Home / Insights / Operations and security
What do you hand over when a client asks how you manage information?
The conclusion first. SOC 3, the URL of the DPA, and the storage-location display in the admin console are the first 3 items to have ready when a client sends a security questionnaire. All 3 are free, and none of them requires a contract change or a plan change. Depending on the questionnaire, though, SOC 2, subprocessors, encryption, access control, breach notification, retention and deletion, and BCP / DR are asked for as well — the 7 items below are the order we suggest working through.
Separately, it is worth recording before anyone asks which foreign countries your data is stored in, and putting that where the people whose data it is can find it. The Personal Information Protection Commission explains that the security measures you have taken are to be placed in a state the individual can know (Q10-25); it does not say that a privacy policy is the only document that can do that. How you display it depends on your own data flows and contract terms, so treat the PPC’s latest Q&A and a check with a specialist as the premise.
- Audit report — SOC 2 Type II if the questionnaire asks for it; SOC 3 is the public summary of the same audit
- DPA — where it is published, and whether any signing work is needed
- Data location — the country the data sits in and the country the vendor sits in, recorded separately
- Subprocessors — the vendor’s published list, and how changes to it are notified
- Encryption and access control — in transit and at rest, SSO, 2-factor authentication, administrator roles
- Breach notification, retention and deletion — what the terms commit to, and what happens to the data after you cancel
- BCP / DR — the availability commitment and the recovery arrangements the vendor publishes
(Which countries each vendor actually places data in is covered in a separate piece, "Which country will your customer data sit in?".)
What does Japan’s Act on the Protection of Personal Information require?
When personal data is provided to a third party located in a foreign country, one of the following is required.
- Consent from the individual. In that case you have to inform them in advance of the name of the destination country, that country’s personal data protection regime, and the measures the recipient takes
- Assurance that the recipient maintains arrangements equivalent to those required in Japan. This includes ongoing checks that those arrangements remain in place, and providing information when the individual asks for it
- That the recipient is located in a country recognized as offering an equivalent level of protection. At present that means the EU and the United Kingdom only
The United States is not in category 3. Services that place your data in the United States when you sign up from Japan, such as HubSpot and monday.com, therefore have to be handled under 1 or 2.
There is, however, another reading: where the contract states that the SaaS vendor does not handle the personal data and access controls are appropriate, the arrangement does not amount to a "provision to a third party located in a foreign country" in the first place (Personal Information Protection Commission Q12-3). Views differ on whether a service such as a CRM, which is premised on the vendor processing the contents, falls within that reading, so check with a specialist against the way your own company actually uses it.
The SCCs (Standard Contractual Clauses), UK addenda and data privacy frameworks that these vendors publish all exist to make transfers from the EU or the UK to a third country lawful, and they do not directly satisfy the requirements of Japan’s Act on the Protection of Personal Information. Do not read them as "we have SCCs, so Japanese law is covered as well".
Just these 4 things, before you are asked
- Publish the country names where the individual can find them. Where personal data is stored on servers in a foreign country, the security measures you have taken are to be placed in a state the individual can know, and the Personal Information Protection Commission lists, among the items to be made available, "the name of the foreign country in which the cloud service provider is located and the name of the foreign country in which the server storing the personal data is located" (Q10-25). A privacy policy is the usual place, but the Q&A does not limit it to that document. The country the vendor sits in and the country the server sits in are different things, so write them separately. Whether your wording and your chosen location are enough is a judgment for a specialist against the PPC’s latest Q&A
- Check the storage location in the admin console and record it. Keeping 1 line each — "HubSpot = US East, Asana = US Virginia" — answers item 3 of the checklist without any further work
- Download SOC 3 now, while you have the time. If you start looking only after being asked, access approval at a Trust Center takes several days
- Note down the URL of the DPA. No signing work is needed, but you will be asked where it is written
The whole thing takes about 30 minutes. What you do not need to do now, by contrast, is changing where the data is stored — that can wait until a specific demand arrives.
Where do you obtain the documents?
| Document required | HubSpot | monday.com | Asana | Shopify |
|---|---|---|---|---|
| SOC 2 Type 2 (under non-disclosure) | Trust Center (trust.hubspot.com) | Request access at the Compliance Hub (trust.monday.com) | Trust page (asana.com/trust). We could not find how it is handed over stated on the vendor’s own pages | Log in to the admin console to obtain it |
| SOC 3 (can be passed on as it is) | Public download from the legal pages | Compliance Hub | Trust page | The vendor’s own Compliance Reports page |
| DPA | legal.hubspot.com/dpa. A signed version is requested through the form on the page | monday.com/l/privacy/dpa. Signed version via DocuSign | asana.com/terms/data-processing | shopify.com/legal/dpa |
| Evidence of the storage location | The data center display in account settings | The data residency section of a support article | The data residency settings screen | We could not find such a feature stated on the vendor’s own pages |
Source: each vendor’s own pages (checked August 2026). SOC 2 is an audit report issued by an outside accounting firm, and what clients ask for is almost always Type 2 (an examination of whether the controls were actually operating over half a year to 1 year). SOC 3 is the summary version of it, and can be handed to anyone without a non-disclosure agreement. A DPA (data processing agreement) is an undertaking that the vendor only holds and processes personal data and does not use it on its own account; all 4 vendors build it automatically into their terms of service, so no signing work is required.
The most informative thing in this table is that the bottom row for Shopify is empty. What you end up writing is the answer "you cannot choose where it is stored".
There is an order to handing things over as well. SOC 2 Type 2 is provided under a non-disclosure agreement with your own company, and that normally does not extend to a right to forward it to a client. The practical route is to hand over SOC 3 first and, if you are told it is not enough, to point them to the vendor’s Trust Center to request access directly.
Who this approach is not enough for
Companies given "stored in Japan, without exception" as a condition. Assembling the documents will not meet the requirement. Of the 4 vendors, only Asana can keep data in Japan, and even there the authentication-related data stays in the United States.
Companies asked to produce an ISO 27001 certificate. Neither HubSpot nor Shopify states a certification of its own, so all you can answer is "the certification of the underlying infrastructure provider". That becomes a question of product selection rather than of preparing documents.
Companies working on public-sector, financial or medical projects. Requirements in these industries sit at a different level, and the 3 documents in this article are not enough.
Conversely, companies whose personal data is only their own staff list and clients’ business cards, with no data entrusted to them by other companies. If you have never been asked for a questionnaire, finishing the 4 items above and keeping a record is enough. Moving up a plan to shift the storage location does not justify the cost.
If you are unsure
Settle Q3 first. If you sign a higher plan while leaving this vague, you can end up unable to meet the requirement anyway. Source: each vendor’s own pages and the Personal Information Protection Commission (checked August 2026)
What you decide first is whether the other side is asking for an explanation or for storage in Japan. If an explanation is enough, the cost is zero and you can answer on the spot. If storage in Japan really is the condition, no amount of documentation will get you there, and the conversation moves to a plan change or a product change. Acting without separating these 2 can end with you signing a higher plan and still failing the requirement.
Sources (all checked August 2026)
- Personal Information Protection Commission: Guidelines on provision to a third party located in a foreign country (the duty to provide information when obtaining consent, the equivalent-arrangements route, and the EU and the UK as the only countries recognized as equivalent) / Q12-3 (the treatment where a cloud provider does not handle the personal data) / Q10-25 (publishing the names of foreign countries)
- HubSpot: Security program (SOC 2 Type 2, SOC 3, certification of the underlying infrastructure provider) / DPA (automatically incorporated, SCCs, UK Addendum, Swiss addendum, DPF) / Trust Center / List of data centers
- monday.com: Trust Center (list of certifications) / Compliance Hub / DPA (SCCs, IDTA B.1.0, EU-US DPF, Swiss addendum) / Data residency
- Asana: Trust (SOC 2, ISO 27001:2022 and others) / DPA (the DPF-then-SCC order of precedence, UK Addendum) / Data residency
- Shopify: DPA (the 2021 SCCs, UK IDTA, BCRs) / Security (PCI DSS Level 1, SOC 2 Type II, SOC 3) / How to view the compliance reports (including SOC 1 Type 2)
This article is not legal advice. Judgments about treatment under the Act on the Protection of Personal Information, and about the level required by your contracts with clients, should be checked with a lawyer or another specialist. We could not find the following stated on the vendors’ own pages: how Asana’s SOC 2 Type 2 is handed over, whether Shopify lets you choose the storage location, and ISO 27001 certification of HubSpot’s and Shopify’s own organizations. Terms change, so please check each vendor’s own pages before signing.
What changed on this page
- correction6 September 2026 Security questionnaires — coverage claim and the legal basis given
these seven items fill in most of a questionnaire; a privacy policy is required by Japan’s personal information protection act → the seven items are a starting point, not most of a questionnaire; the statutory requirement is that the stated purpose be in a state the person can readily know, which a privacy policy is one way to meet
Every recorded change to this site is in the change log.
More in Operations and security
All of operations and security →What does SSO actually cost?
The cheapest published route is $90 per seat per month, but a mandatory $1,500 onboarding fee brings the first year to $2,580 for a single seat.
Read → Operations and security 06What happens to your data when you cancel
Only Shopify and HubSpot state how long data survives cancellation, which makes the export a job for while the contract is still live.
Read → Operations and security 12Will your automation run count be enough?
Only monday.com stops you on monthly run count, and because 1 run can spend several actions, its 250 runs a month cover about 42 pieces of work.
Read →