"On servers in which country is your company's business data stored and processed?"—Have you ever found yourself unable to answer this question on a client's security questionnaire or during an audit? Especially for companies that have introduced generative AI like Gemini into their work, situations requiring an explanation of "where entered content is processed" are on the rise. Even if you intuitively feel that "it's Google's cloud, so it's safe," failing to document "where" in writing can stall deals and audits.
Google Workspace actually features a mechanism called data regions that allows administrators to specify where data is stored and processed. And in 2026, processing for the generative AI Gemini began adhering to these data regions as well. What can and cannot be controlled? From an administrator's viewpoint, we outline where SMBs should begin.
What data regions can control
Data regions is a feature that allows administrators to designate where geographically organization data is stored and how it is processed. Specifically, for covered core Google Workspace services, data at rest (including backups) and the processing of data entered by users can be designated to either the United States or Europe (Google Workspace Admin Help). It is easiest to understand as a mechanism for aligning storage locations with regional regulations or internal information management policies.
There are two points to understand accurately here. First, the selectable options at present are the US or Europe, not an option to "fix data within Japan." Second, not all data is covered. Coverage is limited to select data within specified services. In other words, data regions is not an all-powerful "domestic storage switch"; rather, it is a governance tool to align storage and processing locations to either the US or Europe and make that verifiable and explainable. The prior baseline of "what information is acceptable to pass to AI in the first place" was addressed in Which country does information passed to workplace generative AI go to?, which provides the broader picture when read alongside this article.
In 2026, Gemini processing began adhering to data regions
With the widespread adoption of generative AI, the importance of this mechanism has risen significantly. In 2026, the Gemini app began adhering to organizational data region requirements, allowing administrators to configure storage and processing to Europe only, the US only, or both, with granular control at the organizational unit (OU) level also made possible (Google Workspace Updates).
Practically speaking, this is a major change. Previously, "even if you could designate where emails and documents were stored, where AI processing occurred was a separate matter." Now, even AI processing, such as having Gemini summarize documents or emails, can follow the same regional policy as data storage. Companies using generative AI in their operations can now answer the question "Where is our input processed?" backed by administrative settings. When taking inventory of company-wide settings, including this as an item in your Google Workspace security checklist helps prevent oversights.
Capabilities vary by edition
It is important to note that data region features differ depending on your edition. A rough breakdown is as follows.
| Classification | General capability guide |
|---|---|
| Basic data regions | Apply a single regional policy to all users |
| Higher tiers (Enterprise editions) | Flexible designation for geographically distributed organizations |
| Assured Controls (Add-on) | Visualize and verify storage and processing status with detailed reports |
If you require not just "specifying" the storage location, but verifying it to auditors and clients, higher editions and add-ons like Assured Controls come into play (Data region features across Google Workspace editions, Assured Controls and data region expansion). If you do not verify what is possible under your contract edition first, you risk stumbling on sequence: attempting to configure a setting only to discover your plan does not support it.
What SMBs should check and configure first
There is no need to master every feature all at once. The sequence is as follows. First, verify the extent to which data regions are available under your current contract edition. Next, decide whether to align business data storage and processing to the US or Europe based on client requirements and internal policies. Then, configure in the Admin console which regional policy to apply to each department, including Gemini processing. These three steps will cover most requirements.
The key is positioning this not as an IT hobby, but as essential preparation for meeting business and audit requirements. Between a company that can document where data is stored and processed in writing and one that can only answer based on intuition, client trust and audit outcomes will differ significantly.
What you should tackle first
The first step is not tinkering with settings, but confirming what data regions can do and to what extent under your edition. Once that is clear, how to align your regions for storage, processing, and AI can be determined by working backward from client requirements.
If you want to clarify what can be controlled under your plan, how to configure settings including Gemini processing, and prepare your organization to meet client security requirements, please reach out via our Free IT and Google Workspace consultation. We will provide actionable proposals tailored to your operational realities, from checking your contract edition to designing configurations.








