Movatterモバイル変換


[0]ホーム

URL:


Compliance resource center

Google Cloud’s industry-leading certifications, documentation, and third-party audits to help support your compliance.

Google Cloud compliance

As part of your migration to the cloud, you may need to validate our compliance documentation, certifications, and controls. Google Cloud creates and shares mappings of our industry-leading security, privacy, and compliance controls to standards from around the world. We also regularly undergo independent verification—achieving certifications, attestations, and audit reports to help demonstrate compliance.

AI trust paper

Customers interested in Google Cloud’s approach to AI can referenceGoogle Cloud’s Approach to Trust in Artificial Intelligence for a view into our security, privacy, governance, and responsible AI posture.

Compliance offerings by region

Compliance offerings by category

The Americas

FedRAMP | FIPS 140-2 Validated |HITRUST CSF |Independent Security Evaluators (ISE) Audit |Minimum Acceptable Risk Standards for Exchanges (MARS-E) |Protected B (Canada) |StateRAMP |TruSight |U.S. Cybersecurity Maturity Model Certification (CMMC)U.S. Defense Information Systems Agency Provisional Authorization

EMEA

Spain Esquema Nacional de Seguridad (ENS) | EU Cloud Code of Conduct |HDS |ISAE 3000 Type 2 Report (FINMA) |ISO 14001 |Microfin |NCSC - Cyber Essentials Plus (UK) |Police Assured Secure Facilities (PASF) |Qatar National Information Assurance (NIA) |SWIPO Data Portability Code of ConductTISAX

Asia Pacific

Australia Hosting Certification Framework (HCF) |Cloud Security Assurance Program (CSAP) "Low Level" for Group C |Information System Security Management and Assessment Program (ISMAP) |IRAP (Information Security Registered Assessors Program) |JIIMAK-ISMS (Korea) |MTCS (Singapore) Tier 3 |OSPAR | SNI 27001 |ETDA (Thailand)

Laws and regulations

Cloud service providers can’t provide formal certification of our customers compliance with these laws and regulations. To help support our customers, we review these laws and regulations and where possible provide guidance documents, mappings, and papers that outline our technical capabilities and legal commitments. 

Global and North America

GxPCalifornia Consumer Privacy Act (CCPA) |COPPA (U.S.) |Export Administration Regulations (EAR) |FERPA (U.S.) |FINRA (US) |Google Cloud Data Processing Addendum Mapping - U.S. State Privacy Laws |HIPAA |IRS 1075International Traffic in Arms Regulations (ITAR) |GLBA |OSFI (Canada) |FG16/5 - FCA |NERC CIP |PHIPA (Canada) |StateRAMP |PIPEDA (Canada) |Québec (Canada) Law 25 / la Loi 25 |US Federal Banking Agencies |U.S. Defense Federal Acquisition Regulation Supplement (DFARS)

EMEA

ACN (Italy) |ACPR (France) |BaFin Cloud Outsourcing Guidance |Banco de España | Banco de Portugal |Bank of Italy | BRSA (Turkey)BSI Critical Infrastructure (KRITIS) |BWG (Austria) |Central Bank of Ireland (Ireland)|CSSF (Luxembourg) | De Nederlandsche Bank (the Netherlands) |EU AI Act |EU Data Act |EU DORA |European Union’s Digital Markets Act |EU Solvency II |EU Standard Contractual Clauses |FINMA (Switzerland)FSA (Denmark) |GDPR |Google Cloud & the EU Network and Information Systems Directive (NIS2) |ISO 14001 |Israel’s Privacy Protection AuthorityKNF (Poland)MaRisk AT 9 Outsourcing |PRA (UK) |revFADP (Switzerland) |South Africa POPI |SFSA (Sweden) |Telecoms Security Act (UK) |VAG (Austria)|SYSC 8 Outsourcing - FCA Handbook |UK CHECK


Latin America 

PDPL (Argentina) |BCRA (Argentina) |Central Bank of Brazil (Brazil)CNBV (Mexico) | CNSF (Mexico)CMF (Chile) |Superintendencia de Banca (Peru) |Financial Superintendence of Colombia |Lei Geral de Proteção de Dados (LGPD)ASFI (Bolivia) 

Asia Pacific

Act on the Protection of Personal Information (Japan) |APRA Prudential Standard CPS 234 |APPs (Australia) |APRA (Australia) |Bank Negara (Malaysia) | Bank of Thailand (BOT) |BI Regulation |BSP (Philippines) |DSA (Bangladesh) |FSC Insurance Outsourcing Directions | FSC Banking Outsourcing Regulations |GR 95/2018 guidelines |IA (Hong Kong) | HKMA (Hong Kong) | MAMPU (Malaysia) | PDPO (Hong Kong) | Indonesia Government Regulation No. 71 (GR 71) | IRDAI (India) |FSC (Korea) |Korean Financial Supervisory Service (FSS) |MAS TRM GuidelinesOIC (Thailand) |OJK RegulationPDP Law (Indonesia) |PDPA (Malaysia) | PDPA (Philippines) | PDPA (Taiwan) | PDPA (Thailand) |PDPD (Vietnam) |PIPA (Korea)RBI (India) | Reserve Bank of New Zealand (New Zealand) |Securities and Exchange Board of India (SEBI) |PDPA (Singapore) |State Bank of Vietnam |The Privacy Act (New Zealand)

Alignments and frameworks

Our products, technical capabilities, guidance documents, and legal commitments help our customers map to these frameworks and alignments. These offerings may not require formal certification or attestation, though we may rely on our certifications, attestations, and reports to help our customers map to these frameworks and alignments.

Global

Bitsight |Center for Internet Security (CIS) Benchmarks |CyberGRX |ISO/IEC 27110 |Know Your Third Party (KY3P) Report |MVSP |ProcessUnity Global Risk Exchange |Standardized Information Gathering (SIG) Questionnaire|USDM Life Sciences |Whistic

Take the next step

Tell us what you’re solving for. A Google Cloud expert will help you find the best solution.

Google Cloud
Console
  • Accelerate your digital transformation
  • Whether your business is early in its journey or well on its way to digital transformation, Google Cloud can help solve your toughest challenges.
  • Featured Products
Google Cloud

[8]ページ先頭

©2009-2026 Movatter.jp