ModelCharter

Is Google Gemini SOC 2 compliant?

Yes

Google · AI assistants

Yes. Google holds a SOC 2 report covering Google Gemini, which gives independent assurance over its security controls.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

SOC 2 report
Confirmed
Google reports a SOC 2 attestation. Request the current report and relevant bridge letter during procurement.
ISO 27001
Confirmed
Google also reports ISO/IEC 27001 certification.
Default data training
Opt-out required
On consumer Gemini Apps (personal Google accounts), activity is used to improve Google services and a subset is human-reviewed unless Gemini Apps Activity is turned off.
Business-tier training
No by default
Google Workspace with Gemini does not use customer content to train models outside the customer's domain and content is not human-reviewed.
Practical risk: Personal Gemini accounts have human reviewers reading a sample of chats (kept up to 3 years even after you delete activity), so confidential work content typed into a personal account can be seen by reviewers.

How to make a decision

Check the precise account tier, written contract and intended data before approving Google Gemini. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Google Gemini

See the full Google Gemini risk profile, with every data-handling fact and its source, or browse all rated AI tools.