By Jaikumar Vijayan
Google today dismissed concerns by a former senior federal IT official that the company’s controversial new privacy policy would create problems for customers of Google Apps for Government (GAFG).
In a statement, Google said the new policy will not change existing contracts that define how it handles and stores data belonging to government users of its cloud services. “Enterprise customers using Google Apps for Government, Business or Education have individual contracts that define how we handle and store their data,” Amit Singh, vice president of Google Enterprise said in a statement.
“As always, Google will maintain our enterprise customers’ data in compliance with the confidentiality and security obligations provided to their domain,” he said.
According to Singh, Google’s contractual agreements have always superseded its privacy policy for enterprise customers.
All core productivity and collaboration applications that a government, business or educational institution pays for are covered by contract, a Google spokesman today said. However, if an administrator were to turn on a Google application not covered by the contract, that application would be subject to Google’s new privacy rules, he said.
Singh was responding to concerns raised Wednesday by Karen Evans, former de facto federal CIO and administrator of e-government and IT at the White House Office of Management and Budget.
Evans, who is now an independent consultant, is a founding member of Safegov.org, which is focused on promoting a set of best practices for cloud deployment in the government. On Wednesday, Evans and another Safegov partner, Jeff Gould, CEO of Peerstone Research, released a statement saying that Google’s new privacy policy threatens the security of government data in the cloud.
The two of them called on Google to “immediately suspend” the application of its new privacy policy to GAFG users, calling it a significant change that needed further review by the public sector.
Google earlier this week announced that it was replacing separate privacy policies for each of its services with one universal policy. Under the policy, Google will combine user data from services like YouTube, Gmail and Google search and create a single merged profile for each user of its services. Google said the new policy is shorter, easier to understand and will allow the company to deliver better and more targeted services.
All core productivity and collaboration applications that a government, business or educational institution pays for are covered by contract, a Google spokesman today said. However, if an administrator were to turn on a Google application not covered by the contract, that application would be subject to Google’s new privacy rules, he said.
Singh was responding to concerns raised Wednesday by Karen Evans, former de facto federal CIO and administrator of e-government and IT at the White House Office of Management and Budget.
Evans, who is now an independent consultant, is a founding member of Safegov.org, which is focused on promoting a set of best practices for cloud deployment in the government. On Wednesday, Evans and another Safegov partner, Jeff Gould, CEO of Peerstone Research, released a statement saying that Google’s new privacy policy threatens the security of government data in the cloud.
The two of them called on Google to “immediately suspend” the application of its new privacy policy to GAFG users, calling it a significant change that needed further review by the public sector.
Google earlier this week announced that it was replacing separate privacy policies for each of its services with one universal policy. Under the policy, Google will combine user data from services like YouTube, Gmail and Google search and create a single merged profile for each user of its services. Google said the new policy is shorter, easier to understand and will allow the company to deliver better and more targeted services.
“A government user does not want Google studying everything they do and drawing correlations about what they are doing. Basically Google should not be making inferences about them,” Gould said.
Google maintains that individual contracts it has with GAFG customers clearly define what the company can and cannot do with customer data. Those contracts are unchanged by this week’s announcement, the company said.
John Pescatore, an analyst with Gartner, said its unclear whether the policy changes apply to Google’s paying users. If the personal data of paying users of Google Apps is going to be treated the same as the personal data of the free, advertising supported Google Apps, I think it is a major problem.”
If the answer is yes, it should cause many organizations to thin twice, he said.
Gould called on Google to come out with a privacy policy explicitly for Google Apps for Government. “As far as I can tell, they don’t have one now,” he said. “The policy should state that they won’t do any advertising-related data mining at all of information in government user’s accounts.” He added that Google’s competitors should also adopt similar policies for government users.
Such a disclaimer is vital, because not all government contracts will include specific privacy language, he said. “Mentions of privacy on the GAFG page all seem to point to the generic Google Apps privacy policy, which as we’ve seen … is subject to the changes scheduled for March 1.”