EU Cloud Code of Conduct

The Scope Europe (Scope EU) is an independent third party association that has developed the EU Cloud Code of Conduct (CoC). The CoC is a set of requirements that enable Cloud Service Providers (CSPs) to demonstrate their alignment with the GDPR. Per Art. 40 of the GDPR, codes of conduct should help organizations achieve alignment with the GDPR.

While the EU Cloud Code of Conduct (CoC) is pending official endorsement by supervisory authorities, the Scope EU permits CSPs to demonstrate their adherence to the EU CoC under provisional assessment procedures.

Google Cloud Platform and Google Workspace have demonstrated their adherence to the CoC at the second level of compliance, which means that these services commit to implementing data protection and security policies that align to the GDPR as determined by the Scope EU. To demonstrate compliance, Google Cloud performed an internal audit of over 80 CoC requirements and leveraged our existing independent third-party certificates and audits, such as ISO/IEC 27001.

Google Cloud services that are in scope for EU Cloud Code of Conduct


ISO/IEC 27001

Learn more

ISO/IEC 27701

Learn more