External Transmission Rules and Cookie Compliance: Covered Services, Matters to Publish, and When Consent Is Required
Hello, I'm Noriaki Asato, Representative Attorney at LegalAgent.
Installing a cookie banner on a website does not guarantee that its settings match the analytics tags that are actually running. Only once you know what is sent right after a page opens, and what changes when the opt-out button is pressed, can you evaluate what your compliance actually amounts to.
However, the external transmission rules under the Telecommunications Business Act do not apply to every site that uses analytics tags. The first issue is whether your service is covered by the rules. If it is, you check which transmissions of information require notice, publication or the like, and then consider whether confirmation of consent under the Act on the Protection of Personal Information (APPI) is separately required.
The Difference Between a Site Selling Your Own Products and an Online Mall
The external transmission rules are set out in Article 27-12 of the Telecommunications Business Act (Japanese), which took effect on June 16, 2023. They apply to telecommunications carriers, and to persons engaged in the business described in Article 164, paragraph 1, item 3 of the same Act, who provide telecommunications services specified by Ministry of Internal Affairs and Communications ordinance. The fact that a business has not registered or filed a notification is not enough on its own to conclude that it is outside the rules.
Article 22-2-27 of the Ordinance for Enforcement of the same Act (Japanese) divides services provided through browsers and applications into four categories: intermediating messages between users; SNS, video-sharing services, online malls and the like; online search; and online provision of various kinds of information such as news and maps. Even a news site with few users is covered if the nature of the service falls within these categories.
By contrast, Questions 1-12 and 1-13 of the Ministry of Internal Affairs and Communications "External Transmission Rules FAQ" (Japanese) explain that a retailer selling products on its own website is merely using telecommunications to carry out its core business and is not subject to the external transmission rules. The same applies even if the retailer has no physical store and sells only online.
On the other hand, an online mall where users can buy products from multiple stores or sellers is covered, as a service that provides a venue for transactions for others. Question 1-14 of the same FAQ states that this is the case even where the sellers are limited to group companies. The conclusion changes depending on whether the site sells products itself or provides a venue for other businesses to sell.
Even within the same company's sites, the treatment can differ depending on the role of the page. Pages introducing a service are treated as being for the company's own needs and outside the rules, whereas user support pages and user portals are covered if the underlying service they accompany is covered (Question 1-18 of the same FAQ). If a company decides uniformly, company-wide, that it is or is not covered, this distinction may be lost.
Information Included in External Transmission and Matters to Publish
Article 27-12 covers communications that activate a function sending user information recorded on the user's device to equipment of someone other than that user. A typical example is a browser that has loaded an analytics or advertising tag sending identifiers, browsing history and the like to a server. Even mechanisms that do not use cookies are covered if the communication meets the statutory requirements.
"External" does not mean only outside the site operator's company. Because the user's device is the reference point, the destinations include the site operator's own servers (Question 1-16 of the same FAQ). Transmissions to your own servers cannot be uniformly treated as needing no consideration. Whether they fall within the exception for necessary information described below is judged according to the content and purpose of the transmission.
The default response is to notify users of specified matters in advance or to put those matters in a state where users can easily learn of them. Article 22-2-29 of the Ordinance for Enforcement requires the following matters to be shown for each information transmission instruction communication.
- The content of the user information to be transmitted
- The name of the person who handles the information at the destination equipment
- The purpose of use of the information
As a rule, the purpose of use is stated for both the destination and the business that made the information transmission instruction communication. However, the stage at which the destination later provides the information it has obtained to the site operator or another party is treated separately from the external transmission rules (Questions 4-3 and 4-4 of the same FAQ). It is necessary to understand the transmission from the device and the subsequent provision as distinct.
There are also requirements on how the information is displayed. Under Article 22-2-28 of the Ordinance for Enforcement, it must be in Japanese, use plain language avoiding technical terms, be in an appropriate font size, and be easy for users to check. When publishing on a website, the information is posted on the page that makes the information transmission instruction communication or on a page easily reachable from it. Merely placing a link deep inside the privacy policy does not necessarily satisfy the ease-of-access requirement.
Consent, Opt-Out, and the Exception for Necessary Information
The external transmission rules are not a system that uniformly requires prior consent for every transmission. In addition to notice or publication under the main clause of Article 27-12, exceptions are provided in the proviso to the same Article.
Item 1 covers information whose transmission is necessary for displaying the screen and the like. Article 22-2-30 of the Ordinance for Enforcement lists information truly necessary for providing the service, information necessary for redisplaying input or authentication information, information necessary for detecting fraudulent activity and the like, and information necessary for reducing the load on equipment and the like. In each case, the condition is that transmission is within the necessary scope. The fact that a business wants to use the information to earn advertising revenue does not on its own make it information necessary for the user.
Item 2 covers cases where an identifier that the company sent to the user's device when providing the service is sent back to the company's own equipment. Even a cookie identifier issued by the company itself does not meet the conditions of this item if it is sent to another business. Browsing history and other data sent together with the identifier are not automatically included in this exception.
Item 3 covers information for which the user has consented to transmission to the destination. When relying on consent, the issue is whether the settings that suppress transmission before consent and the settings that limit transmission to the scope explained on the consent screen actually correspond. Even if there is an "I agree" button, if the same information is being sent before it is pressed, this does not amount to compliance based on prior consent.
Item 4 is the provision for cases where the business has an opt-out measure that stops transmission or use at the user's request and has put specified matters in a state where users can easily learn of them. The business states clearly whether the measure stops transmission or stops use. Article 22-2-31 of the Ordinance for Enforcement also requires display of how requests are accepted, any restrictions on use of the service if a user requests a stop, and the content of the information, the businesses handling it, the purposes of use and the like. For users who have requested a stop, the business must make the displayed measure actually work.
Relationship with Provision of Personal-Related Information to Third Parties
A separate consideration is Article 31 of the Act on the Protection of Personal Information (Japanese). When a business handling personal-related information provides personal-related information that is expected to be acquired by the recipient as personal data, there is a rule requiring it to confirm in advance, except in statutory exceptions, that the individual's consent to that acquisition has been obtained, and so on. The rule covers information that forms part of a personal-related information database or the like.
Question 8-1 of the Personal Information Protection Commission's FAQ (Japanese) explains that where a device identifier such as a cookie does not constitute personal information, it usually constitutes personal-related information. Where it can easily be collated with other information to identify a specific individual, the information as a whole constitutes personal information, and the applicable rules also change.
Being able to comply with the external transmission rules through notice or publication and not needing to address consent under the APPI are separate issues. For example, where the recipient links cookie identifiers with member information and acquires them as personal data, consideration of Article 31 may be required. Whether the site operator is providing the information or the destination is acquiring it directly from the user should also be checked based on the actual flow of information, not just on the labels used in the contract.
Matching the List of Tags with the Published Page
For covered services, collect from developers and marketing staff a list of analytics, advertising and external integration tags and SDKs. In addition to the list of tools under contract, examining the actual communications of browsers and apps lets you identify destinations called up by other tags and tags that remain even though you thought they had been removed.
In the list, record the page where each tag is installed, the information sent, the destination business, and the purposes of use on both sides. Then separate transmissions that fall within the exceptions for necessary information and the like from transmissions handled through notice or publication, consent, or opt-out. The draft of the published page is prepared based on this list, which reflects the communications actually observed. Simply copying a vendor's general description may conflict with the features and settings you have actually enabled.
With a consent approach, test what is sent when nothing has been selected and whether the relevant tags stop when the user refuses. With an opt-out approach, in addition to checking whether the button or link is easy for users to find, compare whether what is stopped is transmission or use against what is displayed. If the method stops use but the display says "We will not send information," the description does not match the actual behavior.
When tags are added, reconfigured or removed, the list and the published content are updated accordingly. One approach is to include fields for the destination and the information sent in the request form for introducing a new advertising tool, and have the developer and the legal team cross-check them before release. Updating an existing privacy policy is also related to Reviewing Terms and Policies to Match Business Changes.
A cookie banner is one means of presenting the results of these checks to users. I think that aligning the determination of covered services, the published content, and the behavior of the stop function is what leads to compliance that can be maintained over time.