Introduction
Legal work in the IT field is an area where a deep understanding of both technology and law is indispensable. Even a single set of SaaS terms of use interweaves multiple issues: (1) governing law and jurisdiction; (2) limitation of liability and indemnity; (3) data ownership and deletion obligations; (4) service level agreements (SLAs); and (5) termination and data migration.
Our firm provides seamless support from the upstream of system development (requirements definition and choice of contract form), through the operational phase (incident response and contract amendments), and on to disputes and litigation. Our clients include SaaS providers, contract development companies, the IT departments of operating companies, and startups building data-driven businesses.
Especially important is the ability to legally organize the "ambiguity" that is characteristic of IT contracts. Situations in which development proceeds before requirements are fixed, specification changes are made orally, or the allocation of responsibility is technically unclear are breeding grounds for disputes. Our firm's strength lies in preventive lawyering that translates such technical uncertainty into contract structures and heads off future disputes.
In recent years, demand has surged in new areas such as AI development contracts (rights in training data, liability for outputs, and warranties of model accuracy) and cyber-incident response (ransomware damage and response to supply-chain attacks), and we handle these as well.
Areas of Practice
1. System Development Contracts - Choosing between a contract for work (ukeoi) and a quasi-mandate (jun-inin), and designing the contract structure - Contract models suited to agile development (a master agreement plus individual sprint orders) - The scope and duration of defect liability (liability for nonconformity) - Designing acceptance clauses, additional orders, and specification-change management - Ownership of development deliverables (copyright, know-how, and third-party OSS)
2. SaaS / Cloud Services - Drafting and reviewing SaaS terms of use and privacy policies - Designing MSA (Master Service Agreement) templates for B2B SaaS - Drafting data processing agreements (DPAs) and SCCs (Standard Contractual Clauses) - SLA design, uptime guarantees, and service credits - Data return and deletion obligations on termination, and avoiding vendor lock-in
3. Data Breach and Cyber-Incident Response - Immediate response upon discovery of a breach (evidence preservation and coordinating forensic investigation) - Reporting to the Personal Information Protection Commission and notifying data subjects - Ransomware response (including the legal issues surrounding ransom payment) - Explanations to business partners and customers, and damages negotiations - Formulating measures to prevent recurrence and revising internal rules
4. AI Development and Use Contracts - Licensing of training data and data provision agreements - Ownership of AI-generated works and allocation of liability - The scope of warranties for model accuracy and limitation of liability - Formulating corporate guidelines for generative AI use - Responding to AI regulatory trends (the EU AI Act and Japan's AI Business Operator Guidelines)
5. IT Services Generally - APPI and GDPR compliance (see the "Data Protection" practice area for details) - Compliance with the Telecommunications Business Act, the Act on Specified Commercial Transactions, and the Act against Unjustifiable Premiums and Misleading Representations - Stealth-marketing regulation compliance and the legal issues of operating UGC platforms - API terms of use and developer TOS - M&A and due diligence of IT assets and IP
How We Approach Typical Matters
The following illustrate the kinds of matters we handle and how we would approach them. They are not descriptions of past engagements or results.
Scenario 1: Building Global Contract Templates for a B2B SaaS Provider
Drafting each agreement from scratch increases both sales lead time and legal risk. We are asked to help companies move from bespoke domestic agreements to a standardized MSA operation for global markets.
In such a matter we provide integrated support: (1) preparing MSA, DPA, and SLA templates (bilingual Japanese/English); (2) establishing an internal matrix of acceptable negotiation positions (fall-back positions); (3) delivering contract negotiation training for sales and customer success teams; and (4) setting policy on governing law and jurisdiction across key jurisdictions.
Scenario 2: Responding to a Large-Scale System Development Dispute
Where a core system replacement project gives rise to a dispute with the vendor over unmet requirements or delivery delays, the customer must simultaneously consider termination and damages while restoring the system or switching to an alternative vendor.
In this situation we work through (1) establishing the factual record of the project (review of minutes, correspondence, and related materials); (2) analyzing the allocation of responsibility under the contract; (3) obtaining technical expert input where needed; and (4) structuring negotiations and any settlement with the vendor. We also assist in redesigning the contract structure for the successor project, including staged acceptance of deliverables, rationalized limitations of liability, and clearer governance provisions.
Scenario 3: Emergency Response to a Ransomware Incident
When ransomware encrypts internal systems and the attacker demands payment, legal issues must be organized and a course of action decided within a very short window.
In such a matter we assist with (1) organizing the legal issues around contact with the attacker and any payment (economic sanctions, the Foreign Exchange and Foreign Trade Act, and counter-terrorist financing rules); (2) an initial assessment of whether personal data has been compromised; (3) drafting the preliminary report to the Personal Information Protection Commission; (4) preparing notices to customers and business partners; (5) coordinating with the police and JPCERT/CC; and (6) reviewing the post-recovery forensic report.
How to Engage Us
- Initial Consultation (first 30 minutes free / available online): We hear your challenges and current situation and organize the issues. A confidentiality agreement can be concluded before the consultation.
- Estimate and Proposal: We present the scope, timeline, and fees. We accommodate time-charge, per-matter, and retainer arrangements alike.
- Commencement and Progress Sharing: We report progress regularly and make the issues visible. Where coordination with technical experts is needed, we arrange it.
- Completion and Aftercare: We can provide continued support on related ongoing issues (contract amendments, rule updates, and the like).
Contact
For consultations in the IT field, please reach out via our contact form. If you require emergency incident response, please note this and we will prioritize your matter.