Last Reviewed: 01 Jun 2026
At a Glance
Google's Cloud DPA (updated October 2025) addresses key GDPR requirements across EU, UK, Swiss, US, Brazilian, Israeli and Turkish law, with SCCs incorporated and processor-only restrictions in place. Audit rights are structured: customers access SOC reports and security documentation, with direct inspection available on agreed terms.
Company & Product Details
HQ
United States
Products
Google Workspace / Cloud Identity
Product description
Business productivity and collaboration suite including email, documents, storage, meetings and identity services.
What data is being processed?
Customer Data provided to Google via the services, including communications, files, account data and any personal data contained in Workspace / Cloud Identity content.
Document Details
Date of DPA
23 Oct 2025
Additional date information
DPA last modified 23 October 2025 (current version); previous version was dated 9 April 2024. Multiple incremental revisions were published between May 2024 and October 2025. Google Workspace admin help confirms the Cloud Data Processing Addendum (CDPA) is the current additional term for Workspace and Cloud Identity (CDPA preamble).
What jurisdictions are covered?
EU GDPR, UK GDPR, Swiss FADP, CCPA/CPRA (California), Turkish Data Protection Law No. 6698, Israeli Privacy Protection Law 1981, and Brazilian LGPD are all expressly addressed in Appendix 3 (Specific Privacy Laws) of the CDPA (appendix 3).
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
Not explicitly stated Customer Data may be processed in any country where Google or its sub-processors maintain facilities, subject to data location commitments under the Service Specific Terms and transfer commitments under Appendix 3. Data centre and sub-processor information is published by Google. (section 10.1)
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Appendix 2 details: encryption (HTTPS/TLS, perfect forward secrecy); geographically distributed physically secure data centres with redundant power and CCTV; intrusion detection; access controls based on least privilege, SSH certificates, two-factor authentication; personnel confidentiality agreements and security training; decommissioned disk erasure policy. Certifications: ISO 27001, ISO 27017, ISO 27018, PCI DSS Attestation of Compliance, SOC 2 and SOC 3 updated annually (section 7.4, appendix 2, appendix 4).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Google will notify Customer promptly and without undue delay after becoming aware of a Data Incident, with initial notification describing the nature of the incident and measures taken, and further detail provided without undue delay as it becomes available. No fixed-hour deadline is specified. (section 7.2.1)
What happens to the data on termination?
Google enables customer-initiated deletion during the Term. On termination, remaining Customer Data is deleted after a recovery period of up to 30 days, completed within a maximum of 180 days, unless law requires storage. A deferred deletion rule applies where Customer Data is also processed under a continuing Agreement. (sections 6.1, 6.2, 6.3)