Gemini for Google Workspace
google.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No clear commitment that your data will not train their models
- Data retention window not stated
See Before you sign, with what to ask for ↓
Scanned Oct 5, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.
What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.
“12.11 Training Restriction . Google will not use Customer Data to train or fine-tune any of its generative artificial intelligence models supporting the Google Workspace Generative AI Services without Customer's prior permission or instruction.”
“No. User prompts are considered customer data under the Cloud Data Processing Addendum . Workspace does not use customer data for training models without customer's prior permission or instruction. This commitment is outlined in the 'Training Restriction' section of the Google Workspace Service Specific Terms .”
“Your content is not used for any other customers. Your content is not human reviewed or otherwise used for Generative AI model training outside your domain without permission.”
“Feedback is used to improve generative AI products and services in accordance with the Google Cloud Privacy Notice , but it is not used to train any of the generative AI models that support Google Workspace Generative AI Services.”
“Google may use, and the Customer will (including by collecting or providing any required consents or notices) ensure that Google may use any Customer Data (including Customer Personal Data) submitted, stored, sent or received via any Pre-GA Offerings by the Customer or its End Users ('Customer Test Data') to provide, test, analyse, develop and improve those Pre-GA Offerings and any Google products and services used with them without any restriction or obligation to the Customer, any End User or any third party, other than as stated in the Agreement's confidentiality provisions and below.”
“Google will not use Customer Data to train or fine-tune any AI/ML models without Customer's prior permission or instruction.”
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“Flexible retention: Admins have control over conversation history for their organization. Administrators can choose to: Allow users to delete individual conversations (manual deletion by users is enabled by default) Set automated retention periods based on inactive conversations (such as 3 months, 18 months, or 3 years), or retain conversations indefinitely for the organization”
“If Customer uses the Services to delete any Customer Data during the Term and that Customer Data cannot be recovered by Customer, this use will constitute an Instruction to Google to delete the relevant Customer Data from Google’s systems. Google will comply with this Instruction as soon as reasonably practicable and within a maximum period of 180 days,”
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
!Will they train on your data?Ask the vendor
The Workspace Service Specific Terms contractually bar Google from using Customer Data to train or fine-tune any of the generative AI models that support the Workspace Generative AI Services (which include Gemini in Workspace) unless the customer gives prior permission or instruction.
Requires written confirmation — see Before you sign ↓
“12.11 Training Restriction . Google will not use Customer Data to train or fine-tune any of its generative artificial intelligence models supporting the Google Workspace Generative AI Services without Customer's prior permission or instruction.”
“No. User prompts are considered customer data under the Cloud Data Processing Addendum . Workspace does not use customer data for training models without customer's prior permission or instruction. This commitment is outlined in the 'Training Restriction' section of the Google Workspace Service Specific Terms .”
“Your content is not used for any other customers. Your content is not human reviewed or otherwise used for Generative AI model training outside your domain without permission.”
“Feedback is used to improve generative AI products and services in accordance with the Google Cloud Privacy Notice , but it is not used to train any of the generative AI models that support Google Workspace Generative AI Services.”
“Google may use, and the Customer will (including by collecting or providing any required consents or notices) ensure that Google may use any Customer Data (including Customer Personal Data) submitted, stored, sent or received via any Pre-GA Offerings by the Customer or its End Users ('Customer Test Data') to provide, test, analyse, develop and improve those Pre-GA Offerings and any Google products and services used with them without any restriction or obligation to the Customer, any End User or any third party, other than as stated in the Agreement's confidentiality provisions and below.”
“Google will not use Customer Data to train or fine-tune any AI/ML models without Customer's prior permission or instruction.”
!How long do they keep your data?Ask the vendor
Retention of Gemini in Workspace conversation history is set by the customer's administrators: users may delete conversations (on by default) and admins can set automatic deletion after 3, 18 or 36 months of inactivity or retain conversations indefinitely. The retention table summarises this as 90 days to indefinite, as determined by admins.
Requires written confirmation — see Before you sign ↓
“Flexible retention: Admins have control over conversation history for their organization. Administrators can choose to: Allow users to delete individual conversations (manual deletion by users is enabled by default) Set automated retention periods based on inactive conversations (such as 3 months, 18 months, or 3 years), or retain conversations indefinitely for the organization”
“If Customer uses the Services to delete any Customer Data during the Term and that Customer Data cannot be recovered by Customer, this use will constitute an Instruction to Google to delete the relevant Customer Data from Google’s systems. Google will comply with this Instruction as soon as reasonably practicable and within a maximum period of 180 days,”
!Who else can access your data?Ask the vendor
Google commits to give at least 30 days' notice (name, location and activities) before any new subprocessor processes Customer Data, and the customer may object within 90 days by terminating the agreement for convenience. Workspace subprocessor names, locations and activities are published at the Workspace subprocessor page referenced in Appendix 4.
Confirm in writing: Ask the vendor to state this in writing before signing.
“a. When Google engages any New Subprocessor during the Term, Google will, at least 30 days before the New Subprocessor starts processing any Customer Data, notify Customer of the engagement (including the name, location and activities of the New Subprocessor).”
“These Subprocessors do not have access to Customer Data stored or processed by the Services. They only have access to Customer Data if Customer explicitly elects to enable such access in the course of a support case (e.g., by granting access to a Google Doc, Google Sheet, or Google Drive folder).”
“Security Risk Detection: Human review of indicators of account compromise or abuse. The Subprocessor only accesses Customer Data of accounts suspected of compromise or abuse and access to Customer Data is limited to suspicious search terms.”
“Accenture International Limited All Google Workspace Core Services and Cloud Identity Services Technical Support Bulgaria, Canada, India, Israel, Japan, Malaysia, Mexico, Philippines, Romania and United States of America 1 Grand Canal Square, Grand Canal Harbour, Dublin 2, D02 P820 Ireland 620139 Accenture PLC Cognizant Worldwide Limited All Google Workspace Core Services and Cloud Identity Services Technical Support”
!Where is your data processed?Ask the vendor
Gemini in Workspace user prompts and Generated Output are listed as Located Data, so customers on an In-Scope Edition (G Suite Business, Workspace Enterprise Plus, Education Standard or Education Plus) can select the United States or Europe as the Data Region for processing in use and storage at rest of that data.
Confirm in writing: Ask the vendor to state this in writing before signing.
“(m) Gemini in Workspace: user prompts and Generated Output. ' Data Region '; means: (a) Either the United States or Europe, except in relation to AppSheet; or”
“1.3 Limitation . For any Customer Data that is not covered by the Data Regions Policy, Google may store or process such data, as applicable, anywhere Google or its Subprocessors maintain facilities, subject to the Cloud Data Processing Addendum.”
!What happens in a security incident?Ask the vendor
Google contractually commits to notify the customer promptly and without undue delay after becoming aware of a Data Incident affecting Customer Data, to take steps to minimise harm, and (Section 7.2.2) to describe the incident, remediation measures and a contact point; no fixed hour-based deadline is stated.
Confirm in writing: Ask the vendor to state this in writing before signing.
“7.2.1 Incident Notification . Google will notify Customer promptly and without undue delay after becoming aware of a Data Incident, and promptly take reasonable steps to minimize harm and secure Customer Data.”
Email to send the vendor8 items to confirm in writing
Hello Google team, We are assessing Gemini for Google Workspace (Google) as part of our supplier review. Before we proceed, please confirm the following in writing: 1. Do you use our data (inputs, outputs or uploaded files) to train or improve your models? Please confirm in writing, including any opt-out and whether it applies to every plan. 2. How long do you retain our data, in days, for each type (inputs, outputs, logs and backups), and how is it deleted? 3. Please provide your current, dated subprocessor list and explain how you notify customers of changes. 4. In which countries and regions is our data processed and stored, and can processing be limited to a region we choose? 5. What is your commitment to notify customers of a security incident affecting our data, including the timeframe? 6. Please provide the ISO/IEC 42001, 27001, 27701, 27017 and 27018 certificates (issuer, number, expiry, statement of applicability) and the current SOC 2 Type II report, confirming which Gemini in Workspace features and which Workspace editions are in scope, and the FedRAMP authorisation boundary for Gemini in Workspace. 7. Which Gemini model families and versions currently serve Gemini in Workspace, how are customers notified of model changes, and can Google share the safety evaluation or red-team summary and the ISO/IEC 42001 AI impact assessment covering Gemini in Workspace? 8. Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data. A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date. Thank you,
Key findingsclick a row for the evidence
✓Explicit contractual no-training commitment for Gemini in WorkspaceStrong
The Workspace Service Specific Terms (Section 12.11) state that Google will not use Customer Data to train or fine-tune the generative AI models supporting the Workspace Generative AI Services without the customer's prior permission or instruction, and define Generated Output as Customer Data. The Privacy Hub restates this, adds that content is not human reviewed or used for training outside the customer's domain, and identifies prompts as Customer Data under the Cloud Data Processing Addendum.
A buyer's primary question for an embedded productivity assistant is whether prompts, documents and email are used to improve the vendor's models. Here the answer is contractual rather than only a help-centre statement, and it attaches to generated output as well as inputs.
“12.11 Training Restriction . Google will not use Customer Data to train or fine-tune any of its generative artificial intelligence models supporting the Google Workspace Generative AI Services without Customer's prior permission or instruction.”
“No. User prompts are considered customer data under the Cloud Data Processing Addendum . Workspace does not use customer data for training models without customer's prior permission or instruction. This commitment is outlined in the 'Training Restriction' section of the Google Workspace Service Specific Terms .”
“Your content is not used for any other customers. Your content is not human reviewed or otherwise used for Generative AI model training outside your domain without permission.”
“' Generated Output ' means the data or content generated or received by Customer or its End Users via Workspace Generative AI Services under the Customer’s Workspace Account, as prompted by data or content submitted by them via those services. Generated Output is Customer Data. As between Customer and Google, Google does not assert any ownership rights in any new intellectual property created in the Generated Output.”
✓Published Workspace subprocessor register and DPA incident, deletion and subprocessor-notice commitmentsStrong
Google publishes a dated subprocessor list specific to the Workspace Core Services naming each third party, its activity, processing countries and parent, and states that support subprocessors have no access to Customer Data unless the customer grants it. The Cloud Data Processing Addendum, whose Appendix 4 covers Google Workspace, commits to prompt incident notification, deletion within a maximum of 180 days, and 30 days' advance notice of new subprocessors with a right to terminate.
These are the processing-chain disclosures a buyer needs to complete a vendor risk assessment and a GDPR Article 28 review without a bespoke questionnaire, and they apply to Gemini in Workspace because its prompts and outputs are Customer Data under the same addendum.
“a. When Google engages any New Subprocessor during the Term, Google will, at least 30 days before the New Subprocessor starts processing any Customer Data, notify Customer of the engagement (including the name, location and activities of the New Subprocessor).”
“These Subprocessors do not have access to Customer Data stored or processed by the Services. They only have access to Customer Data if Customer explicitly elects to enable such access in the course of a support case (e.g., by granting access to a Google Doc, Google Sheet, or Google Drive folder).”
“Accenture International Limited All Google Workspace Core Services and Cloud Identity Services Technical Support Bulgaria, Canada, India, Israel, Japan, Malaysia, Mexico, Philippines, Romania and United States of America 1 Grand Canal Square, Grand Canal Harbour, Dublin 2, D02 P820 Ireland 620139 Accenture PLC Cognizant Worldwide Limited All Google Workspace Core Services and Cloud Identity Services Technical Support”
“7.2.1 Incident Notification . Google will notify Customer promptly and without undue delay after becoming aware of a Data Incident, and promptly take reasonable steps to minimize harm and secure Customer Data.”
“If Customer uses the Services to delete any Customer Data during the Term and that Customer Data cannot be recovered by Customer, this use will constitute an Instruction to Google to delete the relevant Customer Data from Google’s systems. Google will comply with this Instruction as soon as reasonably practicable and within a maximum period of 180 days,”
!Certifications claimed for Gemini are vendor-asserted, unscoped to a certificate, and exclude Gemini Notebook and Gemini in ChromeGap
The Privacy Hub claims SOC 1/2/3, ISO 9001, ISO/IEC 27001, 27701, 27017, 27018 and 42001 and FedRAMP High for Gemini, defined as Gemini in Workspace and the Gemini app. No certificate body, certificate number, validity date or statement of applicability is given, and nothing independent in this scan corroborates the claims. The same page states that Gemini Notebook and Gemini in Chrome do not yet support ISO, SOC or FedRAMP and are outside the HIPAA BAA. The CDPA separately commits ISO 27001, 27017, 27018 and SOC 2/3 for Workspace Audited Services, with the in-scope list held at a URL rather than in the document.
ISO/IEC 42001 is the AI-management-system standard buyers increasingly ask for, and a FedRAMP High claim is material for public-sector buyers; both need a certificate or authorisation letter with a scope statement before they can be relied on, and the Gemini-branded feature set a customer actually enables may include components the certifications do not cover.
Question for vendor: Please provide the ISO/IEC 42001, 27001, 27701, 27017 and 27018 certificates (issuer, number, expiry, statement of applicability) and the current SOC 2 Type II report, confirming which Gemini in Workspace features and which Workspace editions are in scope, and the FedRAMP authorisation boundary for Gemini in Workspace.
“Gemini has attained SOC 1/2/3, ISO 9001 , ISO/IEC 27001 , 27701 , 27017 , 27018 , and 42001 certifications. Gemini has FedRAMP High authorization .”
“No. At this stage Gemini Notebook does not support ISO, SOC, or FedRAMP compliance and is not covered by the Google Business Associate Agreement (BAA) for HIPAA compliance.”
“3. Compliance Certifications. The Compliance Certifications for Google Workspace and Cloud Identity Audited Services will also include certificates for ISO 27017 and ISO 27018.”
!Data-handling carve-outs to confirm: admin-set retention up to indefinite, feedback reuse, pre-GA data use, third-party human review and edition-dependent residencyGap
Within the generally favourable Workspace position there are five scoped exceptions a buyer should confirm in writing: Gemini in Workspace conversation retention is set by the customer's administrators and can be indefinite; voluntary in-product feedback (which can include prompts and output) is used to improve Google's generative AI products and kept up to 18 months, though not for model training; Customer Test Data submitted to Pre-GA (Alpha/Beta/Preview) Workspace features may be used to develop and improve Google products; Wipro performs human review of indicators of account compromise with access limited to suspicious search terms; and the US/Europe Data Region choice that covers Gemini prompts and output applies only to In-Scope Editions, with other data processed anywhere Google or its subprocessors have facilities.
None of these contradicts the no-training commitment, but each changes the practical answer to retention, recipients or location for a specific configuration. Organisations enabling pre-GA Gemini features or relying on residency on a non-Enterprise Plus edition are the most exposed.
Question for vendor: Please confirm in writing: (a) the organisation's configured Gemini in Workspace retention setting and that it applies to side-panel history in all apps; (b) which Gemini features in use are Pre-GA Offerings subject to Section 6 of the Workspace Service Specific Terms; (c) whether the organisation's edition is an In-Scope Edition for Data Regions and which Gemini data remains outside the Data Regions Policy; and (d) whether in-product feedback sharing of prompts and output can be disabled by the administrator.
“Flexible retention: Admins have control over conversation history for their organization. Administrators can choose to: Allow users to delete individual conversations (manual deletion by users is enabled by default) Set automated retention periods based on inactive conversations (such as 3 months, 18 months, or 3 years), or retain conversations indefinitely for the organization”
“Feedback is used to improve generative AI products and services in accordance with the Google Cloud Privacy Notice , but it is not used to train any of the generative AI models that support Google Workspace Generative AI Services.”
“Google may use, and the Customer will (including by collecting or providing any required consents or notices) ensure that Google may use any Customer Data (including Customer Personal Data) submitted, stored, sent or received via any Pre-GA Offerings by the Customer or its End Users ('Customer Test Data') to provide, test, analyse, develop and improve those Pre-GA Offerings and any Google products and services used with them without any restriction or obligation to the Customer, any End User or any third party, other than as stated in the Agreement's confidentiality provisions and below.”
“Security Risk Detection: Human review of indicators of account compromise or abuse. The Subprocessor only accesses Customer Data of accounts suspected of compromise or abuse and access to Customer Data is limited to suspicious search terms.”
“(m) Gemini in Workspace: user prompts and Generated Output. ' Data Region '; means: (a) Either the United States or Europe, except in relation to AppSheet; or”
“1.3 Limitation . For any Customer Data that is not covered by the Data Regions Policy, Google may store or process such data, as applicable, anywhere Google or its Subprocessors maintain facilities, subject to the Cloud Data Processing Addendum.”
!Evidence is mostly Workspace-scoped, but model transparency and testing/evaluation are not evidenced for Gemini in WorkspaceGap
Of the 16 stashed documents, the load-bearing Workspace-scoped sources are the Generative AI in Google Workspace Privacy Hub, the Google Workspace Service Specific Terms, the Workspace subprocessor list, the Workspace security page and the January 2023 Workspace trust whitepaper, plus the Cloud Data Processing Addendum (stashed twice) whose Appendix 4 covers Google Workspace. Seven documents are Google Cloud Platform-only (Cloud Service Specific Terms, GCP subprocessors, Gemini Enterprise Agent Platform, Gemini CLI, the Cloud compliance index and security solutions pages) and two are consumer (Google Privacy Policy, Your data in Search); these were scoped as such and did not drive any domain assessment. Across the Workspace sources, Google names the models behind Gemini in Workspace only as a collection of Google models, and publishes no evaluation, red-team or safety-testing results for the Workspace service. Testing and evaluation is marked not_evidenced rather than not_applicable because Gemini in Workspace is a Google-hosted service for which Google could publish such evidence and does so for other products. Vulnerability and incident handling is partial: the DPA notification clause and prompt-injection defences are disclosed, but no vulnerability disclosure or bug-bounty route is described in the stashed Workspace documents.
A buyer cannot tell which Gemini model version processes their data or what safety testing it passed, and a Cloud-side commitment such as the GCP Training Restriction must not be read as covering Workspace. The strength of the Workspace contractual position should not mask these two gaps.
Question for vendor: Which Gemini model families and versions currently serve Gemini in Workspace, how are customers notified of model changes, and can Google share the safety evaluation or red-team summary and the ISO/IEC 42001 AI impact assessment covering Gemini in Workspace?
“Gemini uses a collection of models from Google's rich repository. With these models, Gemini can help you write, visualize, organize, and connect more meaningfully.”
“Google's foundational language models are trained primarily on publicly available, crawlable data from the internet. We give publishers control over how their sites are used with Google-Extended , which web publishers can use to manage whether their sites help improve Gemini Apps and Vertex AI generative APIs.”
“Google will not use Customer Data to train or fine-tune any AI/ML models without Customer's prior permission or instruction.”
“If you’re a member of an organization that uses Google Workspace or Google Cloud Platform, learn how these services collect and use your personal information in the Google Cloud Privacy Notice .”
“When users prompt Gemini to perform an action in Gemini in Workspace or the Gemini app, Gemini checks for threats before performing the action. If Gemini identifies malicious content or detects suspicious activity, it notifies the user and excludes the content, or blocks the action.”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“a. When Google engages any New Subprocessor during the Term, Google will, at least 30 days before the New Subprocessor starts processing any Customer Data, notify Customer of the engagement (including the name, location and activities of the New Subprocessor).”
“These Subprocessors do not have access to Customer Data stored or processed by the Services. They only have access to Customer Data if Customer explicitly elects to enable such access in the course of a support case (e.g., by granting access to a Google Doc, Google Sheet, or Google Drive folder).”
“Security Risk Detection: Human review of indicators of account compromise or abuse. The Subprocessor only accesses Customer Data of accounts suspected of compromise or abuse and access to Customer Data is limited to suspicious search terms.”
“Gemini uses a collection of models from Google's rich repository. With these models, Gemini can help you write, visualize, organize, and connect more meaningfully.”
“Google's foundational language models are trained primarily on publicly available, crawlable data from the internet. We give publishers control over how their sites are used with Google-Extended , which web publishers can use to manage whether their sites help improve Gemini Apps and Vertex AI generative APIs.”
“Accenture International Limited All Google Workspace Core Services and Cloud Identity Services Technical Support Bulgaria, Canada, India, Israel, Japan, Malaysia, Mexico, Philippines, Romania and United States of America 1 Grand Canal Square, Grand Canal Harbour, Dublin 2, D02 P820 Ireland 620139 Accenture PLC Cognizant Worldwide Limited All Google Workspace Core Services and Cloud Identity Services Technical Support”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the scoreorganisation-level evidence45
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“Google Workspace provides admins with a robust set of audit logs to track user activity and interactions with Gemini in the Gemini app and Workspace apps (Chat, Classroom, Docs, Drive, Gmail, Keep, Meet, Sheets, Slides, and Vids).”
“Google is committed to compliance with all applicable laws. Google is signing the European Union's General Purpose AI Code of Practice.”
AI system15% of the score38
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Workspace Intelligence is the secure, underlying engine that powers context-aware generative AI features across Google Workspace. It finds and retrieves content across your active Workspace apps (Gmail, Drive, Calendar, and Chat) to give Gemini the deep context needed to provide highly relevant, personalized assistance.”
“' Workspace Generative AI Services ' includes (i) Gemini in Workspace (formerly known as Gemini for Google Workspace) and (ii) other generative artificial intelligence features or functionality of the Google Workspace Services.”
“Gemini uses a collection of models from Google's rich repository. With these models, Gemini can help you write, visualize, organize, and connect more meaningfully.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
“Google may update the Security Measures from time to time provided that such updates do not result in a material reduction of the security of the Services.”
“a. When Google engages any New Subprocessor during the Term, Google will, at least 30 days before the New Subprocessor starts processing any Customer Data, notify Customer of the engagement (including the name, location and activities of the New Subprocessor).”
Testing & evaluation: not publicly evidenced.
Model10% of the scoreorganisation-level evidence40
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“Gemini uses a collection of models from Google's rich repository. With these models, Gemini can help you write, visualize, organize, and connect more meaningfully.”
“Google's foundational language models are trained primarily on publicly available, crawlable data from the internet. We give publishers control over how their sites are used with Google-Extended , which web publishers can use to manage whether their sites help improve Gemini Apps and Vertex AI generative APIs.”
Customer data15% of the score82
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“12.11 Training Restriction . Google will not use Customer Data to train or fine-tune any of its generative artificial intelligence models supporting the Google Workspace Generative AI Services without Customer's prior permission or instruction.”
“No. User prompts are considered customer data under the Cloud Data Processing Addendum . Workspace does not use customer data for training models without customer's prior permission or instruction. This commitment is outlined in the 'Training Restriction' section of the Google Workspace Service Specific Terms .”
“Your content is not used for any other customers. Your content is not human reviewed or otherwise used for Generative AI model training outside your domain without permission.”
“Flexible retention: Admins have control over conversation history for their organization. Administrators can choose to: Allow users to delete individual conversations (manual deletion by users is enabled by default) Set automated retention periods based on inactive conversations (such as 3 months, 18 months, or 3 years), or retain conversations indefinitely for the organization”
“Feedback is used to improve generative AI products and services in accordance with the Google Cloud Privacy Notice , but it is not used to train any of the generative AI models that support Google Workspace Generative AI Services.”
“Google may use, and the Customer will (including by collecting or providing any required consents or notices) ensure that Google may use any Customer Data (including Customer Personal Data) submitted, stored, sent or received via any Pre-GA Offerings by the Customer or its End Users ('Customer Test Data') to provide, test, analyse, develop and improve those Pre-GA Offerings and any Google products and services used with them without any restriction or obligation to the Customer, any End User or any third party, other than as stated in the Agreement's confidentiality provisions and below.”
“(m) Gemini in Workspace: user prompts and Generated Output. ' Data Region '; means: (a) Either the United States or Europe, except in relation to AppSheet; or”
“1.3 Limitation . For any Customer Data that is not covered by the Data Regions Policy, Google may store or process such data, as applicable, anywhere Google or its Subprocessors maintain facilities, subject to the Cloud Data Processing Addendum.”
“If Customer uses the Services to delete any Customer Data during the Term and that Customer Data cannot be recovered by Customer, this use will constitute an Instruction to Google to delete the relevant Customer Data from Google’s systems. Google will comply with this Instruction as soon as reasonably practicable and within a maximum period of 180 days,”
“Google will not use Customer Data to train or fine-tune any AI/ML models without Customer's prior permission or instruction.”
Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI supply chain10% of the scoreorganisation-level evidence60
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“These Subprocessors do not have access to Customer Data stored or processed by the Services. They only have access to Customer Data if Customer explicitly elects to enable such access in the course of a support case (e.g., by granting access to a Google Doc, Google Sheet, or Google Drive folder).”
“Accenture International Limited All Google Workspace Core Services and Cloud Identity Services Technical Support Bulgaria, Canada, India, Israel, Japan, Malaysia, Mexico, Philippines, Romania and United States of America 1 Grand Canal Square, Grand Canal Harbour, Dublin 2, D02 P820 Ireland 620139 Accenture PLC Cognizant Worldwide Limited All Google Workspace Core Services and Cloud Identity Services Technical Support”
“Security Risk Detection: Human review of indicators of account compromise or abuse. The Subprocessor only accesses Customer Data of accounts suspected of compromise or abuse and access to Customer Data is limited to suspicious search terms.”
“a. When Google engages any New Subprocessor during the Term, Google will, at least 30 days before the New Subprocessor starts processing any Customer Data, notify Customer of the engagement (including the name, location and activities of the New Subprocessor).”
Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.
Security foundation15% of the scoreorganisation-level evidence65
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“7.2.1 Incident Notification . Google will notify Customer promptly and without undue delay after becoming aware of a Data Incident, and promptly take reasonable steps to minimize harm and secure Customer Data.”
“When users prompt Gemini to perform an action in Gemini in Workspace or the Gemini app, Gemini checks for threats before performing the action. If Gemini identifies malicious content or detects suspicious activity, it notifies the user and excludes the content, or blocks the action.”
Independent assurance evidence10% of the scoreorganisation-level evidence63
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“Gemini has attained SOC 1/2/3, ISO 9001 , ISO/IEC 27001 , 27701 , 27017 , 27018 , and 42001 certifications. Gemini has FedRAMP High authorization .”
“3. Compliance Certifications. The Compliance Certifications for Google Workspace and Cloud Identity Audited Services will also include certificates for ISO 27017 and ISO 27018.”
“No. At this stage Gemini Notebook does not support ISO, SOC, or FedRAMP compliance and is not covered by the Google Business Associate Agreement (BAA) for HIPAA compliance.”
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score75
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“12.11 Training Restriction . Google will not use Customer Data to train or fine-tune any of its generative artificial intelligence models supporting the Google Workspace Generative AI Services without Customer's prior permission or instruction.”
“' Workspace Generative AI Services ' includes (i) Gemini in Workspace (formerly known as Gemini for Google Workspace) and (ii) other generative artificial intelligence features or functionality of the Google Workspace Services.”
“' Generated Output ' means the data or content generated or received by Customer or its End Users via Workspace Generative AI Services under the Customer’s Workspace Account, as prompted by data or content submitted by them via those services. Generated Output is Customer Data. As between Customer and Google, Google does not assert any ownership rights in any new intellectual property created in the Generated Output.”
“(a) Generated Output . Google’s indemnification obligations under the Agreement also apply to allegations that an unmodified Generated Output from a Generative AI Indemnified Service infringes a third party’s Intellectual Property Rights.”
“If you’re a member of an organization that uses Google Workspace or Google Cloud Platform, learn how these services collect and use your personal information in the Google Cloud Privacy Notice .”
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 58 → up to 79 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 13 — registry checks and verification ladders, click to view
Claimed for Gemini (Gemini in Workspace and the Gemini app); no issuer, certificate number or validity given; Gemini Notebook and Gemini in Chrome excluded
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Claimed for Gemini in the Privacy Hub; also a CDPA commitment for Workspace Audited Services; issuer and validity not given
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Claimed for Gemini; CDPA Appendix 4 commits it for Workspace Audited Services; issuer and validity not given
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Claimed for Gemini; CDPA Appendix 4 commits it for Workspace Audited Services; issuer and validity not given
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Claimed for Gemini (Gemini in Workspace and the Gemini app); issuer and validity not given
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Quality management certification claimed for Gemini; issuer and validity not given
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Claimed for Gemini; report not provided in public sources
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Claimed for Gemini; CDPA commits annual SOC 2 reports for Audited Services; report available to customers on request only
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Claimed for Gemini; CDPA commits annual SOC 3 reports for Audited Services
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Authorization claimed for Gemini in Workspace apps and the Gemini app; authorisation boundary not stated; Gemini Notebook and Gemini in Chrome excluded
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Checked against Data Privacy Framework (dataprivacyframework.gov), Oct 5, 2026: Verified on the registry
Checked against CSA STAR Registry, Oct 5, 2026: Verified on the registry
Checked against FedRAMP Marketplace (fedramp.gov), Oct 5, 2026: Verified on the registry
Sources 19 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
Monitor for changes
Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.
