July 31, 2026 Measures (Guidance) for Ensuring Protection of Specified User Information and Compliance with External Transmission Regulations at LY Corporation (hereinafter referred to as “LY”)

 Today, the Ministry of Internal Affairs and Communications (MIC) issued a written administrative guidance to LY (headed by IDEZAWA Takeshi, President and Representative Director, CEO) regarding an incident involving the leakage of specified user information at the company, instructing them to ensure the proper management of specified user information and strict compliance with external transmission regulations, take necessary measures to prevent a recurrence, and report on the implementation status of these measures.

Note: The published materials are in Japanese only.

1  Background, etc.

 LY reported that Treenod Inc., which is responsible for the development and operation of the “LINE Games” app provided by LY, transmitted user identifiers (MIDs) and other specified user information from users’ devices to a third-party data analytics service provider for the purpose of analyzing advertisements for the app, without obtaining LY’s approval and without notifying users, and this resulted in cases where, over a period of approximately four years from May 25, 2022, to April 3, 2026, approximately 8.03 million instances of such data (of which approximately 7.52 million were from users in Japan) were leaked.

 LY has been designated as a telecommunications carrier required to handle specified user information appropriately pursuant to Article 27-5 of the Telecommunications Business Act (Act No. 86 of 1984; hereinafter referred to as the “Act”). Although LY is responsible for ensuring the proper handling of specified user information, the fact that its business partner, Treenod Inc., disclosed such information to a third party without authorization indicates that LY failed to handle specified user information appropriately, which is contrary to the intent of the aforementioned article.

 Furthermore, when transmitting user information from a user’s devices to an external party in connection with specified telecommunications services, Article 27-12 of the Act requires that users be given the opportunity to confirm the information to be transmitted, the purpose of use, and the recipient. However, the fact that LY transmitted user identifiers (MIDs) and other information to third parties without notifying users or taking other appropriate measures constitutes a violation of Article 27-12 of the Act.

2  Details of measures, etc.

 Today, MIC issued a written guidance to LY, requiring the company to ensure the proper handling of specified user information and compliance with external transmission regulation, and sternly cautioning the company to take thorough measures to prevent a recurrence and ensure that similar incidents do not occur.

 MIC will continue to provide necessary guidance and supervision to ensure the protection of user information.

Contact

For further information about this press release, please fill in the inquiry form and submit it to MIC on the website
https://www.soumu.go.jp/common/english_opinions.html

Global Strategy Bureau, MIC