kontinent / compliance index

B

Google Vertex AI (EU)

Google Ireland Limited · IE · Last reviewed: 2026-08-04

75

Data Protection Contracts

83/100

Google provides a full Article 28 data processing agreement through its Cloud Data Processing Addendum, which is incorporated automatically into the terms of service and does not need to be requested separately. Google acts as processor and the customer as controller.

ja

Source: Cloud Data Processing Addendum — Google Cloud (Stand 23.07.2026), §4.1 Roles of Parties — 'Google is a processor and Customer is a controller or processor, as applicable'; Weisungsbindung, Vertraulichkeit, Unterauftragsverarbeiter, Löschung und Audits sind in §§5-11 geregelt. (reviewed 2026-08-04)

The data processing addendum incorporates the EU standard contractual clauses in all three relevant modules and makes clear that they apply automatically as soon as data is transferred to a country without an adequacy decision.

ja

Source: Cloud Data Processing Addendum — Google Cloud (Stand 23.07.2026), §4.1 Restricted Transfers (SCCs greifen mangels Angemessenheitsbeschluss oder Alternative Transfer Solution) sowie die Definitionen der Module Controller-to-Processor, Processor-to-Processor und Processor-to-Controller mit Verweis auf cloud.google.com/terms/sccs/. (reviewed 2026-08-04)

Google commits to notifying data incidents promptly and without undue delay, and contractually specifies what the notification must contain. It does not commit to a fixed deadline in hours, however.

teilweise

Source: Cloud Data Processing Addendum — Google Cloud (Stand 23.07.2026), §7.2.1 Incident Notification — 'Google will notify Customer promptly and without undue delay after becoming aware of a Data Incident'; §7.2.2 regelt den Inhalt der Meldung. Keine Stundenfrist genannt. (reviewed 2026-08-04)

Data Residency & Sovereignty

50/100

The Service Specific Terms contractually commit that customer data is both stored at rest and machine-learning-processed by the service exclusively within the multi-region the customer selects. This binds inference to the EU, not merely storage. It requires the EU multi-region to be configured; technical support and sub-processors are not covered by it.

ja

Source: Service Specific Terms — Google Cloud (Stand 23.07.2026), §16 AI/ML Data Location — 'Customer may configure the Services ... to (a) store Customer Data at rest and (b) perform machine learning processing of Customer Data by the Service, in each case in a specific Multi-Region, and Google will perform (a) and (b) only in that Multi-Region.' Ergänzend §1 Data Location (Replikation nur innerhalb der Länder der gewählten Multi-Region). (reviewed 2026-08-04)

Google maintains a public sub-processor list giving name, activity, country of processing, registered address and ultimate parent, announces additions at least 30 days in advance and grants a right to object. The list is clearly not EU-limited, however: processing takes place in India, Canada and Japan among others. The activities concerned are predominantly technical support, which only gains access to customer data if the customer explicitly shares it.

teilweise

Source: Cloud Data Processing Addendum — Google Cloud (Stand 23.07.2026) + Google Cloud Platform Subprocessors (Liste, Stand 23.07.2026), §11.1 (Zustimmung), §11.3 (Flow-down per schriftlichem Vertrag), §11.4 (Vorabmeldung 30 Tage, Widerspruchsrecht, gemeinsame Lösungssuche), Appendix 4 §4 (Veröffentlichung von Namen, Orten und Tätigkeiten). Auszählung der Liste: Indien, Kanada, Japan und Polen stellen die meisten Verarbeitungsorte. (reviewed 2026-08-04)

The contracting entity for EEA customers is Google Ireland Limited, based in Ireland and therefore an EU legal entity. It belongs to the US group Alphabet Inc., however, so the ownership structure sits outside the EU.

nein

Source: Provider-Stammdaten Kontinent (Ranking-Provider) + Google Cloud Platform Terms of Service (Stand 23.07.2026), Rechtsträger Google Ireland Limited (IE) laut Provider-Stammdaten; Konzernmutter Alphabet Inc. (Mountain View, USA). Das archivierte ToS-PDF nennt den EWR-Vertragspartner nicht namentlich, ein amtlicher Registerauszug liegt noch nicht vor. (reviewed 2026-08-04)

Data Use

100/100

Google contractually commits not to store, outside the customer's account and absent the customer's prior permission, either the prompts sent to the service for longer than is reasonably necessary to produce the answer, or the generated output. This is a genuine zero-retention commitment as default behaviour rather than an option that must be requested.

ja

Source: Service Specific Terms — Google Cloud (Stand 23.07.2026), §20.h Handling of Prompts and Generated Output — 'Absent Customer's prior permission or instruction, Google will not store outside Customer's Account (i) Customer Data prompted to a Generative AI Service for longer than is reasonably necessary to create the Generated Output, or (ii) the Generated Output.' (reviewed 2026-08-04)

The Service Specific Terms contractually exclude any use of customer data to train or fine-tune AI models unless the customer explicitly permits or instructs it. The commitment is unconditional and not limited to particular models.

ja

Source: Service Specific Terms — Google Cloud (Stand 23.07.2026), §18 Training Restriction — 'Google will not use Customer Data to train or fine-tune any AI/ML models without Customer's prior permission or instruction.' (reviewed 2026-08-04)

No opt-out is required because both critical uses are excluded by default: training only with prior permission, and prompts and outputs are not stored outside the customer's account at all absent permission. Unlike other providers there is no blanket abuse-detection retention that would need to be opted out of.

ja

Source: Service Specific Terms — Google Cloud (Stand 23.07.2026), §18 Training Restriction in Verbindung mit §20.h Handling of Prompts and Generated Output; in den geprüften Dokumenten findet sich keine Missbrauchserkennungs-Aufbewahrung analog zu AWS Service Terms §50.12.2. (reviewed 2026-08-04)

Certifications

75/100

The service we use is certified by name: Google lists 'Generative AI on Vertex AI' explicitly under ISO 27001, 27017 and 27018 in its services-in-scope overview. Google additionally undertakes in its data processing addendum to maintain those certificates on an ongoing basis. This evidences not merely that a certificate exists, but that its scope covers the inference service.

ja

Source: Google Cloud Platform Services in Scope by Compliance Program (Abruf 14.08.2026) — 03_GCP__VERTEX_AI/Google_Services-in-Scope_Vertex_2026-08-14.pdf; ergänzend Cloud Data Processing Addendum §7.4(a) (Stand 23.07.2026), Services-in-Scope-Tabelle, Zeile 'Generative AI on Vertex AI': Spalte 'ISO 27001, 27017, 27018 Certifications' = done. Ergänzend CDPA §7.4(a): 'Google will maintain at least the following for the Audited Services ... certificates for ISO 27001 and any additional certifications described in Appendix 4'; Appendix 4 §2 nennt ISO 27017, ISO 27018 und PCI DSS AoC. (reviewed 2026-08-14)

SOC 1, 2 and 3 cover the service we use by name: Google lists 'Generative AI on Vertex AI' explicitly under the SOC reports in its services-in-scope overview, and the data processing addendum requires annual renewal. A BSI C5 attestation exists at group level but is not publicly evidenced for this service — C5 does not appear in the services-in-scope overview, and the report is only available through a request portal.

teilweise

Source: Google Cloud Platform Services in Scope by Compliance Program (Abruf 14.08.2026) — 03_GCP__VERTEX_AI/Google_Services-in-Scope_Vertex_2026-08-14.pdf; ergänzend Cloud Data Processing Addendum §7.4(b) (Stand 23.07.2026), Services-in-Scope-Tabelle, Zeile 'Generative AI on Vertex AI': Spalte 'SOC 1, 2, 3 Reports' = done. Die Tabelle führt vier Programme (ISO 27001/27017/27018, SOC 1/2/3, PCI DSS, Penetration Testing) — BSI C5 ist darin GAR NICHT enthalten. Ergänzend CDPA §7.4(b): jährlich erneuerte SOC-2- und SOC-3-Berichte des Drittprüfers. Eine C5:2020-Attestierung besteht laut cloud.google.com/security/compliance/bsi-c5 auf Konzernebene; der Report liegt hinter dem Compliance Reports Manager, der Geltungsbereich für diesen Dienst ist nicht öffentlich belegt. (reviewed 2026-08-14)

AI Act Readiness

50/100

No verifiable commitment

unbelegt

Google is on the European Commission's list of signatories to the EU Code of Practice for general-purpose AI models.

ja

Source: EU GPAI Code of Practice — Signatarliste der Europäischen Kommission, Signatarliste geprüft im Rahmen der Provider-Due-Diligence; Google gelistet. Gleiche Belegquelle wie bei der Bewertung von Amazon. (reviewed 2026-08-04)

Contract Quality & Transparency

83/100

The terms of service, data processing addendum, service specific terms, sub-processor list and the Vertex SLA are all publicly retrievable in full without an existing contractual relationship. The certificates and audit reports themselves are only available under confidentiality obligations.

ja

Source: GCP Terms of Service, Cloud DPA, Service Specific Terms, Subprocessors, Vertex AI SLA (alle öffentlich, archiviert 23.07.2026), Alle fünf Dokumente öffentlich abrufbar und in der Compliance-Ablage archiviert; Einschränkung für Zertifikate und Prüfberichte nach DPA §7.5. (reviewed 2026-08-04)

Vertex AI has its own published service level agreement with availability commitments broken down by sub-service and a tiered financial credit model when they are missed.

ja

Source: Vertex AI Service Level Agreement (SLA) — Google Cloud (Stand 23.07.2026), Mindestens 99,9 % monatliche Verfügbarkeit für Training, Deployment und Batch sowie AutoML; mindestens 99,5 % für Custom Model Online Prediction und Vertex Pipelines. Financial Credits gestaffelt, z. B. 10 % bei 99 % bis unter 99,9 %. (reviewed 2026-08-04)

Liability is capped on both sides at the fees paid in the preceding twelve months, with the customary unlimited carve-outs for fraud, indemnification obligations, IP infringement and mandatory law. That matches market standard but is low in absolute terms at modest spend, and there is no separate, higher cap for data protection breaches.

teilweise

Source: Google Cloud Platform Terms of Service (Stand 23.07.2026), §12.1 (Ausschluss indirekter Schäden), §12.2 ('limited to the Fees Customer paid for such Services during the 12 month period before the event giving rise to Liability'), §12.3 Unlimited Liabilities (Arglist, Freistellung, IP, Zahlungspflichten, zwingendes Recht). (reviewed 2026-08-04)

Do you represent Google Vertex AI (EU) and think something is inaccurate? Write to legal@kontinent.ai. We check every report and correct verified errors with full transparency.

Report error

Methodology Version 2.0