Japan's Unfair Competition Prevention Act and Trade Secret Protection in Practice: Limited Provision Data, the 2023 Amendment, and Penalties (2026 Guide)
Hello, this is Ryuta Hamamoto from TIMEWELL.
Your own drawings and manufacturing methods, your customer lists, your AI training data. When these flow to a competitor or overseas, one of the laws you rely on is Japan's Unfair Competition Prevention Act (UCPA, 不正競争防止法). Yet when it actually reaches court, cases are lost time and again on a single point: "Were you really managing that as a trade secret?" Before the question of whether the information has value, the outcome turns on whether there is evidence that you treated it as a secret.
Technology leakage is no longer a matter of one company's loss. When design data or advanced technology flows abroad, it becomes an economic security risk as well. That is exactly why the Ministry of Economy, Trade and Industry (METI) has asked companies to protect trade secrets and prevent technology leakage on two wheels at once — through guidelines and through a handbook. This article unpacks, for readers new to the topic, the two information assets that the UCPA protects (trade secrets and limited provision data), then organizes the key points of the 2023 amendment, the heavy penalties, and practical countermeasures for the three leakage scenarios of departure, overseas transfer, and joint research — all grounded in METI's primary sources.
Let me give the conclusion up front: the UCPA's confidentiality management alone cannot fully prevent "unintended technology leakage." You need both wheels — defensive legal work and the offensive discipline of export control under the Foreign Exchange and Foreign Trade Act (FEFTA). The reasoning comes in the final section. If you first want a number on how many holes are in your own information management, running our free Export Compliance Check beforehand will let you read this article as your own concern.
The Two Information Assets the UCPA Protects (Summary)
Before we get into the fine print of the statute, here is the whole picture on one page. The UCPA's mechanism for protecting "information" splits broadly into two. The long-standing trade secret, and limited provision data, which was added in 2019. The two look alike but are fundamentally different, and the requirements for protection differ.
| Comparison axis | Trade secret (Art. 2(6)) | Limited provision data (Art. 2(7)) |
|---|---|---|
| Typical examples | Manufacturing methods, blueprints, experimental data, customer rosters | Big data, AI training data, map and weather data, etc. |
| Non-public-knowledge (being secret) | Required | Not required |
| Assumed sharing scope | Kept confidential within a limited scope such as inside the company | Provided as a business to specific multiple persons |
| Start of the regime | Long-standing | Newly created in the 2018 amendment; effective July 1, 2019 |
Put simply, trade secrets protect "secrets you have not let out," while limited provision data protects "data you provide to specific counterparties, often for a fee." And the sanctions for infringement are uniformly heavy: in egregious cases they reach up to 10 years imprisonment for an individual and up to 1 billion yen in fines for a corporation. Once you grasp this weight, the priorities of your day-to-day information management start to shift.
What Is a Trade Secret — the Biggest Battleground Is "Reasonable Secrecy Management"
A trade secret is defined in Article 2(6) of the UCPA as "technical or business information useful for business activities, such as manufacturing methods and sales methods, that is kept secret and is not publicly known." METI derives three requirements from this definition and holds that only information satisfying all three is protected as a trade secret. The three requirements are reasonable secrecy management (秘密管理性), usefulness (有用性), and not being publicly known (非公知性).
Usefulness means the information is technical or business information useful for business activities. Even information that cannot be used directly — such as failed research data that tells you "this method does not work" — may be recognized as useful. Non-public-knowledge means the information is in a state where it is not publicly known. Information anyone can obtain through publications or the internet falls out at this point. So far, this is relatively easy to grasp.
Where companies overwhelmingly stumble in practice is reasonable secrecy management. Even when a company argues in court "this is a trade secret," cases have repeatedly failed to win protection because the company could not show that it had actually managed the information as a secret. Reasonable secrecy management means restricting who can access the information and, at the same time, keeping it in a state where employees can objectively recognize that it is confidential. METI's Trade Secret Management Guidelines (revised March 2025) set out the "minimum level" of measures needed to receive this protection.
So what should you concretely do? For paper documents, a "CONFIDENTIAL" (マル秘) marking; for electronic data, access-rights settings and access logs; and positioning within work rules or a confidentiality agreement. These three points are the basics. If you leave data in a shared folder that every employee can open freely and simply say "it is important data, so of course it is secret," reasonable secrecy management is unlikely to be recognized. Conversely, even without a perfect system, if you clearly identify the target and operate in a way that delivers the message "this is secret" to employees, the requirement becomes easier to satisfy. In short, what is tested is not the sturdiness of the safe, but the consistency of the practice — locking it and posting "authorized personnel only."
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
What Is Limited Provision Data — New Protection for the Age of Big Data and AI
Trade secrets had a decisive weakness. Because they require non-public-knowledge, it is hard to call data you distribute to multiple business partners for use "not publicly known," so such data did not fit neatly within the trade secret framework. Yet in an era where data itself becomes the product, the very thing you want to protect is "data provided to specific counterparties in exchange for value" — like map data, weather data, or AI training datasets. Limited provision data was newly created to fill this gap.
Limited provision data was introduced in the 2018 amendment (Act No. 33 of 2018, promulgated May 30, 2018) and took effect on July 1, 2019. It is positioned as a third category of information-asset protection, distinct from trade secrets and also from intellectual property such as designs and trademarks. The definition, in Article 2(7), is "technical or business information (excluding trade secrets) that is accumulated and managed in substantial quantity by electromagnetic means as information provided to specific persons as a business." The key point is that non-public-knowledge is not a requirement. That is why data provided to multiple parties can be protected.
There is a measure of relief here. Because the traditional limit of "we cannot protect it since it is not secret" has been removed, you can now put data out into the marketplace of transactions while still saying a legal no to wrongful acquisition or leakage. The 2023 amendment widened this scope further. Previously, "information kept secret" was excluded from limited provision data; by rewriting this to "excluding trade secrets," the amendment arranged things so that data under secrecy management can also be protected as limited provision data. I read it as an amendment that makes it harder to drop through the cracks the data you want to protect but that does not meet the trade secret requirements.
What Happens If You Infringe — Civil Remedies and Heavy Criminal Penalties
This is one of the core topics. When someone infringes a trade secret or limited provision data, how heavy are the sanctions the law provides? On the civil side first, the injured company can stop the use or disclosure through an injunction claim (Article 3) and recover its loss through a damages claim (Article 4). Because proving the amount of loss is difficult, presumption provisions on the amount of damages are placed in Article 5 and Article 5-2, designed to lighten the victim's burden of proof. There are also claims for measures to restore business reputation (Article 14) and protective orders that prevent secrets from spreading during litigation (Article 10 and following).
The criminal penalties were substantially strengthened in the 2015 amendment (Act No. 54 of 2015, effective January 1, 2016): higher fine ceilings, aggravated penalties for overseas leakage, an expansion of punishment for those who commit the act abroad, the creation of an attempt offense, a shift to offenses that can be prosecuted without the victim's complaint, and provisions for confiscation of criminal proceeds. The maximum 1-billion-yen corporate fine that now makes companies shudder derives from this amendment. The table below shows the levels under the current provisions.
| Type of infringement | Criminal penalty (individuals) | Corporate fine (dual liability, Art. 22) | Legal basis |
|---|---|---|---|
| Ordinary trade secret infringement (theft, wrongful acquisition, wrongful use or disclosure by current or former employees, etc.) | Up to 10 years imprisonment or a fine up to 20 million yen, or both | Up to 500 million yen | Art. 21(1) and (2) |
| Acquisition for the purpose of overseas use / use overseas, etc. (overseas-leakage type) | Up to 10 years imprisonment or a fine up to 30 million yen, or both | Up to 1 billion yen | Art. 21(4) and (5) |
| Limited provision data infringement, circumvention of technological restriction measures, etc. | (Individual penalties apply) | Up to 300 million yen | Art. 21(3) |
Three footnotes to this. First, acquisition aimed at use overseas, and the act of using overseas a trade secret held by a holder doing business in Japan, push the fine from 20 million yen to 30 million yen for individuals, and from 500 million yen to 1 billion yen for corporations. It is a sign that overseas leakage of technology is treated as especially serious. Second, attempts are also punishable (Article 21(6)), and the penalties reach those who commit the crime abroad (the punishment of acts committed outside Japan under Article 21(8)). Third, criminal proceeds are subject to confiscation and collection. The most accurate reading is that the design leaves no room for the calculation of "if I get caught, I can just pay."
A note on the wording of the statute as well. Under the Act Partially Amending the Penal Code and Other Acts (Act No. 67 of 2022), "imprisonment with work" (懲役) and "imprisonment without work" (禁錮) were unified into a single "imprisonment" (拘禁刑) as of June 1, 2025. Slightly older precedents and news reports write "10 years of imprisonment with work," but the current provisions as of July 2026 read "imprisonment." This article follows the current law.
Key Points of the 2023 Amendment (Act No. 51 of 2023)
The UCPA was substantially revised in 2023. Formally, this is the "Act Partially Amending the Unfair Competition Prevention Act and Other Acts" (Act No. 51 of 2023, promulgated June 14, 2023), part of a package amendment that the Japan Patent Office planned together with the Patent Act, the Design Act, the Trademark Act, and others. The principal provisions took effect on April 1, 2024. Let me walk through the pillars with the greatest business impact, in order.
The first is regulation of imitation in digital spaces. "Imitation of product configuration" (Article 2(1)(iii)), which covers selling goods that closely copy the configuration of another company's product, gained the wording "an act of providing through telecommunications lines." In other words, imitation goods in the metaverse and online are now within the net. The second is the expansion of the scope of protection for limited provision data, touched on above. The third is the revision of how damages are calculated (Article 5): for volumes the infringer sold beyond the rights holder's own production or sales capacity, the rights holder can now add an amount equivalent to a licensing fee on that excess portion. It is an amendment in the direction of reducing "getting away with it." The fourth is the enhancement of the presumption provisions on use and the like (Article 5-2). And the fifth, which connects to the second half of this article, is the response to cross-border trade secret infringement: it applies Japan's UCPA (in civil matters) to overseas use and clarifies international jurisdiction. Alongside this, the penalties for bribery of foreign public officials were also strengthened.
If I sum up the 2023 amendment in a phrase, it is "the objects of protection were extended into the digital realm and overseas." I take it as an amendment where the law caught up to the reality that the flow of technology and data has crossed both national borders and the boundary of physical space. Read it together with our foundational article organizing what economic security is and our complete guide to the Economic Security Promotion Act, and the dots become a line.
The Three Major Technology-Leakage Scenarios and Countermeasures
Enough about the regime — from here we descend to the field. Technology leakage happens in set scenarios. The three I consider most worth watching are these.
The first is removal by departing or job-changing employees. Where an officer or employee wrongfully acquires a trade secret while in service and then uses or discloses it after leaving, the act is clearly subject to criminal penalties (Article 21(2)). The countermeasures in practice are unglamorous but effective: confidentiality pledges on joining and on leaving, prompt removal of access rights in the departure procedure, and confirmed return or deletion of loaned devices and any data taken out. METI's Handbook for the Protection of Confidential Information (revised February 2024) contains sample templates for the various agreements you can use in these situations. Whether a single pledge exists or not utterly changes how easily you can prove your case when a dispute arises.
The second is leakage accompanying overseas transfers, overseas subsidiaries, and local production. What makes this troublesome is that "unintended technology leakage" — with no bad intent — is easy to trigger. METI's Guidelines for Preventing Technology Leakage (March 14, 2003) present patterns of leakage and countermeasures, so that when a company expands overseas, technology does not leak beyond the scope of the intended technology transfer. In the process of handing drawings and know-how to a local joint-venture partner or contractor, technology seeps out little by little from the parts a contract cannot fully cover. This is less a matter of lax secrecy management than a design problem in the first place — "what, how far, and to whom you hand over."
The third is joint research and open innovation. When you team up with a university, another company, or foreign-national researchers, the lines for ownership of results and confidentiality tend to blur. Define the scope and handling of confidential information in advance in the joint research agreement, and narrow the information you hand over to the minimum necessary. Confirming there are no concerns about the counterparty's affiliated institution or funding sources is also indispensable. The spread of telework is another point not to overlook: METI has published Points for Managing Confidential Information During Telework, organizing the focal points for maintaining reasonable secrecy management even in remote environments. The question is whether the whole company can share the sense that reasonable secrecy management can wobble the moment confidential material sits on a shared PC at home.
Technology Leakage Is an "Economic Security" Problem — Run Both Wheels, Defense and Offense
Finally, the point I most want to convey in this article. The UCPA's confidentiality management we have seen so far is, in a sense, "defense." You lock up secrets internally, bind them with contracts, and control access. It matters greatly, but this alone cannot fully prevent overseas leakage of technology. The reason is simple: in scenarios where you hand technology to an overseas subsidiary, a joint research partner, foreign-national researchers, or a departing employee "through a legitimate route," the leakage happens outside the UCPA's confidentiality management.
Moreover, in those scenarios two laws activate at once. One is the UCPA's aggravated penalties for "overseas use of a trade secret" (up to 1 billion yen for corporations, plus punishment of acts committed abroad). The other is the technology-provision controls under FEFTA (the Foreign Exchange and Foreign Trade Act, 外国為替及び外国貿易法). If the technology, drawings, or data you provide overseas fall within the scope of controls, they are caught by the net of list controls, catch-all controls, and even "deemed export controls," which treat provision to foreign nationals within Japan as an export. We cover this export-control dimension in detail in our article explaining the risks of deemed exports, our article on FEFTA violation penalties and cases, and our guide to reading METI's classification determination guidelines. Trade secret management and export control are, in truth, the front and back of a single risk: "overseas leakage of technology."
The problem is that in many companies the two are operated separately. Legal and IP handle confidentiality management; the export control team handles classification determination; each turns its own wheel at its own post. Unless a single transaction that hands over technology is seen through both eyes at once, leakage slips out through the hole on one side. To connect these end to end, we offer the export-control-specialized AI agent TRAFEED (formerly ZEROCK ExCHECK). It supports classification determination to judge whether the technical information or drawings you provide overseas fall within FEFTA's controlled technologies, counterparty screening to verify that a joint research partner, technology-provision recipient, or prospective hire's affiliated institution is not an entity of concern, and pre-provision checks that include deemed exports. Its determination accuracy was confirmed at 95% or higher in a joint proof of concept with Okayama University (internal measurement), and its determination logic has obtained a patent (Japan Patent No. 7862062). The premise that your own export control officer makes the final classification determination does not change, but the reassurance of a machine's double-check at the water's edge, before you hand anything over, should be significant.
If you try to prevent technology leakage with the legal side's confidentiality management alone, or with export control's classification determination alone, a blind spot always remains on one side. Running both wheels together is, I believe, the level that today's economic security demands of companies.
Summary
The Unfair Competition Prevention Act is a law that protects two information assets — trade secrets and limited provision data — and it provides heavy penalties for egregious infringement: up to 10 years for individuals and up to 1 billion yen for corporations. Here are the things you can start on today, in order of priority.
- Inventory the information you want to protect, and turn "reasonable secrecy management" into evidence through confidential markings, access restrictions, and positioning within work rules
- Put confidentiality pledges in place on joining and on leaving, and make access-rights removal and data return at departure a standard procedure
- Determine whether the data you provide is a trade secret or limited provision data, and spell out its scope and handling in the contract
- For overseas transfers, joint research, and technology provision to foreign-national talent, run FEFTA classification determination and counterparty screening before you hand anything over
- Connect confidentiality management (UCPA) and export control (FEFTA) into a structure that views the same transaction through both eyes
Both the Trade Secret Management Guidelines and the Handbook for the Protection of Confidential Information are high-quality primary materials you can read for free. It is fine to start there. But even after you firm up the "defense" the guidelines call for, the hole of unintended technology leakage remains. What fills it is the export control perspective. How much risk your own technology provision carries from an export control standpoint can be made visible in a few minutes with the free Export Compliance Check. If the results make you want to go further into building a proper structure, feel free to reach out through our TRAFEED consultation. We will help you stop technology leakage on both wheels — legal and export control.
