Homeホーム / Insights / Operations and security解説記事 / 運用・セキュリティ

What do you hand over when a client asks how you manage information?取引先に情報管理を聞かれたら、何を出せばいいですか

Verified 17 August 2026 · SaaS COMPASS2026.08.17 確認 ・ SaaS COMPASS

The conclusion first. SOC 3, the URL of the DPA, and the storage-location display in the admin console — those 3 items fill in most of a security questionnaire. All 3 are free, and none of them requires a contract change or a plan change.

On top of that, there is 1 thing worth doing before anyone asks: writing into your privacy policy the names of the foreign countries where your data is stored. That is not about answering clients; it is a requirement of Japan’s Act on the Protection of Personal Information.

(Which countries each vendor actually places data in is covered in a separate piece, "Which country is your customer data stored in?".)

What does Japan’s Act on the Protection of Personal Information require?

When personal data is provided to a third party located in a foreign country, one of the following is required.

  1. Consent from the individual. In that case you have to inform them in advance of the name of the destination country, that country’s personal data protection regime, and the measures the recipient takes
  2. Assurance that the recipient maintains arrangements equivalent to those required in Japan. This includes ongoing checks that those arrangements remain in place, and providing information when the individual asks for it
  3. That the recipient is located in a country recognised as offering an equivalent level of protection. At present that means the EU and the United Kingdom only

The United States is not in category 3. Services that place your data in the United States when you sign up from Japan, such as HubSpot and monday.com, therefore have to be handled under 1 or 2.

There is, however, another reading: where the contract states that the SaaS vendor does not handle the personal data and access controls are appropriate, the arrangement does not amount to a "provision to a third party located in a foreign country" in the first place (Personal Information Protection Commission Q12-3). Views differ on whether a service such as a CRM, which is premised on the vendor processing the contents, falls within that reading, so check with a specialist against the way your own company actually uses it.

The SCCs (Standard Contractual Clauses), UK addenda and data privacy frameworks that these vendors publish all exist to make transfers from the EU or the UK to a third country lawful, and they do not directly satisfy the requirements of Japan’s Act on the Protection of Personal Information. Do not read them as "we have SCCs, so Japanese law is covered as well".

Just these 4 things, before you are asked

  1. Write the country names into your privacy policy. Where personal data is stored on servers in a foreign country, the security measures you have taken must be made available in a form the individual can check, and the Personal Information Protection Commission lists, among the items to be made available, "the name of the foreign country in which the cloud service provider is located and the name of the foreign country in which the server storing the personal data is located" (Q10-25). The country the vendor sits in and the country the server sits in are different things, so write them separately. For the final judgement on whether this wording is enough, check with a specialist
  2. Check the storage location in the admin console and record it. Keeping 1 line each — "HubSpot = US East, Asana = US Virginia" — fills in most of a questionnaire
  3. Download SOC 3 now, while you have the time. If you start looking only after being asked, access approval at a Trust Center takes several days
  4. Note down the URL of the DPA. No signing work is needed, but you will be asked where it is written

The whole thing takes about 30 minutes. What you do not need to do now, by contrast, is changing where the data is stored — that can wait until a specific demand arrives.

Where do you obtain the documents?

Document requiredHubSpotmonday.comAsanaShopify
SOC 2 Type 2 (under non-disclosure)Trust Center (trust.hubspot.com)Request access at the Compliance Hub (trust.monday.com)Trust page (asana.com/trust). We could not find how it is handed over stated on the vendor’s own pagesLog in to the admin console to obtain it
SOC 3 (can be passed on as it is)Public download from the legal pagesCompliance HubTrust pageThe vendor’s own Compliance Reports page
DPAlegal.hubspot.com/dpa. A signed version is requested through the form on the pagemonday.com/l/privacy/dpa. Signed version via DocuSignasana.com/terms/data-processingshopify.com/legal/dpa
Evidence of the storage locationThe data centre display in account settingsThe data residency section of a support articleThe data residency settings screenWe could not find such a feature stated on the vendor’s own pages

Source: each vendor’s own pages (checked August 2026). SOC 2 is an audit report issued by an outside accounting firm, and what clients ask for is almost always Type 2 (an examination of whether the controls were actually operating over half a year to 1 year). SOC 3 is the summary version of it, and can be handed to anyone without a non-disclosure agreement. A DPA (data processing agreement) is an undertaking that the vendor only holds and processes personal data and does not use it on its own account; all 4 vendors build it automatically into their terms of service, so no signing work is required.

The most informative thing in this table is that the bottom row for Shopify is empty. What you end up writing is the answer "you cannot choose where it is stored".

There is an order to handing things over as well. SOC 2 Type 2 is provided under a non-disclosure agreement with your own company, and that normally does not extend to a right to forward it to a client. The practical route is to hand over SOC 3 first and, if you are told it is not enough, to point them to the vendor’s Trust Center to request access directly.

Who this approach is not enough for

Companies given "stored in Japan, without exception" as a condition. Assembling the documents will not meet the requirement. Of the 4 vendors, only Asana can keep data in Japan, and even there the authentication-related data stays in the United States.

Companies asked to produce an ISO 27001 certificate. Neither HubSpot nor Shopify states a certification of its own, so all you can answer is "the certification of the underlying infrastructure provider". That becomes a question of product selection rather than of preparing documents.

Companies working on public-sector, financial or medical projects. Requirements in these industries sit at a different level, and the 3 documents in this article are not enough.

Conversely, companies whose personal data is only their own staff list and clients’ business cards, with no data entrusted to them by other companies. If you have never been asked for a questionnaire, finishing the 4 items above and keeping a record is enough. Moving up a plan in order to shift the storage location does not justify the cost.

If you are unsure

Q1: Has a client asked you for a security questionnaire or for a SOC 2 report?
NoFinish the 4 items above (country names in the policy, a record of the storage location, obtaining SOC 3, the URL of the DPA) in 30 minutes
YesGo to Q2
Q2: Is what they are asking for an explanation of your arrangements, or storage in Japan itself?
An explanation of the arrangementsAnswer with the 3 items: SOC 3, the URL of the DPA and the storage-location display. Do not change where the data is stored
Storage in JapanGo to Q3
Q3: Does the other side accept "business data in Japan is sufficient", or do they mean "in Japan without exception"?
Business data in Japan is sufficientAsana Enterprise+, or Enterprise with the data residency add-on on top
In Japan without exceptionNone of these 4 vendors can meet it. Ask the other side to confirm the basis for the requirement in writing

Settle Q3 first. If you sign a higher plan while leaving this vague, you can end up unable to meet the requirement anyway. Source: each vendor’s own pages and the Personal Information Protection Commission (checked August 2026)

What you decide first is whether the other side is asking for an explanation or for storage in Japan. If an explanation is enough, the cost is zero and you can answer on the spot. If storage in Japan really is the condition, no amount of documentation will get you there, and the conversation moves to a plan change or a product change. Acting without separating these 2 can end with you signing a higher plan and still failing the requirement.

Sources (all checked August 2026)

This article is not legal advice. Judgements about treatment under the Act on the Protection of Personal Information, and about the level required by your contracts with clients, should be checked with a lawyer or another specialist. We could not find the following stated on the vendors’ own pages: how Asana’s SOC 2 Type 2 is handed over, whether Shopify lets you choose the storage location, and ISO 27001 certification of HubSpot’s and Shopify’s own organisations. Terms change, so please check each vendor’s own pages before signing.

← Back to the ranking

結論を先に書きます。SOC 3・DPAのURL・管理画面の保存先表示の3点で、チェックシートの大半は埋まります。この3つはいずれも無料で、契約変更もプラン変更も要りません。

そのうえで、聞かれる前にやっておく価値があるのが1つあります。プライバシーポリシーに、データが保存される外国の名称を書くことです。これは取引先対応ではなく、日本の個人情報保護法の要請です。

(各社が実際にどの国にデータを置いているかは、別記事「自社の顧客データは、どこの国に保存されますか」で扱っています。)

日本の個人情報保護法は、何を求めていますか

個人データを外国にある第三者へ渡すときは、次のいずれかが求められます。

  1. 本人の同意。 このとき、移転先の国名・その国の個人情報保護制度・提供先が講じる措置を事前に伝える必要があります
  2. 提供先が国内と同等の体制を整えていることの確保。 その体制が続いているかの継続的な確認と、本人から求められたときの情報提供を含みます
  3. 提供先が、同等の水準と認められた国にあること。 現在はEUと英国のみです

米国は3に含まれません。HubSpot・monday.com のように日本から申し込むと米国に置かれるサービスは、1か2で整理することになります。

ただし、契約でSaaS事業者が個人データを取り扱わないと定められ、アクセス制御が適切であれば、そもそも「外国にある第三者への提供」に当たらないという整理も示されています(個人情報保護委員会Q12-3)。CRMのように事業者側が中身を処理する前提のサービスがこれに当たるかは判断が分かれるため、自社の使い方に照らして専門家にご確認ください。

なお、各社が公表しているSCC(標準契約条項)・英国向け追補・データプライバシーフレームワークは、いずれもEUや英国から第三国への移転を適法化する枠組みで、日本の個人情報保護法の要件を直接満たすものではありません。 「SCCがあるから日本法も大丈夫」とは読まないでください。

聞かれる前に、この4つだけ済ませてください

  1. プライバシーポリシーに国名を書く。 個人データを外国のサーバに保存している場合、安全管理措置として講じた内容を本人の知り得る状態に置く必要があり、個人情報保護委員会は、置くべき事項として「クラウドサービス提供事業者が所在する外国の名称及び個人データが保存されるサーバが所在する外国の名称」を挙げています(Q10-25)。事業者の所在国とサーバの所在国は別なので、分けて書きます。この記載で足りるかの最終判断は、専門家にご確認ください
  2. 管理画面で保存先を確認して記録する。 「HubSpot=米国東部、Asana=米国バージニア」と1行ずつ残せば、チェックシートの大半は埋まります
  3. SOC 3を今のうちにダウンロードしておく。 聞かれてから探すと、Trust Center のアクセス承認で数日かかります
  4. DPAのURLを控える。 締結作業は不要ですが「どこに書いてあるか」は聞かれます

所要は30分ほどです。逆に今やらなくてよいのは保存先の変更で、これは具体的な要求を受けてからで間に合います。

書類は、どこから取れますか

必要な書類HubSpotmonday.comAsanaShopify
SOC 2 Type 2(秘密保持つき)Trust Center(trust.hubspot.com)Compliance Hub(trust.monday.com)でアクセス申請Trustページ(asana.com/trust)。受け取り方法は公式に確認できず管理画面にログインして取得
SOC 3(そのまま渡せる)法務ページから公開ダウンロードCompliance HubTrustページ公式のCompliance Reportsページ
DPAlegal.hubspot.com/dpa。署名版はページ内フォームから請求monday.com/l/privacy/dpa。DocuSignで署名版asana.com/terms/data-processingshopify.com/legal/dpa
保存先の証明アカウント設定のデータセンター表示サポート記事のデータレジデンシー欄データレジデンシー設定画面該当機能を確認できませんでした

出典:各社公式ページ(2026年8月確認)。SOC 2は外部の会計監査人による検査報告書で、取引先が求めるのはほぼ Type 2(半年〜1年その仕組みが回っていたかの検査)です。SOC 3はその要約版で、秘密保持契約なしに誰へでも渡せます。DPA(データ処理契約)は「個人データを預かって処理するだけで勝手に使わない」という取り決めで、4社とも利用規約に自動で組み込まれており締結作業は要りません。

この表で最も情報量が多いのは、Shopifyの最下段が空いていることです。 「保存先を選べない」という回答をそのまま書くことになります。

渡す順番にも決まりがあります。SOC 2 Type 2 は自社との秘密保持契約に基づいて渡されるもので、取引先へ転送する権利までは通常含まれません。まずSOC 3を渡し、足りないと言われたら「ベンダーのTrust Centerに直接アクセス申請してください」と案内するのが現実的です。

この対応で足りない読者像

「例外なく国内保存」を条件にされている会社。 書類を揃えても要件を満たせません。4社のうち国内に置けるのは Asana だけで、それも認証まわりのデータは米国に残ります。

ISO 27001の認証書の提出を求められている会社。 HubSpot と Shopify は自社認証の記載がなく、「基盤事業者の認証」としか回答できません。書類の準備ではなく、製品選定の問題になります。

官公庁・金融・医療の案件に関わる会社。 業界固有の要求水準があり、本記事の3点セットでは足りません。

逆に、扱う個人データが自社の従業員名簿と取引先の名刺だけで、他社から預かったデータがない会社。 チェックシートを求められた経験がないなら、上の4つを済ませて記録を残すだけで十分です。保存先を動かすために上位プランへ上げるのは費用に見合いません。

迷ったら

Q1: 取引先からチェックシートやSOC 2の提出を求められましたか
いいえ上の4つ(ポリシーへの国名記載・保存先の記録・SOC 3の取得・DPAのURL)を30分で済ませる
はいQ2へ
Q2: 求められているのは「体制の説明」ですか、「国内保存」そのものですか
体制の説明SOC 3・DPAのURL・保存先表示の3点で回答する。保存先は変えない
国内保存Q3へ
Q3: 先方は「業務データが国内であれば可」ですか、「例外なく国内」ですか
業務データが国内なら可Asana の Enterprise+、または Enterprise にデータレジデンシーのアドオンを追加した構成
例外なく国内この4社では満たせません。要件の根拠を先方に文書で確認する

Q3の確認を先にやること。ここを曖昧にしたまま上位プランを契約すると、結局満たせないことがあります 出典:各社公式ページ・個人情報保護委員会(2026年8月確認)

先に決めるのは、先方の要求が「説明」なのか「国内保存」なのかです。 説明で足りるなら費用はゼロで、その場で回答できます。国内保存が本当に条件なら、書類をいくら揃えても届かないので、プラン変更か製品変更の話に切り替えることになります。この2つを分けずに動くと、上位プランを契約したのに要件を満たせない、という結末になりかねません。

出典(2026年8月確認)

本記事は法的助言ではありません。 個人情報保護法上の取扱いや、取引先との契約で求められる水準の判断は、弁護士など専門家にご確認ください。Asana の SOC 2 Type 2 の受け取り方法、Shopify の保存先の選択可否、HubSpot と Shopify の自社 ISO 27001 認証は、公式ページで記載を確認できませんでした。各社の提供条件は変更されます。契約前に必ず各公式ページでご確認ください。

← ランキング一覧に戻る

HubSpot Ranked #1 · free plan available総合1位 ・ 無料プランあり
Visit公式へ