International Practice

Integrating a Japanese Business After M&A: Technology, Data and Export Controls

Being permitted to acquire a Japanese company does not mean that every part of its business can immediately be integrated into the buyer’s global group. Access to technology, personal data, personnel and systems can raise separate questions of Japanese law both before and after closing.

Source code, research and development materials, manufacturing know-how, employee and customer data, security logs and access to certain systems may be subject to export control, data protection or economic security requirements. Reporting lines, overseas engineering support, shared repositories, common cloud environments and group-wide cybersecurity monitoring can therefore require separate analysis even where the acquisition itself has been completed.

This guide deals with integrating technology, data, personnel and systems following a foreign acquisition of a Japanese business. For transaction structure, foreign investment screening, merger control, due diligence, employment and the transaction documents, please see “M&A in Japan for Foreign Acquirers and Investors”.

Our lawyers' backgrounds include cross-border M&A, in-house advice on security-related export controls and inward investment regulation, and work on personal data, IT and related regulatory questions.

Before You Contact Us

The following helps us give a useful first answer. Nothing needs to be settled, and an enquiry at an early stage is welcome.

  1. The target and its business — please describe the target’s products, services, research and development activities, software and any technology or operations that may involve sensitive or controlled information.
  2. The acquisition and its regulatory status — please share the transaction structure, the signing and closing status, and any foreign investment filing, exemption analysis or other regulatory position already identified for the acquisition.
  3. Technology to be shared — please identify the source code, designs, specifications, manufacturing know-how, research data or other technical information that the overseas group expects to access after closing.
  4. Who needs access and from where — please identify the parent company personnel, overseas engineers, contractors or other group entities that will require access, together with their locations and intended roles.
  5. Personnel and reporting lines — please describe proposed reporting lines, secondments, overseas support arrangements and changes affecting researchers, engineers or other personnel who handle technical information.
  6. Personal data and security data — please identify relevant employee, customer and business partner data, together with endpoint logs, user or device identifiers, IP addresses, location-related information or other data processed through security systems.
  7. Systems and infrastructure — please describe the cloud environments, code repositories, identity management systems, remote administration, cybersecurity monitoring and system migrations that are planned.
  8. Economic security status and integration timetable — please let us know whether the target is involved in designated essential infrastructure or other potentially sensitive operations, and which systems, access arrangements or functions are expected to be operational on Day 1 or at a later stage.

Please begin with a short overview rather than sending technical material, personal data or transaction documents with your first enquiry. Once we have confirmed that we are able to act, we will explain how to share detailed material.

Contents
  1. Buying the Company and Accessing Its Information Are Different Questions
  2. Technology After Closing: Export Control and Deemed Exports
  3. People, Reporting Lines and Technical Access
  4. Personal Data, Cybersecurity Monitoring and Global Systems
  5. Economic Security and Building the Integration Plan
  6. Frequently Asked Questions

Buying the Company and Accessing Its Information Are Different Questions

Clearance for the acquisition is not clearance for access

Completing the acquisition of a Japanese company does not, by itself, answer every question about what the overseas group may access after closing. Foreign investment screening addresses the acquisition, and certain related conduct, from one regulatory perspective. The subsequent disclosure of technical information, transfer of personal data, access by overseas personnel and changes to sensitive systems may be governed by separate rules and should be analysed separately.

This distinction can also matter within the foreign investment framework itself. Depending on the investor, the target’s business and the route used for the investment, the conditions applicable to an exemption from prior notification can include restrictions relating to access to non-public technical information and to certain involvement in the target’s management. The acquisition analysis should therefore be read together with any assumptions, exemption conditions or undertakings on which the transaction proceeded.

Three layers, asked in a different order

It helps to keep three layers apart. Foreign investment screening governs whether, and on what terms, the acquisition may be made. Export control governs the provision of certain technology to certain recipients. Data protection and, where relevant, economic security and sector-specific regulation govern what may be done with information, systems and facilities once the business is owned. The first layer is a gateway to the transaction; the others are rules about information and operations, and they continue to apply after the transaction has been completed.

In practice the question usually surfaces as a series of ordinary integration requests rather than as a single legal issue: the buyer’s security team asks to add the Japanese entity to a global monitoring platform, the group engineering function asks for repository access, human resources asks to move employee records into a global system, and procurement asks to replace a vendor. Each request has its own answer, and the answers are not all given by the fact that the acquisition has closed.

Planning before closing is not the same as implementing before closing

Integration planning can begin before closing, but planning and implementation are not the same thing. Pre-closing information sharing and coordination remain subject to the access arrangements established for the transaction and to the applicable competition, confidentiality, data protection and export control constraints. A proposed Day 1 access model should not simply be implemented because the buyer expects to own the company at closing. The practical implementation of Day 1 and later integration is addressed in Chapter 5.

The remaining chapters address these questions through technology and export control, personnel and technical access, personal data and systems, and the implementation of the post-closing plan. The broader rules governing the acquisition itself are covered in our general guide to acquiring a Japanese business.

Technology After Closing: Export Control and Deemed Exports

These are rules about technology, not about passports

Japan’s deemed export rules should be understood as rules about the provision of controlled technology, not as rules about an employee’s passport. Article 25 of the Foreign Exchange and Foreign Trade Act regulates specified transfers of technology, and a transfer from a resident to a non-resident can be subject to control even where the information is made available inside Japan. Nationality, by itself, does not determine whether a technology transfer is subject to Japan’s deemed export controls. Residence, and the circumstances in which the technology is made available, are the starting points.

The analysis can extend to residents in specified categories

Under the relevant notification issued by the Ministry of Economy, Trade and Industry, the analysis can also extend to a resident who is a natural person falling within one of the Specified Categories. In summary, those categories address defined contractual relationships with foreign corporations or foreign governments, certain substantial economic benefits received from a foreign government, and instructions or requests from a foreign government concerning conduct in Japan. Where the relevant criteria are met, providing controlled technology to that resident is treated, for deemed export purposes, in the same manner as providing it to a non-resident. Foreign nationality, or employment by a foreign-owned Japanese company, is not enough by itself.

Classify the technology separately from the recipient

Separately from the recipient analysis, the technology itself must be classified. List control applies where the technology falls within specified controlled categories and technical parameters. Catch-all control can require a licence even where the technology is not list-controlled, depending on the applicable end use, end user and other regulatory criteria, or on a notification from the authorities requiring an application. The two inquiries should therefore be kept separate: who is receiving the technology, and what the technology is.

Identify what is being provided before asking whether it is controlled

The material at issue is frequently wider than a set of drawings. Design information, specifications, manufacturing and process know-how, test and evaluation data, software source code, algorithms and the results of research and development can all be relevant, and so can the assistance given when an engineer explains how something works. At the same time, not everything held by the target is controlled technology, and information that is already published or otherwise treated as publicly available is generally analysed differently. The first step is therefore to describe accurately what will be provided, in what form and for what purpose.

Because this analysis depends on facts that the business side holds, it is usually more efficient to build a short classification record as part of the integration work: what the technology is, which entity holds it, who will receive it, where the recipient is, and what conclusion was reached. Keeping that record also makes it easier to revisit the position when the product, the team or the group structure changes later.

In integration, access is the transfer

In an integration context, the transfer usually takes the form of access rather than of a formal transfer document. Giving overseas engineering teams access to source code, design files or research repositories, adding personnel to technical meetings, or moving material into a global development environment can each require the same analysis. The fact that the recipient is now within the same corporate group does not by itself answer the export control question, so integration planning should identify the technology, the proposed users and the access routes before access is enabled.

People, Reporting Lines and Technical Access

Technology moves through people

Technology is often shared through people rather than through a formal transfer of documents. After an acquisition, a Japanese engineering or research team may begin reporting to an overseas function, join global development meetings, receive support from engineers outside Japan, or allow group personnel to enter repositories that were previously accessible only within the Japanese target. Each of these changes can alter who receives, or can access, technical information.

For deemed export purposes, the analysis should not be based simply on nationality. As set out above, residence, the relevant relationships and the technology being provided can all matter. A Japanese national can fall within a Specified Category, while a foreign national is not subject to the rules merely because of the passport held. The purpose of an integration review is therefore to understand the actual access relationship, rather than to create nationality-based restrictions.

Reporting lines are a separate question from access

Reporting lines deserve separate attention. That an employee reports to an overseas manager does not, by itself, determine the export control result. The relevant questions include what technical information the employee or the manager will receive, whether the recipient is a resident or a non-resident, whether a resident who is a natural person falls within a Specified Category, and how information is made available through meetings, systems and repositories.

Secondees, contractors and joint teams

Integration often brings in people who are not employees of the Japanese target. Secondees from the overseas parent, contractors engaged through a group entity, vendors supporting a migration and members of joint development teams may all obtain access to the same material as the target’s own staff. The contractual route by which a person obtains access does not change the underlying question of who is receiving the technology and where. Where access is granted through a service provider, the arrangements with that provider, and the provider’s own personnel, are part of the analysis.

It is also worth being careful about how any resulting measures are presented internally. Controls that are described in terms of nationality are unlikely to match the legal analysis, and can raise separate employment and equal-treatment concerns. Measures expressed in terms of the technology concerned, the systems involved and the approvals required are both more accurate and easier to operate.

An access matrix turns the analysis into controls

A practical access matrix can bring these questions together. It can identify the categories of technology, the teams that need access, their locations and legal entities, the systems through which access will occur, and any restrictions or approval steps that should remain in place. The resulting matrix can then feed into the broader Day 1 and post-closing integration plan discussed in Chapter 5.

Personal Data, Cybersecurity Monitoring and Global Systems

Start with who can handle the data, not where the server is

Post-closing data integration should begin by identifying who will receive, or be able to handle, the data, rather than by looking only at where a server is located. A foreign parent is a separate legal person from its Japanese subsidiary and may therefore be a third party in a foreign country when the Japanese company provides personal data to it. Membership of the same corporate group does not, by itself, take an intra-group transfer outside the rules of the Act on the Protection of Personal Information. The applicable requirements then depend on the transfer structure, the recipient and the relevant statutory basis or exception.

Cloud architecture requires a different analysis

The location of the server, by itself, does not determine whether there is a transfer to a third party in a foreign country. Guidance issued by the Personal Information Protection Commission distinguishes arrangements in which a foreign cloud provider is contractually not permitted to handle the personal data and appropriate access controls are implemented. In such a case, storing the data on the provider’s foreign server does not, on that basis alone, constitute a transfer to a third party in a foreign country, although separate security management obligations remain relevant.

A label such as “security log” does not settle the classification

The same functional approach is useful for a global security operations centre or endpoint detection and response environment. A label such as “security log” does not determine the classification under the Act. Endpoint logs, user or device identifiers, IP addresses and location-related information may constitute personal information where they identify an individual, including where they can readily be cross-referenced with other information; depending on how they are held, they may also constitute personal data. Where information relating to an individual does not constitute personal information, the separate rules on personal-related information may still need to be considered.

More than one route can support a cross-border transfer

Where a transfer to a recipient outside Japan is involved, Japanese law contemplates more than one basis on which it may be made, including consent obtained after the prescribed information has been provided to the individual, and arrangements under which the recipient maintains a system that meets the standards set for this purpose. Which route is appropriate depends on the recipient, the group structure, the categories of data and how the data will be used after the transfer, and the route chosen carries its own record-keeping and information obligations. The choice is therefore better made at the planning stage than after a migration has begun.

Transparency towards employees deserves particular attention in an integration. Employee data is often the first category to be moved into a global human resources or security platform, and the purpose for which it was originally collected may not cover everything the group now intends to do with it. Reviewing the stated purposes, the internal notices and the arrangements with the group entities that will handle the data is usually more productive than treating the migration as a purely technical project.

Map the access before the migration

Before connecting the Japanese target to a global platform, it is useful to map who can see what, through which legal entity, from which country and for what purpose. A foreign parent’s security team with readable access to employee-linked telemetry presents a different data-flow structure from storage with a cloud provider that is not permitted to handle the data. For integration planning, the access and data-flow map is therefore more informative than asking only where the server is located.

Economic Security and Building the Integration Plan

The economic security regime is not a foreign ownership rule

The Economic Security Promotion Act should be distinguished from Japan’s foreign investment screening regime, and is not a general restriction on foreign ownership of Japanese companies. Among other measures, the Act establishes a system for designated operators of specified essential infrastructure services, under which certain introductions of specified critical facilities and certain outsourcing of critical maintenance and management can require prior notification and review.

This can become relevant after an acquisition even where the acquisition itself has already been completed. A group-wide infrastructure programme may replace a system, appoint an overseas or group vendor, centralise maintenance, migrate a critical function to a different platform or change the parties with access to an important facility. If the Japanese target is a designated operator and the proposed change falls within the statutory framework, the implementation timetable may therefore need to take the applicable process into account.

Move from legal categories to concrete actions

The integration plan should then move from legal categories to concrete actions. First, identify what must be operational on Day 1 and what can follow later. Second, map the proposed transfers of technology and data, the changes in personnel access, the systems to be connected and any material outsourcing or vendor changes. Third, classify each item into measures that can proceed as planned, measures that require further legal or regulatory review, and measures that should remain segregated until the relevant conditions have been addressed.

Vendors, outsourcing and transitional arrangements

Vendor and outsourcing changes deserve separate attention because they often sit at the intersection of several of the issues described above. Replacing a supplier, moving support to a group shared-service centre or consolidating cloud providers can affect who handles personal data, who has access to technical information and, where the target is a designated operator, whether a statutory process applies. Where the seller continues to provide services for a transitional period, the scope of those services, the access they require and the point at which they end should be set out with the same care.

Reflect the plan in practical controls

The resulting plan can be reflected in practical controls rather than in a single legal conclusion. Examples include temporary separation of repositories, staged migration of data, restricted administrator access, transitional service arrangements, revised vendor scopes, export control approval steps and documented access rules. These measures need not be permanent. Their purpose is to allow the business and legal workstreams to distinguish Day 1 requirements from later integration, and to revisit restrictions as the underlying facts, the regulatory position and the operating model develop.

It also helps to decide, at the outset, who owns the plan. Integration decisions are usually taken by the business, the technology function and human resources at different times, and a measure agreed in one workstream can be undone in another. A single record of what was decided, on what basis and subject to what conditions allows the position to be checked when a later change is proposed, and makes it easier to explain the arrangements if a regulator, a customer or a counterparty asks about them.

Where the target conducts a regulated payment, cryptoasset, electronic payment instrument or money lending business, sector-specific registration, outsourcing and operating requirements should also be considered alongside the matters described above; these are covered in “Acquiring a Regulated Financial Business in Japan”.

Frequently Asked Questions

If we have completed the foreign investment process, can our overseas parent access the target’s source code and research information?

Completion of the acquisition process does not by itself authorise unrestricted access to technical information. The position taken for the investment under the Foreign Exchange and Foreign Trade Act, including any applicable exemption conditions, should first be checked. Separately, providing source code, designs, research materials or other technology to overseas personnel can raise export control issues under Article 25 of that Act. The analysis depends on the technology, the proposed recipient and the manner of access. The same-group relationship between the Japanese target and its foreign parent does not by itself resolve those questions.

Does Japan’s deemed export control apply only to foreign nationals?

No. Nationality, by itself, is not the test. Deemed export control traditionally addresses certain transfers of controlled technology to non-residents, including transfers taking place within Japan. The rules can also apply to the provision of controlled technology to a resident who is a natural person falling within one of the Specified Categories because of particular relationships with, or influence from, a foreign corporation or government. The assessment should therefore consider residence, the relevant relationships and the technology being provided, rather than using nationality as a proxy.

Can we move employee and customer data from the Japanese target into our global systems after closing?

Possibly, but ownership of the Japanese company does not by itself resolve the analysis under the Act on the Protection of Personal Information. A foreign parent with a separate legal personality may be a third party in a foreign country when personal data is provided to it. The required analysis depends on the data, the recipient, the legal basis, the transfer structure and the safeguards involved. Server location alone is not determinative: the position can differ where a foreign cloud provider is not permitted to handle the data. Data flows should therefore be mapped before migration.

Can our global security operations centre monitor devices used by employees in Japan?

Potentially, but the data and access model should be reviewed rather than treating all security telemetry alike. Endpoint logs, user or device identifiers, IP addresses and location-related information may constitute personal information depending on whether an individual is identifiable, including through cross-reference with other information. The review should consider what information is collected, the purpose, who can access it, which legal entities receive it, where access occurs and how employees are informed. Cross-border access and outsourcing arrangements may raise additional issues.

Does the Economic Security Promotion Act restrict foreign ownership of Japanese companies?

Not as a general rule. Foreign investment screening under the Foreign Exchange and Foreign Trade Act and the Economic Security Promotion Act should be distinguished. Among other measures, the latter establishes a regime for designated operators of specified essential infrastructure services, including prior procedures for certain introductions of specified critical facilities and certain outsourcing of critical maintenance and management. A foreign acquisition may therefore interact with that regime when post-closing systems, facilities, vendors or outsourcing arrangements are changed, but foreign ownership itself is not the general test under that framework.

Should post-closing integration planning begin before closing?

It is usually useful to identify the integration issues before closing, particularly where Day 1 access to systems, data or technical information is contemplated. Planning does not, however, mean that the planned access should be implemented early. Pre-closing information sharing and coordination remain subject to the transaction’s confidentiality arrangements and may raise competition, data protection or export control issues. A practical approach is to identify the proposed Day 1 and later access in advance, assess the applicable restrictions, and implement each step when the relevant conditions have been addressed.

Contact

Planning the Integration of a Japanese Acquisition?

Tell us which technology, data, systems and people you expect to connect to the overseas group after closing. We advise on the Japanese law questions affecting access, transfer and implementation, and work with counsel in the other jurisdictions involved where the arrangements reach beyond Japan.

Discuss post-acquisition integration in Japan

Whether we are able to act, and the scope of our work, are confirmed individually after a conflict check.

This article is provided for general informational purposes only and does not constitute legal advice on any specific matter. Please consult us regarding your specific situation. The content is based on the laws and regulations in effect as of the date of the last update.