01
Accountability
Role map
Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.
- Name business owners for mail, drive, forms and identity rather than assigning one generic “Google owner”.
- Separate tenant administrators, service-account owners, shared-drive managers and external collaborators.
- Record Google’s role and each Marketplace or OAuth app’s role from current terms and processing facts.
02
Collection surfaces
Collection and notice touchpoints
Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.
- Forms, shared files, calendar bookings and inbound email.
- Employee-created sheets, documents, recordings and message attachments.
- Directory sync, device management, APIs, forwarding and third-party add-ons.
03
Purpose discipline
Purpose and data minimisation checks
Every field and copy should have a named operating reason, accountable owner and review event.
- Inventory forms and shared drives before individual files.
- Challenge unrestricted free-text collection, broad Drive copies and indefinite chat or mail retention.
- Use groups and shared ownership so business records are not stranded in personal drives.
04
Choice evidence
Consent and preference evidence
When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.
- Link public forms to the notice version shown at collection.
- Test preference changes across Forms, mail tools and downstream CRM or marketing systems.
- Do not treat a Drive sharing permission as evidence of a data principal’s consent.
05
Least privilege
Access control and privileged roles
Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.
- Review super admins, delegated admins, service accounts, OAuth grants and external sharing.
- Test shared-drive and link-sharing defaults against the intended audience.
- Exercise account suspension, transfer and revocation for a departing user.
06
Lifecycle
Retention, deletion, backup and export behaviour
A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.
- Define policies by repository and record category; Vault rules and ordinary deletion are not the same operation.
- Test trash, retention, holds, shared-drive ownership and exported copies.
- Document which licence and service coverage are required for search, hold and export.
07
Service chain
Processor, sub-processor and contract checks
Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.
- Retrieve current Workspace terms, data-processing terms, location choices and sub-processor record.
- Review Marketplace apps, Apps Script, forwarding and APIs as separate disclosures.
- Record exit, export, deletion, security and incident-assistance commitments.
08
Detection + response
Logs, monitoring and breach evidence
Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.
- Confirm which admin, login, Drive and OAuth events are available for the edition.
- Save a dated sample for external sharing, privileged role change and export activity.
- Route suspicious access or sharing to an owned investigation and breach-assessment process.
09
Request workflow
Rights-request search, export, correction and erasure workflow
- 01
Search known identifiers across relevant repositories, including shared drives and group-owned records.
- 02
Coordinate record owners so correction does not leave inconsistent copies.
- 03
Review holds and other exceptions before deletion.
- 04
Record residual data in trash, Vault, exports and connected services.
10
Bounded configuration
Configuration checklist
Admin roles, service accounts and OAuth grants are least-privileged and reviewed.
- Admin path
- Verify in the current admin console
- Evidence to save
- Role and grant export, review decision and exceptions.
Drive and shared-drive sharing match purpose and owner expectations.
- Admin path
- Verify in the current admin console
- Evidence to save
- Sharing sample, default settings and exception record.
Rules are repository-specific and tested against holds and deletion.
- Admin path
- Verify in the current admin console
- Evidence to save
- Rule inventory, coverage note and controlled test.
No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.
11
Retrievable proof
Evidence to save
Repository and shared-drive ownership map
Form-to-notice trace
Admin and OAuth review
External-sharing sample
Vault coverage and rule record
Account-exit exercise
Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.
12
Do not overclaim
Known limitations and questions for the vendor
Known limitations
- Vault coverage, audit detail and retention controls vary by edition and service.
- Offline files, forwarding and unmanaged exports sit outside tenant controls.
- A user deletion does not itself demonstrate deletion of shared, held or connected copies.
Questions to resolve
- Which repositories are systems of record?
- Which external domains and OAuth apps can receive personal data?
- What does the current Vault licence cover?
- Who owns records when a user leaves?
13
Traceable record
Official vendor sources, DPDP sources and corrections
Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.
Official vendor documentation
Official DPDP record
- Act No. 22 of 2023Ministry of Law and Justice, Government of India · checked 2026-09-27 ↗
- G.S.R. 843(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 846(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 892(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.
Report or inspect a correctionGoogle Workspace and Google Vault are trademarks of Google LLC. They are referenced nominatively; no affiliation or endorsement is implied.