DxtraBETA
Back to blog
Use CasesJapanNiche CommerceSmall Business July 2026 7 min read

Digging in Tokyo: Privacy Rules for Japanese Record Shops with International Customers

Niche shops sell across a counter in one country to customers from a dozen others. This looks at Tokyo's second-hand vinyl trade to work out which privacy rules actually apply, and which only apply once you start selling abroad on purpose.

Daryl ArnoldDaryl Arnold
A basement record shop in Tokyo: racks of second-hand sleeves under warm light, with a counter, a mailing-list slip and a laptop.

A Saturday afternoon, one floor below street level

You go down a narrow staircase off a Tokyo side street and the temperature drops. Racks to the ceiling, sleeves in clear plastic, a handwritten sign about new arrivals from a collection bought last week. A man in his sixties works the jazz section with the patience of someone who has done this a thousand times. Two people are speaking Swedish by the soul racks. An American who teaches English three stops down the line is at the counter, paying cash for a record he has been chasing since March.

Behind the till: a point-of-sale terminal, a slip of paper for the mailing list, a laptop with the shop's Instagram open, maybe a small storefront page for the new items sold online. That is the whole data operation. Nobody in this room has a compliance function.

And yet the customer base in that basement spans four or five countries. That is what makes niche commerce a distinct privacy situation rather than a smaller version of everyone else's: the business is tiny and entirely domestic, and the customers are international. Owners here tend to make one of two errors. They read something alarming about European rules and start bolting consent banners onto a site nobody outside Japan can order from, or they decide the question belongs to companies with legal departments and stop thinking about it. The useful work lives in between.

Disk Union is the example most people reach for, so it is worth setting out what kind of business we mean. It is a long-established Japanese chain headquartered in Tokyo, with many branches, several specialising by genre — jazz, punk, classical, Latin. It has a mail-order and online arm, runs its own labels, and its main Japanese-language site sits at diskunion.net — a .net domain, not a country-code .jp, which will matter shortly. Roughly ninety percent of its stock is second-hand, and second-hand items cannot be bought online from overseas; an overseas buyer can order new items through the international channel, but the used racks require standing in the shop. Separately, diskunionusa.net is a buying and export operation, not a consumer storefront. That shape — deep domestic retail, a modest online arm, customers who arrive by plane — is niche commerce everywhere, whether you sell records, rare books or vintage cameras.

Why Japan in particular

This is not a nostalgia story. Japan's recorded-music market remains unusually physical: per the Recording Industry Association of Japan, physical media was 57.2 percent of the recorded-music market in 2025, and vinyl production reached ¥8.4 billion and 3.378 million units, passing ¥8 billion for the first time in thirty-seven years.

So a whole category of small, counter-based specialist is commercially healthy here in a way it is not elsewhere — and these shops are destinations. Collectors plan trips around them; expatriates become regulars. The shop that never thought of itself as an exporter is, in customer terms, running an international business out of one basement.

What actually applies when your customers are foreign and your business is not

Start with the law that unambiguously covers you. Japan's Act on the Protection of Personal Information (APPI) applies to your handling of personal information, and the regulator is the Personal Information Protection Commission. That holds regardless of where your customers come from: a Swedish collector's name and email in your mailing list is personal information you hold under Japanese law.

Now the question owners actually worry about. Does the GDPR reach a Tokyo record shop because Europeans shop there? Article 3(2) turns on offering goods or services to people who are in the Union. An EU citizen standing in your shop in Tokyo is not in the Union, so selling to them across the counter does not, by itself, bring you within the GDPR. Citizenship is not the trigger; location and intent are.

What changes the answer is deliberate targeting. Build pages in European languages aimed at those markets, quote prices in euros, offer shipping to EU countries or advertise into Europe, and you are no longer serving people who happened to walk in. So the practical advice for a niche shop is not "install a banner" but "decide, on purpose, whether you are an exporter" — most shops drift across that line rather than crossing it, usually by adding a shipping option one afternoon.

One reassurance: the EU and Japan have had mutual adequacy in place since 23 January 2019, extended to cover the academic and research sector on 18 September 2025.

One more difference catches people out. Japan has no ePrivacy equivalent, so there is no rule requiring consent simply to set a cookie. The relevant hook is APPI Article 31(1): obligations attach at the point where personally-referable information, such as a cookie ID, is provided to a third party who will link it to an identified individual. That narrower trigger explains why cookie banners are much less common on Japanese sites — a Priv Tech survey reported by Nikkei measured prevalence at roughly 4.75 percent in 2020, rising to about 7.0 percent in 2021. Illustrative figures, but the direction is clear.

So the core duties for a shop like this are the APPI ones: specify and publicly state your purpose of use, obtain consent before providing personal data to a third party, take security control measures, and handle overseas transfers with the required consent and information.

What an automated scan sees when the site is in Japanese

Language is not the obstacle people assume. A scan reads a site's public surface — the privacy notice, the consent and tracker behaviour, the route a customer would use to exercise their rights — regardless of the language it is written in.

The more interesting problem is jurisdiction, and this is where a .net domain matters. A naive tool would read .net as generic and guess wrongly. A sensible scan does not decide the applicable regime from the domain suffix alone; it keys off real-world signals, either a country-code domain or an explicit reference in the notice to a named law or regulator. A .net domain carrying a Japanese-language notice that names the APPI or the PPC is anchored by the notice, not the domain. Where those signals are absent, the scan records the limitation rather than guessing — an honest "cannot determine" beats a confident wrong answer.

The check also runs from an in-country vantage, so it observes what a visitor in that region actually sees — which matters because consent surfaces and tag behaviour often vary by visitor location. What comes out is a risk band with findings mapped to named sources: a diagnostic indicator to work from, not a determination of compliance.

What you actually do about it

Publish a purpose-of-use statement in the language your customers read. The APPI asks you to specify and publicly state why you collect personal information. For most shops that is a short paragraph: we use your name and email to tell you about new arrivals and to handle your order. Write it in Japanese, and add an English version if enough of your customers read English. Highest-value item here, and it takes an afternoon.

Be deliberate about who else touches the data. This is where the APPI's obligations actually bite, because third-party provision is the regulated event rather than the mere existence of a cookie. List every tool that receives customer information — the mailing platform, the analytics, the pixel a friend added to help with ads, the storefront provider — and for each, ask whether personal data is going to a third party and whether you have the consent that requires. Most shops find a surprise.

Decide consciously whether you are targeting overseas customers. Not "would we take an order from Berlin" but "are we offering our goods to people in Europe." Euro pricing, European-language marketing pages, EU shipping and ads aimed at EU countries are the signals, and they are all things you choose. Either commit and accept the European rules that come with it, or keep the online arm domestic and let overseas customers do what they already do — come to the shop.

Make the rights route findable. Someone should be able to read your notice and see, in ten seconds, how to ask what you hold about them or to come off your list. An email address is enough. The failure mode is rarely refusal; it is that nobody can find where to ask.

Review the notice when something structural changes. A new shipping destination, a new storefront platform, a new mailing tool, an international channel — each is a moment when the notice you wrote two years ago stops describing what you do. An annual reminder is a fine backstop, but the real trigger is the change.

Where Dxtra fits

Dxtra generates a privacy program from a questionnaire — a privacy policy, cookie notice, consent records, processing records, a public Transparency Center and DSAR handling — covering more than 500 obligations across 140-plus countries, from $10 a month. For a shop where the owner also does the buying, the grading and the counter, it turns an open-ended research task into a form you fill in once and revisit when something changes.

Dxtra's free scan reads a site's public pages in about two minutes with no signup, and returns a risk band with findings mapped to named sources.

The short version

Where your customer is physically standing, and who you deliberately set out to sell to, do most of the work in answering which rules apply. A collector who flies in from Stockholm to spend three hours in your basement is your customer under Japanese law. The day you put up a euro-priced page that ships to Sweden, that changes — and it should change on purpose, not as a side effect of a checkbox.

Niche commerce has always been about knowing exactly what you have and who wants it. The privacy version is knowing exactly what you hold and who you give it to. Same discipline, different shelves.

This article is general information, not legal advice. Rules change; confirm anything that matters with the Personal Information Protection Commission (ppc.go.jp) or a qualified adviser before you rely on it.

Ready to get compliant?

Start your privacy program today — from $10/month.