“We know that having Gemini summarize meeting minutes and emails clearly speeds up work. However, because we handle client blueprints and personal data, the board asked us, ‘Which country's servers will process that input data?’ Unable to answer, the proposal was sent back to us”—this was a consultation we received from a solo IT manager in the manufacturing sector. It is not about the convenience of the tool; rather, being unable to explain where the data goes halts the final step of adoption. This is by no means an uncommon story.
When introducing generative AI into business operations, knowing where entered information is stored and processed is not just a “nice-to-have” for many companies—it is a mandatory condition without which internal approval will not pass. Gemini for Google Workspace provides administrative features to address this issue head-on. In this article, we break down what this configuration can and cannot do so that those commissioning projects and approving proposals, rather than just engineers, can make informed decisions. For an overall picture of how to establish internal rules for generative AI in general regarding this topic, see Which country's servers receive the information passed to generative AI used for work?
What "data storage region" means for internal approval
Google Workspace has a setting called "data regions (data storage regions)" that allows administrators to choose the geographic location where stored data (data at rest) is placed. While this previously applied to core services like Gmail and Drive, the framework has now expanded to the Gemini app and Gemini features within Workspace.
Translated into the language of internal approvals, this means the following: previously, one could only explain that "when documents are provided to Gemini, they are processed on some Google server somewhere." Going forward, you will be able to state with solid justification that "our administrator has locked the storage region for data entered by our company to Europe (EU) or the United States." Moving from "it seems reasonably safe" to "the storage region has been designated." This puts you in a position to properly explain your setup to the board of directors or client information security audits.
Here is one point that Japanese companies often misunderstand: the storage regions available for selection are currently centered around the United States and Europe (EU), and an option to "limit storage to servers within Japan" is not provided. In other words, the practical decision is not "Japan or overseas," but rather choosing between "leaving the storage region unspecified, or explicitly locking it to the EU (or the US)." Failing to keep this reality in mind will create a mismatch in expectations during internal approval.
What you actually choose in the Admin Console
The configuration itself is simpler than expected. In the data region settings of the Admin Console, set the scope to "data at rest (stored data)" and select one of the following regions:
| Option | Meaning | Ideal use cases |
|---|---|---|
| No preference | Google distributes data to the optimal location. The region is not fixed | When there are no specific regional requirements or you just want to test things out |
| United States | Locks stored data within the United States | Aligns with requirements for US offices or US-based clients |
| Europe | Locks stored data within the EU | When mindful of EU data protection requirements (GDPR, etc.) |
The key point is that this setting does not need to be applied uniformly across the entire organization. In the Admin Console, you can narrow down the targets by Organizational Unit (OU) or configuration groups. For example, you can implement a phased rollout where "only the R&D and legal departments have their storage region locked to the EU, while the rest remain unspecified." Rather than an all-at-once company-wide deployment, securing departments handling sensitive information first is a practical approach that proves highly effective in business operations.
Note that designating regions via data regions is a feature available in higher-tier plans (Enterprise editions). Before proceeding, check your contracted edition to see if your current plan supports it. If you are still at the stage of evaluating plans, our comparison of Google Workspace and Microsoft 365 will also serve as helpful decision-making material.
Three checks so you do not stop at simply "locking in a region"
Specifying a storage region does not mean your information governance is complete. Before passing internal approval, you should verify the following three points in your company's own terms.
First, this setting protects "where stored data is kept," not "who is allowed to input what." Even if a region is locked in, that does not justify employees carelessly pasting client secrets into Gemini. You must prepare the storage region configuration and the internal rules governing what information can be input side by side, as two complementary wheels. The conceptual approach to this boundary is detailed in the previously mentioned article, Where does information provided to generative AI go?
Second, existing stored data is not moved immediately. Region settings determine the location for future data, and reflecting the change may take time. Claiming that "everything moved to the EU the moment we configured it" will create discrepancies later on.
Third is the preliminary setting of who gets access to Gemini in the first place. Even before addressing data regions, you can control which departments are allowed to use Gemini directly from the Admin Console. In practice, companies often encounter situations where Gemini was rolled out but went unused; the background behind this is covered in Reasons why Gemini remains unused after being deployed in Google Workspace. A realistic progression is to first narrow down and open access to target groups, and then lock in the storage region for sensitive departments.
Conclusion from the client and IT team perspectives
The ultimate barrier to adopting generative AI internally is not performance, but whether you can account for where your data goes. The ability to pin data storage regions by organizational unit in Google Workspace's Gemini lowers this hurdle with a single administrative setting, marking a practical step forward for IT teams and approvers alike.
On the other hand, the setting only guarantees where data is stored at rest. It only stands up to internal approval when combined with clear internal rules on what information can be shared, by whom, and with which AI, alongside narrowing down target departments and verifying plans. If you would like guidance on what options your plan supports, which departments to prioritize, and how to combine them with internal guidelines, we can help with everything from Google Workspace administrative design to day-to-day operations.








