Home›Guides›Sovereignty

Sovereignty

GDPR and Google Workspace: what a business needs to check

Google Workspace can be used within a GDPR framework. As with Microsoft 365, compliance is verified in the contract, in the region actually covered and in the ability to respond to individuals. The software vendor is an American company. That sentence opens the review. It does not close it.

Updated October 20269 min readOfficial sources cited

1. Who is the controller, who is the processor

For the content your organisation places in Gmail, Drive, Docs and Calendar, you are generally the controller and Google the processor. Google also describes processing for which it is the controller, related to the account, security and the operation of the service. The Google Workspace Data Processing Amendment and the transfer annexes are the documents to file alongside the record of processing activities.

Why. The role determines who informs individuals, who responds to them and who sets retention periods. For content, that is you; Google acts on your instructions, under Article 28 of the GDPR.

How to check. Check that the amendment covers the services enabled, including those added after the initial order. A 30-person communications agency that started with Gmail and Drive, then opened Chat, Sites and forms, has often documented only the first two.

In the record. One line per service, with Google’s role, the activation date and the archived version of the amendment.

Common mistake. Filing the contract signed when the account was opened and never reading it again.

2. The data region does not cover everything

Depending on the edition, an administrator can choose to store covered data in the United States or in Europe, and to limit part of the processing to that region. Google publishes the list: covered content at rest for Gmail, Calendar, Drive, Chat, Docs, Sheets, Slides and other core services, covered processing for some of them. The documentation states that the region policy does not apply to data it does not list, notably certain logs or cached content.

Practical consequences.

  • An account whose edition does not include data regions is not covered, even if a rule has been set on the organisational unit.
  • Two users in different regions who write to each other may have their data stored in both regions.
  • The editions that display a residency report are not the entry-level editions.

Why. “Europe region” describes a listed scope, not the service as a whole. What is not listed is what your record of processing activities must account for.

How to check. Ask your administrator for a screenshot of the actual setting, not the sales brochure. Cross-check it against the edition subscribed for each group of users. An industrial SME with two sites, one of which is equipped with a more modest edition, may have a region rule that applies to only half of its accounts.

In the record. The edition, the region chosen, the organisational units covered, the excluded categories (logs, cache), the date of the check.

Common mistake. Writing “data stored in Europe” without mentioning the exclusions published by Google.

3. Who at Google can open a ticket

Access Management makes it possible to restrict the Google personnel who act on certain support data: for example, personnel located in the EU, or working through a virtual desktop located in the EU. This feature is tied to specific editions and to the Assured Controls option. It is not the default setting on all Business plans.

Why. A technician who views data to resolve an incident is processing that data. The storage location says nothing about where that access takes place.

How to check. If your compliance file assumes “support only from within the Union”, check that the option has been purchased and is active, and keep proof of it.

Client-side encryption, where available for your edition, leaves you in control of keys over a defined scope of content. It changes what Google can read. It also changes search, anti-abuse and certain collaborative features. It should be tested before being announced to business teams: a pilot with one team, with the list of what no longer works, is worth more than a general memo.

In the record. The active options, their scope, and what remains accessible to support.

Common mistake. Assuming the option was included in the renewal because it had been mentioned during pre-sales.

4. The legal basis for transfers

Google is an American company. As soon as access or a copy leaves the Union, the transfer must have a legal basis. As of 5 October 2026, adequacy decision (EU) 2023/1795 remains in force for certified US organisations, while being challenged. According to a commentary by the law firm WilmerHale, the General Court of the European Union dismissed an action for annulment on 3 September 2025, and an appeal was lodged before the Court of Justice on 31 October 2025. The law firm DAC Beachcroft, in the title of its commentary, speaks of stability for now and uncertainty ahead.

Standard contractual clauses remain the other usual tool. The 2020 precedent shows why you need to know them: on 16 July 2020, in judgment C-311/18 (known as Schrems II), the Court of Justice invalidated the Privacy Shield (decision 2016/1250), owing in particular to the scope of US surveillance programmes and the absence of effective redress. Standard contractual clauses remained valid, subject to a case-by-case assessment.

The details of the CLOUD Act are on the page protecting a business from the CLOUD Act: a European region does not remove Google from US law if Google holds or controls the data. Article 48 of the GDPR, for its part, provides that a judgment of a court or a decision of an authority of a third country requiring the disclosure of personal data may only be recognised or enforceable if it is based on an international agreement, such as a mutual legal assistance treaty, in force between that country and the Union or the Member State. A US provider operating in Europe may therefore find itself caught between two sets of rules. Article 48 describes this conflict; it does not resolve it.

In the record. The tool your contract uses, and the fallback plan should the adequacy decision fall.

Common mistake. Thinking that the data region (point 2) answers the transfer question. It says where certain data is stored, not who can access it or under which law.

5. Individuals’ rights

Export via the data export tool (Takeout) and the administration tools, search in Vault if you have it, and a one-month response deadline that falls on the controller.

How to check. Designate the internal person who knows how to extract a Gmail mailbox, a Drive and a Calendar, and have them run a trial on a test account. Check group mailboxes and files whose owner has left the company: these are the requests that fall behind.

In the record. The procedure, the person in charge, their deputy, and the tool used depending on the edition.

Common mistake. Deleting the account of an employee who has left without having decided what happens to their shared files, then receiving a request that concerns them.

6. What goes wrong on the day you leave the service

Messages and files leave relatively well (IMAP, Drive export). Google Chat histories, Sites, Apps Script, forms linked to automations and administration rules do not carry over as they are to another suite. The page migrating from Google Workspace lists these gaps.

Why. Exit is part of compliance: it determines portability, the end of retention periods and the recovery of your data if the contract ends.

In the record. The inventory of content that does not export as is, and what you would do with it.

Common mistake. Discovering critical automations in the month of termination.

Frequently asked questions

Does the GDPR require leaving Google Workspace?

No. It governs roles, transfers and individuals’ rights. It does not prohibit a software vendor on account of its nationality; it requires you to describe what you do and on what legal basis.

Is choosing the Europe region enough?

No. The region covers the data that Google lists, depending on your edition. Certain logs and cached content are not included, and the region does not change the software vendor’s nationality.

Does client-side encryption settle the access question?

It changes what Google can read within the encrypted scope. It does not cover everything, and it changes search and certain collaborative features. Test it before rolling it out.

What should we do if the Data Privacy Framework is annulled?

The record of processing activities should already provide for the fallback, generally standard contractual clauses with a case-by-case assessment. Preparing that assessment in advance avoids having to draft it in a hurry.

When staying is the right conclusion

When teams live in Docs and Drive, when your edition’s data region covers the content that matters to you, and when the record of processing activities accounts for logs and residual access. The GDPR does not require leaving Google. It requires you to describe what you do.

The reasons for staying are sound in this case. Simultaneous editing in Docs and Sheets, search across the whole of Drive and teams’ habits have a value that must be measured before leaving. A poorly prepared migration creates its own risks for data. Subscribing to the edition that includes regions and support controls may be more proportionate than changing suite. The trade-offs are detailed in staying with or leaving Google Workspace.

When changing operator is the right conclusion

When you want a European or Swiss company to hold the files and emails, or when the edition subscribed does not include the region and support controls your analysis requires. If the gap between the current edition and the one that would meet the need weighs as much as a change, the question is worth asking.

Changing operator places the data holder under the law of its own country, provided its processors do not reintroduce a US provider. It does not exempt you from the data processing agreement, the record of processing activities or the procedure for individuals’ rights. Infomaniak, a Nextcloud operated by a European hosting provider, OVHcloud or Klytic meet different needs. The guide European alternatives to Microsoft 365 and the page alternatives to Google Workspace set them apart. The same checks on the Microsoft side are in GDPR and Microsoft 365.

Klytic is operated by Dedicace Software, a French company. It covers email, documents in a dedicated Nextcloud instance per customer (sharing, online editing alone or with others, version history), video conferencing, a CRM and telephony, which can be purchased separately. Nextcloud is published by Nextcloud GmbH (Germany); the email service is based on Zimbra, published by Synacor (United States) and operated by Klytic. Hosting is provided in any geographical area corresponding to the applicable jurisdiction, subject to the availability of the required services, for example in Europe or Mauritius, or on the customer’s servers. The data is held by the customer, or by Klytic on its behalf, and encrypted natively or according to the customer’s choice; the key is held by the customer or kept in its account, and Klytic has no access to it. The steps where encryption is managed by Klytic are detailed on the page protecting a business from the CLOUD Act. The contract must describe this holding and this encryption. Online editing, alone or with others, takes place within the instance; it is not the Google editor, and Klytic does not replicate identically its search across the whole body of content. It is not SecNumCloud-qualified.

This page describes a general framework. It does not constitute legal advice.

Sources

Accessed in October 2026.

  • Regulation (EU) 2016/679, Articles 28 and 44 to 49, including Article 48 (decisions of third-country authorities). EUR-Lex
  • Google, data covered by data regions, and excluded types. Google Help
  • Google, choice of region depending on the edition. Google Help
  • Google, Access Management and the Assured Controls option. Google Help
  • Decision (EU) 2023/1795. EUR-Lex
  • Court of Justice of the European Union, 16 July 2020, C-311/18 (Schrems II). EUR-Lex
  • On the Data Privacy Framework litigation, a lawyers’ commentary, not a decision: WilmerHale, “European Court of Justice to Review Challenge to EU-U.S. Data Privacy Framework”, 1 December 2025. wilmerhale.com
  • On the litigation and the ongoing review, a lawyers’ commentary, not a decision: DAC Beachcroft, “The EU–US Data Privacy Framework: stability for now, uncertainty ahead”. dacbeachcroft.com
  • 18 U.S.C. § 2713. govinfo

A French operator for your data

Email, documents, video conferencing, CRM and telephony, hosted in the zone that matches your jurisdiction, for example in Europe or Mauritius, or on your premises.

Talk to an advisor →

Klytic hosting

Welcome offer

30 days free trial, migration support included

No-commitment trial. An advisor calls you back to understand your needs and prepare your Klytic workspace.