Compliance8 min read

Is Google Gemini GDPR compliant? What companies need to know

Short answer: it depends on the version. The consumer app and Workspace or Vertex AI differ legally. What companies must settle for GDPR before using it.

By Alexis de ONYRI
Worried about your data? Anonymize it before AI

The honest answer: it depends on the version. The consumer Gemini apps and Gemini inside Google Workspace or Vertex AI are not the same thing legally. For companies, what matters most is the right contract and a clean legal basis. According to Google, data from Cloud and Workspace customers is not used to train the models without permission. But "GDPR compliant" is not a switch a tool flips — it depends on your setup.

Consumer app or enterprise version?

The first step is spotting the right version. With a personal Google account you use the consumer apps. Companies should use Gemini in Google Workspace or Vertex AI in Google Cloud. Only the enterprise versions carry the contractual promises you need for GDPR.

  • Consumer apps: personal Google account, meant for private use.
  • Google Workspace: Gemini in a business plan with a contract.
  • Vertex AI: Gemini via Google Cloud, with a Data Processing Addendum.
  • According to Google, Cloud customers get different data terms than consumers.
  • A personal account at work is rarely the right choice.

"No training" does not mean "no storage"

Many people mix up two things. "Not used for training" does not mean "not stored". According to Google, inputs from Workspace and Cloud customers are not used to train the models without permission. For the consumer apps, Google's documentation says snippets of conversations can be reviewed by people and kept for a time. So check your activity settings.

  • Training: are your inputs used to improve the models?
  • Storage: are your inputs kept, and for how long?
  • Human review: can staff read snippets?
  • According to Google, consumer apps follow different rules than Cloud.
  • These settings change — check the current documentation.

What GDPR asks of companies

A tool alone does not make you GDPR compliant. You need the right building blocks. Google is a US vendor, so data transfer matters. The points below are the core.

  1. 1Processing: a DPA under Art. 28 GDPR (for Google, the Data Processing Addendum).
  2. 2Legal basis: a valid basis under Art. 6, such as legitimate interest or contract.
  3. 3Third-country transfer: standard contractual clauses and safeguards under Art. 44 ff.
  4. 4Data subject rights: access, erasure and objection must stay possible.
  5. 5Documentation: a record of processing and, if needed, an impact assessment.

A checklist before you start

Before a team uses Gemini, settle a few questions. This avoids nasty surprises. The list is no substitute for a review, but it points the right way.

  • Which Gemini version are we using — consumer or enterprise?
  • Is there a signed DPA with Google?
  • Is the legal basis clear for each use?
  • Are the US transfer mechanisms documented?
  • What data may staff actually enter?

Data minimisation is the first defence

The data minimisation principle in Art. 5 GDPR helps here directly. The less personal data you enter, the smaller the risk. You rarely need to send real names or customer IDs to an AI model. Often the context works fine without the identifying details.

  • Ask yourself: does the model really need this name?
  • Replace real customer data with placeholders.
  • Avoid special categories under Art. 9 (e.g. health data).
  • Less input means less storage and less risk.
  • Minimisation lowers exposure but replaces no contract.
ScenarioRecommended Gemini versionGDPR note
Personal notes without customer dataConsumer app possibleCheck activity settings
Business use across a teamWorkspace or Vertex AIDPA is mandatory
Processing customer dataVertex AI with DPAClarify basis under Art. 6
Sensitive data (Art. 9)Avoid where possibleHigh bar, consider a DPIA
Tests and prototypesEnterprise versionPseudonymised data only

This is exactly where ONYRI Sanitize fits in. The tool detects sensitive data in your text and replaces it with reversible placeholders (tokens) before the text reaches the AI. The token-to-value mapping stays in your browser and is never sent to a server. After the AI replies, the real values are restored. To stay honest: this is pseudonymisation, not anonymisation. Pseudonymised data still counts as personal under Recital 26 of the GDPR. ONYRI lowers your exposure, but it replaces neither a DPA nor a legal basis.

The takeaway: "Is Gemini GDPR compliant?" is the wrong question. The right one is: use the correct version, with the right contract, and as little personal data as possible. Then the AI becomes a manageable tool instead of a risk.

Frequently asked questions

Is the consumer Gemini app fine for business?
Usually not. The consumer app is meant for private use. For business data you need Workspace or Vertex AI with a contract. Also check the activity settings.
Does Google use my inputs for training?
According to Google, inputs from Workspace and Cloud customers are not used for training without permission. Consumer apps follow different rules. Since these change, check Google's current documentation.
Do I need a DPA with Google?
Yes. If you have personal data processed, you need a data processing agreement under Art. 28 GDPR. For Google, that is the Cloud Data Processing Addendum.
Does pseudonymisation make my use GDPR compliant?
No, but it helps. Pseudonymised data stays personal (Recital 26). It lowers risk and data volume, but replaces no contract and no legal basis.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next