Google

Last Reviewed: 01 Jun 2026

GDPR Addressed

At a Glance

Google's Cloud DPA (updated October 2025) addresses key GDPR requirements across EU, UK, Swiss, US, Brazilian, Israeli and Turkish law, with SCCs incorporated and processor-only restrictions in place. Audit rights are structured: customers access SOC reports and security documentation, with direct inspection available on agreed terms.

Company & Product Details

HQ

United States

Products

Google Workspace / Cloud Identity

Product description

Business productivity and collaboration suite including email, documents, storage, meetings and identity services.

What data is being processed?

Customer Data provided to Google via the services, including communications, files, account data and any personal data contained in Workspace / Cloud Identity content.

Document Details

Date of DPA

23 Oct 2025

Additional date information

DPA last modified 23 October 2025 (current version); previous version was dated 9 April 2024. Multiple incremental revisions were published between May 2024 and October 2025. Google Workspace admin help confirms the Cloud Data Processing Addendum (CDPA) is the current additional term for Workspace and Cloud Identity (CDPA preamble).

What jurisdictions are covered?

EU GDPR, UK GDPR, Swiss FADP, CCPA/CPRA (California), Turkish Data Protection Law No. 6698, Israeli Privacy Protection Law 1981, and Brazilian LGPD are all expressly addressed in Appendix 3 (Specific Privacy Laws) of the CDPA (appendix 3).

Is the DPA incorporated into service or customer agreements?

Yes
The CDPA is incorporated into the Agreement(s) under which Google provides Google Cloud Platform, Google Workspace, Cloud Identity, Looker (original), Google SecOps Services, Google Skills for Organizations, and Mandiant Consulting Services (CDPA preamble).

Location & Transfers

Where is data held or processed?

Not explicitly stated Customer Data may be processed in any country where Google or its sub-processors maintain facilities, subject to data location commitments under the Service Specific Terms and transfer commitments under Appendix 3. Data centre and sub-processor information is published by Google. (section 10.1)

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
The CDPA incorporates EU SCCs in three modules: Controller-to-Processor (cloud.google.com/terms/sccs/eu-c2p), Processor-to-Processor (eu-p2p), and Processor-to-Controller (eu-p2c). UK GDPR and Swiss FADP transfers addressed under European Data Protection Law section. Brazilian BR SCCs (C2P and P2P) under LGPD section. Turkish SCCs available under Turkey section. All referenced in Appendix 3 (section 4).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Appendix 2 details: encryption (HTTPS/TLS, perfect forward secrecy); geographically distributed physically secure data centres with redundant power and CCTV; intrusion detection; access controls based on least privilege, SSH certificates, two-factor authentication; personnel confidentiality agreements and security training; decommissioned disk erasure policy. Certifications: ISO 27001, ISO 27017, ISO 27018, PCI DSS Attestation of Compliance, SOC 2 and SOC 3 updated annually (section 7.4, appendix 2, appendix 4).

Non Processor Data Use

Does the company process data solely as a processor?

Yes
Section 4.1 states Google is a processor and Customer is a controller or processor. The CCPA section (Appendix 3) prohibits Google from selling, sharing or using Customer Personal Data outside the direct business relationship or for purposes other than performing the Services. No language found granting Google independent controller rights.

Subprocessing

General authorization

General
Google gives at least 30 days' notice before a new sub-processor starts processing Customer Data (section 11.4(a)). Customers may object within 90 days of notification by terminating the Agreement for convenience (section 11.4(b)). Sub-processor names, locations and activities published at cloud.google.com/terms/subprocessors.

Do all the DPA terms flow down to sub-processors?

Yes
Google must use a written contract imposing relevant data protection obligations on each sub-processor and remains fully liable for all acts and omissions of the sub-processor. (section 11.3)

Is data only processed on the instruction of the controller?

Yes
Google processes Customer Data only in accordance with the Agreement and CDPA, via Customer's use of the Services or Admin Console, and via other written instructions acknowledged by Google as constituting instructions under this Addendum. (section 5.2)

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Google enables access, rectification, restricted processing and portability via the Services, and assists with data subject rights requests by forwarding requests, advising data subjects to contact Customer, and providing additional reasonable co-operation on request. (sections 9.1, 9.2.2)

Does the contract include staff confidentiality clauses?

Yes
All persons authorised to process Customer Data must be under an obligation of confidentiality; personnel must acknowledge privacy and confidentiality policies and receive security training, and may not process Customer Data without authorisation. (section 7.1.2)

Are there audit rights for the data?

Structured
Customer may review Security Documentation (ISO 27001 certificates, SOC 2/3 reports) at any time and may request a direct audit where required under Applicable Privacy Law, subject to advance agreement on scope, duration and confidentiality controls and Google's reasonable costs. Google may object to manifestly unsuitable auditors. (sections 7.5.1, 7.5.2, 7.5.3)

Is there assistance with DPIA requests?

Yes
Google assists Customer with DPIAs, risk assessments, prior regulatory consultations and equivalent procedures under applicable privacy law by making security documentation and Additional Security Controls available, and providing additional reasonable co-operation on request. (section 8)

How much notice is provided for data breaches?

Google will notify Customer promptly and without undue delay after becoming aware of a Data Incident, with initial notification describing the nature of the incident and measures taken, and further detail provided without undue delay as it becomes available. No fixed-hour deadline is specified. (section 7.2.1)

What happens to the data on termination?

Google enables customer-initiated deletion during the Term. On termination, remaining Customer Data is deleted after a recovery period of up to 30 days, completed within a maximum of 180 days, unless law requires storage. A deferred deletion rule applies where Customer Data is also processed under a continuing Agreement. (sections 6.1, 6.2, 6.3)