Gemini Notebook
Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.
Pricing / Contract Route
Official pricing and bundling vary across consumer, Workspace and Cloud routes
Enterprise Features
Workspace CDPA and admin enablement; separate Gemini Notebook Enterprise with project, IAM and regional controls
Last Updated
September 10, 2026
Version: 10 September 2026 - prepared by WAIMAKERS B.V.
Purpose and context
Google renamed NotebookLM to Gemini Notebook. This page keeps the existing URL for continuity. Consumer, qualifying Workspace and Gemini Notebook Enterprise are distinct routes.
Gemini Notebook can support a GDPR-compliant deployment when used through a qualifying commercial route and when the organisation assesses the actual storage, sharing and feature settings. No route is automatically "GDPR compliant".
🏢 Company and service overview
Gemini Notebook creates notebooks from uploaded or connected sources and can generate answers and other artifacts from them. Imported sources are copied into the notebook. Deleting the original Drive file does not by itself prove that the notebook copy was deleted.
📊 Service routes comparison
| Feature | Personal Google account | Qualifying Workspace / Education | Gemini Notebook Enterprise |
|---|---|---|---|
| Contract | ⚠️ Consumer terms | ✅ Workspace agreement and CDPA | ✅ Separate Google Cloud service and contract; confirm the applicable DPA and order form |
| Training | ⚠️ Files and notebook chats are not used directly to train foundational generative-AI models unless feedback is provided | ✅ Uploads, queries and responses are not human-reviewed or used to train generative-AI models | ⚠️ Confirm the current Cloud and order-form commitments for the exact service |
| Retention | Notebooks and copied sources persist until deletion; connected Gemini chats follow separate Gemini Apps activity settings | Prompts and responses are not retained after the session. Uploaded files and user-created notebooks follow CDPA section 6 and remain user-deletable/exportable | Source data stays in the selected project and is deleted with the notebook or project, subject to contract and legal exceptions |
| EU data residency | ❌ No selectable organisational region | ❌ Workspace data-region settings do not apply to Gemini Notebook data | ✅ EU and US multi-regions are available, with feature and location limitations |
| Admin controls | ❌ No organisational control plane | ⚠️ Group/organisational-unit enablement and Context-Aware Access. Workspace file-sharing and DLP controls do not apply | ✅ Project and region-specific access, IAM, VPC Service Controls and CMEK options, subject to feature support |
| Practical assessment | Avoid sensitive organisational personal data unless consumer terms, feedback and sharing are acceptable | Viable commercial route if missing Workspace region and DLP coverage fits the use case | Stronger route when EU location or Cloud governance is required; verify the regional feature matrix |
Public prices, plan names and bundles change frequently. Verify Google's live pricing and order form before purchase. Price does not determine whether the CDPA or a regional commitment applies.
✅ GDPR assessment
Strengths
- ✅ Qualifying Workspace uploads, queries and responses are covered by the Workspace agreement and CDPA.
- ✅ Google says those Workspace data are not human-reviewed or used to train generative-AI models.
- ✅ Workspace prompts and responses are not retained after the session.
- ✅ Context-Aware Access can support controlled Workspace access.
- ✅ Enterprise can store source data in a selected EU or US project and provides project-level governance options.
Important limits
- ⚠️ Uploaded files and user-created notebooks persist separately from session prompts and responses.
- ⚠️ Workspace file-sharing and data-region settings do not apply to Gemini Notebook data.
- ⚠️ Workspace DLP is not integrated.
- ⚠️ Consumer feedback creates a training and review exception.
- ⚠️ Imported sources are static copies and require their own deletion test.
🌍 Infrastructure and data residency
Qualifying Workspace route
The Workspace privacy hub says that data-region settings do not cover Gemini Notebook. An EU Workspace tenant must not be treated as proof of EU residency for this product.
Gemini Notebook Enterprise
The separate Cloud product stores source data in the selected US or EU project. Notebooks cannot be shared publicly, and project deletion removes the project data, subject to contract and legal exceptions. Google's location documentation lists feature-specific limitations, so every required model and feature must be checked against the selected region.
📝 Training, retention and deletion
- ✅ Qualifying Workspace uploads, queries and responses are not used to train generative-AI models.
- ✅ Workspace prompts and responses are not retained after the session.
- ⚠️ Workspace source files and notebooks follow the CDPA lifecycle and remain until the user deletes them.
- ⚠️ Personal-account files and notebook chats are not used directly for foundational-model training unless feedback is submitted.
- ⚠️ Deleting a source in Drive does not automatically prove deletion of the notebook copy.
- ⚠️ Deleting a notebook can return linked Gemini conversations to the Gemini chat list; deleting Gemini activity does not delete Gemini Notebook data.
🔒 Security and certification limits
Do not inherit certifications from "Google Cloud" or "Google Workspace" without checking product scope. Google's Workspace privacy hub states that Gemini Notebook does not support ISO, SOC or FedRAMP compliance and is not covered by Google's HIPAA Business Associate Agreement. This statement concerns the Workspace product. Assess Gemini Notebook Enterprise against its own Google Cloud compliance documentation and contract.
EU business rollout checklist
- Record whether every user is on a personal account, qualifying Workspace edition or Enterprise project.
- Confirm that the CDPA or Google Cloud DPA applies to the exact service.
- For Workspace, document that data-region, file-sharing and DLP settings do not cover Gemini Notebook data.
- For Enterprise, capture the project location and verify each required feature against current location limits.
- Review collaborators, sharing and every copied source.
- Test deletion of notebooks, imported sources, generated artifacts and connected Gemini conversations.
- Limit feedback submission when prompts or sources contain personal or confidential data.
- Complete the lawful-basis, transparency, DPIA and transfer assessment required by the use case.
📚 Key documentation and references
- Generative AI in Google Workspace Privacy Hub
- Notebooks in Gemini Apps
- Gemini Notebook Enterprise overview
- Gemini Enterprise and Gemini Notebook Enterprise locations
- Google Cloud Data Processing Addendum
📋 Verdict summary
| Factor | Status | Impact |
|---|---|---|
| Commercial DPA coverage | ✅ Available for qualifying Workspace and Enterprise routes | High |
| No-training commitment | ✅ Verified for qualifying Workspace; consumer feedback is an exception | High |
| EU data residency | ⚠️ Available for Enterprise, not inherited from Workspace data-region settings | High |
| Workspace certification scope | ❌ ISO, SOC, FedRAMP and HIPAA BAA support are not provided for Gemini Notebook in Workspace | High |
| Deletion control | ⚠️ Notebook, source-copy and connected Gemini lifecycles must be tested separately | High |
Disclaimer
This overview is an informational procurement aid, not legal advice or certification of a deployment. Verify the current edition, contract, region and feature settings before production use. The customer remains responsible for its GDPR obligations.
Prepared and issued by WAIMAKERS B.V. - 10 September 2026.