Compliance resource center

Google Cloud’s industry-leading certifications, documentation, and third-party audits to help support your compliance.

Google Cloud compliance

As part of your migration to the cloud, you may need to validate our compliance documentation, certifications, and controls. Google Cloud creates and shares mappings of our industry-leading security, privacy, and compliance controls to standards from around the world. We also regularly undergo independent verification—achieving certifications, attestations, and audit reports to help demonstrate compliance.

AI trust paper

Customers interested in Google Cloud’s approach to AI can reference Google Cloud’s Approach to Trust in Artificial Intelligence for a view into our security, privacy, governance, and responsible AI posture.

Compliance offerings by category

Auditor-validated certifications and attestations

Laws and regulations

Cloud service providers can’t provide formal certification of our customers compliance with these laws and regulations. To help support our customers, we review these laws and regulations and where possible provide guidance documents, mappings, and papers that outline our technical capabilities and legal commitments. 

Global and North America

GxPCalifornia Consumer Privacy Act (CCPA) | COPPA (U.S.) | Export Administration Regulations (EAR) | FERPA (U.S.) | FINRA (US) | Google Cloud Data Processing Addendum Mapping - U.S. State Privacy Laws | HIPAA | IRS 1075International Traffic in Arms Regulations (ITAR) | GLBA | OSFI (Canada) | FG16/5 - FCA | NERC CIP | PHIPA (Canada) | StateRAMP | PIPEDA (Canada)  | US Federal Banking Agencies | U.S. Defense Federal Acquisition Regulation Supplement (DFARS)

EMEA

ACPR (France) | BaFin Cloud Outsourcing Guidance | Banco de España | Banco de Portugal | Bank of Italy | BRSA (Turkey)BSI Critical Infrastructure (KRITIS) |BWG (Austria) | Central Bank of Ireland (Ireland) | CSSF (Luxembourg) | De Nederlandsche Bank (the Netherlands) | EU DORA | European Union’s Digital Markets Act | EU Solvency II | EU Standard Contractual Clauses | FINMA (Switzerland)FSA (Denmark) | GDPR | ISO 14001 | Israel’s Privacy Protection AuthorityKNF (Poland)MaRisk AT 9 Outsourcing | PRA (UK) | revFADP (Switzerland) | South Africa POPI | SFSA (Sweden) | Telecoms Security Act (UK) | VAG (Austria)| SYSC 8 Outsourcing - FCA Handbook | UK CHECK

Alignments and frameworks

Our products, technical capabilities, guidance documents, and legal commitments help our customers map to these frameworks and alignments. These offerings may not require formal certification or attestation, though we may rely on our certifications, attestations, and reports to help our customers map to these frameworks and alignments.

Global

Bitsight | Center for Internet Security (CIS) Benchmarks | CyberGRX | ISO/IEC 27110 | Know Your Third Party (KY3P) Report | MVSP | Standardized Information Gathering (SIG) Questionnaire | USDM Life Sciences | Whistic

Take the next step

Tell us what you’re solving for. A Google Cloud expert will help you find the best solution.

Google Cloud
  • ‪English‬
  • ‪Deutsch‬
  • ‪Español‬
  • ‪Español (Latinoamérica)‬
  • ‪Français‬
  • ‪Indonesia‬
  • ‪Italiano‬
  • ‪Português (Brasil)‬
  • ‪简体中文‬
  • ‪繁體中文‬
  • ‪日本語‬
  • ‪한국어‬
Console
Google Cloud