Is Web Scraping Legal in Japan? Article 30-4 and APPI (2026)
Published 2026-10-11 · Updated 2026-10-11 · By the Scrapeshop team
Web scraping is legal in Japan when you access only publicly available pages, keep your request rate low enough not to interfere with the target’s operations, honour terms you agreed to, and handle personal information under the Act on the Protection of Personal Information (APPI). Japan is unusual in two directions at once: its Copyright Act contains one of the broadest statutory permissions for data analysis in the world, and its criminal law has been applied to a scraper whose only fault was crashing a fragile server.
This guide covers Article 30-4, the APPI, the Unauthorized Computer Access Act, the Penal Code’s obstruction-of-business offence, and contract. General information current as of October 2026, not legal advice. The overview across jurisdictions is Is Web Scraping Legal? What the Law Actually Says.
Quick answer
Scraping for analysis is expressly permitted by Japanese copyright law. Article 30-4 of the Copyright Act, as amended in 2018, allows any person to exploit a work for information analysis without the owner’s permission, for commercial or non-commercial purposes, provided the use does not aim at enjoying the work itself and does not unreasonably prejudice the owner’s interests. Databases are protected only where the selection or systematic construction is creative (Article 12-2), and there is no sui generis database right. The limits are elsewhere. The APPI applies to scraped personal information and prohibits acquisition by improper means. The Unauthorized Computer Access Act covers gated systems only. The Penal Code’s obstruction-of-business offences (Articles 233 and 234-2) have been applied to a crawler that overloaded a library server, so rate limiting is a legal safeguard in Japan, not only an etiquette.
Which Japanese laws govern web scraping?
| Law | What it covers | What it means for scrapers |
|---|---|---|
| Copyright Act, Art. 30-4 and Art. 47-5 | Exploitation of works for information analysis; incidental use in data-processing services | Commercial scraping and AI training for analysis are permitted unless they unreasonably prejudice the owner. Republishing the works is not covered. |
| Copyright Act, Art. 12-2 | Database works protected where selection or systematic construction is creative | Factual listings are free. Curated, creatively structured databases are protected against reproduction of their structure. |
| Act on the Protection of Personal Information (APPI) | Acquisition, use and transfer of personal information by business operators | Specify purpose of use; no acquisition by deceit or improper means (Art. 20); consent for sensitive information; rules on transfer to third parties and abroad. |
| Unauthorized Computer Access Act (1999) | Access using another's identification code or by circumventing access-control functions | Public pages are outside it. Credential misuse and defeating technical restrictions are inside it. |
| Penal Code, Arts. 233, 234 and 234-2 | Obstruction of business by fraudulent means, by force, or by damaging or interfering with a computer | A scraper that degrades a service can be prosecuted even without intent to harm (Librahack, 2010). Keep request rates conservative. |
| Civil Code (standard terms, Arts. 548-2 to 548-4) and Unfair Competition Prevention Act | Enforceability of terms of use; protection of trade secrets and shared data with limited access | Terms bind users who agreed. Data behind access controls provided to limited parties can be protected as 'shared data with limited access' since 2019. |
How does Article 30-4 work?
The 2018 amendment to the Copyright Act, effective January 2019, replaced an earlier, narrower information-analysis exception with a flexible provision. Article 30-4 permits exploiting a work in any manner, to the extent considered necessary, in cases where the purpose is not to enjoy the thoughts or sentiments expressed in the work. Information analysis, defined as extracting, comparing, classifying or otherwise analysing information from a large number of works, is the leading example. Three features make it broader than the EU’s text-and-data-mining exception:
- No commercial restriction. Companies can rely on it for product development and training commercial AI models.
- No opt-out mechanism.Unlike Article 4 of the EU Directive, a rights holder cannot reserve its rights by a robots.txt entry or metadata. Whether a contractual prohibition overrides the exception is debated; the Agency for Cultural Affairs’ 2024 guidance suggests technical measures and clear contractual restrictions can be relevant to the “unreasonable prejudice” test.
- A proportionality limit. The exception does not apply where the use would unreasonably prejudice the interests of the copyright owner, for example scraping a database that is itself sold for analysis purposes, or where outputs reproduce the expressive content of the works.
Article 47-5 separately permits minor incidental use of works in services such as search engines and data-analysis services that present results to users. The practical conclusion is that scraping public Japanese sites to analyse them is on solid copyright footing; scraping to republish is not.
Can I scrape personal information in Japan?
The APPI applies to any business operator that handles personal information, including foreign operators that handle information about people in Japan. Three obligations bite on scrapers. Article 17 requires the purpose of use to be specified as concretely as possible, and use beyond it requires consent. Article 20 prohibits acquiring personal information by deceit or other improper means, and prohibits acquiring sensitive personal information (race, creed, medical history, criminal record and similar) without consent except in listed cases. Articles 27 and 28 restrict providing personal data to third parties and transferring it outside Japan.
The Personal Information Protection Commission (PPC) issued a formal caution to OpenAI in June 2023, warning that acquiring sensitive personal information through scraping without consent would breach the Act and that purposes of use must be notified to individuals in Japanese. The PPC also joined the 2023 global regulators’ statement on data scraping. Scraping profiles, names and contact details of people in Japan requires a stated purpose, exclusion of sensitive categories, and a transfer mechanism if the data leaves the country.
Obstruction of business: the Librahack lesson
In March 2010 a software engineer wrote a crawler to build a better interface to the Okazaki City Library’s online catalogue. It requested roughly one page per second. The library’s server, running a vendor system with a connection leak, became unresponsive. The library reported an attack, and Aichi police arrested the engineer for obstruction of business by damaging a computer under Article 234-2 of the Penal Code. He was held for twenty days before prosecution was suspended. The vendor later acknowledged the bug and the library expressed regret, but no court ever ruled that the crawler was lawful.
The case is the reason Japanese engineers treat rate limiting as a legal control. The offence does not require intent to harm the business; it requires an act that interferes with the operation of a computer used in business. A scraper that causes an outage is exposed regardless of how public the data was. Conservative request rates, backoff on errors, and a crawler that identifies itself with contact details are the safeguards.
Unauthorised access and terms of use
The Unauthorized Computer Access Act criminalises three things: using another person’s identification code to access a computer, entering information that circumvents an access-control function, and attacking a computer through a connected one. Public pages involve none of these. Credential sharing, defeating a login or token check, and using leaked API keys are squarely inside the Act. Terms of use are enforced as standard terms under the 2020 Civil Code amendment where the user agreed to deal on their basis; registration on a Japanese site normally satisfies this. The Unfair Competition Prevention Act adds civil protection for “shared data with limited access”, meaning data that a business provides to specified parties under technical access restrictions. Scraping such data after obtaining access under an account can be misappropriation.
Checklist for scraping Japanese websites
- Rate-limit conservatively, back off on errors, and identify your crawler. Disruption is the primary criminal risk in Japan.
- Scrape public pages only. Never use shared credentials or bypass access controls.
- Rely on Article 30-4 for analysis and training; do not republish works or reproduce a creatively structured database.
- For personal information, publish a Japanese-language purpose of use, exclude sensitive categories, and arrange a lawful transfer basis before moving data out of Japan.
- Honour terms you agreed to; registered-user anti-scraping clauses are enforceable.
- Stop on a demand and take advice; continuing after notice strengthens both civil and criminal arguments.
Engineering guidance is in Web Scraping Best Practices.
Frequently asked questions
- Is web scraping illegal in Japan?
- No. Japan has no law that prohibits web scraping, and Article 30-4 of the Copyright Act expressly permits using works for information analysis, including for commercial purposes. Limits come from the APPI for personal information, the Unauthorized Computer Access Act for gated systems, the Penal Code's obstruction-of-business offence for scrapers that overload servers, and contract law.
- What does Article 30-4 of the Japanese Copyright Act allow?
- Since the 2018 amendment, Article 30-4 permits exploiting a work, to the extent necessary, for information analysis and other uses that do not aim at enjoying the expressed thoughts or sentiments of the work, unless doing so would unreasonably prejudice the interests of the copyright owner. It covers commercial and non-commercial scraping for analysis and AI training.
- Is scraping personal information legal in Japan?
- The APPI applies to scraped personal information. A business must specify the purpose of use, must not acquire personal information by deceit or other improper means, and needs consent to acquire sensitive information. The Personal Information Protection Commission formally cautioned OpenAI in June 2023 about scraping sensitive data without consent.
- What was the Librahack case?
- In 2010 a developer in Okazaki was arrested for obstruction of business after his crawler, which requested one page per second from a library catalogue, caused the poorly configured server to fail. Prosecution was suspended, and the library later acknowledged the server bug, but the case established that scraping which disrupts a service can be treated as a criminal matter in Japan.
- Does the Unauthorized Computer Access Act apply to scraping public pages?
- No. The Act criminalises accessing a computer by entering another person's identification code or by circumventing access-control functions. Public pages have no access control to circumvent. Logging in with credentials you are not entitled to, or defeating a technical restriction, falls within it.
- Do website terms of use bind a scraper in Japan?
- Yes, where the user agreed to them. The 2020 Civil Code amendment on standard terms (teikei yakkan) makes standardised terms binding when the user agreed to deal on their basis or was shown them in advance. Anti-scraping clauses are common on Japanese sites and are enforced against registered users.