Quick answer: Yes, provided staff use a managed Google Workspace account with Gemini enabled and the work is covered by your organisation’s controls. Google says that, for Gemini in Google Workspace, customer data is not used to train its generative AI models without the customer’s permission or instruction. However, this does not bypass UK GDPR obligations for human review and data minimisation.

Many UK organisations are reviewing whether staff can safely input client records or meeting details into AI tools. The decision requires understanding both Google's data privacy boundaries and your own obligations under the UK General Data Protection Regulation.

AHAI Recommendation

Do not put client data into a personal Gemini account or an unapproved AI tool. Start with a low-risk, non-sensitive workflow in your managed Google Workspace environment, then review it before wider use.

The short answer

Staff can use Gemini with client information where the information is already held in your managed Google Workspace, the user already has permission to access it, and the task has been approved. Gemini in Workspace is designed to respect existing Google Workspace permissions. A user should not be able to use it to retrieve content they cannot already access. Review Drive sharing and Shared Drive membership before enabling wider use.

However, "Google does not train on our data" is only one part of the decision. You still need a lawful basis, appropriate processor arrangements, clear staff instructions, access controls, retention decisions and a process for checking AI-generated output. This aligns with the ICO Consultation on Generative AI and general ICO data protection guidelines.

What Google says

Google states that prompts, Workspace content and generated responses are customer data under the Cloud Data Processing Addendum. It says this customer data processed through Gemini in Google Workspace is not used to train or fine-tune Google’s generative AI models without the customer’s prior permission or instruction, which is verified in Google Workspace Privacy and Security terms and the overarching Generative AI in Google Workspace Privacy Hub.

Gemini can use Workspace content to answer a prompt. That is the feature working as intended. It may retrieve relevant information from Gmail, Drive, Calendar or Chat that the individual already has permission to see, so good file-sharing discipline still matters under standard Workspace data protection defaults.

What staff can do

Suitable first uses usually involve client information that is not special category data, has a clear business purpose and can be checked by the person using it.

Lower-risk starting point Check before approving
Summarising a client meeting note held in a restricted Drive folder The attendee list, file permissions and output
Turning a client email thread into actions and deadlines Whether sensitive details should be removed first
Drafting a project update from approved source documents Every fact, commitment and deadline
Rewriting your own proposal for tone and structure That no confidential content is sent outside approved Workspace services

This is an AHAI recommendation, not blanket compliance approval. Your Data Protection Officer, client contract terms and internal policy determine what is appropriate for your organisation.

What needs extra care

Do not treat Gemini as a safe place for all data simply because it is connected to Workspace. Pause and obtain an appropriate review before using it with special category personal data, legal advice, commercially sensitive negotiations, security information, HR records, financial data or information restricted by a client contract.

Also check whether a user is working inside the managed Workspace Gemini service. Third-party apps connected to Gemini are governed by different terms, so do not assume they receive the same protections as defined in the terms for the specific Workspace or third-party service.

UK GDPR checks

UK GDPR requires more than choosing a reputable supplier. Before approving a workflow involving client personal data, document:

1

Purpose

What exact task is Gemini helping with?

2

Data minimisation

What is the smallest amount of data needed?

3

Lawful basis

Why is processing this personal data necessary?

4

Processor review

Does your Google Workspace agreement and data-processing documentation cover the intended use?

5

Access controls

Which staff can use the workflow and which files can Gemini reach?

6

Human review

Who checks the output before it is sent, acted on or added to a client record?

7

Retention

How long are prompts and conversations retained, and does this align with your policy?

The ICO provides AI and data-protection guidance plus a risk toolkit for organisations assessing effects on people’s rights and freedoms, which can be evaluated using the ICO AI & Data Protection Risk Toolkit.

Admin controls to check

1. Gemini app access

In the Admin console, check whether the Gemini app is enabled for the right organisational units or groups. Turning this off restricts the standalone Gemini experience, but it does not turn off Gemini features embedded in Gmail, Docs or Drive, as outlined in the Google Workspace Admin Console guide for Generative AI.

2. Gemini in Workspace

Go to:

Admin console > Generative AI > Gemini for Workspace > Feature access

Google allows settings by organisational unit or configuration group. Where both apply, check the effective setting for the user group before rollout.

AHAI Recommendation

Start with a small group if you have not yet tested the workflow. Do not enable the whole organisation simply because the setting is available.

3. Workspace Intelligence sources

If available in your edition, review the data sources that Gemini can actively search for context, including Gmail, Drive, Calendar and Chat. You can disable a source, but this does not prevent a user from explicitly asking Gemini about a file they have access to or from using Gemini within an open file, under standard Workspace data boundaries.

Treat this as a relevance control, not a complete data boundary.

4. Drive permissions and classification

Gemini respects existing file access. Review Drive sharing, Shared Drive membership and any folders containing sensitive client material before enabling a wider rollout. Google says information-rights controls and client-side encryption can restrict Gemini’s ability to retrieve protected content, in line with Google Workspace security details.

Where your edition supports it, use classification labels and data loss prevention rules to identify sensitive content and limit what can be copied, downloaded or used in generated output.

5. Conversation retention and audit

Review the conversation-history settings available in your edition before approving client-data use. Current user options include deletion after 3, 18 or 36 months, or manual deletion only. Google may change the available controls and retention options. Confirm how Gemini activity can be audited in your existing investigation and reporting process.

A practical policy rule

Use a simple three-level rule in your acceptable-use policy:

Data type Default position
Public or non-confidential information Usually suitable for approved Gemini use, with human checking
Routine client information in managed Workspace Allowed only for approved tasks, with access checks and human review
Special category, highly confidential, legal, HR, security or contract-restricted information Do not use until the DPO, information-security lead or contract owner has approved the specific use case

Before you enable it

Confirm staff use managed Workspace accounts, not personal Gemini accounts.
Choose one routine, low-risk task.
Check Drive permissions and remove unnecessary access.
Set the relevant Gemini access controls for a pilot group.
Write the approved data boundary into your AI policy.
Test several real examples and check every output manually.
Review the result with your DPO or data-protection lead before wider rollout.

Gemini can help staff reduce drafting and sorting work. It does not transfer accountability for confidential client data, contractual commitments or factual accuracy. The person using the output, and the organisation deploying the workflow, remain responsible for the decision.

Need to set the boundary first?

Download the free AI Acceptable Use Policy Template to document approved tools, prohibited data, human review and escalation. This template is a starting point. Review it against your client contracts, data-protection arrangements and Google Workspace configuration before adoption.

Free AI Policy Template