Prototype — static build (Lane C). Content mirrored from the Zoho CMS staging site.
In force

Google agreement stack

Latest changes

Last check 2026-10-11 — 15 instruments verified live across both stacks, 3 changed. Each change below carries an impact score; the schema is at the foot of this section.

  • 2026-10-11
    Google Terms of Service — Google Terms of Service now show an effective date of 30 July 2026 (registry recorded no date); service-specific/Generative-AI Prohibited Use Policy cross-references present. source
    Minor · 7/15privacy 1 · user-adjacent data 1 · stack 1 · reach 2 · notice 2

    Privacy / user data: Framework terms only. The Google Privacy Policy and the Cloud DPA sit elsewhere in the stack and were unchanged in this check.

    Effect on the stack: Sets the general framework; service-specific terms and the DPA take precedence for their subject matter, so the practical effect on data handling is limited.

Coverage: 13 of 13 instruments have a monitored public source.

At a glance

Vendor
Google
Layer model
Framework (Master Agreement / ToS) → Product/Cloud terms (+ service-specific terms) → Data (DPA) → Policies incorporated by reference (Privacy Policy, AUP, subprocessors) → Service SLAs
Instruments tracked
13 registry rows (GO-01–GO-13)
Primary change signal
Cloud / Workspace terms update history
Status
In-force (form); underlying documents not opened here

How the stack is built

Each layer is incorporated by reference into the one above it; service-specific and data-protection terms take precedence for their own subject matter.

Framework
Google Cloud Terms of Service (consolidated)Google Terms of Service
Core framework; incorporates the URL terms below by reference and updates online.
Product / service terms
Workspace Service Specific Terms (s.13 agentic AI)Cloud Identity terms
Override the general terms for their subject matter. New features are governed on release.
Data
Google Cloud DPAGoogle Privacy Policy
Personal-data processing. The DPA takes precedence for its subject matter.
Policies
Cloud Acceptable Use PolicySubprocessor list
Prohibited use and processing locations. New subprocessors change routing and jurisdiction.
Service levels
Workspace SLAGCP SLA
Uptime commitments and service credits.

Instruments

Each instrument links to its live document where one exists.

IDInstrumentLayerHow it is read inChange mechanismStatus
GO-01Google Cloud Platform Terms of ServiceCloudGoverns use of Cloud services; incorporated.Online updatein-force
GO-02Google Cloud Master AgreementMasterFramework for Cloud; incorporates URL terms by reference; subprocessor rules at s 11.4.Online update / noticesuperseded
GO-03Google Cloud Data Processing AddendumData addendumGoverns personal-data processing; incorporated.Versionedin-force (form)
GO-04Google Terms of ServiceFrameworkGeneral terms; incorporated.Online updatein-force
GO-05Google Privacy PolicyPrivacy noticeIncorporated; applies to data practices.Online updatein-force
GO-06Google Workspace Terms of ServiceWorkspaceGoverns Workspace; incorporates service-specific terms.Online updatein-force
GO-07Google Cloud Acceptable Use PolicyAUPIncorporated; governs prohibited use.Online updatein-force
GO-08Google Workspace Service Level AgreementSLAUptime commitments.Updatedin-force
GO-09Google subprocessor listSubprocessorsNew processors change routing / jurisdiction; s 11.4 gives 30-day notice and the right to terminate to object.Updated on changein-force
GO-10Cloud Identity Terms of ServiceService-specific§1.4(c)(ii) new-feature carve-outs.Updatedin-force (form)
GO-11Google Cloud Platform / SecOps ToS (2025) §4.3Service-specific"Generative AI Safety and Abuse" carve-out permits prompt logging on abuse detection.Updatedin-force
GO-12Google Workspace Service Specific Terms §13Service-specificOverrides general terms for Workspace; §13 covers agentic AI (customer responsible).Updatedin-force (form)
GO-13YouTube / Google AnalyticsSeparate services"Separately governed additional services" — no document or URL cited by the source material.—unknown

Incorporation and precedence

  • The stack is driven by core terms plus "URL terms" incorporated by reference and updated online.
  • New features are governed immediately on release.
  • Service-specific terms (Workspace §13, Cloud Identity §1.4(c)(ii)) and the DPA take precedence for their subject matter.
  • The subprocessor clause (s 11.4) gives only 30-day notice plus termination to object — impractical for dependent institutions.

What the monthly check diffs

  • Version / effective date (DPA versions; master-agreement dates).
  • Content hash / change-log entry (Google terms update history).
  • New-feature carve-out text — does newly released AI functionality sit inside or outside protections?
  • Data-use / retention statements (for example, Workspace Privacy Hub feedback retention).
  • Subprocessor lists (additions and removals; processing locations).
  • Precedence / order-of-precedence clauses — any reordering changes how documents are read.
  • New instruments appearing in the stack, or instruments renamed or withdrawn.
  • Data-residency commitments.

Watch list: Google Cloud / Workspace terms. Workspace Privacy Hub feedback retention. Subprocessor list; new AI / agentic terms.

Changelog

The full running log for this stack, newest first.

  • 2026-10-11
    Google Terms of Service — Google Terms of Service now show an effective date of 30 July 2026 (registry recorded no date); service-specific/Generative-AI Prohibited Use Policy cross-references present. sourceMinor · 7/15

Sources and further reading

  • Google Cloud Terms: https://cloud.google.com/terms
  • Google Workspace terms: https://workspace.google.com/terms/
  • Google Workspace Privacy Hub: https://workspace.google.com/privacy/
  • Google subprocessors: https://cloud.google.com/terms/subprocessors

Change-impact schema

Every change found by the check is scored on five dimensions (0-3 each, total 0-15) and placed in one of three bands. The point is to separate housekeeping from changes that belong in a review.

  1. Privacy / data-protection effect — Does it change what personal data is processed, why, where, or for how long?
  2. User-adjacent data — Does it touch data generated by or about end users — prompts, content, telemetry, feedback, identifiers?
  3. Stack effect — Does it change how the stack is read — incorporation, precedence, scope, or a shared definition?
  4. Reach — How many services, surfaces or customers are affected?
  5. Notice and reversibility — Was there notice? Can a customer object, exit, or negotiate — or is it unilateral?
  • 0-3Incidental — Housekeeping. Nothing substantive changes; safe to skip in a review.
  • 4-8Minor — Real but bounded. A defined subset, a clarification, or a date/label change without a change to the underlying obligation.
  • 9-15Major — Substantive. Changes obligations, data flows, or how the stack reads — belongs in a review or a client briefing.

Compiled from public vendor documents and the tracked change log. Not legal advice — verify against the primary source before relying on it.

← All enterprise agreement stacks