Homeホーム / Insights / Operations and security解説記事 / 運用・セキュリティ
Which country will your customer data sit in?自社の顧客データは、どこの国に保存されますか
Of the 4 vendors we checked, Asana is the only one that can hold your data inside Japan — and it comes with conditions: a paid add-on on Enterprise, included as standard on Enterprise+, with authentication data never reaching Japan. monday.com places every sign-up from Japan in the United States, HubSpot has no data centre in Japan, and for Shopify we could not find a mechanism for the customer to choose a storage location stated on its own pages. For a small or mid-sized company signing up in the ordinary way, customer data is almost certainly held outside Japan.
(Semrush and Squarespace are not covered here, because we could not find a mechanism for choosing a storage location stated on their own pages.)
Why does the storage location matter?
One reason is the information-security questionnaire that clients send. A form of 100 to 200 questions will ask things like whether personal data is handled overseas and which countries are involved, and even 1 blank answer gets it sent back, delaying the start of trading by 2 to 4 weeks. As long as you can answer, an answer of "the United States" rarely stops the deal. What stops it is being unable to answer.
The other is Japan’s Act on the Protection of Personal Information. To pass personal data to a third party located overseas, you need the individual’s consent, or assurance that the recipient maintains a framework equivalent to the domestic standard, or the recipient must be in a country recognised as offering an equivalent standard (currently the EU and the UK only). The United States does not fall under that 3rd route. The statutory requirements, and the documents you hand over when you are asked, are covered in a separate piece, "What do you show a client who asks how you manage information?".
Just 2 terms
SOC 2 / SOC 3 — an examination report by an external accounting auditor, and its summary version. What clients ask for is almost always SOC 2 Type 2 (an examination of whether the controls actually operated over a period of half a year to 1 year), released under a non-disclosure agreement. All 4 vendors can produce a Type 2, so product selection does not turn on this item.
Region / data residency — a region is the unit of geography in which data is placed; data residency is the name for the feature that lets the customer specify that geography.
The 4 vendors split into those that let you choose a region and those that do not
| Countries and regions where data is stored | Can the customer choose? | Inside Japan | Own ISO 27001 | How to read this row | |
|---|---|---|---|---|---|
| HubSpot | US East (Virginia) / US West (Oregon) / EU (Germany) / Canada (Montreal) / Australia (Sydney). On AWS | Assigned automatically from the IP address at sign-up. For as long as you use only the free version it is the United States, wherever you signed up from. After a paid contract you can migrate free of charge from the admin settings | None | We could not confirm a certification in its own name (what appears on the vendor’s own pages is the certification of its infrastructure provider) | Sign up from Japan and you get the United States. You do not choose it; you move it afterwards |
| monday.com | 3 regions: US / EU / APAC (Australia). On AWS | The EU is limited to Enterprise, and to Standard and Pro accounts created on or after January 23, 2023. Once an account has begun storing data it cannot be moved | None (sign-ups from Japan go to the United States) | ISO 27001:2022 | A Japanese company cannot choose the region, and there is no way back once you have signed |
| Asana | US Virginia (default) / Frankfurt, Germany / Tokyo, Japan / Sydney, Australia | Yes. A paid add-on on Enterprise; included as standard on Enterprise+ | Yes (Tokyo, with backups in Osaka) | ISO 27001:2022 | The only vendor storing data inside Japan — subject to the exclusions described below |
| Shopify | A Canadian company. The contracting entity differs by region, and for Asia, Australia and New Zealand the Singapore entity is the recipient | We could not find this stated on the vendor’s own pages | We could not find this stated on the vendor’s own pages | We could not confirm a certification in its own name | This is not a product built around specifying where data is stored |
Scroll sideways to see every column
Checked on each vendor’s own pages as of August 2026. SOC 2 Type 2 and SOC 3 are available from all 4 vendors. Sources are at the end of this article.
A note on the ISO 27001 column alone. monday.com and Asana hold ISO 27001:2022 in their own name, while HubSpot and Shopify state no certification of their own. What HubSpot’s own pages carry is "HubSpot products are hosted with cloud infrastructure providers with SOC 2 Type 2 and ISO 27001 certifications, among others.", and that is the certification of AWS, the provider renting them the infrastructure. For these 2 vendors, a company asked to submit an ISO 27001 certificate can only answer "the infrastructure provider’s certification".
As a basis for taking personal data out of the EU and the UK, all 4 vendors have the standard contractual clauses and the UK addendum in place, so this item separates none of them.
What "there is a data centre in Japan" actually covers
Asana’s storage in Japan comes with an exclusion set out explicitly in its own help pages.
What sits in Tokyo is teams, projects, tasks, exports and attachments. What stays in the United States is authentication-related data such as email addresses, passwords, one-time keys, IP addresses and internal identifiers; measurement data on seat counts, usage and revenue; and data passed to external partners for AI features (customers in the EU excepted). Business data in Japan, account information in the United States — with the line drawn there, you cannot write "all of it stays in the country" on a questionnaire.
monday.com states plainly that "All accounts from Japan are hosted in the US Data Region.", and because the APAC region is in Australia, sign-ups from Japan do not land there either. It goes on to state the following.
That leaves no option other than starting again: creating a new account, exporting the existing boards and importing them back in. We could not confirm on the vendor’s own pages whether comments, update history, automation settings and connected apps carry over. If there is even a small chance you will need the EU region, telling the sales team before you create your first account is the only low-cost route.
Who should not choose these 4 vendors
Asana — companies required to store data inside the country without exception. Because credentials remain in the United States, the requirement cannot be met. Neither Enterprise and Enterprise+ pricing nor the price of the data residency add-on is published on the vendor’s own pages (sales enquiry only), and this is not a configuration a company of 10 people or fewer moves up to for the storage location alone. If domestic storage is a requirement, say "with the Tokyo region included" from the quotation stage onwards. Quotes do come back without it.
monday.com — companies where there is even a small chance that the storage location becomes a requirement. Every sign-up from Japan is fixed to the United States, and once data has been stored it cannot be moved. It is the only product here where the way back closes at the moment of signing.
HubSpot — companies asked to submit ISO 27001. What appears on the vendor’s own pages is the certification of its infrastructure provider. Companies starting on the free version need care as well: while it is free, data is placed in the United States wherever the sign-up came from.
Shopify — companies that need to specify where data is stored. We could not find a mechanism for the customer to choose stated on the vendor’s own pages, and the personal data of users in Asia, Australia and New Zealand is received by the Singapore entity.
Which of these applies to you?
Source: each vendor’s own pages (checked August 2026)
If the personal data you handle is only your own staff roster and the business cards of your clients, if you hold no data entrusted to you by another company, and if you have no plans to work on public-sector, financial or medical accounts, then moving up a plan in order to move the storage location should not be worth the cost. A DPA (data processing agreement) is built into the terms of service automatically at all 4 vendors, so a minimum contractual relationship is in place without you doing anything. How to produce the documents, and what to put in place before you are asked, are set out in a separate piece, "What do you show a client who asks how you manage information?".
Sources (checked August 2026)
- Personal Information Protection Commission: guidelines on provision to a third party located overseas (information to be given when obtaining consent, the equivalent-framework route, countries with an equivalent standard) / Q12-3 (treatment where a cloud provider does not handle the personal data) / Q10-25 (disclosing the name of the foreign country)
- HubSpot: data centre list (EU, Canada, Australia, US East and West / automatic assignment by IP / free users in the US / free migration for paid customers) / cloud infrastructure and data hosting FAQ (AWS, host cities) / security programme (SOC 2 Type 2, SOC 3, infrastructure provider certifications) / DPA (built in automatically, SCCs, UK Addendum, Swiss addendum, DPF) / Trust Center
- monday.com: data residency (US/EU/APAC, Japan in the US, no move once storage has begun, the plan conditions for the EU) / Trust Center (ISO 27001:2022 and others) / Compliance Hub / DPA (SCCs, IDTA B.1.0, EU-US DPF, Swiss addendum)
- Asana: data residency (4 regions, Enterprise add-on / standard on Enterprise+, the scope of data that remains in the US) / Japan data centre (Tokyo, Osaka) / Trust (SOC 2, ISO 27001:2022 and others) / DPA (the DPF-then-SCCs order of precedence, UK Addendum)
- Shopify: DPA (2021 SCCs, UK IDTA, BCRs) / security (PCI DSS Level 1, SOC 2 Type II, SOC 3) / how to view the compliance reports (including SOC 1 Type 2) / privacy policy (contracting entity by region)
This article is not legal advice. For treatment under the Act on the Protection of Personal Information, and for judgements about the standard required by a contract with a client, please consult a lawyer or another specialist. We could not find the following stated on the vendors’ own pages: whether the storage location can be chosen at Shopify, how a SOC 2 Type 2 report is obtained from Asana and the pricing of its Enterprise tiers, the scope of data that carries over if a monday.com account is recreated, and ISO 27001 certification in the names of HubSpot and Shopify. Vendor terms, certifications and data centre configurations change. Please check the latest information on each vendor’s own pages before signing.
4社を調べたところ、日本国内に置けるのはAsanaだけでした。しかも Enterprise では有料アドオン、Enterprise+ では標準搭載という条件つきで、認証まわりのデータは日本に来ません。monday.comは日本からの申込みを全部アメリカに置き、HubSpotは日本にデータセンターを持たず、Shopifyは利用者が保存先を選ぶ仕組みを公式に確認できませんでした。中小企業が普通に契約すると、顧客データはほぼ確実に日本国外にあります。
(Semrush と Squarespace は、保存先を選ぶ仕組みを公式に確認できなかったため、この記事では扱いません。)
なぜ保存場所が問題になるのですか
ひとつは取引先の情報管理チェックシートです。100〜200問の質問票に「個人データを外国で取り扱いますか」「国名を記載してください」といった設問が並び、1問でも空欄があると差し戻されて取引開始が2〜4週間遅れます。答えられさえすれば、内容が「米国」でも取引が止まることはほとんどありません。止まるのは、答えられないときです。
もうひとつは日本の個人情報保護法です。個人データを外国にある第三者へ渡すときは、本人の同意か、提供先が国内と同等の体制を整えていることの確保か、提供先が同等の水準と認められた国(現在はEUと英国のみ)にあることが求められます。米国はこの3番目に含まれません。法令上の要件と、聞かれたときに出す書類は、別記事「取引先に情報管理を聞かれたら、何を出せばいいですか」で扱っています。
用語を2つだけ
SOC 2 / SOC 3 — 外部の会計監査人による検査報告書と、その要約版です。取引先が求めるのはほぼ SOC 2 の Type 2(半年〜1年その仕組みが回っていたかの検査)で、秘密保持契約つきで渡されます。4社とも Type 2 を出せるため、この項目で製品選定は動きません。
リージョン/データレジデンシー — リージョンはデータを置く地域の単位、データレジデンシーは利用者側がその地域を指定できる機能の呼び名です。
4社の保存先は、選べるものと選べないものに分かれます
| 保存される国・地域 | 利用者が選べるか | 日本国内 | 自社のISO 27001 | この欄の読み方 | |
|---|---|---|---|---|---|
| HubSpot | 米国東部(バージニア)/米国西部(オレゴン)/EU(ドイツ)/カナダ(モントリオール)/豪州(シドニー)。AWS上 | 申込時のIPアドレスで自動決定。無料版だけを使う間は申込元に関係なく米国。有料契約後は管理画面から無償で移行できる | なし | 記載を確認できず(公式にあるのは基盤事業者の認証) | 日本から申し込むと米国。選ぶのではなく後から移す |
| monday.com | 米国/EU/APAC(豪州)の3リージョン。AWS上 | EUは Enterprise、および2023年1月23日以降に作成された Standard・Pro に限る。データ保存開始後は移せない | なし(日本からの申込みは米国) | ISO 27001:2022 | 日本企業はリージョンを選べず、契約時点で退路がなくなる |
| Asana | 米国バージニア(既定)/独フランクフルト/日本・東京/豪シドニー | 選べる。Enterprise は有料アドオン、Enterprise+ は標準搭載 | あり(東京。バックアップは大阪) | ISO 27001:2022 | 唯一の国内保存。ただし後述の除外あり |
| Shopify | カナダの会社。地域別に契約主体が分かれ、アジア・豪州・NZはシンガポール法人が受領 | 公式に記載を確認できませんでした | 公式に記載を確認できませんでした | 記載を確認できず | 保存先を指定する発想の製品ではない |
※ 横にスクロールすると全項目を確認できます
2026年8月時点・各社公式ページで確認。SOC 2 Type 2 と SOC 3 は4社とも入手できます。出典は記事末尾。
ISO 27001の列だけ補足します。monday.com と Asana は自社で ISO 27001:2022 を取得していますが、HubSpot と Shopify は自社認証の記載がありません。HubSpot の公式ページにあるのは「HubSpot products are hosted with cloud infrastructure providers with SOC 2 Type 2 and ISO 27001 certifications, among others.」(日本語訳:HubSpot製品は、SOC 2 Type 2やISO 27001をはじめとする認証を持つクラウド基盤事業者上でホストされています)で、これは基盤を貸すAWSの認証です。ISO 27001の提出を求められている会社は、この2社では「基盤事業者の認証」としか回答できません。
なお、EU・英国から個人データを持ち出す根拠としては4社とも標準契約条項と英国向け追補を用意しており、この項目で優劣はつきません。
「日本にデータセンターがある」の実際の中身
Asanaの日本保存には、公式ヘルプに明記された除外があります。
東京に置かれるのはチーム、プロジェクト、タスク、エクスポート、添付ファイル。米国に残るのは、メールアドレス・パスワード・ワンタイムキー・IPアドレス・内部識別子といった認証まわりのデータ、席数や利用量・売上の計測データ、AI機能で外部パートナーに渡るデータ(EUの顧客を除く)です。業務データは日本、アカウント情報は米国という切り分けなので、チェックシートに「すべて国内」とは書けません。
monday.comは「All accounts from Japan are hosted in the US Data Region.」(日本語訳:日本からのアカウントはすべて米国データリージョンでホストされます)と明記し、APACリージョンは豪州なので日本からの申込みはそこにも入りません。さらに次の記載があります。
つまり作り直す以外に選択肢がありません。新規アカウントを作り、既存のボードをエクスポートして取り込み直す作業になります。コメント・更新履歴・自動化設定・連携アプリが引き継げるかは公式に確認できませんでした。EUリージョンが必要になる可能性が少しでもあるなら、最初のアカウントを作る前に営業へ申し出るのが唯一の低コストな手段です。
この4社を選ぶべきでない読者像
Asana — 「例外なく国内保存」を求められている会社。認証情報が米国に残るため要件を満たせません。Enterprise・Enterprise+ の価格もデータレジデンシーアドオンの価格も公式に掲載がなく(営業への問い合わせのみ)、10名以下の会社が保存先だけのために上げる構成ではありません。国内保存が要件なら、見積もりの段階から「東京リージョンを含む構成で」と伝えてください。含めずに見積もりが出ることがあります。
monday.com — 保存先が要件になる可能性が少しでもある会社。日本からの申込みは全件米国に固定され、一度データを保存すると移せません。契約時点で退路がなくなる唯一の製品です。
HubSpot — ISO 27001の提出を求められている会社。公式にあるのは基盤事業者の認証です。無料版から使い始める会社も注意が必要で、無料の間は申込元に関係なく米国に置かれます。
Shopify — 保存先を指定する必要がある会社。利用者が選ぶ仕組みを公式に確認できず、アジア・豪州・NZの利用者の個人データはシンガポール法人が受領します。
自社はどれに当てはまりますか
出典:各社公式ページ(2026年8月確認)
扱う個人データが自社の従業員名簿と取引先の名刺だけで、他社から預かったデータがなく、官公庁・金融・医療の案件に関わる予定もないなら、保存先を動かすために上位プランへ上げるのは費用に見合わないはずです。DPA(データ処理契約)は4社とも利用規約に自動で組み込まれているため、何もしなくても最低限の契約関係は成立しています。書類の出し方と、聞かれる前にやっておくことは、別記事「取引先に情報管理を聞かれたら、何を出せばいいですか」にまとめました。
出典(2026年8月確認)
- 個人情報保護委員会:外国にある第三者への提供に関するガイドライン(同意時の情報提供義務、基準適合体制、同等水準国)/Q12-3(クラウド事業者が個人データを取り扱わない場合の整理)/Q10-25(外国の名称の公表)
- HubSpot:データセンター一覧(EU・カナダ・豪州・米国東西/IPで自動割当/無料利用者は米国/有料は無償で移行)/クラウド基盤とデータホスティングFAQ(AWS・所在都市)/セキュリティプログラム(SOC 2 Type 2・SOC 3・基盤事業者の認証)/DPA(自動組込み・SCC・UK Addendum・スイス追補・DPF)/Trust Center
- monday.com:データレジデンシー(US/EU/APAC・日本は米国・保存開始後は移動不可・EUのプラン条件)/Trust Center(ISO 27001:2022ほか)/Compliance Hub/DPA(SCC・IDTA B.1.0・EU-US DPF・スイス追補)
- Asana:データレジデンシー(4地域・Enterpriseアドオン/Enterprise+標準・米国に残るデータの範囲)/日本データセンター(東京・大阪)/Trust(SOC 2・ISO 27001:2022ほか)/DPA(DPF→SCCの優先順位・UK Addendum)
- Shopify:DPA(2021年版SCC・UK IDTA・BCR)/セキュリティ(PCI DSS レベル1・SOC 2 Type II・SOC 3)/コンプライアンス報告書の閲覧方法(SOC 1 Type 2を含む)/プライバシーポリシー(地域別の契約主体)
本記事は法的助言ではありません。 個人情報保護法上の取扱いや、取引先との契約で求められる水準の判断は、弁護士など専門家にご確認ください。Shopify の保存先の選択可否、Asana の SOC 2 Type 2 の受け取り方法と Enterprise 系の価格、monday.com でアカウントを作り直した場合に引き継げるデータの範囲、HubSpot と Shopify の自社 ISO 27001 認証は、公式ページで記載を確認できませんでした。各社の提供条件・認証・データセンターの構成は変更されます。契約前に必ず各公式ページで最新の内容をご確認ください。