Home / Insights / Operations and security

What do you hand over when a client asks how you manage information?

Verified 17 August 2026 · SaaS COMPASS · Updated 6 September 2026

The conclusion first. SOC 3, the URL of the DPA, and the storage-location display in the admin console are the first 3 items to have ready when a client sends a security questionnaire. All 3 are free, and none of them requires a contract change or a plan change. Depending on the questionnaire, though, SOC 2, subprocessors, encryption, access control, breach notification, retention and deletion, and BCP / DR are asked for as well — the 7 items below are the order we suggest working through.

Separately, it is worth recording before anyone asks which foreign countries your data is stored in, and putting that where the people whose data it is can find it. The Personal Information Protection Commission explains that the security measures you have taken are to be placed in a state the individual can know (Q10-25); it does not say that a privacy policy is the only document that can do that. How you display it depends on your own data flows and contract terms, so treat the PPC’s latest Q&A and a check with a specialist as the premise.

SaaS COMPASS checklist — the order below is our own suggestion for working through a questionnaire, not a standard published by any body. The wording of your own answers is a legal judgment, not an editorial one.
  1. Audit report — SOC 2 Type II if the questionnaire asks for it; SOC 3 is the public summary of the same audit
  2. DPA — where it is published, and whether any signing work is needed
  3. Data location — the country the data sits in and the country the vendor sits in, recorded separately
  4. Subprocessors — the vendor’s published list, and how changes to it are notified
  5. Encryption and access control — in transit and at rest, SSO, 2-factor authentication, administrator roles
  6. Breach notification, retention and deletion — what the terms commit to, and what happens to the data after you cancel
  7. BCP / DR — the availability commitment and the recovery arrangements the vendor publishes

(Which countries each vendor actually places data in is covered in a separate piece, "Which country will your customer data sit in?".)

What does Japan’s Act on the Protection of Personal Information require?

When personal data is provided to a third party located in a foreign country, one of the following is required.

  1. Consent from the individual. In that case you have to inform them in advance of the name of the destination country, that country’s personal data protection regime, and the measures the recipient takes
  2. Assurance that the recipient maintains arrangements equivalent to those required in Japan. This includes ongoing checks that those arrangements remain in place, and providing information when the individual asks for it
  3. That the recipient is located in a country recognized as offering an equivalent level of protection. At present that means the EU and the United Kingdom only

The United States is not in category 3. Services that place your data in the United States when you sign up from Japan, such as HubSpot and monday.com, therefore have to be handled under 1 or 2.

There is, however, another reading: where the contract states that the SaaS vendor does not handle the personal data and access controls are appropriate, the arrangement does not amount to a "provision to a third party located in a foreign country" in the first place (Personal Information Protection Commission Q12-3). Views differ on whether a service such as a CRM, which is premised on the vendor processing the contents, falls within that reading, so check with a specialist against the way your own company actually uses it.

The SCCs (Standard Contractual Clauses), UK addenda and data privacy frameworks that these vendors publish all exist to make transfers from the EU or the UK to a third country lawful, and they do not directly satisfy the requirements of Japan’s Act on the Protection of Personal Information. Do not read them as "we have SCCs, so Japanese law is covered as well".

Just these 4 things, before you are asked

  1. Publish the country names where the individual can find them. Where personal data is stored on servers in a foreign country, the security measures you have taken are to be placed in a state the individual can know, and the Personal Information Protection Commission lists, among the items to be made available, "the name of the foreign country in which the cloud service provider is located and the name of the foreign country in which the server storing the personal data is located" (Q10-25). A privacy policy is the usual place, but the Q&A does not limit it to that document. The country the vendor sits in and the country the server sits in are different things, so write them separately. Whether your wording and your chosen location are enough is a judgment for a specialist against the PPC’s latest Q&A
  2. Check the storage location in the admin console and record it. Keeping 1 line each — "HubSpot = US East, Asana = US Virginia" — answers item 3 of the checklist without any further work
  3. Download SOC 3 now, while you have the time. If you start looking only after being asked, access approval at a Trust Center takes several days
  4. Note down the URL of the DPA. No signing work is needed, but you will be asked where it is written

The whole thing takes about 30 minutes. What you do not need to do now, by contrast, is changing where the data is stored — that can wait until a specific demand arrives.

Where do you obtain the documents?

Document requiredHubSpotmonday.comAsanaShopify
SOC 2 Type 2 (under non-disclosure)Trust Center (trust.hubspot.com)Request access at the Compliance Hub (trust.monday.com)Trust page (asana.com/trust). We could not find how it is handed over stated on the vendor’s own pagesLog in to the admin console to obtain it
SOC 3 (can be passed on as it is)Public download from the legal pagesCompliance HubTrust pageThe vendor’s own Compliance Reports page
DPAlegal.hubspot.com/dpa. A signed version is requested through the form on the pagemonday.com/l/privacy/dpa. Signed version via DocuSignasana.com/terms/data-processingshopify.com/legal/dpa
Evidence of the storage locationThe data center display in account settingsThe data residency section of a support articleThe data residency settings screenWe could not find such a feature stated on the vendor’s own pages

Source: each vendor’s own pages (checked August 2026). SOC 2 is an audit report issued by an outside accounting firm, and what clients ask for is almost always Type 2 (an examination of whether the controls were actually operating over half a year to 1 year). SOC 3 is the summary version of it, and can be handed to anyone without a non-disclosure agreement. A DPA (data processing agreement) is an undertaking that the vendor only holds and processes personal data and does not use it on its own account; all 4 vendors build it automatically into their terms of service, so no signing work is required.

The most informative thing in this table is that the bottom row for Shopify is empty. What you end up writing is the answer "you cannot choose where it is stored".

There is an order to handing things over as well. SOC 2 Type 2 is provided under a non-disclosure agreement with your own company, and that normally does not extend to a right to forward it to a client. The practical route is to hand over SOC 3 first and, if you are told it is not enough, to point them to the vendor’s Trust Center to request access directly.

Who this approach is not enough for

Companies given "stored in Japan, without exception" as a condition. Assembling the documents will not meet the requirement. Of the 4 vendors, only Asana can keep data in Japan, and even there the authentication-related data stays in the United States.

Companies asked to produce an ISO 27001 certificate. Neither HubSpot nor Shopify states a certification of its own, so all you can answer is "the certification of the underlying infrastructure provider". That becomes a question of product selection rather than of preparing documents.

Companies working on public-sector, financial or medical projects. Requirements in these industries sit at a different level, and the 3 documents in this article are not enough.

Conversely, companies whose personal data is only their own staff list and clients’ business cards, with no data entrusted to them by other companies. If you have never been asked for a questionnaire, finishing the 4 items above and keeping a record is enough. Moving up a plan to shift the storage location does not justify the cost.

If you are unsure

Q1: Has a client asked you for a security questionnaire or for a SOC 2 report?
NoFinish the 4 items above (country names in the policy, a record of the storage location, obtaining SOC 3, the URL of the DPA) in 30 minutes
YesGo to Q2
Q2: Is what they are asking for an explanation of your arrangements, or storage in Japan itself?
An explanation of the arrangementsAnswer with the 3 items: SOC 3, the URL of the DPA and the storage-location display. Do not change where the data is stored
Storage in JapanGo to Q3
Q3: Does the other side accept "business data in Japan is sufficient", or do they mean "in Japan without exception"?
Business data in Japan is sufficientAsana Enterprise+, or Enterprise with the data residency add-on on top
In Japan without exceptionNone of these 4 vendors can meet it. Ask the other side to confirm the basis for the requirement in writing

Settle Q3 first. If you sign a higher plan while leaving this vague, you can end up unable to meet the requirement anyway. Source: each vendor’s own pages and the Personal Information Protection Commission (checked August 2026)

What you decide first is whether the other side is asking for an explanation or for storage in Japan. If an explanation is enough, the cost is zero and you can answer on the spot. If storage in Japan really is the condition, no amount of documentation will get you there, and the conversation moves to a plan change or a product change. Acting without separating these 2 can end with you signing a higher plan and still failing the requirement.

Sources (all checked August 2026)

This article is not legal advice. Judgments about treatment under the Act on the Protection of Personal Information, and about the level required by your contracts with clients, should be checked with a lawyer or another specialist. We could not find the following stated on the vendors’ own pages: how Asana’s SOC 2 Type 2 is handed over, whether Shopify lets you choose the storage location, and ISO 27001 certification of HubSpot’s and Shopify’s own organizations. Terms change, so please check each vendor’s own pages before signing.

← Back to the comparison

What changed on this page

  • correction6 September 2026 Security questionnairescoverage claim and the legal basis given
    these seven items fill in most of a questionnaire; a privacy policy is required by Japan’s personal information protection act → the seven items are a starting point, not most of a questionnaire; the statutory requirement is that the stated purpose be in a state the person can readily know, which a privacy policy is one way to meet

Every recorded change to this site is in the change log.

HubSpot Free plan available
Visit