Summary

  • Japan’s communications ministry issued written administrative guidance to LY Corporation on 31 July 2026.
  • Treenod Inc., a partner operating LINE game applications, sent MID identifiers and other specified user information to an external analytics service.
  • The ministry says the transmissions lacked LY Corporation’s approval and user notice or an equivalent confirmation opportunity.
  • The reported period ran from 25 May 2022 to 3 April 2026.
  • The regulator counted about 8.03 million records, of which about 7.52 million related to users in Japan.
  • The public notice establishes neither a data sale nor exposure of credentials, message contents or payment information.

A partner action remained LY Corporation’s governance problem

The ministry says Treenod acted independently, but it did not treat that fact as removing LY Corporation’s responsibility. LY Corporation is a designated telecommunications operator under Article 27-5 and must ensure appropriate handling of specified user information.

That is the important control boundary. Outsourcing application development or advertising analytics can transfer execution, but it does not transfer the operator’s statutory duty. The operator must know which code sends which information to which destination.

A defensible partner model therefore requires an inventory of software development kits, approved endpoints, contractual restrictions and technical verification. A policy document cannot detect an unapproved network call by itself.

The record count is not a disclosed number of people

The ministry reports approximately 8.03 million records, including 7.52 million associated with users in Japan. It does not say that each record represents a unique individual. One device or user may generate more than one record.

Nor does the notice enumerate every field covered by “MID and other specified user information”. MID is an identifier, but the public evidence does not support adding passwords, private messages or payment data to the list.

Keeping those distinctions matters. Inflating a record count into a population count, or turning an identifier transmission into an account breach, would create facts the regulator did not publish.

Article 27-12 makes the interface part of compliance

Japan’s external-transmission rule requires an opportunity for users to confirm what information is sent, why it is sent and where it goes. The ministry found that the LINE game path did not meet that standard.

Compliance therefore cannot end in a privacy policy stored elsewhere. It must be represented in the application experience and remain aligned with the actual destination and purpose of the network request.

When a partner adds or changes an analytics library, the notice layer and the technical allow-list should change together. Otherwise the interface describes one system while the application runs another.

Nearly four years points to detection failure

The reported transmission period begins on 25 May 2022 and ends on 3 April 2026. A path lasting that long raises questions beyond the initial approval error: inventory, code review, outbound monitoring and periodic reassessment all failed to surface it quickly.

The public notice does not say how the activity was discovered or how frequently records were sent. It also does not establish intentional misuse by the analytics provider.

What it does show is that partner governance must be continuous. A one-time security review before launch cannot cover later code, library and endpoint changes.

Written guidance is not a monetary penalty

The ministry issued written administrative guidance, demanded proper handling, required recurrence-prevention measures and asked LY Corporation to report their implementation. The public page does not announce a fine.

That distinction does not make the measure symbolic. Written guidance creates a record against which future conduct and remediation can be assessed. It also identifies the two legal dimensions: appropriate management under Article 27-5 and external-transmission compliance under Article 27-12.

Readers should nevertheless avoid upgrading the measure into a sanction the ministry did not impose. The operative question is whether LY Corporation can demonstrate a changed control system.

Evidence of repair must come from the data path

A credible response would reconcile every LINE game, software development kit, identifier, purpose and destination. It would show that unapproved endpoints are technically blocked, notices match actual transmissions and changes trigger a new review.

It should also define how LY Corporation tests partners rather than relying only on written assurances. Logs, allow-list exceptions, deployment approvals and independent sampling would provide stronger evidence than a restated policy.

The ministry’s notice establishes a governance failure with a precise duration and scale. Completion will require proof that the operator can see and control external transmissions before users generate another record.

Sources