Privacy & Security Centre
Google is committed to building products that help protect student and teacher privacy and provide best-in-class security for your institution.
Four things to know
Google takes security seriously, with industry-leading safeguards and privacy policies that put you in control of your school’s data. Here’s how you know that students and educators are protected.
We keep your data secure
Schools own their data – it’s our responsibility to keep it secure. Google builds and operates our own secure servers and platform services, and we make it easy for administrators to monitor and manage data security. Watch video.
There are no ads in G Suite for Education core services
There are no ads in G Suite for Education core services, and students’ personal information won’t be used to create ad profiles for targeting. Watch video.
Google supports compliance with industry regulations and best practices.
Our services support compliance with privacy and security requirements. Independent organisations have audited our services, ensuring our data protection practices meet demanding standards. Watch video.
You have clear information about Google’s privacy and security policies
Google is committed to transparency about our data collection policies and practices. The G Suite for Education Privacy Notice and G Suite Agreement explain our contractual obligations to protect your data. Watch video.
G Suite for Education and Chromebooks support compliance with rigorous standards
US FERPA (Family Educational Rights and Privacy Act)
The Software & Information Industry Association
COPPA (Children’s Online Privacy Protection Act of 1998)
Student Privacy Pledge introduced by the Future of Privacy Forum (FPF)
ISO/IEC 27018:2014 (Data standards)
Read and share information about how Google products keep your data secure
G Suite for Education
Learn how G Suite for Education tools protect the more than 60 million students and teachers using it today.
Chromebooks for Education
Get details on the privacy and security features built into Google Chromebooks.
Google Cloud Platform
See how Google Cloud Platform’s security solutions safeguard your information and keep your organisation compliant.
Privacy and security FAQs
Find answers to common questions about how Google protects your privacy and keeps your data safe.
What are G Suite for Education core services?Learn more about G Suite core and additional services
The G Suite for Education (formerly called Google Apps for Education) core services are the heart of Google’s educational offering to schools. The core services are Gmail (including Inbox by Gmail), Calendar, Classroom, Jamboard, Contacts, Drive, Docs, Forms, Groups, Sheets, Sites, Slides, Talk/Hangouts and Vault. These services are provided under the G Suite agreement.
Schools can use G Suite core services in compliance with the US COPPA and FERPA. G Suite core services contain no advertising and do not use information in those services for advertising purposes.
More than 50 million students, teachers and administrators in almost every country in the world rely on G Suite to learn and work together. We are committed to protecting the privacy and security of all our users, including students.
Read our G Suite Privacy Notice
Read our G Suite agreement (Google's contract with schools covering G Suite core services)
Does Google own school/university or student data?Learn how to take data out of Google
We provide powerful, easy-to-use management tools and dashboards to help administrators keep track of their organisation's services, usage and data. We only keep your personal information as long as you ask us to keep it. If an education department, school or university decides to stop using Google, we make it easy for them to take their data with them.
Read the contract (section on "Intellectual Property")
Does Google sell school or student data to third parties?More about information sharing
What is G Suite for Education’s commitment to the GDPR?Google Cloud & the General Data Protection Regulation (GDPR)
Our users can count on the fact that Google is committed to GDPR compliance across G Suite for Education. Please refer to our GDPR website for further information, including tips on how to get ready for the GDPR, which will take effect on May 25, 2018.
Are there ads in G Suite?Read our G Suite agreement (Google's contract with schools covering G Suite core services)
No. There are no ads in the suite of G Suite core services. Outside of the G Suite Core Services, additional Google services may show ads, as described in the G Suite Privacy Notice. For G Suite users in Primary/Secondary (K-12) schools, Google does not use any user personal information (or any information associated with a Google Account) to target ads.
Read our G Suite Privacy Notice
More about privacy
How does Google keep data secure?More about security
We are fully committed to the security and privacy of your data and protecting you and your school from attempts to compromise it. Our systems are among the industry’s most secure and we vigorously resist any unlawful attempt to access our customers’ data.
Google’s data centres use custom hardware running a custom hardened operating system and file system. Each of these systems has been optimised for security and performance. Because Google controls the entire hardware stack, we are able to respond quickly to any threats or weaknesses that may emerge.
Google encrypts Gmail (including attachments) and Drive data while on the move. This ensures that your messages are safe not only when they move between you and Google's servers, but also as they move between Google's data centres.
How does Google ensure that its tools are reliable?More about reliability
Our proven infrastructure handles more than 100 billion search queries each month and scales services such as Gmail to hundreds of millions of users with 99.978% availability and no scheduled downtime. Google invests heavily in securing its infrastructure with many hundreds of engineers dedicated to security and privacy distributed across all of Google, including many who are recognised industry authorities.
Which third parties have reviewed Google’s security practices?More about compliance
We connect with independent auditors to review our data protection practices. Ernst & Young, an independent auditor, has verified that our practices and contractual commitments for G Suite comply with ISO/IEC 27018:2014. G Suite and our data centres are also SSAE 16/ISAE 3402 Type II SOC 2-audited and have achieved ISO 27001 certification.
See our security audit certifications
How do I know that other customers sharing the same servers can't access my data?
Your data is logically protected as if it were on its own server. Unauthorised parties cannot access your data. Other customers cannot access your data, and you can’t access theirs. In fact, all user accounts are protected by this secure architecture that ensures that one user cannot see another user's data. This is similar to how customer data is segmented in other shared infrastructures, such as online banking applications.
How do you know that we're keeping our word?More about transparency
We make contractual commitments in our G Suite agreement and commit to comply with privacy and security standards here. And whether it’s real-time dashboards to verify system performance, our ongoing auditing of our processes or sharing the location of our data centres, we’re committed to providing all of our users with utmost transparency. It’s your data, and we want you to know what happens with it so that you can always make informed choices.
UK Department of Education Cloud Services Checklist?Read the checklist
The Cloud Services Checklist covers important legal requirements including data processing, data confidentiality and integrity, service availability and much more to help ensure that schools are fully aware of their legal obligations.
Has Google signed the US Student Privacy Pledge?Read the Student Privacy Pledge
Yes. In order to reaffirm the commitments we've made to schools, Google has signed the US Student Privacy Pledge. This pledge, introduced by the US Future of Privacy Forum (FPF) and The Software & Information Industry Association (SIIA), is intended to reflect our commitment to safeguard student personal information in our services designed for use in schools.
Does Google encrypt my data?
Yes. Data is encrypted at several levels. Google forces HTTPS (Hypertext Transfer Protocol Secure) for all transmissions between users and G Suite services and uses Perfect Forward Secrecy (PFS) for all its services. Google also encrypts message transmissions with other mail servers using 256-bit Transport Layer Security (TLS) and utilises 2048 RSA encryption keys for the validation and key exchange phases. This protects message communications when users send and receive emails with external parties also using TLS.
How do Google services collect and use information with G Suite for Education accounts?Read our G Suite Privacy Notice
The G Suite for Education Privacy Notice can help schools, students and parents understand what information Google services collect when used with G Suite for Education accounts, and what they do with that information.
What kind of scanning or indexing of user data is done on G Suite for Education accounts?Read our G Suite Privacy Notice
G Suite services don't collect or use information in those services for advertising purposes or to create ads profiles.
Gmail for consumers and G Suite users run on the same infrastructure, which helps us deliver high performance, reliability and security to all of our users. However, G Suite is a separate offering that provides additional security, administrative and archiving controls for education, work and government customers.
Like many email providers, we carry out scanning in Gmail to keep our customers secure and to improve their product experience. In Gmail for G Suite, this includes virus and spam protection, spell checking, relevant search results and features such as Priority Inbox and auto-detection of calendar events. Scanning to provide product features is carried out on all incoming emails and is 100% automated. We do NOT scan G Suite emails for advertising purposes.
Can G Suite for Education be used in compliance with the US Family Educational Rights and Privacy Act (FERPA)?
What options does G Suite for Education offer for complying with European privacy law (GDPR)?See opt-in instructions
Schools can opt in to our data processing amendment and model contract clauses. Model contract clauses were created specifically by the European Commission to permit the transfer of personal data from Europe.
If you have not already done so, we’d like to remind our G Suite customers to consider opting in to the data processing amendment and model contract clauses.
More about model contract clauses
Can G Suite for Education be used in compliance with the US Children’s Online Privacy Protection Act of 1998 (COPPA)?Read COPPA
Yes. We contractually require that schools using G Suite get the parental consent required by the US COPPA. Our services can be used in compliance with the US COPPA as long as a school has parental consent.
Read our help centre article "Getting consent for G Suite"
Who uses Chromebooks for Education?
Millions of students use Chromebooks for learning. Privacy and security features helped make Chromebooks the top-selling device to US K-12 schools for the past two years. Administrators can manage settings to give students as much or as little access as the school desires.
Although Chromebooks are not a core service, we ensure that they comply with the US Student Privacy Pledge so that schools can use these in compliance with the US COPPA and FERPA. Specifically, we ensure that no data entered into a Chromebook is used to target advertisements to students. Learn more below.
Are Chromebooks secure for my students?More about Chromebook security
Yes. Chromebooks are designed with multiple layers of security to keep them safe from viruses and malware without any additional security software. A full 10% of boot time is dedicated to re-verifying that the device has not been tampered with, so every time you power on a Chromebook, your security is checked. And because they can be managed from the web, Chromebooks make it easy for school administrators to configure policies and settings, such as enabling safe browsing or blocking malicious sites.
More about Chromebook privacy
Read the Chrome Privacy Whitepaper
Are Chromebooks compatible with online testing?Configure Chromebooks for testing
Chromebooks are a secure platform for administering student assessments, and when set up properly, these devices meet US K-12 education testing standards. With Chromebooks, you can disable students’ access to browse the web during an exam in addition to disabling external storage, screenshots and the ability to print. Both the US PARCC (see TestNav) and the Smarter Balanced Assessment consortia have verified that Chromebooks meet hardware and operating system requirements for online students.
How is data used and protected for students on Chromebooks for Education?Learn more about Chrome Sync
Chrome Sync enables Google Account holders to log in to any Chromebook or Chrome browser and find all their apps, extensions, bookmarks and frequently visited web pages. For students, this means that they can get to work straight away. That's one of the reasons Chromebooks have become so popular in classrooms, especially for schools that can't afford a device for every child. With Chromebooks and Chrome Sync, students can have a personalised experience on any device that they share with their classmates.
Personally identifiable Chrome Sync data in G Suite accounts is only used to power features in Chrome for that person; for example, allowing students to access their own browsing data and settings, securely, across devices. In addition, our systems compile data aggregated from millions of users of Chrome Sync and, after completely removing information about individual users, we use this data to holistically improve the services that we provide. For example, if data shows that millions of people are visiting a web page that is broken, that site would be moved lower in the search results. This is not connected to any specific person nor is it used to analyse student behaviours. If they choose to, administrators can disable Chrome Sync and users can choose what information to sync. G Suite users’ Chrome Sync data is not used to target ads to individual students.
Learn how to manage Chrome devices
See how to encrypt your synced data
How can families keep their kids safe online?Visit the Google family safety centre
Along with this page, which provides detail on the services we offer to schools, you can find guidance for keeping your children safe online outside of school. We worked with many partners to create the Google Family Safety Centre.
Where can I get more details?
Schools can control whether students or teachers can use additional Google consumer services with their G Suite accounts. We are committed to ensuring that K-12 student personal information is not used to target ads in these services, and in some cases we show no ads at all.
We allow schools to decide whether to turn these services on or off for certain groups of teachers and students. Every organisation and community is different and so we give schools the power to configure tools as they wish to meet the unique needs of students and educators.