ModelCharter

Is NotebookLM GDPR compliant?

Unverified

Google · Search

Not verified. Check Google's terms for a GDPR Data Processing Agreement (DPA) before processing EU personal data in NotebookLM.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

Data Processing Agreement
Not verified
No public DPA was confirmed. Do not process EU personal data until the vendor supplies suitable processor terms.
EU data residency
Not verified
No EU-residency option was confirmed in the sources reviewed for this profile.
Default data training
No by default
Google states uploads, queries and responses are not used to train generative AI models, on consumer or Workspace and Education accounts alike. Consumer thumbs up or down feedback can get de-identified human review.
Business-tier training
No by default
None of the consumer or Workspace-core tiers carry HIPAA, SOC or ISO coverage. Only NotebookLM Enterprise, a separate Google Cloud SKU with its own IAM, VPC-SC and CMEK controls, targets regulated use. is the business tier recorded for this profile.
Practical risk: NotebookLM does not train on your uploads or queries on either tier, a genuinely strong default. But Google is explicit that the product carries no SOC 2, ISO 27001 or HIPAA BAA today; for regulated data you would need the separate NotebookLM Enterprise product.

How to make a decision

Check the precise account tier, written contract and intended data before approving NotebookLM. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on NotebookLM

See the full NotebookLM risk profile, with every data-handling fact and its source, or browse all rated AI tools.