General-purpose AI / LLM API
Google Gemini compliance: GDPR, AI Act, DPA, training, transfers
Independent compliance research from Janus Compliance. Reviewed by Michael K. Onyekwere, CIPP/E. Last reviewed 2026-06-29. Not legal advice.
TL;DR. Three distinct surfaces buyers conflate: Gemini Enterprise / Vertex AI (contractually no training, ZDR available, broad cert portfolio); the Gemini API via AI Studio at
ai.google.dev(the free tier trains on your inputs; a billed key does not); consumer Gemini atgemini.google.comand embedded in Workspace (training on by default unless disabled). EU residency is configurable per API call on Vertex AI and defaults to US routing, so it leaks easily. Google Cloud has the broadest compliance certification portfolio of any major LLM provider.DPO action: lock down which Gemini surface your staff actually use; configure region pinning at the SDK call level; review the Workspace generative-AI training control at tenant scope; sign a BAA before any PHI (Vertex AI or a covered Workspace SKU only, never consumer Gemini or AI Studio).
What the tool does
Google ships Gemini in three places that buyers commonly conflate:
- Gemini Enterprise / Vertex AI (rebranded "Gemini Enterprise Agent Platform" at Google Cloud Next 2026) — the enterprise platform for building, deploying, and governing AI agents grounded in your own data. Runs inside Google Cloud, billed via GCP, governed by Google's Cloud DPA.
- Gemini API via AI Studio at
ai.google.dev— developer-facing free / paid tier for prototyping. Different terms from Vertex AI. - Gemini consumer surfaces — the standalone chat at
gemini.google.comand the embedded Gemini features inside Google Workspace (Gmail, Docs, Slides, Sheets, Meet). For most enterprise buyers using Workspace, this is the most-touched surface.
Compliance defaults differ across all three. Most enterprise procurement should be looking at Gemini Enterprise / Vertex AI; AI Studio is fine for prototyping but is not the enterprise contracting surface.
Data processed
- Text and multimodal input (image, audio, video, PDF — Gemini is natively multimodal)
- Document content via Vertex AI grounding / RAG
- Prompts, function-call payloads, tool-use intermediates
- Embeddings (Vertex AI offers first-party embeddings)
- Optional grounding from Google Search (Vertex AI feature, off by default)
- For Workspace Gemini: any content the signed-in user has access to in Gmail, Drive, Calendar, etc.
Special-category likelihood: High in any free-form deployment. Gemini's multimodal nature means staff may upload images / scanned documents that contain Article 9 categories (medical scans, ID photos, etc.) without realising. UI controls and DPIA matter more than usual.
Default geographic processing: Vertex AI processing region is configurable (EU, US, multi-region). EU residency available but not the default — must be configured at the project / model-call level. Default in many quickstart paths is us-central1.
DPA availability
Google Cloud Data Processing Addendum (Cloud DPA) governs Vertex AI and Gemini Enterprise. Auto-incorporated into Google Cloud commercial agreements. Publicly available without a sales call.
- URL:
https://cloud.google.com/terms/data-processing-addendum - Includes SCCs and the UK International Data Transfer Addendum (UK Addendum)
- Updated regularly; check version date on each review
For AI Studio (Gemini API direct), the Google APIs Terms of Service apply and DPA coverage is more limited. Most enterprises should not be using AI Studio for production workloads.
For Workspace Gemini, the existing Google Workspace DPA applies — verify your Workspace tier covers the AI features you use.
Subprocessor list
Google Cloud publishes a subprocessor list applicable to all Google Cloud services including Vertex AI / Gemini Enterprise.
- URL:
https://cloud.google.com/terms/subprocessors - Updates announced via Google Cloud subprocessor email list (subscribable)
- Last updated date and added/removed entries are tracked in the document
For Gemini-specific data flows, the relevant subprocessors are largely Google's own subsidiaries plus standard infrastructure providers. Less third-party reliance than peers.
Training-on-customer-data position
Vertex AI / Gemini Enterprise: Customer data is not used to train Google's AI/ML models without prior permission or instruction. Google's Service Specific Terms Section 17 ("Training Restriction") makes this an explicit contractual commitment for Cloud customers.
Vertex AI Zero Data Retention (ZDR): Available for Generative AI on Vertex AI. When enabled, prompts and responses are not retained at all (beyond the immediate request lifecycle). Configurable per project / model.
Gemini API free tier (AI Studio / unbilled keys): Inputs and outputs are used to improve Google's models. This is the current published policy (confirmed June 2026), not a historical artefact. The dividing line is billing, not surface: the moment a Gemini API key is linked to a paid billing account, prompts and responses are no longer used for training, the same position as Vertex AI. So the free tier is the unmanaged-risk surface, and the fix is often as small as enabling billing on the key staff already use.
Gemini consumer (gemini.google.com) and Workspace Gemini: Conversations may be used to improve Google's products (with human reviewers seeing samples of conversations) unless training is disabled. The relevant admin control lives in the Workspace admin console under "Control Workspace Intelligence for generative AI features" (renamed from the older "Gemini Apps Activity" label). Workspace admin docs state explicitly: "Your content is not human reviewed or used for Generative AI model training outside your domain without permission." Many admins have not actively reviewed this control.
The enterprise no-training story for Vertex AI is solid and contractual. The free-tier API and consumer-chat defaults are not. The biggest unmanaged risk is staff using
gemini.google.comon personal Google accounts, sometimes signed in as their work identity if Workspace is configured permissively. — My read
EU / UK transfer position
Google Cloud DPA relies on Standard Contractual Clauses (SCCs) for EU transfers and incorporates the UK International Data Transfer Addendum for UK transfers.
EU-US Data Privacy Framework (DPF) certification: Google LLC and its US subsidiaries are DPF-certified and listed Active (confirmed June 2026), covering the EU-US and Swiss-US frameworks plus the UK Extension. The framework survived its first court test — the EU General Court dismissed the challenge to it on 3 September 2025 — but an appeal is pending at the Court of Justice of the EU (filed October 2025). So DPF is a valid transfer basis today with a live appeal in the background, which is why the SCCs in the Cloud DPA matter as the fallback. Same position as OpenAI and Anthropic.
EU data residency: Vertex AI offers EU regions (europe-west1, europe-west4, others). Configuration is per-call, not per-project by default — a DPIA must specify and verify region pinning. Multi-region configurations can route EU subjects' data outside the EU unless explicitly constrained.
Google's "Sovereign Cloud" partnerships (with T-Systems in Germany, others) offer additional EU data sovereignty options for highly regulated buyers. Out of scope for most SMEs, but relevant if your sector requires it.
Security documentation
Google Cloud has the broadest certification portfolio of any major LLM provider:
- SOC 1 / 2 / 3 — yes, all
- ISO 9001, 27001, 27017, 27018, 27701 — yes
- ISO/IEC 42001:2023 — yes, accredited certification covers Google Cloud Platform, Google Workspace, and the Gemini App (the assessment was conducted by Coalfire, mapped against both ISO 42001 and the NIST AI Risk Management Framework)
- FedRAMP High — yes (US government)
- HIPAA BAA — available for qualifying customers
- PCI DSS — yes
- C5 (Germany), IRAP (Australia), MTCS (Singapore) — multiple regional certs
The breadth here is a real advantage in compliance audits. Standards coverage is rarely the gap with Google; the gap is configuration defaults.
HIPAA & BAA position
Gemini is not HIPAA-eligible by default on any plan. Which surface you use decides everything, the same split that drives the rest of this profile. Google will sign a BAA, covering two surfaces once it is in place:
- Vertex AI (Gemini on Google Cloud). Vertex AI is on Google Cloud's HIPAA-eligible services list, and the BAA comes through the Google Cloud DPA path. This is the route for most enterprise PHI workloads.
- Workspace Gemini, covered under the Google Workspace BAA on an eligible (Healthcare and Life Sciences) SKU, for the Gemini features inside Gmail, Docs, and the rest.
- Not eligible: consumer Gemini at
gemini.google.comand the AI Studio free tier (which also trains on inputs). Staff touching either with PHI creates a breach no later contract can cure.
This is the HIPAA version of the vendor's core trap: "we use Gemini" is not an inventory entry. Pin the surface in writing (Vertex AI, or a covered Workspace SKU, with the BAA executed) before any PHI moves. The BAA is the contractual piece; HIPAA's Security Rule (risk analysis, minimum-necessary, workforce training, audit controls, breach notification) still falls on the covered entity. See HIPAA for AI tools for the full walkthrough across vendors.
AI Act role + risk classification
- Role: Google is a provider of general-purpose AI models (the Gemini family). GPAI provider obligations (Articles 51-55) have applied since 2 August 2025.
- Your role as a buyer: deployer, with deployer obligations.
- The dates that matter now: Article 50 transparency obligations (telling users they are interacting with AI, and marking AI-generated content) apply from 2 August 2026; generative-AI systems already on the market by then have until 2 December 2026 to meet the machine-readable marking requirement of Article 50(2). High-risk obligations for stand-alone Annex III systems have been deferred to 2 December 2027 by the Digital Omnibus, which entered into force on 27 July 2026.
- Risk tier: depends on the use case. An Annex III use case (recruitment, credit, education, law enforcement, migration, justice) carries deployer high-risk obligations regardless of the model. Vertex AI's enterprise governance features (Model Garden filtering, safety filters, Vertex AI Model Monitoring) help evidence deployer due diligence; keep audit trails.
Google publishes AI Act readiness materials and a Model Card for Gemini family models.
DPIA prompts (for your use case)
- Which Gemini surface are you actually deploying — Vertex AI, AI Studio, consumer chat, or Workspace Gemini? They have different DPAs, different training defaults, and different data residency stories. Get this on paper before anything else.
- Have you configured EU data residency at the call level for any EU subject data? Default routing may be US-resident.
- Have you applied for ZDR on Vertex AI Generative AI if your data sensitivity warrants it?
- Have you mapped staff use of
gemini.google.comand Workspace Gemini features? Personal Google accounts using consumer Gemini fall under consumer terms; this is the most-missed risk in Workspace-using SMEs. For Workspace tenants, confirm the "Control Workspace Intelligence for generative AI features" admin setting reflects your training-restriction stance. - AI Act Annex III applicability: if your use case touches recruitment, credit, education, law enforcement, migration, or justice, deployer high-risk obligations engage.
- Multimodal input: are users uploading images/PDFs that may contain Article 9 special-category data? UI controls plus a DPIA covering this scenario.
Unresolved questions / red flags
- Three distinct surfaces with different defaults confuse procurement. Most "Gemini compliance" assertions in SME marketing material conflate them.
- EU residency is configurable, not default. Same problem as OpenAI; commonly missed.
- Free-tier AI Studio defaults shift periodically. Don't assume yesterday's read still holds — re-check on each profile refresh.
- Workspace Gemini training defaults track Workspace policy. Workspace Business / Enterprise admins can set training restrictions via the "Control Workspace Intelligence for generative AI features" admin control; many haven't actively reviewed it.
- Vertex AI's regional pinning happens at the SDK call level, not project level — a missed config in code can quietly route EU data to US.
- "Gemini Enterprise Agent Platform" rebrand from Vertex AI (Cloud Next 2026) folded Vertex AI, Agentspace, and the Gemini Code Assist enterprise tier into one console and billing surface, priced per agent. Existing Vertex AI workloads, SDKs, and APIs run unchanged, and the Cloud DPA and Service Specific Terms position carries over; the rebrand is commercial packaging, and the data-processing terms are the same. Some older Vertex AI doc URLs still redirect, so verify links against the canonical product page (
cloud.google.com/products/gemini-enterprise-agent-platform).
Related profiles
- OpenAI — same general-purpose LLM category, US-centric defaults
- Anthropic — same category, multi-cloud subprocessing
Sources checked
- Google Cloud Service Specific Terms Section 17 ("Training Restriction") — re-corroborated 2026-06-23
- Gemini API free-vs-paid data-use policy (free tier improves Google's models; billed keys excluded) — Gemini API docs, confirmed 2026-06-23
- Vertex AI ZDR documentation:
https://docs.cloud.google.com/vertex-ai/generative-ai/docs/vertex-ai-zero-data-retention - Google Cloud DPA (EU SCCs 2021/914 Annex 1B + UK IDTA):
https://cloud.google.com/terms/data-processing-addendum— checked 2026-06-23 - Google Cloud subprocessor list:
https://cloud.google.com/terms/subprocessors - EU-US Data Privacy Framework — Google LLC listed Active (dataprivacyframework.gov); EU General Court dismissal 3 Sep 2025, CJEU appeal pending — checked 2026-06-23
- EU AI Act timeline — Art 50 from 2 Aug 2026 (Art 50(2) marking grace to 2 Dec 2026); Annex III high-risk deferred to 2 Dec 2027 (Digital Omnibus, in force 27 Jul 2026) — checked 2026-07-29
- Gemini Enterprise Agent Platform (Cloud Next 2026):
https://cloud.google.com/products/gemini-enterprise-agent-platform— checked 2026-06-23
Related reading
- DPA for AI vendors — the eight clauses to check on any AI vendor DPA, applied to Workspace Gemini
- EU AI Act for AI buyers — deployer-side obligations for buyers running Workspace Gemini or Vertex AI
- HIPAA for AI tools — Workspace BAA scope for Healthcare and Life Sciences customers
- Copilot 365 vs Google Workspace AI compliance — the closest enterprise-tier alternative
- Gemini vs Vertex AI compliance — picking between the Workspace surface and the Google Cloud developer surface
- Practitioner how-to (Janus Compliance): Is the Gemini API GDPR compliant? — configuring the GDPR-compliant path step by step (DPA, EU residency, DPIA, transfers)
Talk to Michael about Google Gemini — or your AI vendor governance more broadly
CompanyScope's public profiles cover the general picture. Michael runs Janus DPO-as-a-Service for businesses that need ongoing AI vendor governance, and writes one-off CIPP/E-reviewed Vendor Risk Notes for specific procurement decisions. Tell him what you're actually trying to clear.
Your context goes only to Michael. We don't share with the vendor or anyone else. Privacy notice.
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe — freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.
For ongoing AI compliance support, work with Janus DPO-as-a-Service. For other vendors, browse the full index, or see real agent failures analysed legally in the AI Agent Incident Register.