CompanyScope
by Janus Compliance

General-purpose AI / LLM API

Google Gemini compliance: GDPR, AI Act, DPA, training, transfers

Independent compliance research from Janus Compliance. Reviewed by Michael K. Onyekwere, CIPP/E. Last reviewed 2026-10-04. Not legal advice.

Share this Google Gemini profile:Share on XBluesky

TL;DR. Three distinct surfaces buyers conflate: Gemini Enterprise / Vertex AI (contractually no training, ZDR available, broad cert portfolio); the Gemini API via AI Studio at ai.google.dev (a billed key is covered by Google's processor DPA and is not used for training, while the free tier is used to improve Google's products except for users in the EEA, Switzerland and the UK, to whom the paid-tier data terms apply); consumer Gemini at gemini.google.com and embedded in Workspace (training on by default unless disabled). On Vertex AI, data at rest stays in the location you select, whereas ML processing stays in Europe only when you call the EU multi-region or a European regional endpoint, because the global endpoint gives no residency guarantee. The Gemini API via AI Studio offers no residency option at all. Vertex AI is within the scope of Google Cloud's ISO/IEC 42001, ISO/IEC 27001 and SOC 2 certifications, which do not name the Gemini Developer API.

DPO action: lock down which Gemini surface your staff actually use; for EU personal data on Vertex AI, call the EU multi-region or a European regional endpoint and never the global endpoint; review the Workspace generative-AI training control at tenant scope; sign a BAA before any PHI (Vertex AI or a covered Workspace SKU only, never consumer Gemini or AI Studio).

What the tool does

Google ships Gemini in three places that buyers commonly conflate:

  1. Gemini Enterprise / Vertex AI (rebranded "Gemini Enterprise Agent Platform" at Google Cloud Next 2026) - the enterprise platform for building, deploying, and governing AI agents grounded in your own data. Runs inside Google Cloud, billed via GCP, governed by Google's Cloud DPA.
  2. Gemini API via AI Studio at ai.google.dev - the developer API, with a free tier and a paid tier. Paid use, meaning use through a Cloud project linked to an active billing account, is governed by Google's processor Data Processing Addendum, which is a different agreement from the Vertex AI terms.
  3. Gemini consumer surfaces - the standalone chat at gemini.google.com and the embedded Gemini features inside Google Workspace (Gmail, Docs, Slides, Sheets, Meet). For most enterprise buyers using Workspace, this is the most-touched surface.

Compliance defaults differ across all three. Most enterprise procurement should be looking at Gemini Enterprise / Vertex AI; AI Studio is fine for prototyping but is not the enterprise contracting surface.

Data processed

Special-category likelihood: High in any free-form deployment. Gemini's multimodal nature means staff may upload images / scanned documents that contain Article 9 categories (medical scans, ID photos, etc.) without realising. UI controls and DPIA matter more than usual.

Default geographic processing: on Vertex AI, data at rest remains in the location the customer selects, whichever endpoint is called. ML processing depends on the endpoint: "Requests submitted to a global endpoint may be processed in any Google Cloud location around the world, and therefore don't provide any data residency guarantees." The EU multi-region endpoint keeps processing within EU member states for the models Google lists. On the Gemini Developer API, Google states that data "may be stored transiently or cached in any country in which Google or its agents maintain facilities".

DPA availability

Google Cloud Data Processing Addendum (Cloud DPA) governs Vertex AI and Gemini Enterprise. It is incorporated into Google Cloud commercial agreements and publicly available without a sales call. The version checked on 4 October 2026 was last modified on 8 June 2026.

For the paid Gemini Developer API, the Gemini API Additional Terms provide that Google "will process your prompts and responses in accordance with the Data Processing Addendum for Products Where Google is a Data Processor". That addendum, Version 10 of 7 May 2026, lists "Gemini API Paid Services" among the services it covers and includes the Data Privacy Framework, SCCs, UK terms and Swiss terms. The Developer API lacks Vertex AI's data residency and zero data retention routes, and Google itself advises: "If your workload requires guaranteed zero data retention or enterprise data processing agreements, use Vertex AI."

For Workspace Gemini, the existing Google Workspace DPA applies - verify your Workspace tier covers the AI features you use.

Subprocessor list

Google Cloud publishes a subprocessor list applicable to all Google Cloud services including Vertex AI / Gemini Enterprise.

For the paid Gemini Developer API, the processor DPA points to business.safety.google/subprocessors/, which on 4 October 2026 carried no Gemini API entry. The DPA gives the same 30-day notice and 90-day termination right.

Training-on-customer-data position

Vertex AI / Gemini Enterprise: Customer data is not used to train Google's AI/ML models without prior permission or instruction. Section 18 of Google's Service Specific Terms ("Training Restriction", formerly Section 17) makes this an explicit contractual commitment: "Google will not use Customer Data to train or fine-tune any AI/ML models without Customer's prior permission or instruction."

Vertex AI Zero Data Retention (ZDR): Google describes zero data retention as a set of conditions to meet, not a single setting. Where a customer is in scope for abuse-monitoring prompt logging, flagged prompts are kept "for up to 90 days in the same region or multi-region selected by the customer" unless the customer requests an exception, although "customers with a Google Cloud Master Agreement are exempt from prompt logging for this abuse monitoring by default." Grounding with Google Search stores data for up to three days and cannot be switched off, the Interactions API stores state unless store is set to false, and session resumption and request-response logging have to stay disabled. Claude Mythos and Fable models on the platform carry a 30-day log.

Gemini API paid tier retention: "Google retains the following data for fifty-five (55) days for the purposes of detecting and preventing violations of the Prohibited Use Policy", and Google offers no zero data retention route on the Developer API.

Gemini API free tier (AI Studio / unbilled keys): Inputs and outputs are used to improve Google's models. This is the current published policy (confirmed June 2026), not a historical artefact. The dividing line is billing, not surface: the moment a Gemini API key is linked to a paid billing account, prompts and responses are no longer used for training, the same position as Vertex AI. Users in the EEA, Switzerland and the UK are treated differently: for them, the paid-tier data terms apply to all services, including AI Studio and unpaid quota, and "You may use only Paid Services when making API Clients available to users in the European Economic Area, Switzerland, or the United Kingdom." Outside those territories the free tier is the unmanaged-risk surface, and the fix is often as small as enabling billing on the key staff already use.

Gemini consumer (gemini.google.com) and Workspace Gemini: Conversations may be used to improve Google's products (with human reviewers seeing samples of conversations) unless training is disabled. The relevant admin control lives in the Workspace admin console under "Control Workspace Intelligence for generative AI features" (renamed from the older "Gemini Apps Activity" label). Workspace admin docs state explicitly: "Your content is not human reviewed or used for Generative AI model training outside your domain without permission." Many admins have not actively reviewed this control.

The enterprise no-training story for Vertex AI is solid and contractual. The free-tier API and consumer-chat defaults are not. The biggest unmanaged risk is staff using gemini.google.com on personal Google accounts, sometimes signed in as their work identity if Workspace is configured permissively. - My read

EU / UK transfer position

The Google Cloud DPA uses an "Alternative Transfer Solution" where Google has adopted one, and the Standard Contractual Clauses (SCCs) where it has not. Google states: "As of September 1, 2023, Google has adopted an Alternative Transfer Solution for transfers of EU/EEA personal data to, and onwards from, the U.S.", namely the EU-US Data Privacy Framework, and it adopted the UK Extension and the Swiss-US framework on the same basis from 16 September 2024. The SCCs, with UK and Swiss supplementary terms that use the ICO's International Data Transfer Addendum, remain in the DPA as the fallback. Google also reserves the right to rely on Article 49(1) GDPR for transfers to countries other than the US. The processor DPA for the paid Gemini API follows the same structure.

EU-US Data Privacy Framework (DPF) certification: Google LLC and its US subsidiaries hold all three certifications, EU-US, Swiss-US and the UK Extension. When the participant registry was checked on 4 October 2026, with a control query in the same run, each showed the status "Active", with the current period running to 13 September 2027. On 14 September 2026 the same entries read "Active - Re-certification under Review", the register's wording for an annual re-certification in progress, so the review closed within three weeks. Google stayed on the active list throughout. It has held the EU-US entry since 22 September 2016. The framework survived its first court test when the EU General Court dismissed the challenge to it on 3 September 2025, however an appeal is pending at the Court of Justice of the EU (filed October 2025). So DPF is a valid transfer basis today with a live appeal in the background, which is why the SCCs in the Cloud DPA matter as the fallback. Google is the only one of the three largest model vendors on the participant list. Neither OpenAI nor Anthropic appears on it.

EU data residency: Google's data residency terms allow a customer to configure covered services to store data at rest and perform ML processing in a specific multi-region, and Google then performs both only there. For generative AI this applies only to the models listed in Google's ML-processing documentation and excludes Grounding with Google Search, Web Grounding for Enterprise, Grounding with Google Maps and RAG Engine. The EU multi-region endpoint keeps processing within EU member states, and Google states that geographies outside the EU, "including the United Kingdom and Switzerland, are excluded from this endpoint." In the United Kingdom region (europe-west2), in-country ML processing was available on 4 October 2026 for only Gemini 3.5 Flash, Gemini 2.5 Flash 128k and two text-embedding models. A DPIA should therefore record the endpoint each integration calls and the models it uses, and UK buyers should check whether the model they need is processed in the UK.

Google's "Sovereign Cloud" partnerships (with T-Systems in Germany, others) offer additional EU data sovereignty options for highly regulated buyers. Out of scope for most SMEs, but relevant if your sector requires it.

Security documentation

Google Cloud's compliance pages, checked on 4 October 2026, state:

These scope statements name the Agent Platform and do not name the Gemini Developer API, whose processor DPA commits only to "ISO/IEC 27001:2013 certification or a comparable certification for the Processor Services." A buyer using the Developer API should not rely on the Vertex AI certifications. Google's wider certifications, including FedRAMP High, C5, IRAP and MTCS, were last checked for this profile in June 2026.

HIPAA & BAA position

Gemini is not HIPAA-eligible by default on any plan. Which surface you use decides everything, the same split that drives the rest of this profile. Google will sign a BAA, covering two surfaces once it is in place:

This is the HIPAA version of the vendor's core trap: "we use Gemini" is not an inventory entry. Pin the surface in writing (Vertex AI, or a covered Workspace SKU, with the BAA executed) before any PHI moves. The BAA is the contractual piece; HIPAA's Security Rule (risk analysis, minimum-necessary, workforce training, audit controls, breach notification) still falls on the covered entity. See HIPAA for AI tools for the full walkthrough across vendors.

AI Act role + risk classification

Google publishes AI Act readiness materials and a Model Card for Gemini family models.

DPIA prompts (for your use case)

  1. Which Gemini surface are you actually deploying - Vertex AI, AI Studio, consumer chat, or Workspace Gemini? They have different DPAs, different training defaults, and different data residency stories. Get this on paper before anything else.
  2. Which endpoint does each integration call? For EU personal data on Vertex AI, use the EU multi-region or a European regional endpoint and a model listed for ML processing there, and avoid the global endpoint and grounding features. For UK data, check whether the model is processed in the UK region.
  3. Have you met the zero data retention conditions on Vertex AI if your data sensitivity warrants it, including an abuse-monitoring exception where you are in scope for prompt logging?
  4. Have you mapped staff use of gemini.google.com and Workspace Gemini features? Personal Google accounts using consumer Gemini fall under consumer terms; this is the most-missed risk in Workspace-using SMEs. For Workspace tenants, confirm the "Control Workspace Intelligence for generative AI features" admin setting reflects your training-restriction stance.
  5. AI Act Annex III applicability: if your use case touches recruitment, credit, education, law enforcement, migration, or justice, deployer high-risk obligations engage.
  6. Multimodal input: are users uploading images/PDFs that may contain Article 9 special-category data? UI controls plus a DPIA covering this scenario.

Unresolved questions / red flags

Related profiles

Sources checked

Related reading


Share this Google Gemini profile:Share on XBluesky

Talk to Michael about Google Gemini - or your AI vendor governance more broadly

CompanyScope's public profiles cover the general picture. Michael runs Janus DPO-as-a-Service for businesses that need ongoing AI vendor governance, and writes one-off CIPP/E-reviewed Vendor Risk Notes for specific procurement decisions. Tell him what you're actually trying to clear.

A sentence or two is plenty.

Your context goes only to Michael. We don't share with the vendor or anyone else. Privacy notice.

Subscribe to the AI Agent Incident Register

Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.

Subscribe - free

Delivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.

For ongoing AI compliance support, work with Janus DPO-as-a-Service. For other vendors, browse the full index, or see real agent failures analysed legally in the AI Agent Incident Register.