
You can count on the fact that Google is committed to GDPR compliance for Google Cloud. The GDPR strengthens the rights that individuals have regarding personal data relating to them and seeks to unify data protection laws across Europe, regardless of where that data is processed. The EU General Data Protection Regulation (GDPR) replaces the 1995 EU Data Protection Directive. How does Google Cloud comply with the EU’s General Data Protection Regulation (GDPR)? Organization and administration-Controls provide reasonable assurance that management provides the infrastructure and mechanisms to track and communicate initiatives within the company that impact Google Cloud.Change management-Controls provide reasonable assurance that development of and changes to Google Cloud undergo testing and independent code review prior to release into production.Incident management and availability-Controls provide reasonable assurance that Google Cloud systems are redundant and incidents are properly reported, responded to, and recorded.Data center physical security-Controls provide reasonable assurance that data centers that house Google Cloud data and corporate offices are protected.Privacy-Controls provide reasonable assurance that Google has implemented policies and procedures addressing the privacy of customer data related to Google Cloud.Logical security-Controls provide reasonable assurance that logical access to Google Cloud production systems and data is restricted to authorized individuals.

The independent third party auditor verified that Google Cloud has the following controls and protocols in place: Learn more about the SOC3 public report. You can get a copy of our SOC 2 report from the Cloud Compliance Reports Manager.

Google is proud to provide Google Cloud administrators the peace of mind knowing that their data is secure under the SOC 2/3 auditing industry standards. An independent third-party auditor issued Google Cloud an unqualified Service Organizations Controls (SOC) 2/3 audit opinion.
