Google ToS interpretation

alexgrutza
Contributor III

Just curious how others would interpret (USA) the last sentence of this screenshot. My interpretation is that no HIPPA related data will be housed in any Google Services without signing a BAA (with Google?). 

alexgrutza_0-1690375829458.png

 

--
CISSP | LinkedIn | @Phyxiis
3 REPLIES 3

Kim_Nilsson
Admin Moderator

Nahhh, that's not what it says.

It says that you are not allowed to store such data.

Google will handle (store, read and modify) any data you give them.

It's ALWAYS your responsibility to not give them data they aren't allowed to handle.

--
https://wheretofind.me/@NoSubstitute

Yeah perhaps I didn't use the right words, I'd agree with your wording.

It also generally doesn't apply to Higher Education because Higher Ed isn't considered a protected/covered entity even if it has or maintains HIPPA related data. 

--
CISSP | LinkedIn | @Phyxiis

Yeah, and AFAIK the HIPPA thing is still always something that you have to do.

I am fairly sure Google doesn't suddenly change things, or make services work differently.

It's just a new agreement where you verify that you understand how you must work, and that you will maybe have to turn some services off and work differently, and Google suggests that should mean that you are in compliance.

--
https://wheretofind.me/@NoSubstitute