September 22, 2026. Cold email to Japan is legal, and it is opt-in. Japan switched from an opt-out regime to an opt-in regime in 2008, so the default is that you may not send advertising email to a Japanese recipient without consent. The reason outbound teams still run Japan sequences is a fourth exception written into the statute itself: an organization, or an individual engaged in business, who has disclosed their own email address. That carve-out is what makes B2B prospecting into Japan workable, and it is narrower than most sales teams assume.
The governing statute is the Act on Regulation of Transmission of Specified Electronic Mail, Act No. 26 of 17 April 2002, amended by Act No. 54 of 6 June 2008. It is enforced jointly by the Ministry of Internal Affairs and Communications and the Consumer Affairs Agency, not by the Personal Information Protection Commission, which administers the separate privacy statute. Article 31 of the Act delegates the Prime Minister's powers to the Secretary-General of the Consumer Affairs Agency.
What the Act actually requires
- Prior consent, with four exceptions. Article 3 paragraph 1 says a sender shall not transmit specified electronic mail to persons other than four categories: someone who requested or consented to it in advance; someone who gave the sender their own email address in the manner set by ordinance; someone who has a business relationship with the party whose goods are advertised; and an organization, or a person engaged in business, who has disclosed their own email address in the manner set by ordinance.
- You must keep the proof. Article 3 paragraph 2 requires the sender to maintain a record of the request or consent, in the form set by ordinance. The obligation is on you to produce it, not on the regulator to disprove it.
- Opt-out overrides everything. Article 3 paragraph 3 bars sending to anyone who has notified you that they do not want it, including people who fall inside the four permitted categories.
- Every message carries an identity block. Article 4 requires the message to display the sender's personal or legal name and address, plus the email address or facility identifier that receives opt-out notifications. A name with no postal address does not satisfy it.
- No spoofing, no generated lists. Article 5 prohibits falsifying sender information, and Article 6 prohibits sending to fictitious addresses generated by software or not in use by anyone.
- Foreign senders are inside the scope. Article 2 item 2 defines specified electronic mail to include transmissions to telecommunications facilities located in Japan, not only transmissions from them. An agency sending from Dubai, London or Toronto into a Tokyo inbox is covered.
The trap in the official English translation
Anyone checking Japanese law in English usually lands on the government's own Japanese Law Translation database. Its page for this Act is headed Act No. 26 of 2002 with the note Last Version: Act No. 87 of 2005. That version predates the 2008 amendment. Reading it today, the word consent appears exactly once, inside a definition, and the phrase opt-in appears zero times. Its Article 3 is a labelling duty and its Article 4 is the old opt-out rule that a sender must stop only after a recipient objects.
In other words, the official English text describes a regime Japan abandoned eighteen years ago. The current English text of the Act, final revision 2009, is published by the Japan Data Communications Association, the body registered under Chapter III of the Act, alongside the joint MIC and Consumer Affairs Agency Guidelines Concerning the Transmission, Etc. of Specified Electronic Mail of August 2011. Those Guidelines carry a dedicated section on Article 3 paragraph 1 item 4, the disclosure of one's own electronic mail address, and that is the section a Japan sequence should be built against.
The B2B exception, and where it stops
Item 4 is the provision that makes lawful Japanese cold email possible, and it has three limits worth stating plainly. It covers organizations and individuals who are engaged in business, so a personal address on a hobby site is not in scope. It requires the address to have been disclosed, in the manner the ordinance sets, which points at an address the business itself published rather than one a scraper assembled from a pattern. And it does not survive Article 3 paragraph 3: the moment a recipient asks you to stop, the published address stops being a permission.
The practical consequence for a list build is that a Japan segment should be sourced from addresses the target company published itself, with the source URL and capture date stored next to the address. If you cannot evidence where the address came from, you cannot rely on item 4, and you have no record for Article 3 paragraph 2 either. This is the same discipline that keeps a sending domain healthy, so it costs you nothing you were not already paying for in cold email infrastructure.
What the penalties actually attach to
The figure quoted everywhere is thirty million yen, and it is real, but it does not attach to the thing most people think. Article 34 punishes a violation of Article 5, false sender information, or the breach of an administrative order made under Article 7, with up to one year of imprisonment with labour or a fine up to one million yen. Article 37 item 1 then makes a juridical person liable for a fine up to thirty million yen where its representative, agent or employee commits an Article 34 offence in the course of business. Article 35 carries a one million yen fine and Article 36 three hundred thousand yen.
Sending without consent under Article 3 is not itself on that list. The path runs through Article 7: the Minister issues an order to improve your sending, and ignoring that order is what becomes the criminal offence with the corporate fine behind it. Two other provisions matter to a foreign sender. Article 29 lets the Minister demand from telecommunications carriers the name and address of whoever holds a given address or facility identifier, and Article 30 lets the Minister hand information to foreign enforcement authorities. Distance is not the defence it looks like.
Your client can be ordered too
Article 7 reaches past the sender. Where a consignor of transmission, the party that commissioned the sending, took the consent notification, kept the records and performed part of the work, and the transmission is attributable to them, the order can name both the sender and the consignor. For an agency this cuts both ways. If you hold the consent records for a client campaign, you are inside the frame. If your client holds them and will not show you, you are sending blind on their exposure and your own.
APPI sits on top, not instead
The Act on the Protection of Personal Information is a separate statute with a separate regulator, the Personal Information Protection Commission, and the amended version took effect on 1 April 2022. It governs how you acquire, hold and transfer the personal data in your list, including transfers out of Japan. The anti-spam Act governs whether you may press send. Clearing one does not clear the other, and a Japan sequence that satisfies Article 3 item 4 can still fail on the data handling behind it.
What it means for operators
Japan is one of the better opt-in markets for B2B outbound precisely because the legislature wrote a business carve-out into the consent rule instead of leaving it to guidance. It is also a market where the cheap shortcuts are exactly the criminal ones. Pattern-generated addresses hit Article 6. A cleaned-up From header hits Article 5. Those are the two provisions with imprisonment and the thirty million yen corporate fine attached, and they are the two that scraped-and-sprayed sequences break first.
If you run outbound into Asia Pacific, treat Japan and South Korea as opposites rather than a block. Japan gives you a published-address route. South Korea gives you none, and the same list will be lawful in one and unlawful in the other. Our opt-in versus opt-out map sets both against the wider picture.
How to run a compliant Japan sequence
Five things, in order. Segment Japan out of your global list so the rules apply cleanly. Source Japanese addresses only from pages the target business published, and store the URL and date with each record so Article 3 paragraph 2 is satisfied by the same field. Put the legal entity name and a real postal address in the footer of every send, next to an opt-out address that a human monitors. Suppress on the first request, permanently and across every campaign. And agree in writing with your client who holds the consent record, because Article 7 can name them as well as you.
Done that way, a Japan segment behaves like any other well-run cold email programme, with one extra field in the database and one extra line in the footer. Done the other way, it is the segment that attracts an order you cannot ignore. If you are building the sending estate and the record keeping from scratch, that is the work our lead generation team scopes before a single message is queued.
Frequently Asked Questions
Yes, within limits. Japan runs an opt-in regime under the Act on Regulation of Transmission of Specified Electronic Mail, but Article 3 paragraph 1 item 4 permits sending to an organization, or an individual engaged in business, that has disclosed its own email address. B2B cold email to a published business address is therefore lawful, provided you also meet the labelling, record keeping and opt-out duties.
In 2008. The Act was amended by Act No. 54 of 6 June 2008 and the opt-in regime took effect from 1 December 2008. The Ministry of Internal Affairs and Communications describes the change in its own overview as the opt-out regulation being amended to the opt-in regulation in 2008.
Yes. Article 2 item 2 defines specified electronic mail to cover transmissions to telecommunications facilities located in Japan, not only transmissions sent from them. Article 30 also allows the Minister to provide information to foreign enforcement authorities, so a sender based abroad is inside both the scope and the enforcement route.
Article 34 carries up to one year of imprisonment with labour or a fine up to one million yen for false sender information or for ignoring an administrative order made under Article 7. Article 37 item 1 then allows a fine up to thirty million yen against the company itself for an Article 34 offence committed in the course of its business.
Article 3 paragraph 2 requires a sender who relies on a request or consent to maintain a record proving it, in the form set by ordinance. In practice that means storing, for each Japanese contact, the basis you are relying on, the source, and the date it was captured, so the record can be produced on request.
The Ministry of Internal Affairs and Communications and the Consumer Affairs Agency enforce the anti-spam Act jointly, with Article 31 delegating the Prime Minister's powers to the Secretary-General of the Consumer Affairs Agency. The Personal Information Protection Commission is a different regulator and administers the separate privacy statute covering how you handle the data.