Skip to main content

LINE Governance, Security and Compliance

LINE's Official Account Guidelines are unusually prescriptive, and enforcement is unilateral: LINE may refuse, suspend, or terminate an account and is under no obligation to explain why, offer compensation, or issue a refund. A team that reads only the API pages will not know this. This page states the rules that apply to your account, the enforcement model behind them, LINE's development obligations that survive the 8x8 abstraction, and the 8x8 platform controls available to you.

Sections 1 through 5 are LINE's rules, not 8x8's. The authoritative text is LINE's Official Account Guidelines.

Account Eligibility

LINE states that the service is unavailable to any company, organization, or individual it deems to fall into any of these categories:

  1. Providing a product or service which may be used for the purposes of criminal activity.
  2. Engaged in illegal or criminal activity, or facilitating it.
  3. Involved in the illegal or illicit sale or purchase of another individual's personal details, registration details, or usage history, or acting as an intermediary or agent for it.
  4. Committing acts in violation of laws and ordinances, or of standards of public order and decency, or which may be considered to be in violation of the same.
  5. Determined by LINE to have committed any prohibited act established in Article 17 of the Terms of Use.
  6. Determined by LINE to be inappropriate as a customer of the service for any other reason. LINE gives examples: parties which may confer any disadvantage to LINE users, may adversely affect trust in LINE's public image, or may involve LINE in complaints, claims for damages, or other conflicts.

LINE separately publishes a list of product and service categories for which promotion via LINE is prohibited, and may reject, suspend, or nullify a contract on those grounds. The categories include adult products and services, dating and matchmaking services, get-rich-quick and easy-success marketing schemes, trading of virtual goods or game currency for real money, sale of social media accounts or followers, network marketing schemes, sales using fear or pressure tactics, sales claiming guaranteed outcomes, credit-card-limit cash conversion services, casinos and online casinos, sale or brokerage of personally identifying information, sale of counterfeit or pirated goods, and medical products not yet approved for use in Thailand.

Important: LINE states explicitly that this list is not exhaustive, and that the service may also be declined or suspended in cases other than those listed. Do not read the published list as a safe harbour. If your business sits near any of these categories, resolve it before provisioning rather than after.

Prohibited Content and Activities

Irrespective of account type, it is your responsibility to ensure that nothing distributed from your account, including chats, posts, and auto-replies, and nothing in your account settings, involves any of the activities prohibited under Article 17 of LINE's Terms of Use. Condensed into the categories that most affect a messaging programme:

  1. Illegality:
    • Activities that violate the law, court verdicts, resolutions, orders, or legally binding administrative measures.
    • Illegal activities, or activities that aid or encourage illegal activity.
  2. Third-party rights:
    • Activities that infringe intellectual property rights, including copyright, trademark, patent, fame, and privacy, whether LINE's or a third party's.
    • Activities that illegally or improperly lead to the collection, disclosure, or provision of a third party's personal information, registered information, or user history.
  3. Third-party advertising and user profiling:
    • Using the account as an advertising medium for a third party is prohibited.
    • When delivering advertisements or messages that use deemed attributes, identifying the attributes of the users who come into contact with them is prohibited. LINE names two specific techniques: specifying individual transition destinations per attribute, and adding information to the destination URL that makes the transition path traceable. If your campaign design relies on per-segment landing pages or per-segment tracking parameters, it breaches this rule.
  4. Misrepresentation and scope:
    • Activities that lead to misrepresentation of LINE or a third party, or that intentionally spread false information.
    • Distributing content unrelated to the business you declared at the time of application. Your account must stay within the business it was approved for.
  5. Harmful expression:
    • Violent or sexual expressions; expressions that discriminate by race, national origin, religion, gender, social status, or family origin; expressions that induce or encourage suicide, self-injury, or drug abuse; and anti-social expressions.
    • Using the service for sexual or obscene purposes, for arranging sexual or romantic encounters, for harassment or libel against other users, or for purposes other than the service's main purpose.
  6. Platform abuse:
    • Distributing content that may cause discomfort or inconvenience to users or third parties.
    • Interfering with the service's servers or network systems, with LINE's operation of the service, or with users' use of it.
    • Deliberately taking advantage of defects in the service.
    • Making unreasonable inquiries or undue claims of LINE.
  7. Other LINE terms:
    • Distributing content that contravenes the LY Corporation Common Terms of Use or the LINE Logo Usage Guidelines.
    • Aiding or encouraging any of the above, or anything else LINE deems inappropriate.

LINE publishes user-protection precautions that apply to everything distributed from an account, whether or not it is used commercially:

  • No links that do not work on a smartphone. LINE asks you to refrain from posting links that cannot be viewed or operated on iOS or Android, and recommends that every linked page display properly on a smartphone.
  • Links must be related to the message. Links to pages with no direct relationship to the text or creative content are prohibited, as are links to pages not under your practical control. The message title, the content, and the linked page must all be related and must not strike users as unnatural.
  • No confusing or non-functional interface elements. Unclear links, non-functional buttons or menus, and anything else that may confuse users or cause operational errors is prohibited.
  • App download prompts. Consult the App Store and Google Play regulations, alongside LINE's own terms, before inducing users to download an app. LINE also warns that if Apple or Google determines that significant ranking changes resulted from app notifications via LINE, the promoted app risks rejection for ranking manipulation.
  • Corrections must be labelled as corrections, and LINE charges a correction message at the same rate as a normal message.
  • Icon image changes are rate-limited by LINE. An icon image cannot be changed again for one hour after being changed. For accounts whose friend count exceeds a threshold, the icon cannot be changed unilaterally at all and a separate request must be filed. LINE asks you to avoid sudden or frequent changes.

Advertising and Promotion Rules

  • The advertiser's name must be clearly displayed. In images it must be displayed at a clearly visible size.
  • Credit the rights holder. When you use materials that do not belong to you, the rights holder's name must be displayed and the relationship between the rights holder and you clearly explained.
  • Resale of advertising space to a third party is prohibited, except where LINE specifically permits it. Advertisements for multiple entities, and purchase of advertising space by groups of entities, are not allowed. Using the account to release information about unrelated third parties is fundamentally prohibited on user-protection grounds.
  • The three published exceptions to the resale prohibition are: a clear controlling relationship between the two entities where users will not be confused or misled; a clear logical necessity for the two entities to produce a combined advertisement; or the two entities sharing a Collaborative Account, which LINE provides as a separate advertising menu.
  • You may promote only your own products and services, or those produced by an entity with whom you share a Collaborative Account.

Verified Account Naming Rules

LINE requires Verified Account names to follow four rules:

  1. Names must include the official name of the company, organization, or self-employed person, or the official name of the product or service they provide.
  2. Names must not imply the existence of companies, organizations, self-employed persons, products, or services which do not exist.
  3. Names must not include text strings which are non-factual or which may lead to erroneous inferences.
  4. Names must not imply that they pertain to products or services offered by LINE or its affiliated companies.

Names that infringe these rules may be subject to a request for amendment from LINE. LINE states that, in principle, it does not accept account name changes for Verified Accounts. Where the company or service name has genuinely changed, a name change request triggers a separate screening process. See Why Verified Account Matters.

Enforcement and Penalties

LINE's enforcement model has four properties that materially affect risk planning:

  • No pre-publication approval, but real-time monitoring. LINE states that as a rule there are no pre-posting checks, but that it may monitor all transmissions in real time. Transmissions found to infringe the precautions may be deleted and the associated account suspended.
  • Unilateral penalties. Where LINE determines that content distributed from an account, or the account's settings, are inappropriate or breach the guidelines, LINE may impose any or all of the published penalties, or others of a similar type, including rejecting the opening of accounts, suspending accounts, and nullifying the contract.
  • No obligation to explain. LINE states it shall not be required in any instance to provide reasons for any penalty imposed.
  • No liability, compensation, or refund. LINE states it shall not be subject to any liability, compensation, or refund arising from a penalty.

Two further operational facts belong here:

  • A sent message cannot be recalled. Once transmitted to users, messages cannot be deleted or amended by you or by LINE. There is no unsend, and no correction mechanism other than sending a further message clearly labelled as a correction.
  • Guidelines and functionality can change without notice. LINE states that the service's functionality, including the Official Account admin screen, and the content of the guidelines may be changed without prior notice, and that continued use after such a change constitutes your agreement to it.

Development Obligations

These are LINE's own engineering rules for the Messaging API. They apply directly if you operate your own LINE bot server, and the principles behind them survive the 8x8 abstraction.

Prohibited by LINE

  • Do not exceed LINE's rate limits. Requests over the limit receive 429 Too Many Requests. Limits are applied per endpoint, per channel, and an endpoint with a different HTTP method counts as a different endpoint. Most endpoints allow 2,000 requests per second, but several are far lower, including 60 requests per hour for broadcast and narrowcast sends and for the statistics endpoints.
  • Do not load test through the LINE Platform. LINE offers no load-testing service and asks you to prepare a separate environment for load testing your own servers.
  • Do not send mass messages to the same user.
  • Do not send requests to user IDs that do not exist.
  • Do not attempt to identify user attributes for a specific user ID, including by using the audience management API or narrowcast messages to infer them.
  • Do not restrict access by IP address on servers that receive LINE webhooks. LINE does not disclose its platform IP addresses and they change without notice. Verify the signature instead.
  • Honour unsend events. When a user unsends a message, LINE sends an unsend event. LINE asks you to respect the user's intent and handle the message so it cannot be seen or used in future.
  • Verify webhook signatures before processing any webhook event. See If You Also Receive Webhooks Directly from LINE.
  • Assume non-breaking additions. LINE may add endpoints, optional request parameters, response fields, webhook event properties, and new enumerated values without advance notice. Build so that none of those break you.
  • Keep your own logs. LINE states it does not provide logs for Messaging API requests or for webhooks it sent, even on request. LINE recommends logging the request ID, timestamp, HTTP method, endpoint, and status code for each API call, and the sender IP, timestamp, method, request path, and returned status code for each webhook received.

Note

The rate limits above are LINE's, and they govern calls made directly to the LINE Platform. They are not the throughput of the 8x8 send endpoint. No LINE-specific send throughput limit is published for the 8x8 Messaging Apps API. For account-level protections against traffic abuse, see Recommendations for securing your traffic.

Data Protection

  • Profile access requires consent, and without it a user is unaddressable. If a user has not consented to allow access to their profile information, that information is omitted from webhook events, which means no user ID reaches you at all. See Consent and Profile Information.
  • LINE will not disclose friend or chat information. LINE states that user information about the account's friends, including account name and LINE ID, and message information sent in chats by those friends, cannot be disclosed by LINE under any circumstances, with the exception of certain functions.
  • Operator country must be registered and disclosed. Following amendments to Japan's Act on the Protection of Personal Information that took effect on April 1, 2022, LINE requires the country or region of the account operator to be registered in LINE and disclosed on the account. For a corporation or sole proprietor, that is where the entity is located. For an individual, it is where the individual lives. Register it in LINE Official Account Manager under account details.
  • Platform limits on non-smartphone devices. LINE states that it is a service developed for smartphones, and that while it has minimum functionality for PCs and for smartphones on other operating systems, it cannot guarantee correct display of all Official Account functionality on such devices.

Regional Availability

LINE restricts several parts of the product by country or region. All four of these are LINE's restrictions.

RestrictionScope
LINE Official Account is not available in the European UnionThe product itself
Verified Account review applications are accepted only for Japan, Taiwan, and ThailandVerified Accounts are not being issued for other countries or regions at this time
Premium IDs are not available in Indonesia, Singapore, and the United StatesCustom account handles
Only the Free plan is available for Indonesia, Singapore, and the United StatesSubscription plans

8x8 Platform Controls

These are 8x8's controls, and they apply to the LINE channel the same way they apply to every Messaging Apps channel.

  • API key handling. Your API key is a bearer token and is your master credential for the sub-account. Generate and rotate keys in the 8x8 Connect portal. Never hard-code a key in application source; use environment variables or a secret store. Rotate immediately if you suspect a leak.
  • Separate credentials per product. The LINE Official Account channel and LINE Official Notification are separate sub-accounts with separate keys, which also means a compromised key has a smaller blast radius. See Sub-accounts and Authentication.
  • Traffic protection. See Recommendations for securing your traffic for the account-level controls available to you.
  • Portal access control. See Security (SSO) for SAML-based single sign-on configuration on the 8x8 Connect portal.
  • PII removal. 8x8 provides a PII Removal API for programmatically deleting personally identifiable information from 8x8's logs in line with your own retention policy.
  • Data residency. Choose the platform deployment region appropriate to your data residency obligations. See Platform Deployment Regions and Base URLs.

References and Resources

LINE's Official Policies:

8x8 Documentation: