Google can read every file on your Drive. They scan them for policy violations, their Gemini AI processes them, and they complied with government data requests 80% of the time in 2023 — 209,000 requests globally. A Minnesota teacher was arrested after Google automatically scanned his Drive photos and reported them to NCMEC. Google isn't a filing cabinet. It's a filing cabinet with an employee who reads everything you put in it. Varonis research found the average company on Google Drive has 700,000 sensitive files accidentally exposed to anyone with the link. No native option exists for end users to encrypt files so Google can't read them. If you're a journalist, lawyer, or doctor using Google Drive, your files are readable by Google, indexable by its AI, and one sharing mistake away from being public.
What they claim: Google Drive keeps your files secure and private.
What we found: Google holds encryption keys -- not zero-knowledge. Scans files for violations. Gemini AI caught reading PDFs (July 2024). PRISM since 2009. 150K+ govt requests H1 2023, ~80% compliance. Can provide full file contents.
What they claim: Google Drive is safe for sensitive documents.
What we found: Enterprise: 709K publicly exposed sensitive assets per org. 120K sensitive assets shared to personal emails. Sharing defaults lean accessible. No consumer client-side encryption. PRISM.
What they claim: Files are encrypted and protected.
What we found: AES-256 but Google holds keys. No zero-knowledge for consumers. ToS: license to 'use, reproduce, modify, create derivative works.' False positive scanning flags innocent files. Account suspension affects all Google services.
What they claim: Gemini AI features require user consent.
What we found: Google says users must 'proactively enable.' Privacy researcher found it reading documents without clear opt-in. Documents processed by AI infrastructure.
What they claim: Google says Gemini in Workspace "requires a user to proactively enable it" and that content "is used in a privacy-preserving manner"
What we found: The "Organize My Files" feature is now generally available and enabled by default for eligible organisations where admins have Gemini for Workspace globally active. Outside the EEA, Japan, Switzerland, and the UK, Workspace smart features are turned on by default. Senior adviser Kevin Bankston documented that Gemini generated a summary of his private tax return without permission, and the opt-out settings were buried and non-functional.
What they claim: Google states it does "not use Workspace data to train or improve the underlying generative AI and large language models that power Gemini" without permission
What we found: The "Organize My Files" feature requires Gemini to read, classify, and categorise every eligible file in a user's Drive — PDFs, Google Docs, Sheets, Slides, Office files, images, and videos with transcripts. Google processes all this content server-side to generate organisation suggestions. Regulatory frameworks like GDPR, HIPAA, and SOC 2 consider any AI access to files containing personal data or protected health information a compliance concern, regardless of whether the data is used for training.
What they claim: Google says users maintain full control over the "Organize My Files" feature and that "files are never moved automatically"
What we found: While files aren't moved automatically, the AI scanning of file contents happens before users make any decisions — Gemini must read and classify every eligible file to generate suggestions. The feature comes with a promotional access period through July 15, 2026, after which per-user usage limits apply. Additionally, the feature requires "Editor access" to files, meaning shared documents from colleagues are also subject to scanning when any editor uses the feature.