Instiq
Chapter 6 · Corporate activities, law & security governance·v1.0.0·Updated 8/7/2026·~15 min

What's changed: Initial version

6.4Law, standardization & security governance

Key points

Covers intellectual property (copyright/patent/unfair-competition-prevention), the compliance duties under the Subcontract Act (Act on Optimizing Small/Medium Subcontract Transactions), the PL Act, worker dispatch and disguised subcontracting, standardization (ISO/JIS/de facto), and information-security governance, so an IT strategist can wield them when judging compliance risks in procurement, outsourcing, and the business.

In procuring or outsourcing systems and planning new businesses, an IT strategist is asked to make judgments that pre-empt the management risk of legal violation. This section covers, from the standpoint of how to judge in the procurement and outsourcing field: intellectual property (copyright, patents, unfair-competition prevention) for protecting one's own technology and brand without infringing others' rights; the Subcontract Act (Act on Optimizing Small/Medium Subcontract Transactions) that keeps subcontracting fair; the PL Act on liability for product defects; worker dispatch and disguised subcontracting over how to use external personnel; standardization (ISO/JIS, de facto) that governs market interoperability; and information-security governance that governs information security as a management agenda.

6.4.1Intellectual property and fair subcontracting

  • Copyright protects the expression of programs and the like and arises automatically at creation (no formalities, no registration required), but does not protect the idea (technical concept) itself, such as an algorithm. To monopolize a technical concept, protect it with a patent (rights arise after application and examination). Unfair imitation of a brand or product indication is guarded by the Unfair Competition Prevention Act (a trade secret requires being managed as secret).
  • The Subcontract Act (Act on Optimizing Small/Medium Subcontract Transactions; name revised 2026-01) imposes on the ordering party (parent business) duties such as issuing a document at order time (Article 3 document) and setting the payment date within 60 days of receipt, and prohibits refusal of receipt, delayed payment, reductions, and beating-down of prices. Note that the 1 January 2026 revision prohibits payment by promissory note in principle, whether or not the note is easy to discount; payment must be made in cash (e.g. bank transfer) by the payment date. (The former Subcontract Act only regulated issuing a *hard-to-discount* note — this is the crux of the change.) Electronically recorded monetary claims and factoring are likewise prohibited where the supplier cannot obtain the full amount (including fees) by the payment date, and making the supplier bear bank transfer fees is prohibited. The revision also adds a duty to engage in price negotiation and extends scope with an employee-count test (300 for manufacturing-type, 100 for service-type consignment).

6.4.2Liability, employment, standardization, and security governance

  • The PL Act (Product Liability Act): when a product's defect causes harm to life, body, or property, the manufacturer bears liability regardless of fault (no-fault liability). In worker dispatch, the right to direct lies with the client (dispatch destination), whereas in subcontracting it lies with the contractor (the outsourced party), and if the ordering party directs the contractor's personnel directly and routinely, it becomes disguised subcontracting (violating the Worker Dispatch Act, etc.).
  • Standardization includes public standards such as ISO (international) and JIS (domestic), and the de facto standard that becomes the standard in practice through market competition. It affects interoperability and procurement options, and one judges strategically which standard to comply with or follow. Information-security governance means governing information security as a management agenda—not leaving it to the field, but having management decide and oversee policy and investment based on risk (security investment is decided by cost-effectiveness and management judgment).
Exam point

Most-tested: "copyright protects expression, not ideas, and needs no registration / a patent protects a technical concept via application and examination", "under the revised Act (in force 1 Jan 2026) payment by promissory note is prohibited in principle — pay in cash by the payment date; the payment date is within 60 days of receipt; issuing a document is a duty", "in subcontracting the right to direct lies with the contractor and direct direction by the ordering party is disguised subcontracting / in dispatch the right to direct lies with the client", and "the PL Act is no-fault liability." Learning the former rule ("only hard-to-discount notes are regulated") will now cost you the mark — the 2026 revision changed it to a general prohibition.

An IT strategist is reviewing the contract and payment terms of an outsourced system-development engagement and judging compliance risk. On payment terms, the accounting department consults: "We plan to keep paying the subcontract price by promissory note as before; that should be fine as long as the note is not hard to discount." The strategist judges that the revised Act (Act on Optimizing Small/Medium Subcontract Transactions), in force on 1 January 2026, prohibits payment by promissory note in principle. Under the former Subcontract Act only "issuing a note the subcontractor finds hard to discount" was regulated, but after the revision a note cannot be used regardless of how easy it is to discount, and payment must be made in cash (e.g. bank transfer) by the payment date. Alongside this, the ordering party must issue an Article 3 document at order time, set the payment date within 60 days of receipt, and engage in price negotiation (a newly added duty); the review confirms whether these are met. Because scope now also includes an employee-count test (300 for manufacturing-type, 100 for service-type consignment) on top of the capital test, the strategist rechecks whether counterparties previously out of scope have come into scope. Next, on how to run development, the business unit hopes to "outsource development to an external vendor under a subcontract, but have our staff give the vendor's engineers detailed daily work instructions directly." The strategist judges that this carries a risk of disguised subcontracting. Under a subcontract, the right to direct lies with the contractor (vendor), and if the ordering party directs the contractor's personnel directly and routinely, the substance amounts to worker dispatch and becomes disguised subcontracting violating the Worker Dispatch Act, etc. If the ordering party truly needs to direct the personnel, the correct response is to make the contract form a worker-dispatch contract. Finally, the strategist also considers whether the deliverables infringe another company's intellectual property (unauthorized use of others' works or patent infringement), and whether protecting the firm's own processing method requires a patent application because copyright (protection of expression) is insufficient. The IT strategist thus judges each procurement and outsourcing term against the law and roots out the management risk of legal violation at the design stage—here, judging from memory of the former Subcontract Act that "a note is fine as long as it is not hard to discount", or conversely overlooking the disguised-subcontracting risk and allowing direct direction, would each be a compliance-judgment error.

TopicCorrect understandingCommon error
Copyright/patentCopyright protects expression, no registration / patent protects the technical concept via applicationCopyright protects ideas / a patent arises automatically
Notes under Subcontract ActThe 2026-01 revision prohibits note payment in principle; pay cash by the due dateRemembering the former rule that only hard-to-discount notes were regulated
Subcontract/dispatchContractor directs in subcontracting / client directs in dispatchOrdering party directs directly in a subcontract (disguised)
PL ActNo-fault liability for harm from a defectNo liability unless fault is proven
Warning

Trap: "A note is fine as long as it is not hard to discount" was the rule under the former Subcontract Act and is now wrong—the revised Act in force on 1 January 2026 prohibits payment by promissory note in principle, whatever its discountability, and payment must be made in cash (e.g. bank transfer) by the payment date. On top of that the ordering party must issue an Article 3 document, set the payment date within 60 days of receipt, and engage in price negotiation (a newly added duty).Also wrong: "even under a subcontract the ordering party may directly direct the contractor's personnel"—routine direct direction is disguised subcontracting, and if direct direction is needed, use a worker-dispatch contract. "Registering a copyright lets you monopolize even the algorithm (idea)" is also wrong (copyright protects expression and needs no registration; ideas are for patents).

Legal checks in procurement and outsourcing.
Judge contract terms against the law

6.4.3Section summary

  • Copyright protects expression, needs no registration, and does not protect ideas; a patent protects a technical concept via application and examination
  • The revised Act (formerly the Subcontract Act), in force 2026-01, prohibits note payment in principle — pay cash by the due date. Duty to issue a document; payment date within 60 days of receipt; duty to engage in price negotiation
  • In subcontracting, direct direction by the ordering party becomes disguised subcontracting (direct direction requires a dispatch contract); the PL Act is no-fault liability

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. For an outsourced system-development engagement in FY2026, the accounting department says, "We plan to keep paying the subcontract price by promissory note; that should be fine as long as the note is not hard to discount." Which judgment by the IT strategist is most appropriate?

Q2. A firm wants to protect the processing method (a technical idea) of its independently developed business system from imitation by competitors. Which advice by the IT strategist is most appropriate?

Q3. A firm outsources system development to an external vendor under a subcontract, but the ordering party's staff wish to give the vendor's engineers detailed daily work instructions directly. Which judgment by the IT strategist is most appropriate?

Check your understandingPractice questions for Chapter 6: Corporate activities, law & security governance

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.