SAKURA Law Office | Legal Update by Managing Partner Kenshiro Michishita
September 24, 2026
SAKURA Law Office | Kenshiro Michishita, Managing Partner
SAKURA Law Office has published the fourteenth edition of the Legal Update series by Managing Partner Kenshiro Michishita: “Legal Due Diligence in Japanese M&A — Key Issues for Buyers and How to Translate DD Findings into Price, SPA Protections, Closing Conditions and PMI (2026).”
Legal due diligence is not merely a process for identifying whether a target company has violated laws or is involved in litigation. Its function is to determine what supports the value of the business the buyer intends to acquire, identify legal risks that may impair that value, and decide how those risks should affect transaction price, structure, the share purchase agreement or other definitive documents, conditions to closing, indemnification, pre-closing remediation and post-merger integration.
The quality of legal due diligence is not measured by the number of documents reviewed or the number of issues listed in a report. Effective diligence requires the buyer and its advisers to understand the target’s business model, transaction rationale, investment amount, risk tolerance, regulatory environment and post-closing strategy, and to concentrate resources on matters that can actually affect the investment decision.
A material issue discovered in diligence is not solved merely because it appears in a DD report. If a major customer agreement contains a change-of-control clause, the deal team must decide whether consent should be a condition precedent, whether a replacement arrangement is required, whether the issue should affect price or whether the risk can be accepted. The same discipline applies to unpaid overtime, licensing defects, IP ownership gaps, cybersecurity weaknesses, data protection issues, litigation and compliance concerns.
This Legal Update explains, based on Japanese law and public materials available as of September 24, 2026, the principal issues buyers, foreign companies, private equity sponsors, venture investors and other investors should examine in Japanese legal due diligence and how the results should be translated into transaction terms.
Executive Summary
The purpose of legal due diligence is not to discover the maximum possible number of issues. It is to identify legal risks that matter to the investment decision and to determine, for each material risk, whether the appropriate response is to terminate the transaction, adjust price, allocate the risk to the seller, require remediation before closing or address the issue through PMI.
The scope of diligence should be tailored to the target’s business model, transaction structure, investment thesis, expected holding period, regulatory environment and dependence on intellectual property, key personnel, customer relationships, technology and data. Applying the same document request list to every transaction is neither efficient nor sufficiently risk-sensitive.
Typical areas include corporate matters, material contracts, licences, financing, employment, intellectual property, IT and cybersecurity, data protection, compliance and whistleblowing, disputes, real estate, environmental matters and product liability. These areas must then be evaluated together in light of the target’s enterprise value.
Japan’s Personal Information Protection Commission expressly addresses disclosure of personal data during pre-signing due diligence in the context of business succession. Where personal data is shared for diligence purposes, the parties should design contractual and operational safeguards covering purpose limitation, handling methods, security incidents and the treatment of data if negotiations fail.
SAKURA Law Office and Managing Partner Kenshiro Michishita view legal due diligence as a core M&A decision-making process: understanding business value, identifying material legal risk and converting that risk into price, contractual protection, closing conditions, remediation and integration.
1. What legal due diligence is really for
Legal due diligence should not become an encyclopaedia of legal observations. The transaction team needs to know which issues can impair enterprise value, business continuity, regulatory status or the buyer’s strategic rationale.
A change-of-control clause in a contract representing 40% of annual revenue may be critical. A technical notice defect in a minor contract may not deserve the same level of reporting.
Materiality should therefore be assessed by likelihood, potential loss, operational impact, remediability, third-party dependency and the buyer’s ability to manage the risk after closing.
2. Designing the scope — start with the investment thesis
The diligence plan should be designed from the transaction rationale. If the buyer is acquiring technology, IP diligence should be deep. If the objective is acqui-hiring, key employees, restrictive covenants, compensation and employment risk deserve greater attention. If customer relationships drive value, major contracts, termination rights, change-of-control provisions and customer concentration become central.
A share acquisition and an asset acquisition also create different diligence priorities. A share deal generally carries historical liabilities within the target company, while an asset deal places greater emphasis on transferability of contracts, licences, employees and assets.
Before diligence begins, the legal team should understand the business, valuation, structure, regulated activities, key assets and transaction timetable and define priority areas and materiality thresholds accordingly.
3. Materiality thresholds — quantitative and qualitative
Legal DD is performed under time and cost constraints. Materiality thresholds may therefore be set for contract value, major customers, significant borrowing, litigation exposure and similar items.
But monetary thresholds do not capture every material risk. Missing core licences, defective title to core technology, major data breaches, bribery, cartel conduct, relationships with anti-social forces or the departure of a critical founder can be decisive even if no immediate monetary amount is large.
Effective diligence uses quantitative thresholds together with qualitative red-flag criteria relating to business continuity, regulation, reputation and governance.
4. Data rooms and Q&A — missing documents can be a finding
Targets commonly provide documents through a virtual data room and answer follow-up questions through a Q&A process.
The buyer should not focus only on the documents that appear in the data room. The absence of documents that should exist may itself reveal control weakness: missing board minutes, inability to locate executed agreements, uncertainty over the current work rules or the absence of a licence register.
Q&A should test not only facts but also explanations: why documents are missing, whether exceptions have become routine and whether management explanations match the written record.
5. Corporate diligence — ownership and validity of corporate actions
Corporate diligence generally covers the articles of incorporation, commercial registry, shareholder register, issuance and transfer history, shareholder and board minutes, classes of shares, options, convertible securities and shareholder agreements.
The buyer must confirm that the seller validly owns the shares, that no third-party security interests attach to them and that required transfer approvals can be obtained. Transfer restrictions are common in private Japanese companies.
In startups and companies that have completed multiple financing rounds, historic issuances, preferred shares, stock options, investment agreements and shareholder agreements may materially affect dilution, consent rights, drag-along rights, tag-along rights and exit mechanics.
6. Material contracts — will the contractual base survive the acquisition?
Major customer, supplier, distributor, outsourcing, licensing, cloud, joint research and financing agreements may directly support enterprise value.
Review should cover term, termination, renewal, pricing, minimum commitments, exclusivity, non-compete, MFN provisions, liability, IP, confidentiality, subcontracting, governing law and dispute resolution, with particular attention to change-of-control, assignment and consent provisions.
If a material consent is required, the transaction team should decide whether obtaining it is a condition to closing, a seller covenant, a basis for alternative arrangements or a pricing issue.
7. Financing, security and guarantees
Diligence should examine bank facilities, bonds, leases, factoring arrangements, security interests, guarantees and financial covenants, including change-of-control or consent provisions that may be triggered by the acquisition.
Targets may guarantee third-party debt, or founder guarantees may support target borrowings and require release at closing. Refinancing may therefore need to be coordinated with the transaction.
Acquisition financing and existing target debt should be analysed early with finance and financial advisers.
8. Licences and regulated businesses
For regulated businesses such as finance, payments, crypto-assets, insurance, communications, pharmaceuticals, healthcare, staffing, construction, real estate, waste management and transport, licensing status can be central to value.
In a share acquisition the target remains the same legal entity, but changes in ownership, major shareholders, directors or control may still trigger approval or notification requirements. Asset deals may require new licences rather than automatic transfer.
Diligence should review not only the existence of licences but also renewal status, conditions, regulator correspondence, administrative guidance, improvement orders, past violations and change notifications.
9. Employment diligence — far beyond unpaid overtime
Employment diligence covers employment agreements, work rules, wages, bonuses, working hours, overtime, fixed overtime schemes, manager classification, leave, severance, social insurance, unions, labour-management agreements, discipline, harassment, terminations and disputes.
In practice, long working hours, misclassification, Article 36 overtime agreements, discretionary work schemes, fixed overtime arrangements, unused leave, harassment, disputes with former employees and key-person retention can all affect value.
From October 1, 2026, Japanese employers are required to implement measures against customer harassment, making related policies, consultation systems and worker protection increasingly relevant to employment diligence.
10. Whistleblowing and compliance — evaluate response quality, not report count
A whistleblowing system should be evaluated by who receives reports, how whistleblower identity is protected, whether investigations are independent and whether there is an alternative route for allegations involving senior management.
Japan’s amended Whistleblower Protection Act takes effect on December 1, 2026 and expands freelancer protection, prohibits interference with whistleblowing and searching for whistleblowers, introduces presumptions in certain dismissal and disciplinary cases and strengthens enforcement. Diligence should therefore review policies, designated personnel, investigation procedures and employment practices.
Bribery, cartels, accounting misconduct, anti-social forces, AML, export control, consumer representations and other compliance areas should be assessed not only for historic violations but also for the effectiveness of internal controls and remediation.
11. Intellectual property diligence — does the value actually belong to the target?
For technology, content, brand and software businesses, intellectual property may be the core of enterprise value. The Japan Patent Office has published standard procedures for IP due diligence in investments, alliances and M&A, covering ownership, licences, disputes, third-party infringement risk and IP management.
The buyer should confirm ownership of patents, trademarks, copyrights, software, know-how, trade secrets and domains and verify that necessary rights have been acquired from employees, officers and contractors.
Where the business depends on third-party licences, the diligence should examine duration, territory, permitted use, sublicensing, change of control, assignment and termination.
12. IT and cybersecurity diligence — technology failure is also a legal risk
Companies heavily dependent on cloud, SaaS or external vendors require diligence on IT contracts and system architecture.
Past data breaches, ransomware, vulnerabilities, access controls, backups, business continuity, logging, incident response and vendor management should be reviewed.
Where AI is used, diligence should also consider confidential and personal data entered into generative AI, unapproved AI, AI-agent permissions, training use and contracts with external AI providers.
13. Data protection — due diligence itself is subject to the APPI
Where the target holds customer, employee, member or user information, diligence should review purposes of use, privacy notices, third-party transfers, outsourcing, joint use, cross-border transfers, security measures, data breaches and data subject requests under Japan’s APPI.
An equally important issue is disclosure of personal data to the buyer during diligence. The PPC’s guidelines treat certain disclosures in the context of merger, corporate separation, business transfer and other business succession as outside ordinary third-party transfer rules.
The guidelines also recognize that personal data may be provided during pre-contract negotiations for purposes of diligence, subject to appropriate contractual safeguards concerning purpose, handling, incident response and measures if negotiations fail.
Accordingly, employee lists, customer data, complaint records and whistleblowing records should not be placed indiscriminately into the data room. Necessity, masking, access restrictions, download controls, purpose limitation and deletion obligations should be designed deliberately.
14. The 2026 APPI amendments — distinguish enacted law from law not yet in force
Amendments to Japan’s APPI were promulgated on July 17, 2026. Major provisions remain subject to future commencement, so diligence conducted on September 24, 2026 must distinguish current law from enacted but not-yet-effective requirements.
For data-driven businesses, future compliance cost can affect value even where current practices are lawful. Buyers should monitor implementing orders, PPC rules and guidance as the amended framework develops.
15. Litigation and disputes — look beyond cases already filed
Diligence should cover pending litigation, arbitration and regulatory investigations, as well as warning letters, threatened claims, customer complaints, product incidents, IP notices and employment disputes.
Evaluation should consider not only claim value but also likelihood, injunction risk, business continuity, key customer relationships, reputation and management involvement.
Material disputes may warrant a specific indemnity, escrow, holdback, pre-closing settlement or other tailored solution rather than reliance on general warranties.
16. Real estate, environmental and product liability matters
For manufacturing, real estate, logistics, energy and similar businesses, title, leases, soil contamination, waste, environmental regulation, building and fire compliance and equipment maintenance may become core diligence areas.
Product businesses may require review of product liability, recalls, safety standards, quality assurance, serious incidents and insurance coverage.
Technical, environmental or insurance specialists may need to work alongside legal counsel rather than treating every issue as purely legal.
17. Antitrust, FEFTA and sector regulation — transaction regulation should run in parallel with DD
Legal DD examines the target; regulatory analysis examines the transaction itself. The two workstreams should proceed together.
Japan merger control, FEFTA foreign investment screening and sector-specific change-of-control rules can directly affect timetable and closing certainty.
For foreign buyers, the target’s business, important technology, investor attributes and ultimate ownership should be reviewed early so that FEFTA analysis runs in parallel with diligence.
18. Classifying red flags — terminate, price, contract, remediate or integrate
Findings should be classified by the appropriate response. A missing licence that makes continued operation unlawful, ownership of core technology by a third party or ongoing serious misconduct may be a deal breaker.
Quantifiable liabilities may be handled through price or indemnification. Curable matters may become closing conditions or pre-closing covenants. Control weaknesses that can be improved after closing may become PMI items.
This classification transforms a DD report into a transaction decision tool.
19. Translating DD into price
Where diligence identifies liabilities or future costs that affect value, the buyer may revisit the purchase price.
Potential examples include unpaid overtime, under-reserved litigation, licensing costs, facility remediation and cybersecurity upgrades.
Not every risk can be solved through price. Uncertain or high-impact matters may require a combination of indemnities, escrow, holdback or closing conditions.
20. Translating DD into representations and warranties
SPAs commonly include representations concerning shares, financial statements, contracts, licences, employment, tax, IP, data protection, disputes and compliance.
But where the buyer knows of a specific issue, general warranties may not be enough. Disclosure schedules, knowledge qualifiers, materiality, caps and survival periods may limit recovery.
Known material risks should often be addressed through specific indemnities, remediation covenants or pricing mechanisms.
21. Specific indemnities, escrow and W&I insurance
Identified litigation, tax, employment, IP or regulatory risks may justify specific indemnification provisions.
Where the seller is a fund or SPV expected to distribute proceeds after closing, contractual rights may have limited practical value unless recoverability is secured. Escrow, holdback, guarantees, parent support or warranty and indemnity insurance may therefore be relevant.
Diligence should inform not only what the buyer is entitled to claim, but whether recovery will realistically be available.
22. Conditions precedent and pre-closing covenants
Required regulatory approvals, material third-party consents, release of security, IP transfers, dispute resolution or other essential steps may be structured as conditions precedent.
Matters that should be fixed before closing but do not justify a CP may be addressed through pre-closing covenants.
Too many conditions can reduce deal certainty. Drafting should take account of materiality, remediability, third-party dependency and termination rights.
23. Carrying DD findings into PMI
Many diligence findings cannot be fully remediated by closing. Policies, contract management, privacy controls, cybersecurity, IP management, whistleblowing and employment systems may require post-closing improvement.
DD reports should therefore identify PMI owners, deadlines, priorities and completion standards rather than being archived after closing.
Foreign buyers should adapt global policies to Japanese law and employment practice rather than imposing them mechanically.
24. Vendor due diligence — the seller can prepare too
A seller may conduct vendor or sell-side due diligence before launching a process.
The objective is not to conceal issues, but to identify and remediate problems in advance, improve documentation, regularize IP ownership, renew contracts, complete licence filings and organize disputes, thereby improving deal certainty.
Vendor diligence can also support efficient disclosure in auction processes involving multiple bidders.
25. Using generative AI in due diligence
Generative AI is increasingly used for contract review, data-room summarization and Q&A organization.
DD materials, however, contain trade secrets, personal data, confidential M&A information and third-party confidential information. AI provider terms, training use, retention, access, cross-border processing and security must therefore be reviewed before documents are uploaded.
AI-generated issue spotting and clause extraction can be wrong. Human legal review remains necessary for final judgments, particularly on red flags and transaction protections.
26. Cross-border M&A — integrate Japanese diligence into the global process
In acquisitions by foreign companies, Japanese legal diligence should be integrated into the global diligence framework.
Headquarters, foreign counsel, financial advisers, accountants and tax advisers should align materiality thresholds, reporting format, red-flag definitions, Q&A ownership and timing.
Japanese counsel should also explain why Japan-specific issues — employment law, licensing, APPI, FEFTA and tender offer regulation — matter in terms that allow overseas decision-makers and investment committees to act.
27. SAKURA Law Office’s approach to legal due diligence
SAKURA Law Office and Managing Partner Kenshiro Michishita view legal due diligence not as an exercise in finding problems, but as an information platform for investment decisions and M&A contract design.
The key is to understand the target’s business value, identify the contracts, licences, people, IP, data and technology supporting that value, determine where material legal risk exists and then convert those findings into price, warranties, specific indemnities, closing conditions, pre-closing remediation or PMI.
SAKURA Law Office advises Japanese and foreign clients across M&A, corporate law, international transactions, AI/IT, data protection, IP, employment and crisis management, supporting legal diligence, transaction documents, regulatory analysis, closing and post-merger integration on an integrated basis.
28. Frequently Asked Questions
Q1. How much documentation should be reviewed in legal due diligence?
There is no universal amount. The scope should reflect the target’s business, value, structure and acquisition rationale, using quantitative and qualitative materiality thresholds.
Q2. Does a red flag mean the acquisition should be abandoned?
Not necessarily. The issue may be a deal breaker, or it may be manageable through price, indemnity, conditions precedent, pre-closing remediation or PMI.
Q3. Can representations and warranties replace legal due diligence?
Generally no. Warranties are subject to disclosure, caps, survival periods, knowledge qualifiers and seller credit risk. Diligence and contractual protection should complement each other.
Q4. Can personal data be disclosed to a buyer through a data room?
Japanese PPC guidance recognizes certain disclosures during pre-signing due diligence in the context of business succession, but contractual and operational safeguards are required concerning purpose, handling, incidents and failed negotiations.
Q5. What should a buyer do if a key contract contains a change-of-control clause?
Depending on materiality, the buyer may require consent as a closing condition, impose a seller covenant, establish an alternative arrangement or reflect the risk in price.
Q6. How should unpaid overtime risk be reflected in the transaction?
The potential exposure should be estimated and may affect price, specific indemnification or escrow, together with post-closing employment remediation.
Q7. Is cybersecurity part of legal due diligence?
Yes. Data breaches, ransomware, access controls, vendor management, backups and incident response can materially affect enterprise value and should be reviewed together with IT specialists.
Q8. What is especially important in startup M&A diligence?
Cap table, options, investment and shareholder agreements, IP ownership, founder and key-person arrangements, customer concentration, data/AI use and financing documents are often critical.
Q9. Should sellers conduct legal due diligence before a sale?
In appropriate cases yes. Vendor diligence can identify and remediate issues, improve disclosure quality and increase transaction certainty.
Q10. What additional diligence applies when a foreign company acquires a Japanese target?
FEFTA, merger control, sector licences and, for listed targets, tender offer and securities rules should be analysed from the beginning alongside the target-level diligence.
29. About the Legal Update Series by Kenshiro Michishita
SAKURA Law Office publishes the Legal Update series through the profile of Managing Partner Kenshiro Michishita, addressing major issues affecting businesses and management in M&A, corporate law, international transactions, AI/IT, data protection, intellectual property, crisis management, employment, whistleblowing and Web3/financial regulation.
This fourteenth edition follows Legal Update No. 11 on Japan’s 2027 FEFTA reform, No. 12 Doing Business in Japan 2026 and No. 13 on acquiring a Japanese company, and provides a deeper analysis of one of the central stages of M&A execution: legal due diligence.
Future Legal Updates will address share purchase agreements, representations and warranties, litigation in Japan, recognition and enforcement of foreign judgments and international arbitration.
30. How SAKURA Law Office Can Assist with Legal Due Diligence and M&A
SAKURA Law Office advises Japanese and foreign clients on buyer-side and seller-side legal due diligence, vendor due diligence, scope and request-list design, data-room and Q&A processes, red-flag analysis, transaction documents, FEFTA and antitrust issues, closing and post-merger integration.
For cross-border transactions, we work in English with overseas headquarters, General Counsel, M&A teams, investment committees, foreign counsel, financial advisers and accounting and tax professionals to integrate Japanese-law findings into the global transaction process.
Clients may consult us at an early stage before a target is finally selected, before an LOI is signed or while the diligence scope is being designed.
31. Contact
For advice on M&A, legal due diligence, share purchase agreements, FEFTA, merger control, cross-border transactions and other Japanese corporate or international legal matters, please contact SAKURA Law Office.
When contacting us, please indicate that your inquiry concerns M&A or legal due diligence so that it can be directed promptly to the appropriate lawyer.
SAKURA Law Office
Kenshiro Michishita, Managing Partner
4F Ark Hills South Tower, 4-5 Roppongi 1-chome, Minato-ku, Tokyo 106-0032, Japan
Tel: +81-3-6910-0692
Written and supervised by
Kenshiro Michishita
Managing Partner, SAKURA Law Office
Principal References
Japan Patent Office — Standard Procedures for Intellectual Property Due Diligence (SKIPDD)
Personal Information Protection Commission — Materials on the 2026 amendments to the APPI
Ministry of Health, Labour and Welfare — Materials on customer harassment prevention measures
Consumer Affairs Agency — Whistleblower Protection Act and 2026 amendment materials
Japan Fair Trade Commission — Merger Review
Ministry of Finance — Inward Direct Investment Screening under FEFTA and 2026 reform materials
Ministry of Justice / e-Gov — Companies Act and related statutes
This article provides general information based on Japanese law, public materials and general M&A practice available as of September 24, 2026. It does not constitute legal advice concerning any specific transaction. The scope, materiality thresholds and methodology of legal due diligence, the manner in which findings should be reflected in definitive agreements, and the applicability of licensing, FEFTA, antitrust and other regulatory requirements vary according to the target’s business, size, listed or unlisted status, transaction structure, buyer attributes, ownership percentage, regulated activities, timetable and other facts. Certain laws enacted in 2026 had not yet entered into force as of the date of this article. Specific transactions should be assessed by reference to the laws, regulations, official guidance and public materials in effect at the relevant time.