CompanyScope
by Janus Compliance

General-purpose AI / LLM API

Google Gemini compliance: GDPR, AI Act, DPA, training, transfers

Independent compliance research from Janus Compliance. Reviewed by Michael K. Onyekwere, CIPP/E. Last reviewed 2026-06-29. Not legal advice.

Share this Google Gemini profile:Share on XBluesky

TL;DR. Three distinct surfaces buyers conflate: Gemini Enterprise / Vertex AI (contractually no training, ZDR available, broad cert portfolio); the Gemini API via AI Studio at ai.google.dev (the free tier trains on your inputs; a billed key does not); consumer Gemini at gemini.google.com and embedded in Workspace (training on by default unless disabled). EU residency is configurable per API call on Vertex AI and defaults to US routing, so it leaks easily. Google Cloud has the broadest compliance certification portfolio of any major LLM provider.

DPO action: lock down which Gemini surface your staff actually use; configure region pinning at the SDK call level; review the Workspace generative-AI training control at tenant scope; sign a BAA before any PHI (Vertex AI or a covered Workspace SKU only, never consumer Gemini or AI Studio).

What the tool does

Google ships Gemini in three places that buyers commonly conflate:

  1. Gemini Enterprise / Vertex AI (rebranded "Gemini Enterprise Agent Platform" at Google Cloud Next 2026) — the enterprise platform for building, deploying, and governing AI agents grounded in your own data. Runs inside Google Cloud, billed via GCP, governed by Google's Cloud DPA.
  2. Gemini API via AI Studio at ai.google.dev — developer-facing free / paid tier for prototyping. Different terms from Vertex AI.
  3. Gemini consumer surfaces — the standalone chat at gemini.google.com and the embedded Gemini features inside Google Workspace (Gmail, Docs, Slides, Sheets, Meet). For most enterprise buyers using Workspace, this is the most-touched surface.

Compliance defaults differ across all three. Most enterprise procurement should be looking at Gemini Enterprise / Vertex AI; AI Studio is fine for prototyping but is not the enterprise contracting surface.

Data processed

Special-category likelihood: High in any free-form deployment. Gemini's multimodal nature means staff may upload images / scanned documents that contain Article 9 categories (medical scans, ID photos, etc.) without realising. UI controls and DPIA matter more than usual.

Default geographic processing: Vertex AI processing region is configurable (EU, US, multi-region). EU residency available but not the default — must be configured at the project / model-call level. Default in many quickstart paths is us-central1.

DPA availability

Google Cloud Data Processing Addendum (Cloud DPA) governs Vertex AI and Gemini Enterprise. Auto-incorporated into Google Cloud commercial agreements. Publicly available without a sales call.

For AI Studio (Gemini API direct), the Google APIs Terms of Service apply and DPA coverage is more limited. Most enterprises should not be using AI Studio for production workloads.

For Workspace Gemini, the existing Google Workspace DPA applies — verify your Workspace tier covers the AI features you use.

Subprocessor list

Google Cloud publishes a subprocessor list applicable to all Google Cloud services including Vertex AI / Gemini Enterprise.

For Gemini-specific data flows, the relevant subprocessors are largely Google's own subsidiaries plus standard infrastructure providers. Less third-party reliance than peers.

Training-on-customer-data position

Vertex AI / Gemini Enterprise: Customer data is not used to train Google's AI/ML models without prior permission or instruction. Google's Service Specific Terms Section 17 ("Training Restriction") makes this an explicit contractual commitment for Cloud customers.

Vertex AI Zero Data Retention (ZDR): Available for Generative AI on Vertex AI. When enabled, prompts and responses are not retained at all (beyond the immediate request lifecycle). Configurable per project / model.

Gemini API free tier (AI Studio / unbilled keys): Inputs and outputs are used to improve Google's models. This is the current published policy (confirmed June 2026), not a historical artefact. The dividing line is billing, not surface: the moment a Gemini API key is linked to a paid billing account, prompts and responses are no longer used for training, the same position as Vertex AI. So the free tier is the unmanaged-risk surface, and the fix is often as small as enabling billing on the key staff already use.

Gemini consumer (gemini.google.com) and Workspace Gemini: Conversations may be used to improve Google's products (with human reviewers seeing samples of conversations) unless training is disabled. The relevant admin control lives in the Workspace admin console under "Control Workspace Intelligence for generative AI features" (renamed from the older "Gemini Apps Activity" label). Workspace admin docs state explicitly: "Your content is not human reviewed or used for Generative AI model training outside your domain without permission." Many admins have not actively reviewed this control.

The enterprise no-training story for Vertex AI is solid and contractual. The free-tier API and consumer-chat defaults are not. The biggest unmanaged risk is staff using gemini.google.com on personal Google accounts, sometimes signed in as their work identity if Workspace is configured permissively. — My read

EU / UK transfer position

Google Cloud DPA relies on Standard Contractual Clauses (SCCs) for EU transfers and incorporates the UK International Data Transfer Addendum for UK transfers.

EU-US Data Privacy Framework (DPF) certification: Google LLC and its US subsidiaries are DPF-certified and listed Active (confirmed June 2026), covering the EU-US and Swiss-US frameworks plus the UK Extension. The framework survived its first court test — the EU General Court dismissed the challenge to it on 3 September 2025 — but an appeal is pending at the Court of Justice of the EU (filed October 2025). So DPF is a valid transfer basis today with a live appeal in the background, which is why the SCCs in the Cloud DPA matter as the fallback. Same position as OpenAI and Anthropic.

EU data residency: Vertex AI offers EU regions (europe-west1, europe-west4, others). Configuration is per-call, not per-project by default — a DPIA must specify and verify region pinning. Multi-region configurations can route EU subjects' data outside the EU unless explicitly constrained.

Google's "Sovereign Cloud" partnerships (with T-Systems in Germany, others) offer additional EU data sovereignty options for highly regulated buyers. Out of scope for most SMEs, but relevant if your sector requires it.

Security documentation

Google Cloud has the broadest certification portfolio of any major LLM provider:

The breadth here is a real advantage in compliance audits. Standards coverage is rarely the gap with Google; the gap is configuration defaults.

HIPAA & BAA position

Gemini is not HIPAA-eligible by default on any plan. Which surface you use decides everything, the same split that drives the rest of this profile. Google will sign a BAA, covering two surfaces once it is in place:

This is the HIPAA version of the vendor's core trap: "we use Gemini" is not an inventory entry. Pin the surface in writing (Vertex AI, or a covered Workspace SKU, with the BAA executed) before any PHI moves. The BAA is the contractual piece; HIPAA's Security Rule (risk analysis, minimum-necessary, workforce training, audit controls, breach notification) still falls on the covered entity. See HIPAA for AI tools for the full walkthrough across vendors.

AI Act role + risk classification

Google publishes AI Act readiness materials and a Model Card for Gemini family models.

DPIA prompts (for your use case)

  1. Which Gemini surface are you actually deploying — Vertex AI, AI Studio, consumer chat, or Workspace Gemini? They have different DPAs, different training defaults, and different data residency stories. Get this on paper before anything else.
  2. Have you configured EU data residency at the call level for any EU subject data? Default routing may be US-resident.
  3. Have you applied for ZDR on Vertex AI Generative AI if your data sensitivity warrants it?
  4. Have you mapped staff use of gemini.google.com and Workspace Gemini features? Personal Google accounts using consumer Gemini fall under consumer terms; this is the most-missed risk in Workspace-using SMEs. For Workspace tenants, confirm the "Control Workspace Intelligence for generative AI features" admin setting reflects your training-restriction stance.
  5. AI Act Annex III applicability: if your use case touches recruitment, credit, education, law enforcement, migration, or justice, deployer high-risk obligations engage.
  6. Multimodal input: are users uploading images/PDFs that may contain Article 9 special-category data? UI controls plus a DPIA covering this scenario.

Unresolved questions / red flags

Related profiles

Sources checked

Related reading

<!-- Phase C residual items resolved (browser agent run 2026-05-02). 2026-06-23 currency refresh (joint with the Janus Gemini-API article): free-vs-paid training line clarified (free tier trains, billed key excluded, same as Vertex); DPF status updated (Active; EU General Court dismissal Sep 2025, CJEU appeal pending); EU AI Act timeline added (Art 50 -> 2 Aug 2026, Art 50(2) marking grace to 2 Dec 2026, Annex III -> provisionally 2 Dec 2027 via May 2026 Omnibus pending adoption); Gemini Enterprise rebrand confirmed with terms-carry-over note; DPA mechanism re-confirmed (SCCs 2021/914 Annex 1B + UK IDTA). ISO 42001 (Coalfire, GCP/Workspace/Gemini App) and Workspace control label ('Control Workspace Intelligence for generative AI features') unchanged since May. 2026-06-29: added a consolidated HIPAA & BAA section (BAA on Vertex AI + a covered Workspace SKU only; not consumer Gemini or AI Studio; the surface-pinning trap); DPO-action line gained a BAA pointer and dropped the stale 'Gemini Apps Activity' control name. -->
Share this Google Gemini profile:Share on XBluesky

Talk to Michael about Google Gemini — or your AI vendor governance more broadly

CompanyScope's public profiles cover the general picture. Michael runs Janus DPO-as-a-Service for businesses that need ongoing AI vendor governance, and writes one-off CIPP/E-reviewed Vendor Risk Notes for specific procurement decisions. Tell him what you're actually trying to clear.

A sentence or two is plenty.

Your context goes only to Michael. We don't share with the vendor or anyone else. Privacy notice.

Subscribe to the AI Agent Incident Register

Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.

Subscribe — free

Delivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.

For ongoing AI compliance support, work with Janus DPO-as-a-Service. For other vendors, browse the full index, or see real agent failures analysed legally in the AI Agent Incident Register.