
Running Business Apps in Your Own Cloud Tenant: Access, Data Location, and Personal Data
If you are dropping a SaaS product and building the business app yourself, my view is that it usually runs better inside your own cloud environment, your own tenant. The fifth and final article in this series covers how that differs from multi-tenant SaaS, what you gain in identity, access, data integration, and audit logs, why "who can touch the data" rather than where it sits decides whether Japan's APPI treats a vendor as an entrusted party, why choosing a Tokyo region does not remove the duty to understand foreign rules, and how operational responsibility shifts to you. It draws on NIST, AWS, the Japanese Personal Information Protection Commission's Q&A and the 2026 APPI amendment, and ISO/IEC 27001.