Regulatory compliance 14 Data processing amendment EU Data Protection Directive EU model contract clauses U.S. Health Insurance Portability and Accountability Act (HIPAA) U.S. Family Educational Rights and Privacy Act (FERPA) Children’s Online Privacy Protection Act of 1998 (COPPA) Empowering Users and Administrators to Improve Security and Compliance 16 User authentication/authorization features 2-step veriication Security Key Single sign-on (SAML 2.0) OAuth 2.0 and OpenID Connect Data management features Information Rights Management (IRM) Drive audit log Drive content compliance / alerting Trusted domains for drivesharing Email security features Secure transport (TLS) enforcement Phishing prevention Data Loss Prevention (DLP) for Gmail Email content compliance Objectionable content Restricted email delivery eDiscovery features Email retention policy Legal holds Search/discovery Evidence export Support for third-party email platforms Securing endpoints Mobile device management (MDM) Policy-based Chrome browser security Chrome device management Data recovery Restore a recently deleted user Restore a user’s Drive or Gmail data Security reports Conclusion 23
Google Cloud Security and Compliance Whitepaper Page 3 Page 5