Google Cloud Platform Services with Data Residency

General

The following Services may be configured for data location pursuant to the 'Data Location' Section of the General Terms at https://cloud.google.com/terms/service-terms:

  • Agent Assist
  • Agent Search on Gemini Enterprise Agent Platform (formerly Vertex AI Search)
  • AlloyDB
  • API Gateway
  • Apigee (as described here)
  • Application Integration
  • Artifact Registry
  • Assured Workloads
  • Backup and DR Service (as described here)
  • Backup for GKE
  • BigQuery
  • Certificate Authority Service
  • Cloud Bigtable
  • Cloud Build
  • Cloud Data Fusion
  • Cloud Deploy
  • Cloud External Key Manager
  • Cloud Healthcare API
  • Cloud HSM (Hardware Security Module)
  • Cloud Intrusion Detection System (Cloud IDS)
  • Cloud Interconnect
  • Cloud Key Management Service (Cloud KMS)
  • Cloud Key Management Service
  • Cloud Load Balancing - Regional Load Balancers (Application, Proxy Network)
  • Cloud Logging
  • Cloud NAT (Network Address Translation)
  • Cloud Router
  • Cloud Run
  • Cloud Run functions (formerly Cloud Run (2nd Gen))
  • Cloud SQL
  • Cloud Storage
  • Cloud VPN
  • Cloud Workstations
  • Compute Engine
  • Contact Center AI Insights
  • Conversational Agents (formerly as Vertex AI Agents)
  • Dataflow
  • Dataform
  • Dataproc Metastore
  • Eventarc
  • Filestore
  • Firestore
  • Gemini Enterprise (except when certain features are enabled; as described here)
  • Gemini for Google Cloud (Gemini Code Assist only)
  • Generative AI on Gemini Enterprise Agent Platform (formerly Generative AI on Vertex AI) (except for Grounding with Google Search, Grounding with Google Maps, and RAG Engine)
  • Google Cloud Armor
  • Google Cloud NetApp Volumes
  • Google Kubernetes Engine (GKE Connect Agent, GKE Hub, and GKE Policy Controller only)
  • Integration Connectors
  • Looker (Google Cloud core)
  • Managed Service for Apache Airflow (formerly Cloud Composer)
  • Managed Service for Apache Spark (formerly Dataproc)
  • Memorystore for Memcached
  • Memorystore for Redis
  • Memorystore for Redis Cluster
  • Model Armor
  • Persistent Disk
  • Pub/Sub
  • Secret Manager
  • Secure Source Manager
  • Security Command Center (as described here)
  • Sensitive Data Protection (including Cloud Data Loss Prevention or DLP)
  • Spanner (including geo-partitioning, as described here)
  • Transcoder API
  • Workflows

AI/ML Data Location

The following Services may be configured for data location pursuant to the 'AI/ML Data Location' Section of the Service Terms for AI/ML Services at https://cloud.google.com/terms/service-terms:

  • Agent Assist
  • Anti Money Laundering AI (AML AI)
  • AutoML Natural Language
  • AutoML Tables
  • Cloud Natural Language API
  • Cloud Speech-to-Text
  • Cloud Text-to-Speech
  • Cloud Translation
  • Cloud Vision (OCR functionality API end point only)
  • Custom Voice
  • Dialogflow Customer Experience Edition (CX)
  • Document AI
  • Gemini Enterprise (except when certain features are enabled; see here for more details)
  • Gemini Enterprise Agent Platform (formerly Vertex AI Platform) (except Agent Platform Feature Store, Agent Runtime, Memory Bank, Sessions, Code Execution, and RAG Engine)
  • Generative AI on Gemini Enterprise Agent Platform (only for models listed in the "ML processing" section of the Generative AI on Gemini Enterprise Agent Platform documentation and excluding Grounding with Google Search, Web Grounding for Enterprise, Grounding with Google Maps, and RAG Engine)

Assured Workloads

The following Services may be configured for data location pursuant to the 'Assured Workloads' Section of the Service Terms at https://cloud.google.com/terms/service-terms:

  • AlloyDB
  • Apigee (as described here)
  • Artifact Registry
  • BigQuery
  • Bigtable
  • Certificate Authority Service
  • Cloud HSM
  • Cloud Interconnect
  • Cloud Key Management Service
  • Cloud Load Balancing - Regional Load Balancers (Application, Proxy Network)
  • Cloud Logging
  • Cloud Monitoring (also subject to the "General" Section above if used as part of Assured Workloads)
  • Cloud NAT (Network Address Translation)
  • Cloud Router
  • Cloud Run
  • Cloud SQL
  • Cloud VPN
  • Cloud Storage
  • Compute Engine
  • Dataflow
  • Filestore
  • Firestore
  • Google Cloud Armor 
  • Google Kubernetes Engine (GKE Connect Agent, GKE Hub, and GKE Policy Controller only)
  • Managed Service for Apache Airflow (formerly Cloud Composer)
  • Persistent Disk
  • Pub/Sub
  • Sensitive Data Protection (including Cloud Data Loss Prevention or DLP)

Additional Google Cloud Platform Services Supporting Data Residency (without location configuration)

Customers with data residency requirements may consider using the following Services, which do not store Customer Data at-rest or process Customer Data in use:

  • Access Approval
  • Access Context Manager
  • Access Transparency
  • Cloud DNS
  • GKE Enterprise (Identity Service)
  • Google Cloud Migration Center
  • Identity-Aware Proxy (IAP)
  • Identity and Access Management (IAM)
  • Network Connectivity Center
  • Organization Policy Service
  • Resource Manager
  • Service Directory
  • Traffic Director
  • Virtual Private Cloud
  • VPC Service Controls
Google Cloud