A claim which is backed up by a statement from the GSA – “The recent changes announced by Google pertain only to their free, publicly available services. These changes do not apply to Google Apps for Government, which is the version used by GSA. Our usage of the Google Apps solution is governed by contractual agreement with Google and our prime contractor, Unisys. The solution is compliant with all federal regulations and requirements, including those regarding privacy and data protection.”
Despite that, some concerns remain about the overall process of using Google Apps in a public sector setting. Users who use Google services for both personal and public sector use are in essence subject to two privacy policies depending on how they are logged in.
If an individual is logged into their government account, they’ll be protected under the contract governing their agency. If an individual logs in on their personal account they’ll be governed by the consumer policy. Drinan notes that no data will be shared between the two accounts.
Although these nuances may not be immediately clear to an individual user. Google is in a unique position, being a government service provider that is also the custodian of the retail consumer internet experience. A position which may not be fully understood by individuals.
Drinan explains that Google Apps for Government account administrators may open or block access to other sites and services like YouTube, although most clients maintain blocks on many of these areas. However, once a user logs in from a device that is not behind a wall like that, now they are governed by both policies depending on how they are logged in – conditions which can be risky in the era of mobile access, telework and multiple workflows.
I asked Drinan if there is a warning process or some kind of education that comes from Google about how these worlds work together or when users are switching between them. He notes that they leave the education component largely up to the clients themselves. He also also pointed me to a two blog posts that the company has put up to help clear up any questions about the two policies.
“We went through an extensive notification process before the policy took effect for Google users. It was one of the largest notification efforts we’ve undertaken,” He says.