Google Cloud: Our Commitment to the General Data Protection Regulation (GDPR)

The EU General Data Protection Regulation (GDPR) is the most significant piece of European privacy legislation in the last twenty years.  It replaces the 1995 EU Data Protection Directive, strengthening the rights that EU individuals have over their data, seeking to unify data protection laws across Europe.

Our users can count on the fact that Google is committed to GDPR compliance across G Suite and Google Cloud Platform (GCP) services when the GDPR takes effect on May 25, 2018. We'll make important updates to contractual commitments that directly address GDPR requirements. We're also a committed partner in customers’ GDPR compliance efforts. Users can leverage Google Cloud services with confidence understanding the robust data protection capabilities built-in to Google Cloud.

Where do we stand?

We've worked diligently over the last decade to help our customers directly address EU data protection requirements. These efforts have been critical in our ongoing preparations for the GDPR:

Data processing terms: Strong data protection commitments between cloud providers and customers are fundamental to compliance. Our data processing terms for G Suite and Google Cloud Platform clearly articulate our privacy commitments to customers. We've evolved our terms over the years based on feedback from our customers and regulators.  Our terms will be updated for the GDPR as well.

Third-party audits and certifications: We offer a number of third-party audits and certifications for G Suite and GCP. We undergo ISO 27001 security audits, and have done so for several years.  In 2016, we introduced two new security and privacy certifications, ISO 27017 for cloud security and ISO 27018 for protection of personally identifiable information in public clouds. These certifications, as well as other third-party audits such as SOC1, SOC2 and SOC3 cover numerous services within Google Cloud.

International data transfers: The GDPR, like the Data Protection Directive it will replace, includes provisions on international data transfer mechanisms. To address current EU data protection laws, G Suite and GCP are certified under Privacy Shield. We've also gained confirmation of compliance from European Data Protection Authorities for our model contract clauses, affirming that G Suite and GCP contractual commitments fully meet the requirements to legally frame transfers of data from the EU to the rest of the world, in accordance with the Data Protection Directive.

Data export: The GDPR includes certain requirements for the export of personal data. The data you store in Google Cloud is yours. We've included data portability commitments in our data processing terms for several years, and are continually working to enhance the robustness of our data export capabilities.

Incident notifications: GDPR contains requirements around breach notifications. G Suite and GCP have provided contractual obligations around incident notification for many years. With hundreds of Google engineers dedicated to security, Google Cloud has and will continue to invest in our security, incident response, threat detection and prevention capabilities.

Where do you stand?

As a current or future customer of Google Cloud, now is a great time for you to begin preparing for the GDPR.  Consider these tips:

  • Familiarize yourself with the provisions of the new regulation, particularly how they may differ from your current data protection obligations. Be aware that new requirements may require new agreements with service providers or completely new solutions that meet the stringent requirements ahead.
  • Consider creating an updated and precise inventory of personal information that you process (you can use some of our tools like Data Loss Prevention to help).
  • Review your current controls and processes to ensure that they're adequate, and build a plan to address any gaps.
  • Consider how you can leverage Google Cloud compliance capabilities as part of your own regulatory compliance framework. Conduct a review of G Suite or Google Cloud Platform third-party audit and certification materials to see how they may help with this exercise. 
  • Stay abreast of updated regulatory guidance as it becomes available and consider consulting a legal expert to obtain guidance applicable to you.

What’s next

We’re working to make additional operational changes in light of the new legislation, and will collaborate closely with our customers, partners and regulatory authorities throughout this process. We have a global team of regulatory compliance specialists, product managers, engineers, counsel and public policy specialists who continue to carefully monitor GDPR implementation guidance, and will update our contractual commitments accordingly. We'll make our updated data processing amendment available to our customers soon. We're also producing additional materials to assist customers with their due diligence efforts as they prepare for GDPR.

At Google Cloud, we work to earn the trust of our users every day. As such, protecting the privacy and security of our customers’ information is a top priority, and compliance is central to this mission. We'll continue to evolve our capabilities in accordance with the changing regulatory landscape and work with you to help facilitate your GDPR compliance efforts.