute formal legal advice for specific situations. For legal counsel regarding specific matters, please contact our firm directly.