Is Gemini Safe for Confidential Business Data in Workspace?

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Is Gemini Safe for Confidential Business Data in Workspace?
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Is Gemini Safe for Confidential Business Data in Workspace?

Yes, with conditions. On a qualifying Google Workspace business plan, Gemini doesn't use your prompts or files to train models outside your organisation, doesn't send them for human review, and only reaches content the user can already open. The real risks sit elsewhere: staff using personal Gmail accounts, overshared Drive folders, and features with weaker certifications.

"Safe" here means Google's handling of the data. It doesn't change your own duties. A physiotherapy clinic still owes its patients confidentiality, a nursery still has obligations about children's information, and data-protection law such as the GDPR still asks whether processing is necessary and proportionate. Gemini on a business plan can fit inside those duties; it doesn't discharge them for you, and anything borderline is a question for your data-protection adviser.

Follow me on Instagram@sagnikteaches

The most common failure isn't a Google breach. It's a well-meaning person pasting a patient letter into the Gemini app on their phone while signed in to a personal account, where different rules apply. The second most common is Gemini surfacing a file that was shared too widely years ago. Both are fixable in an afternoon.

Connect on LinkedInSagnik Bhattacharya

What Google commits to on Workspace business plans

Google's generative AI privacy hub for Workspace, last updated in August 2026, covers Gemini in Gmail, Docs, Drive, Meet and the other Workspace apps, the Gemini app used with a work account, and Gemini Notebook (formerly NotebookLM). For qualifying editions, it says:

Subscribe on YouTube@codingliquids
  • No training outside your domain. Prompts, Workspace content and responses aren't used to train generative AI models without your permission, a commitment written into Google's Workspace service terms.
  • No human review. Your content isn't reviewed by people for model training outside your domain without permission.
  • Existing permissions apply. Gemini only retrieves content the user already has access to, and can't reach a file or email the user couldn't open.
  • Private between colleagues. Your prompts and Gemini's answers are visible only to you, even in shared files, and Google says session content doesn't leak across user boundaries.
  • Your protections carry over. Data loss prevention rules apply to Gemini output inserted into Gmail, Drive and Docs on supported editions, and admins get audit logs of Gemini activity.

Google also lists independent certifications for Gemini, including SOC 1/2/3, ISO/IEC 27001 and ISO/IEC 42001 (the AI management systems standard published in December 2023). Those are useful evidence when a client asks how you handle their data.

Work account or personal account: the difference that decides it

Everything above applies only when someone uses Gemini signed in to a work account on a qualifying Workspace edition. The consumer Gemini app on a personal Google account runs under different rules, and staff often don't notice which account their phone is using.

QuestionGemini with a Workspace work accountGemini with a personal account
Used to train Google's models?No, without your permissionCan be, when Keep Activity is on
Read by human reviewers?No, without your permissionSome chats may be, when Keep Activity is on
How long chats are keptSet by your admin (see below)18 months by default, or 3 or 36 months, or indefinitely; reviewed chats up to 3 years
With the history setting offNew chats kept up to 72 hoursKept 72 hours; not used for training unless you send feedback
Google's own adviceBusiness data is customer data under your agreementDon't enter confidential information you wouldn't want a reviewer to see

That last row is Google's wording for consumer users, and it settles the question for client data. Even with Keep Activity off, Google says it still uses consumer chats to respond and to protect its services, including with help from human reviewers. For anything confidential, the only acceptable route is a work account.

How the wrong account showed up in one clinic

Here's how that plays out, as an illustration. A physiotherapist wanted a plain-English version of a consultant's letter for a patient. On the clinic laptop she'd have used her work account, but she was on her phone, where the Gemini app was signed in to her personal Gmail. She pasted the whole letter, patient name and all. Nothing visible went wrong; the summary was good. The problem surfaced a month later when the practice manager ran the checks further down and found three staff members using the Gemini app on personal accounts for work. None of them had been told there was a difference.

The fix had three parts: a one-line rule ("Gemini for work only on your work account"), ten minutes per person checking which account each phone's Gemini app used, and removing the personal account from the app on work phones.

Where confidential data is actually exposed

  • Overshared Drive folders. Gemini respects permissions, but permissions are often wider than anyone intends. A folder shared with "anyone in the organisation" years ago was always readable by everyone; Gemini makes it findable with one question.
  • Feedback with context attached. When a user rates a Gemini response and leaves the boxes ticked to share the prompt and output, Google receives the prompt, the relevant document or email context and the response. Google says feedback isn't used to train the models behind Workspace's AI services, but it may keep it for up to 18 months. Tell staff to untick those boxes when the content is confidential.
  • Features with narrower certifications. Google's own FAQ says Gemini Notebook and Gemini in Chrome don't yet carry the ISO and SOC certifications that Gemini in Workspace apps and the Gemini app do. If a client contract requires certified processing, keep that client's documents out of both. Gemini Notebook for small business teams covers what it's good for otherwise.
  • Long retention. Conversation history in Gemini in Workspace can be kept from 90 days to indefinitely, depending on admin settings. Keeping everything forever means every pasted patient detail stays searchable by that user for as long as the account exists.
  • Gems shared too widely. A Gem (a saved Gemini assistant with its own instructions and files, becoming a skill from November 2026 as Google replaces Gems with skills) shows its instructions and uploaded files to the people it's shared with. A Gem built on a folder of client contracts and then shared with the whole team hands those contracts to everyone it reaches, so keep client files out of widely shared Gems, and check how sharing works for the skill yours becomes.
  • Outputs that leave Workspace. A summary exported to a personal device or emailed to a personal address is outside every Workspace protection, whatever produced it.

Controls an admin can set in an afternoon

  1. Confirm your edition. The commitments apply to qualifying Workspace editions. Business Starter includes Gemini in Gmail and the Gemini app; Business Standard (about $14 a user a month on an annual plan) and above add Gemini across Docs, Sheets, Drive, Meet and more. What Gemini includes on each Workspace plan has the full list.
  2. Decide who gets which Gemini features. The Gemini app is on by default and admins can switch it off. On supported editions, admins can also turn Gemini features and the side panel on or off in Gmail, Drive, Docs, Meet and Chat.
  3. Set conversation retention. For the Gemini app, admins choose automatic deletion after 3, 18 or 36 months (18 is the default), or turn conversation history off so new chats are kept only up to 72 hours. For Gemini in Workspace apps, admins can set retention periods and let users delete conversations.
  4. Choose what Gemini searches in the background. Admins can stop Gemini actively searching Gmail, Drive, Calendar or Chat for context. Users can still point it at a file they link or have open.
  5. Lock down the most sensitive files. Google says Information Rights Management restrictions (no download, copy or print) stop Gemini retrieving those files for restricted users, and client-side encryption, on editions that offer it, puts content beyond Gemini's reach entirely.
  6. Check the audit logs occasionally. Gemini activity appears in Workspace audit logs, which is useful after an incident and as a deterrent.

Drawing the line in a physiotherapy clinic

The clinic in this example has nine staff (five physiotherapists, two receptionists, a practice manager and a sports therapist) on Business Standard. Its clinical notes live in a practice-management system outside Google, and its Drive holds policies, rotas, marketing, supplier invoices and a folder of referral letters. The practice manager worked through three questions:

DataGemini on work accounts?Why
Policies, rotas, marketing, supplier emailsYesBusiness-confidential at most; covered by the commitments
Patient letters and referral summariesYes, minimum necessaryAllowed after checking with the clinic's data-protection adviser; names removed where the task doesn't need them
Clinical notes in the practice systemNo copying into GeminiThe system is the record; copying creates uncontrolled duplicates
Staff HR and payroll filesRestricted with IRMOnly the manager has access; Gemini can't retrieve them for anyone else
Anything on personal accountsNeverConsumer terms, possible human review

Set-up took about three hours: an hour reviewing Drive sharing (they found the referral-letters folder shared with the whole organisation, including two freelance therapists who didn't need it), an hour on admin settings (Gemini app retention set to 3 months, Drive left on as a source), and an hour writing and explaining the rules below. The cost was nothing beyond the Workspace plan they already had.

A nursery and a tutoring agency, briefly

A nursery drew the line more tightly, because the data is about children. Its rule: Gemini on work accounts for newsletters, policies and planning, never for anything that names a child, including learning journal entries and incident reports. Staff draft general wording with Gemini and add the child's details themselves afterwards. The patient-data confidentiality checklist for small practices uses the same "minimum necessary" logic and adapts well to children's data.

A tutoring agency drew it more loosely: tutors use Gemini on work accounts to draft progress reports that include pupils' first names and scores, because parents agreed to that use when they signed up and the agency's adviser was comfortable with it. What the agency did insist on was a Drive clean-up first, because two years of lesson notes sat in a folder any tutor could open.

Minimum-necessary prompts, before and after

Most tasks need far less personal detail than people paste. Here's the physiotherapist's letter task done properly. Her first attempt pasted the consultant's letter in full, including the patient's name, date of birth, address and hospital number:

BEFORE
Rewrite this letter in plain English for the patient:
[full letter: name, date of birth, address, hospital number,
diagnosis, scan findings, recommended exercises]

None of the identifiers helped Gemini explain a scan result. The rewritten prompt kept only the clinical content:

AFTER
Rewrite the clinical findings below in plain English for a
patient with no medical background. Keep it under 200 words,
use short sentences, and end with "Your physiotherapist will
go through this with you at your next appointment."
Findings: [scan findings and recommended exercises only]

The illustrative output was a clear 170-word explanation of the findings and the three exercises. One thing needed fixing: it described one exercise as "safe to do daily", which the consultant hadn't said. The physiotherapist deleted the phrase and added a line to the prompt for next time: "don't add advice that isn't in the findings." She then pasted the plain-English text into the clinic's own letter template, where the patient's name went back in. Same result, a fraction of the exposure.

A rule sheet staff can follow

Rules only work if they fit on one screen. The clinic's version, as a template to adapt:

GEMINI AT [CLINIC NAME]: RULES FOR CONFIDENTIAL DATA

1. Use Gemini for work only while signed in to your work account.
   Check the account picture in the corner before you paste.
2. Never use the Gemini app on a personal account for anything
   about a patient, colleague or supplier.
3. Patient letters: include only what the task needs. Remove
   names and dates of birth unless the output must contain them.
4. Clinical notes stay in [practice system]. Don't copy them into
   Gemini, Docs or email to work on them.
5. When you rate a Gemini answer, untick "share prompt and
   output" if the content is confidential.
6. Don't use Gemini Notebook or Gemini in Chrome for patient
   material.
7. Found something in Gemini you shouldn't be able to see? Tell
   [practice manager] the same day; it means a sharing setting
   is wrong.

Rule 7 matters more than it looks. Gemini is an excellent detector of oversharing, and staff who report surprises help fix permissions faster than any audit.

If client data has already gone into a personal account

It happens, and the response matters more than the slip. The practical steps, in order:

  1. Delete the conversation from the personal account's Gemini history straight away, and ask the person to check whether Keep Activity was on at the time.
  2. Write down what happened: which data, roughly how many people it concerned, when, and which account. A short factual note is enough.
  3. Ask your data-protection adviser whether it needs reporting or telling the people concerned. Deleting the chat reduces the risk, but Google's consumer privacy hub says chats already selected for human review are kept for up to three years even after you delete your activity, so don't assume deletion erases everything.
  4. Fix the cause, not just the person. In the clinic's case the cause was a phone with the wrong account in the Gemini app and a rule nobody had written down. Both took minutes to fix once found.

Staff who report their own slips quickly are the ones you want, so make it clear that reporting is expected and not punished. A culture where people hide mistakes is a bigger risk than any setting.

Testing the set-up in twenty minutes

Sign in as an ordinary staff member (or ask one to sit with you) and run three checks. First, confirm the Gemini app on every work phone shows the work account. Second, ask Gemini the questions an overshared Drive would answer:

Find any documents that mention salaries, disciplinary action,
or staff sickness, and summarise what they say.

In the clinic's first test, the illustrative answer listed two files: a salary review spreadsheet from three years earlier and a disciplinary letter template with a former employee's name still in it. Both sat in a folder shared with the whole organisation. After moving them and tightening the folder's sharing, the same question returned "I couldn't find any documents matching that request," which is the answer you want for an ordinary user.

Third, check your retention and feedback settings match the rule sheet, and put a reminder in the calendar to repeat all three checks every six months and whenever someone joins or leaves. For more on the wider question of keeping customer data private across tools, see keeping customer data private when your team uses AI, and before adding any new AI tool, what to check in its privacy policy and terms.

Gemini and confidential data: follow-up questions

Can Google employees read what we type into Gemini at work?

Google's Workspace privacy hub says content from qualifying business editions isn't human reviewed or used for model training outside your domain without permission. The exception is feedback: if a user sends a thumbs-down and leaves the boxes ticked to share the prompt and output, that material, including relevant document context, goes to Google as feedback and may be kept for up to 18 months.

Does Gemini make overshared files visible to more people?

It doesn't grant new access, but it makes existing access easier to use. Gemini only retrieves content the user can already open, so a payroll sheet shared with everyone in the organisation was always readable by everyone; Gemini just makes it findable with one question. Fix sharing before rolling Gemini out widely.

Is the free personal Gemini app safe for client data?

Treat it as unsuitable. On personal accounts, Google's own privacy hub asks you not to enter confidential information you wouldn't want a reviewer to see, because with Keep Activity on, some chats may be reviewed by people and used to improve Google's services. Business data belongs in Gemini signed in with a work account on a qualifying Workspace plan.

How long does Google keep Gemini conversations from work accounts?

It depends on the product and your admin's settings. Gemini in Workspace apps keeps prompts and responses for 90 days up to indefinitely, as your admin decides. The Gemini app keeps them for up to 36 months, with 18 months the default, and just 72 hours if conversation history is off. Gemini Notebook doesn't retain prompts after the session ends.

Further reads

Sources: Google Workspace Help 'Generative AI in Google Workspace Privacy Hub' (last updated 14 Aug 2026); Gemini Apps Help 'Gemini Apps Privacy Hub' (checked September 2026).

Want Gemini set up safely for confidential work?

On a 1:1 call we'll check your Workspace edition and sharing settings, agree what staff may put into Gemini, and set the admin controls before it reaches client or patient data.

Book a 1:1 call with me