Executive Summary

This report examines the specifications of three generative AI platforms—Microsoft Azure OpenAI Service, Google Cloud Vertex AI (Gemini), and Amazon Bedrock—with particular focus on the retention of prompt and output logs, generally for up to 30 days, for so-called abuse monitoring. It also explains the measures companies in Japan take when handling personal information and the additional considerations that apply in regulated sectors such as finance and healthcare.

In broad terms, all three providers state that they do not use customer data to train their own foundation models. The primary concern for companies in Japan, however, is that Azure OpenAI and Vertex AI may retain prompts and outputs for up to 30 days for abuse-monitoring purposes, and that automated classifiers—and, in some cases, human reviewers—may be able to access that data. Amazon Bedrock is designed not to retain the user’s actual inputs and outputs, although organizations still need to confirm how classifier metrics are handled and what occurs when content is flagged.

Companies in Japan pay close attention to this issue because abuse-monitoring logs intersect with four overlapping obligations under Japan’s Act on the Protection of Personal Information (APPI): (1) determining whether processing constitutes outsourcing, provision to a third party, or a cross-border transfer; (2) understanding the external environment in which data is handled; (3) implementing appropriate security controls; and (4) meeting breach-reporting obligations. In practice, organizations generally combine several measures, including applying for Azure Modified Abuse Monitoring (MAM), configuring Vertex AI for Zero Data Retention (ZDR), adopting Bedrock’s data-protection architecture, removing personally identifiable information (PII), using guardrails, establishing contractual and internal-use rules, and fixing processing to a specified region.

Microsoft Azure and Microsoft 365 are widely accepted in Japan for workloads involving personal information and log retention because several factors reinforce one another: (a) Microsoft has maintained a Japanese subsidiary and a long enterprise track record since 1986; (b) Japan East and Japan West regions support data residency; (c) Azure is registered under ISMAP and has been selected for Japan’s Government Cloud; (d) Microsoft provides a formal application route for Modified Abuse Monitoring; (e) its contracts and support structure are closely integrated with Microsoft 365 and Office; and (f) Microsoft has announced approximately JPY 1.6 trillion in additional data-center investment in Japan.

30 days Default abuse-monitoring log-retention period for Azure OpenAI and Vertex AI
JPY 1.6 trillion Additional Microsoft data-center investment in Japan announced in April 2026
4 issues Outsourcing, cross-border transfers, the external environment, and security controls interact at multiple levels

Chapter 1: Background and Purpose of This Report

1.1 The Intersection of Generative AI and Personal Information Protection

Since the emergence of ChatGPT, generative AI has rapidly entered the day-to-day operations of companies in Japan. In particular, enterprise AI platforms offered by the three major hyperscalers—Microsoft Azure, Google Cloud, and Amazon Web Services—such as Azure OpenAI Service, Vertex AI (Gemini), and Amazon Bedrock, are commonly used with internal documents, customer information, contact-center histories, medical records, and other data that may contain personal information.

At the same time, Japan’s APPI, as amended in 2020 and 2021 and implemented thereafter, together with guidelines issued by the Personal Information Protection Commission (PPC), expressly requires organizations to address cloud use, provision of personal data to third parties located overseas, the external environment in which data is handled, and appropriate security controls. Generative AI introduces an additional issue that was uncommon in conventional cloud use: the provider’s retention of logs for abuse-monitoring purposes. That issue is the central subject of this report.

1.2 What Is Abuse Monitoring?

Abuse monitoring refers to mechanisms through which a generative AI provider temporarily retains and automatically classifies user prompts and model outputs to detect violations of its terms of service or content policies. Examples include child sexual abuse material, encouragement of violence or self-harm, terrorism-related content, election interference, intellectual-property infringement, and misuse of the service. When necessary, flagged content may also be reviewed by a human reviewer. OpenAI, Microsoft, Google, Anthropic, AWS, and other providers use different names and methods, but the underlying concept is broadly similar.

For generative AI providers, abuse monitoring supports enforcement of service-use policies, responsible-AI operations, protection of minors, and compliance with contractual obligations owed to third-party model providers—for example, Anthropic, Meta, or AI21 Labs when their models are offered through Bedrock. It is therefore generally enabled by default.

1.3 Why 30-Day Log Retention Matters

Azure OpenAI Service and Vertex AI (Gemini) may store prompt and output data for abuse-monitoring purposes for up to 30 days, encrypted in secure provider-managed storage outside the customer tenant. AWS states that Bedrock does not store user inputs or model outputs, while using classifier metrics as part of its abuse-detection process.

The concern with 30-day retention is that: (a) prompts may contain personal information, trade secrets, or medical information; (b) employees of the cloud provider may be able to view the content under specified conditions; and (c) the continued presence of personal data on the servers of a cloud provider—a separate legal entity—directly affects APPI analysis concerning processor oversight, cross-border transfers, assessment of the external environment, and security controls.

This report explains that structure in a form that legal, executive, and technical stakeholders can use to make decisions. It compares the three cloud platforms, summarizes practical measures adopted by companies in Japan, identifies additional requirements in regulated sectors, examines why Microsoft has gained broad acceptance in Japan, and describes the relevant basis under the APPI.

Chapter 2: Detailed Comparison of Abuse Monitoring and Log Retention

2.1 Microsoft Azure OpenAI Service

2.1.1 Default Configuration

By default, Azure OpenAI Service operates as follows:

  • Prompts and generated responses, or completions, may be retained for up to 30 days in encrypted, Microsoft-managed secure storage.
  • Content filtering—five categories with four severity levels—and abuse monitoring are enabled.
  • If an automated classifier detects a pattern that may indicate misuse, authorized Microsoft engineers may access the data through a Secure Access Workstation under Just-In-Time access controls and managerial approval.
  • Prompts and responses are not shared with OpenAI, other Azure tenants, or other third parties, and are not used to train the foundation models.
  • For resources in the European Economic Area (EEA), human reviewers are also located within the EEA. The location applicable to data in a Japanese region is defined by the relevant contract and service terms.

2.1.2 Opting Out Through Modified Abuse Monitoring (MAM)

Azure OpenAI Service provides an access-control framework known as Limited Access, separate from the general service terms. Within that framework, eligible customers may apply for Modified Abuse Monitoring (MAM). Under the current documentation, approval of MAM results in a configuration in which: (1) prompts and responses are not retained for 30 days; (2) human review is not performed; and (3) automated classification for abuse-monitoring purposes continues.

The principal application requirements include being a managed customer with a Microsoft account team or applying through an authorized partner; having an Enterprise Agreement (EA) or Microsoft Customer Agreement (MCA), rather than a Pay-As-You-Go arrangement; applying from an organizational-domain email address; explaining that the use case involves personal or confidential information; and demonstrating an internal risk-assessment and content-moderation design that supplements Microsoft’s controls. Approval generally takes approximately five to ten business days.

Importantly, MAM is not automatically approved merely because a workload contains personal information. Microsoft reviews the intended use and the organization’s risk-management framework before deciding whether to approve the application. Approval is granted per application or use case.

2.1.3 Region and Data Residency

Azure OpenAI Service is available in the Japan East region. When that region is selected, prompts, outputs, and abuse-monitoring data processed for the resource generally remain in Japan. A Global Standard deployment, however, may process inference requests at any eligible Azure OpenAI location. Organizations with data-residency requirements should therefore select a Standard deployment fixed to a specific region.

2.2 Google Cloud Vertex AI / Gemini

2.2.1 Default Configuration

For customers using Vertex AI or Gemini under the Google Cloud Platform Terms of Service, Google may retain prompts as logs to detect violations of its Acceptable Use Policy or Prohibited Use Policy.

  • Automated detection: Google’s automated safety-classification systems detect potentially abusive or policy-violating activity.
  • Prompt logging: Google logs prompts for investigation only when its automated safety systems identify suspicious activity that warrants review. The data is stored securely for up to 30 days within the region or multi-region selected by the customer. This processing is subject to Google Cloud assurances relating to data location, Access Transparency, VPC Service Controls, and other controls.
  • Response: Flagged messages may be evaluated by authorized Google employees, who may ask the customer for clarification or corrective action. If concerns are not addressed, recur, or are serious, access to Vertex AI or other Google Cloud services may be suspended or terminated.
  • Logged data is used only for policy enforcement and prevention of violations. It is not used to train or tune AI or machine-learning models for purposes unrelated to policy enforcement.
  • Gemini-family models available through Vertex AI may cache customer data—inputs, outputs, and derived data—in memory to reduce latency. The cache is memory-only, isolated by project, and has a 24-hour time-to-live. This mechanism is separate from abuse-monitoring prompt logging.

Unlike Azure OpenAI’s standard 30-day retention model, Vertex AI logs prompts for up to 30 days only when activity is flagged. The fact that retained data remains within the customer-selected region is also an important data-residency assurance.

2.2.2 Opting Out Through Zero Data Retention (ZDR)

Vertex AI supports a configuration commonly referred to as Zero Data Retention (ZDR), under which prompts are not retained for abuse-monitoring purposes. The following steps are generally required:

  1. Disable data caching for Google models.
  2. Set up invoiced billing and request an exception that disables prompt logging for abuse-monitoring purposes.
  3. Apply for the abuse-monitoring exception through a Google sales representative and obtain approval.

ZDR is designed to support compliance with regimes that emphasize data minimization and deletion rights, including the GDPR, CCPA, and Japan’s APPI. It allows organizations to avoid persistent storage of data outside the designated region.

2.2.3 Region and Data Residency

Vertex AI is available in asia-northeast1 (Tokyo) and asia-northeast2 (Osaka). Some models, including certain preview versions of Gemini, may be available only in a limited set of regions. Organizations should confirm regional availability for each intended model before deployment.

2.3 Amazon Web Services (AWS) Bedrock

2.3.1 Default Configuration

Of the three platforms, Amazon Bedrock takes the most data-minimizing approach to provider-side log retention. AWS’s standard statements in its official documentation and FAQs include the following:

  • User prompts and model outputs are not used to train foundation models by default. No explicit opt-out action is required.
  • User inputs and model outputs are not shared with third-party model providers such as Anthropic, Meta, AI21 Labs, or Cohere.
  • Abuse detection is fully automated, and AWS states that human reviewers do not view or access user inputs or model outputs.
  • Automated classifiers assign harm categories and confidence scores to inputs and outputs. AWS may share anonymized classifier metrics—not the underlying text of individual inputs or outputs—with third-party model providers.
  • Model-invocation logging to CloudWatch Logs or Amazon S3 occurs only when the customer enables it, and the resulting logs remain within the customer’s own AWS account and control environment.

2.3.2 Important Logging Considerations

AWS does not document a standard mechanism under which Bedrock persistently stores the body of user inputs and outputs on the AWS side. Organizations should nevertheless evaluate: (a) what occurs when an automated classifier identifies suspected policy violations; (b) whether to use the AWS Organizations AI services opt-out policy; and (c) how to design Bedrock Guardrails and PII filters. Before deployment, legal teams should review the AWS Service Terms and AWS Customer Agreement and reflect the findings in the operating model.

2.3.3 Region and Data Residency

Bedrock is available in ap-northeast-1 (Tokyo), although the specific models offered vary over time. Cross-Region Inference can process requests in other regions; organizations with strict data-residency requirements should disable that feature.

2.4 Comparison Summary

The table below summarizes the principal specifications of the three services, based on publicly available information as of April 2026. Organizations should always reconfirm the current official documentation before deployment.

ItemAzure OpenAI ServiceVertex AI (Gemini)Amazon Bedrock
Provider-side retention of prompts and outputs by defaultYes, encrypted, for up to 30 daysLogged only when flagged, for up to 30 days within the customer-selected region; Gemini-family models may also use a 24-hour in-memory cacheGenerally not retained
Human reviewYes, by authorized Microsoft engineers under Just-In-Time approval controlsYes, authorized Google employees may evaluate flagged messagesNo; AWS states that the process is fully automated
Use for model trainingNoNot used for models unrelated to policy enforcementNo
Sharing with third-party model providersNot shared, including with OpenAINot applicable to Google-owned modelsUser inputs and outputs are not shared; anonymized metrics may be shared
Opt-out routeApply for Modified Abuse Monitoring (MAM)Apply for Zero Data Retention (ZDR)No standard provider-side retention; AI services opt-out policies may provide additional control
Opt-out requirementsEA or MCA and managed-customer statusInvoiced billing and an application through Google salesGenerally no application required; organizational policy configuration is recommended
Japan regionsJapan EastTokyo and OsakaTokyo (ap-northeast-1)
Potential cross-region inferenceGlobal deployments may process in other regionsCan be fixed by selecting a regionCross-Region Inference is optional
ISMAP registrationYes, for Microsoft AzureYes, for Google CloudYes, for AWS

Chapter 3: Japan’s APPI—Why Organizations Treat This as a Material Issue

This chapter explains why retention of abuse-monitoring logs raises legal questions under Japan’s APPI. The conclusion is that organizational concern is not simply an overreaction. It is a reasonable operational response to several overlapping statutory and regulatory obligations.

3.1 Outsourcing, Third-Party Provision, and the Cloud Exception

Article 27 of the APPI generally requires the data subject’s consent when personal data is provided to a third party. Article 27, paragraph 5, item 1, however, excludes provision made in connection with the outsourcing of all or part of the handling of personal data. Consent is not required in that case, but the entrusting party becomes subject to the processor-supervision obligation under Article 25.

The PPC has also articulated the so-called cloud exception in FAQ 7-53. Where a cloud provider is contractually prohibited from handling personal data stored on its servers and appropriate access controls are in place, use of the cloud is not treated as a “provision” of personal data. Consequently, neither data-subject consent nor processor supervision is required on that basis.

Thirty-day abuse-monitoring retention complicates this analysis because: (a) employees of the cloud provider, acting as human reviewers, may be able to access the data; and (b) the provider performs content assessment, which may itself constitute handling of personal data. Organizations therefore need to determine whether the conditions of the cloud exception remain satisfied. In practical terms:

  • Microsoft: Approval for Modified Abuse Monitoring removes human review and 30-day retention, making it easier to structure the service within the cloud-exception analysis.
  • Vertex AI: ZDR can support a similar analysis.
  • Bedrock: The absence of standard provider-side retention and human review makes the cloud-exception analysis more straightforward.

Under the default configuration, without an approved exception, the provider may be regarded as handling personal data. An organization would then need to structure the arrangement either as: (i) outsourcing, with processor supervision and any applicable cross-border-transfer requirements; or (ii) provision to a third party, with data-subject consent.

3.2 Cross-Border Transfers and the External Environment

Article 28 of the APPI generally requires the data subject’s consent when personal data is provided to a third party located in a foreign country, subject to exceptions such as the recipient maintaining a system that meets prescribed standards. Even when a cloud provider stores data in a Japanese region, cross-border-transfer issues may arise if support or operations are conducted from overseas or if human abuse-monitoring reviewers are located outside Japan.

The 2020 amendments also introduced requirements commonly described as understanding or ascertaining the external environment. Under Article 7, item 1 of the APPI Enforcement Rules and the security-control guidance, an organization that handles data in a foreign country must understand that country’s personal-information protection regime and implement necessary and appropriate safeguards. In practice, organizations are often expected to identify the countries in which data is stored or handled in their privacy notices.

For abuse monitoring, organizations should separately confirm: (a) the region in which 30-day logs are stored; (b) the countries in which human reviewers are located; (c) the regions in which automated classification is performed; and (d) the countries in which support personnel are located. Those facts should be disclosed where required.

3.3 Personal Data Contained in Logs and Prompts

Another important question is whether abuse-monitoring logs qualify as “personal data” in the first place. Under the APPI, personal data is personal information that forms part of a personal-information database or equivalent structured collection. Logs fall within that definition when they contain information that identifies an individual, such as a name, employee number, customer ID, email address, or information that can readily be cross-referenced with other data.

Prompts commonly include: (i) names, addresses, and contract numbers referenced in customer support; (ii) the contents of employee chats; (iii) medical information or patient questionnaires; and (iv) the text of a job applicant’s résumé. It is therefore common, rather than exceptional, for prompt logs to contain personal data.

Access logs may also constitute personal data when they can be searched using a user ID and timestamp that identify a particular person. Abuse-monitoring logs may consequently be subject to all relevant APPI requirements, including specification of purpose of use, security controls, restrictions on third-party provision, cross-border-transfer rules, and breach reporting.

3.4 Security Control Measures: Organizational, Personnel, Physical, and Technical

The PPC’s General Guidelines identify four categories of security control measures: (1) organizational controls; (2) personnel controls; (3) physical controls; and (4) technical controls. Because 30-day abuse-monitoring logs are stored outside the direct control of the customer organization, those safeguards must be assured through the cloud provider and the contractual framework. Examples include:

  • Organizational: Entering into outsourcing agreements and data-protection addenda, including terms aligned with GDPR Article 28 where appropriate, and clearly defining the division of responsibility.
  • Personnel: Training employees on prompt-input rules, including policies that prohibit or minimize entry of personal information.
  • Physical: Reviewing the provider’s data-center security through certifications and assessments such as ISMAP, ISO/IEC 27001, and SOC 2.
  • Technical: Encryption, including provider-managed keys and customer-managed-key options such as CMK or BYOK; PII removal; access controls; and audit logging.

3.5 Breach-Reporting Obligations

Following the 2020 amendments, reporting to the PPC and notification to affected individuals became mandatory for certain leaks and similar incidents, including those involving sensitive personal information, a risk of financial harm, suspected malicious conduct, or data relating to more than 1,000 individuals.

If logs retained by a provider for abuse-monitoring purposes are exposed because of: (a) a provider-side outage or security incident; or (b) intentional or negligent disclosure by a human reviewer, the customer organization may still need to make the required reports and notifications as the entrusting party. If the contract does not clearly define the provider’s notification timing and level of detail, the organization may be unable to meet the applicable reporting periods, including an initial report generally expected within three to five days and a final report within 30 days.

3.6 Summary: Why Organizations Care

The reasons companies focus on abuse-monitoring log retention can be summarized as follows:

  1. Prompts may contain personal data, causing the logs themselves to qualify as personal data.
  2. Where the provider uses human review, the assumptions underlying the cloud exception may no longer hold, requiring analysis of outsourcing, cross-border transfers, or data-subject consent.
  3. The obligation to understand the external environment requires organizations to identify and, where necessary, disclose the countries in which data is stored and human reviewers are located.
  4. Organizations need an architecture and contractual assurances that maintain security controls through the provider.
  5. Because an incident may originate in the provider’s log-retention environment, contractual notification and reporting arrangements are essential.
  6. In regulated sectors such as finance and healthcare, industry guidance often requires controls beyond the basic cloud-exception analysis. Uncertainty around the abuse-monitoring design therefore becomes a problem of demonstrable accountability.

This is not merely a question of whether a provider keeps logs for 30 days. It is a broader governance question: how should an organization translate multiple APPI obligations into system architecture, contracts, and operating controls?

Chapter 4: Additional Requirements in Regulated Industries

4.1 FISC Security Guidelines

The FISC Security Guidelines on Computer Systems for Banking and Related Financial Institutions, issued by the Center for Financial Industry Information Systems (FISC), function as a de facto standard for Japan’s financial sector and are referenced in supervisory guidance issued by the Financial Services Agency. The latest version is the 13th edition, published in March 2025. It added measures addressing the FSA’s cybersecurity guidelines and new items concerning the safe use of AI, following earlier expansions of cloud-related requirements in the 9th and 11th editions.

The FISC approach to cloud use includes the following principles:

  • Because the original standards assumed on-premises environments, cloud-service control items were developed through expert-panel reports and later revisions.
  • Encryption and password protection are required for storage and transmission of personal data so that the information cannot be understood if it is copied or stolen without authorization.
  • The 11th edition, together with related Bank of Japan and FSA materials on cloud-service controls, requires organizations to assess the division of responsibility, conduct risk assessments, review third-party certifications such as ISMAP and ISO/IEC 27017, establish recovery arrangements, and develop an exit strategy.

In the context of abuse monitoring, key issues include: (a) whether the log-storage environment is subject to appropriate data-center controls; (b) whether audit evidence is available; (c) whether customer-controlled key-management options such as BYOK or HYOK are available; and (d) whether human access is logged and controlled. Microsoft publishes documentation mapping its services to the FISC guidelines, and AWS and Google Cloud provide similar materials.

4.2 Japan’s Three-Ministry, Two-Guideline Framework for Medical Information

Japan’s healthcare information security framework is commonly referred to as the Three-Ministry, Two-Guideline framework. It combines the Ministry of Health, Labour and Welfare’s Guidelines for the Security Management of Health Information Systems, currently version 6.0, with the integrated guidelines issued by the Ministry of Economy, Trade and Industry and the Ministry of Internal Affairs and Communications for providers of systems and services that handle medical information.

  • The framework establishes requirements for both healthcare institutions and service providers, including the division of responsibility, security controls, patient consent, and protection of patient privacy.
  • When patient information, clinical records, or prescription information is entered into generative AI, organizations are generally expected to establish: (i) internal governance and, where appropriate, ethics-committee-level approval; (ii) appropriate outsourcing contracts; (iii) pseudonymization or anonymization; and (iv) written allocation of responsibilities under the guidelines.
  • The country in which cloud data is stored receives particularly strict scrutiny because of established practices concerning cross-border handling of medical information and the need to maintain transparency for patients.

Under this framework, the practical baseline for Azure OpenAI, Vertex AI, or Bedrock generally combines: (a) use of a fixed Japanese region; (b) approval of an abuse-monitoring exception where applicable; (c) a PII-removal layer; and (d) preservation of audit logs.

4.3 Financial Services Agency and Bank of Japan Guidance

The Financial Services Agency’s supervisory guidelines for major banks and for small and regional financial institutions, together with its guidelines on personal-information protection in the financial sector, require controls for sensitive personal information, management of external service providers, and system-risk management. These requirements naturally extend to generative AI use.

The Bank of Japan’s January 2024 Financial System Report annex, Key Management Items and Practical Examples for the Use of Cloud Services, also addresses: (a) cloud-provider selection criteria; (b) contracts and service-level agreements; (c) risk monitoring; (d) exit strategies; and (e) incident response. Abuse monitoring should be governed within the same framework.

4.4 ISMAP: Information System Security Management and Assessment Program

ISMAP is Japan’s advance security-assessment program for cloud services used in government information systems. Government organizations may procure services registered under the program. Microsoft Azure, Google Cloud, and AWS are registered, as are Oracle Cloud Infrastructure and Sakura Internet, the first Japan-headquartered provider to be registered.

ISMAP registration serves as: (a) a prerequisite for government cloud procurement; (b) a condition relevant to selection for the Digital Agency’s Government Cloud; and (c) a benchmark used by private-sector regulated industries. For generative AI services that include abuse monitoring, organizations should confirm the exact service and scope covered by the ISMAP registration and conduct a separate risk assessment for any service outside that scope.

Chapter 5: Why Microsoft Is Widely Accepted in Japan

This chapter examines why companies in Japan—including organizations in finance, healthcare, and the public sector—often favor Microsoft Azure, Microsoft 365, and Copilot for workloads involving personal information and log retention.

5.1 History and Enterprise Relationships Since 1986

Microsoft Japan, formerly Microsoft Co., Ltd., was established in February 1986. From the 1990s onward, Microsoft Office became a standard office environment across government agencies and large enterprises. As Windows, Office, and Active Directory became de facto enterprise standards, Azure, Microsoft 365, and Microsoft Entra ID, formerly Azure AD, came to be viewed less as entirely new platforms and more as extensions of existing IT infrastructure.

Large enterprises typically have access to Microsoft account executives, technical specialists, customer-success teams, and support personnel, with Japanese-language channels for contracts, implementation, and incident handling. This structure aligns with the requirement that applications for Modified Abuse Monitoring generally be submitted by managed customers.

5.2 Data-Residency Strategy

Microsoft operates Japan East, in Saitama, and Japan West, in Osaka, allowing organizations to design many services—including Azure OpenAI—to remain within Japan. In April 2026, Microsoft also announced approximately JPY 1.6 trillion in additional investment in Japanese data-center infrastructure, including collaboration with SoftBank and Sakura Internet, signaling a strong commitment to data sovereignty.

Google Cloud also operates Tokyo and Osaka regions, and AWS operates Tokyo and Osaka regions. In some cases, however, Azure OpenAI has made newly released generative AI models available in Japanese regions earlier, which can affect enterprise adoption decisions.

5.3 Position in the Government Cloud and ISMAP

Japan’s Digital Agency selected AWS, Google Cloud, Microsoft Azure, and Oracle Cloud Infrastructure for the Government Cloud in fiscal 2022, and added Sakura Internet as a domestic provider from fiscal 2025 onward. Microsoft Azure was included from the initial selection and has become a major option for the migration of municipalities’ twenty core administrative systems.

In the private sector, the combination of ISMAP registration and government adoption functions as a significant trust indicator. For financial, healthcare, and public-sector proposals, Microsoft is often positioned through a combination of ISMAP registration, Japanese regions, and an existing Microsoft 365 contract.

5.4 A Formal Route for Modified Abuse Monitoring Approval

Azure OpenAI documentation describes MAM as available only to managed customers. In Japan, applications based on personal-information protection requirements can be coordinated through Microsoft sales teams and customer-success units. Publicly disclosed and non-public implementations are reported across financial institutions, major manufacturers, telecommunications carriers, and healthcare organizations.

Google Cloud offers a comparable function through ZDR, but its use is more limited because invoiced billing and a sales-led application are required. AWS Bedrock does not use human review by default, so an application equivalent to MAM is generally unnecessary. Microsoft’s formal application and approval framework for enterprise workloads that handle personal information is therefore one factor in its acceptance in the Japanese market.

5.5 Continuity with the Microsoft 365 and Office Ecosystem

Microsoft 365 Copilot, formerly Microsoft 365 Copilot for Enterprise, operates within Office products already deployed in many organizations, including Word, Excel, PowerPoint, Outlook, and Teams. Its data governance is integrated with the handling of data within the Microsoft 365 tenant.

Companies already store personal and confidential information in Microsoft 365, including Exchange Online email, SharePoint Online documents, and Teams chats. Microsoft has long provided data-protection addenda, certifications and attestations—including ISO/IEC 27001, 27017, 27018, and 27701; SOC 1, 2, and 3; ISMAP; HIPAA-related offerings; and FISC mappings—as well as compliance dashboards. Because Copilot is added within an existing governance framework rather than introduced as an isolated new environment, legal and information-security teams can often limit their review to the incremental changes.

5.6 Why Microsoft Is Often Considered Acceptable

The following factors operate together:

  1. Established trust: Nearly four decades of relationships through Office, Windows, and Microsoft Entra ID allow organizations to conduct an incremental assessment rather than a completely new vendor review.
  2. Japanese regions and location assurances: Japan East and Japan West, documented data-residency policies, and substantial domestic investment.
  3. ISMAP and Government Cloud: Government approval functions as an authoritative, third-party trust signal.
  4. A formal exception mechanism through MAM: An established procedure can disable 30-day retention and human review for approved use cases involving personal information.
  5. Japanese-language support and account teams: Legal inquiries, incident response, and contract negotiations can be handled in Japanese.
  6. Integrated governance with Microsoft 365: Copilot can be governed as an extension of personal information already held within Microsoft’s ecosystem.
  7. A migration path from on-premises systems: Hybrid-cloud offerings such as Azure Arc and Azure Stack support phased migration.

This does not mean that Microsoft is inherently superior to other providers. Rather, Microsoft’s delivery model aligns well with the procurement and legal processes of many companies in Japan. AWS and Google Cloud also provide mature technical and contractual controls, and each platform may be preferred depending on the use case.

References and Sources

This report is based on publicly available information as of April 2026. Service specifications and eligibility requirements may change, so organizations should always review the latest official documentation before deployment.

8.1 Official Hyperscaler Documentation

8.2 APPI and Public-Sector Guidance

8.3 Commentary and Practical Resources

Appendix A: Glossary

TermDefinition
Abuse MonitoringA mechanism through which a cloud AI provider temporarily retains prompts and outputs, applies automated classification, and, in some cases, conducts human review to detect violations of its terms of service or content policies.
MAM (Modified Abuse Monitoring)An application-based Azure OpenAI configuration under which 30-day log retention and human review are not performed for an approved use case.
ZDR (Zero Data Retention)A Vertex AI or Gemini configuration that disables abuse-monitoring log retention of up to 30 days when flagged. It generally requires disabling data caching, invoiced billing, and approval of an exception request.
Cloud ExceptionThe analysis described in PPC FAQ Q7-53 under which cloud use is not treated as provision or outsourcing when the cloud provider does not handle the personal data.
Understanding the External EnvironmentAn APPI security-control requirement to understand the legal and institutional environment of a foreign country when data is handled there and to implement appropriate measures.
FISCThe Center for Financial Industry Information Systems, which publishes security guidelines used across Japan’s financial industry. The 13th edition, issued in March 2025, is the latest version referenced in this report.
Three-Ministry, Two-Guideline FrameworkJapan’s medical-information security framework combining MHLW guidance for healthcare institutions with integrated METI and MIC guidance for service providers.
ISMAPJapan’s Information System Security Management and Assessment Program, an advance security-assessment framework for cloud services procured by government organizations.
BYOK / CMK / HYOKBring Your Own Key, Customer Managed Key, and Hold Your Own Key—architectures in which the customer exercises varying degrees of control over encryption keys.
DPAData Protection Addendum, a contractual annex governing the handling of personal data by a service provider.
DPIA / PIAData Protection Impact Assessment / Privacy Impact Assessment.
GuardrailsAdditional safeguards available in Amazon Bedrock, including PII filtering, denied-topic controls, content filtering, and contextual-grounding checks.