Features

Power your results with AI, data, and teamwork. All you need for web operations in one platform

User Support

Your go-to support page for troubleshooting and getting the most out of MONJI+

Blog
Jul 31, 2026
WebOps

External transmission rules in Japan: where to start, and how to separate consent from notice

“Does this apply to our site too?”

A WebOps manager using MONJI+ told us this comes up more and more, usually right after they ask to add an analytics or ad tag.

What struck us first was how consistently people stall in the same place.
It gets tangled with the cookie banner question, then with whether consent is enough, or whether writing it in the privacy policy is enough, and it ends at “wait, who put this tag in, and what for?” We’re in no position to be smug about it. Tags our past selves installed leave our future selves squinting at the screen. WebOps is full of these small time capsules.

This article lays out Japan’s external transmission rules as a working order for WebOps managers, not as a legal breakdown. If you run or maintain a site for users in Japan, this one is yours to deal with.

The external transmission rules ask you to tell users in advance what information leaves their device, where it goes, and what it will be used for. They sit in Article 27-12 of Japan’s Telecommunications Business Act and took effect on June 16, 2023. The way in isn’t reading the statute. It’s building a list of the tags actually running on your site.

  • Coverage isn’t decided by having a website. It’s decided by whether the service you provide falls into one of the covered categories.

  • What’s required is notifying users of, or publishing, the information sent, the name of the recipient, and the purpose.

  • Consent and notice are two different obligations. Mix them and your response drifts.

Why this work stalls halfway through

Let’s name the wall first.

Work doesn’t stall because the statute is hard.
It stalls because you go looking for the right wording and get sent back a step: nobody knows which tags are on the site in the first place.

Tags accumulate a little at a time, every time the person in charge changes. Something added for a campaign. Something added to test attribution. Something an agency asked for. If the reason isn’t written down, you can’t even decide whether it’s safe to remove.

Then there’s the cookie banner crossover. Collecting consent and giving notice come from different sources. Treat them as one task and, when staff turn over, nobody remembers what the banner was there for.
So the gap isn’t understanding the rule. It’s not having a working habit around it.

What information the rules actually cover

Before the steps, the scope.

The external transmission rules sit in Article 27-12 of Japan’s Telecommunications Business Act and took effect on June 16, 2023. When a tag on your site or a module in your app sends information about a user from that user’s device to an outside party, the rules ask you to say so in advance.

The information in scope isn’t limited to cookies. Browsing history, IP addresses, anything that helps identify a device: if it leaves the user’s device, it’s in the conversation.

This is the first place people trip. Read it as a cookie story and you’ll misjudge the scope.
Adding one tag is treated as an act of sending information outward. Once that swap clicks, the rest of the decisions get faster.

Source: Japan’s Ministry of Internal Affairs and Communications, external transmission rules (laws, guidelines, and overview) https://www.soumu.go.jp/main_sosiki/joho_tsusin/d_syohi/gaibusoushin_kiritsu_00001.html

Five steps to work through it

On our own projects, we work in this order.

STEP 1: Settle coverage with three questions

The starting point isn’t whether you have a website. It’s whether the service the business provides counts as a telecommunications service with a significant effect on users’ interests.

The ministry’s FAQ lists categories like these:

  • Messaging between users

  • Social networks and email

  • Online shopping

  • Online games

  • News distribution

Then run these three in order.

  1. Does your site or app provide a service that falls into one of those categories?

  2. If it does, are you using tags or modules that send information from the user’s device to an outside party?

  3. If you are, can a user currently find out what information is sent, who receives it, and why?

If all three land, you need to notify or publish. If the first one doesn’t land, this particular obligation doesn’t arise, though your duty to explain how you handle personal data is a separate matter and stays. When it’s a close call, don’t decide it on instinct. Check the ministry’s FAQ.

Source: Japan’s Ministry of Internal Affairs and Communications, external transmission rules FAQ https://www.soumu.go.jp/main_sosiki/joho_tsusin/d_syohi/gaibusoushin_kiritsu_00002.html

STEP 2: Pull consent and notice apart

What the external transmission rules ask for is notice or publication. They don’t uniformly require you to collect consent.

Consent flows usually come from somewhere else: European privacy law, or the requirements each ad platform sets for its own customers. Different basis, different obligation. So “we put up a banner, so we’re done” doesn’t hold. Neither does “no banner, so we’re non-compliant.”

When the basis is different, record the reason separately. Keep the decision to show a banner and the decision to publish a notice as two entries, not one.

STEP 3: Inventory the tags on the site

This is where the work actually starts. List every tag on the site, broken out by page type. Something unexpected usually turns up.

Go one by one and confirm the recipient and the purpose. For the ones nobody can explain, start by tracing why they were added. Then decide what stays and what goes. Removing unused tags is faster than describing them.

STEP 4: Line up what to write and where to put it

Three things have to be knowable:

  • What information is sent

  • The name of the company receiving it

  • What that information is used for

For placement, the condition is that users can reach it easily. Folding it into the privacy policy works. So does a standalone page about external transmission. Either way, it needs to be reachable from somewhere like the footer.

You don’t have to list everything, either. The ministry’s FAQ sets out categories that fall outside, including:

  • Information the user asked to have sent

  • Information needed for authentication

  • Information genuinely necessary to provide the service

  • Information the business uses only for itself

Keeping someone logged in, or holding the contents of a cart, isn’t something you need to write out item by item.

STEP 5: Record the reasoning and add it to the pre-launch checks

The last step is the one that gets skipped. Record what you decided and why, somewhere the whole team can see it. Then add that decision to the checklist you use whenever a new tag goes in.

Skip it and you’ll run the same investigation again in six months, when everyone’s memory has gone fuzzy. You dig through Slack, search old email, and end up saying “I think we probably needed it,” then make the same call again. At that point it isn’t research. It’s an excavation.

MONJI+ is a WebOps platform that keeps your operating decisions and your review history in one place. Policies and the reasoning behind them live in the Wiki, and the things to check before adding a tag sit in a checklist. When something breaks after launch, you can hand it off as a feedback request with an assignee and a due date attached.

What changed once we fixed the order

None of this is flashy. Still, fixing the order changed a few things.

  • We stopped opening with the statute and started with the tag inventory instead.

  • Unused tags surfaced during the inventory, which shrank the list of things we had to describe at all.

  • “Why is this banner here?” became answerable from the record, even after the person in charge changed.

  • The decision now sits in the checklist for adding a tag, so we pause once before adding another one.

What went down isn’t the amount of work. It’s the time spent running the same investigation twice.

The limits: analytics and ad tags are the hard calls

So you don’t expect too much, here’s where it stops.

What you can turn into a procedure is the inventory and the record. Judging whether an individual tag is in scope can’t be automated. Analytics and ad tags are the worst of it, because it’s not obvious whether the data stays with you or goes to someone else. Read the vendor’s documentation and decide based on who the data actually reaches.

This article isn’t legal advice either. Read it as an order of operations. If you’re unsure whether your service is covered, or whether your wording holds up, check the ministry’s FAQ and bring in a specialist where it matters.

FAQ

Q. Is a corporate website covered by the external transmission rules?
A. Coverage depends on the service you provide, not the type of site. The test is whether it counts as a telecommunications service with a significant effect on users’ interests. A site that’s mostly company information and job listings may not fall into the listed categories, but don’t decide alone. Check your own service against the ministry’s FAQ.

Q. If we don’t use cookies, are we in the clear?
A. Cookies aren’t the boundary. Browsing history, IP addresses, and anything that helps identify a device are all in scope when they leave the user’s device. If you have tags or SDKs installed, you need to check what they send.

Q. Does showing a consent button mean we’ve handled it?
A. The external transmission rules ask for notice or publication, not consent across the board. Consent flows usually come from a different legal or contractual basis, so record what each mechanism is there for. That way the reasoning survives a change of staff.

Q. What exactly do we have to write?
A. Three items: what information is sent, the name of the company receiving it, and what it’s used for. The placement condition is that users can reach it easily, so make sure it’s linked from somewhere like the footer.

Q. Where should we start?
A. With a list of the tags on your site. Knowing how many tags are actually in scope will speed up every decision after that, more than researching the wording first.

Wrap-up

  • The external transmission rules sit in Article 27-12 of Japan’s Telecommunications Business Act and took effect on June 16, 2023.

  • The information in scope isn’t limited to cookies. Browsing history, IP addresses, and anything else leaving the user’s device is included.

  • Coverage depends on whether the service you provide counts as a telecommunications service with a significant effect on users’ interests, not on the type of site.

  • What’s required is notifying users of, or publishing somewhere they can easily reach, the information sent, the name of the recipient, and the purpose.

  • Information the user asked to have sent, information needed for authentication, information genuinely necessary to provide the service, and information the business uses only for itself are set out as falling outside the rules.

  • As a procedure: settle coverage, separate consent from notice, inventory the tags, decide what to publish and where, then record the reasoning and add it to your checks.

Every new tag brings a new judgment call, so leave the reasoning somewhere the next person can read it.

MONJI+, a Collaborative AI WebOps Platform

MONJI+ grew out of the problems we kept running into on real sites.
We never aimed to ship something finished from day one. We built it piece by piece, alongside the people doing the work.

▼About MONJI+
https://monji.tech/plus/

▼Start free
A 30-day trial gives you every feature. There is also a Free plan that stays free.
https://monji.tech/plus/trial/

▼Sign up and start using it
https://tool.monji.tech/signup



check the list.