Nigerian banks, fintechs, asset managers and law firms move sensitive data through the cloud every day; client records, statements of account, contracts, litigation files and regulatory filings.
So the question we hear most often in first meetings is a fair one. Is Google Workspace secure enough to hold all of it?
The short answer is yes. But that answer is incomplete on its own, and the incomplete version is what gets firms into trouble.
Google Workspace is secure at the platform level. That much is well established. Whether your deployment is secure is a different question. It depends on three things Google cannot do for you: the edition you buy, how you configure it, and what data you put in it.
This guide covers all three. It also answers the two questions most vendor content skips. Where does your data actually sit? And what does the CBN’s January 2027 deadline mean for you?
Key takeaways
- Google Workspace is secure at the infrastructure level. It holds ISO/IEC 27001, 27017, 27018 and 27701 certifications, plus SOC 1, 2 and 3 reports.
- Your data lives in the United States or Europe. There is no Nigerian data region. Residency controls let you pin data to one of those two places. Nigeria is not an option.
- The CBN directive covers payment transaction data. It does not cover email and documents. So regulated firms can still use Workspace. Payment records simply have to live elsewhere.
- The NDPA allows cross-border transfer. However, it is not automatic. You need a lawful transfer basis on file before an audit.
- Vault, DLP, data regions and client-side encryption are not in the entry-level plans. Buying Business Starter and assuming otherwise is the most common mistake we see.
Who is responsible for Google Workspace security?
Cloud security works on a shared responsibility model. In short, Google secures the platform. You secure your use of it.
This matters more than most firms expect. Very few breaches at Nigerian professional services firms come from failures in Google’s infrastructure. Instead, they come from compromised passwords, over-permissive sharing links, an ex-employee whose account nobody disabled, or a partner forwarding a privileged document to personal Gmail.
Google is responsible for:
- Physical data centre security
- Infrastructure hardening
- Encryption in transit and at rest
- Threat detection across Gmail and Drive
- Service availability and its certifications
You are responsible for:
- Identity and access management
- Sharing policy and device policy
- Data classification, retention and legal hold
- Staff offboarding
- Marketplace app governance
- Staff training
- Your own regulatory filings
The platform half is genuinely excellent. The customer half is where firms get breached. It is also the half that decides whether an NDPC audit goes well.
Where is Google Workspace data actually stored?
This is the first question a serious compliance officer asks. It deserves a direct answer rather than a reassurance.
Google Workspace has no Nigerian data region. With residency controls switched on, you can pin covered data at rest to the United States or to Europe. Those are the only two choices. Without a data region policy, your data sits across Google’s global infrastructure.
Three caveats are worth knowing before you promise anything to a client or a regulator.
First, not all data is covered. Data region policies cover primary data at rest in core services such as Gmail, Drive, Docs, Calendar, Chat and Vault. Logs, cached content and third-party Marketplace app data fall outside the policy.
Second, storage and processing are separate settings. Full control over where processing happens sits in a higher tier.
Third, Google is a US company. US legal process can in principle reach your data whichever region you picked. The CLOUD Act is the usual concern here. Client-side encryption is the mitigation, because Google then holds only ciphertext it cannot read. You keep the keys.
None of this rules Google Workspace out. It simply means you configure it deliberately. Above all, answer the residency question before you migrate, not during a client due diligence review.
What does the CBN 2027 data localisation directive mean for Google Workspace?
In June 2026 the Central Bank of Nigeria issued a circular through its Payments System Supervision Department. It requires that payment transaction data generated in Nigeria be stored and managed in Nigeria.
The rule covers deposit money banks, microfinance banks, mobile money operators, switching and processing companies, PTSPs, PSSPs and super agents. They must comply by 1 January 2027. The CBN has said it will apply supervisory sanctions to those that do not.
This has caused a good deal of alarm. Much of it is misplaced. Here is the distinction that matters.
| Data type | Covered by the CBN directive? | Can it live in Google Workspace? |
| Payment transaction, switching and settlement data | Yes | No. It must stay in Nigeria |
| Core banking data | Treat as in scope. Take advice | No |
| Internal email, memos, board packs | No | Yes |
| Contracts, legal opinions, policy documents | No | Yes |
| HR files, vendor records, marketing assets | No | Yes |
| Spreadsheets holding exported transaction data | Yes, in substance | No. This is the trap |
That last row catches firms out. The reason is simple: the directive follows the data, not the system.
For example, an analyst exports a month of transaction records into a Google Sheet to build a report. Regulated payment data has now moved offshore, whatever the architecture diagram says.
This is exactly what DLP rules and Drive classification prevent. So it is a configuration decision, not a licensing one.
For most Nigerian financial institutions, the practical answer is a split estate. Payment and core banking workloads stay on Nigerian infrastructure. Collaboration and productivity run on Google Workspace. Enforced controls sit at the boundary between the two.
That is an architecture question. Resolve it well before the deadline.
Does Google Workspace meet NDPA and GAID 2025 requirements?
Partly; and the part it does not cover is your responsibility, not Google’s.
The Nigeria Data Protection Act 2023 sets the rules. The General Application and Implementation Directive (GAID) 2025 puts them into practice. The NDPC issued GAID in March 2025 and it took effect on 19 September 2025. It replaced the NDPR 2019 and set detailed rules on registration, DPOs, DPIAs, breach notification and cross-border transfers.
Your Workspace data sits in the US or Europe. Every deployment is therefore a cross-border transfer, and Nigerian law does not wave that through.
Part VIII of the NDPA and Article 45 and Schedule 5 of GAID set out two main routes. Either the recipient jurisdiction holds an adequacy decision from the NDPC. Or you put an approved transfer instrument in place, such as standard contractual clauses, binding corporate rules or a recognised certification. Notably, GAID requires the Commission to approve controllers who rely on instruments like SCCs and BCRs. Beyond those two routes, the remaining bases are narrow.
What Google gives you:
- A data processing agreement with model contract clauses
- ISO/IEC 27001, 27017, 27018 and 27701 certifications
- SOC reports and audit logs
- The technical measures the Act expects of a processor
What you must do yourself:
- Register with the NDPC if you are a data controller of major importance. Most firms handling the personal data of more than 200 data subjects in six months in the financial, insurance or ICT sectors will qualify.
- Complete a DPIA before migration
- Appoint or engage a DPO
- Get your transfer instrument in order
- Maintain breach notification procedures
The penalties are real; for data controllers of major importance, the NDPA reaches ₦10 million or 2% of annual gross revenue, whichever is higher.
So Google Workspace can support NDPA compliance. It cannot deliver it. Any vendor calling their platform “NDPA compliant” is selling you something that does not exist.
This is a technology overview, not legal advice. Confirm your cross-border transfer position with your data protection counsel and your DPO.
Which Google Workspace edition do you actually need?
Most articles list features without saying what they cost. As a result, firms buy Business Starter and then discover at their first litigation hold that they have no Vault.
Here is the rough shape as at July 2026.
| Capability | Available from |
| Encryption in transit and at rest, 2-step verification, passkeys | All editions |
| AI-based phishing, spam and malware filtering | All editions |
| Shared drives, richer admin controls | Business Standard |
| Google Vault: retention, legal hold, eDiscovery, archiving | Business Plus |
| Advanced endpoint management | Business Plus |
| DLP, Context-Aware Access, security investigation tool | Enterprise Standard |
| Data regions (US or Europe residency) | Enterprise Standard. Full controls at Enterprise Plus |
| Client-side encryption, Access Transparency, S/MIME | Enterprise Plus |
| Assured Controls, AI classification | Add-on |
Two practical notes. Business editions cap out at 300 users, while Enterprise editions have no cap.
Also, for a law firm, Vault is not optional. Retention and legal hold are the difference between defensible eDiscovery and an embarrassing affidavit. So the realistic floor for a Nigerian law firm is Business Plus. For anything holding client money or regulated financial data, look at Enterprise Standard or Plus.
Google moves features between editions from time to time. Confirm current allocations before you buy.
Is Google Workspace secure enough for a Nigerian law firm?
Yes, with conditions. Law firms hold privileged communications, and privilege is easier to lose than most people assume.
Google Workspace supports the confidentiality duties in the Rules of Professional Conduct. It does this through encrypted storage and transmission, granular access controls, version history, and Vault for retention and legal hold.
These are the five controls that matter most in practice, during deployments for Nigerian firms:
- Matter-based shared drives instead of personal My Drive ownership, so files survive a partner’s departure.
- Domain-restricted sharing by default. Turn link sharing off. Allow external sharing by exception. This is the single highest-value setting in the console.
- Ethical walls built with organisational units and access groups, so a conflicted team is separated technically, not just instructed.
- Vault retention rules by matter type, aligned to your file retention policy rather than left open-ended.
- Context-Aware Access, so privileged material stays unreachable from an unmanaged device on an untrusted network.
Configured this way, Workspace strengthens a firm’s confidentiality posture. Left on defaults, it produces a firm where any associate can generate a public link to a settlement agreement in two clicks.
When Google Workspace is not the right fit
We deploy Google, Microsoft and Adobe, so we have no reason to oversell one of them. Workspace is the wrong answer in five situations:
1. You are a payment operator under the CBN directive and want one platform for everything. You need a split estate instead.
2. A client or regulator demands Nigerian residency for all data. Google cannot offer that today. A local or hybrid deployment is the honest answer.
3. Your organisation runs deep on Microsoft. Think heavy Excel modelling with add-ins, Active Directory-dependent applications, or existing E5 entitlements; migration cost may then exceed the benefit.
4. You need top-tier controls on a tight budget. Client-side encryption sits at Enterprise Plus. Check those numbers before a migration, not after.
5. Your real problem is governance, not tooling. No platform fixes an organisation with no data classification, no offboarding process and no DPO.
Google Workspace migration checklist for Nigerian firms
Settle these ten things before the first mailbox moves.
- Confirm your edition against the feature table above, not against the brochure.
- Complete a DPIA and document it.
- Choose and configure your data region. Record the decision.
- Execute your NDPA transfer instrument. Confirm your NDPC registration status.
- Turn off external link sharing by default. Enable external sharing by exception and by group.
- Enforce 2-step verification across the organisation. Add passkeys or security keys for admins and partners.
- Configure DLP rules for data you cannot afford to leak: BVNs, account numbers, exported transaction data, client identifiers.
- Set Vault retention and hold policies by department or matter type.
- Restrict Marketplace app installation to an allowlist. Third-party apps are the least governed egress path in most deployments.
- Write and rehearse your offboarding runbook. Then train staff on phishing and business email compromise, still the most common first step in an attack on a Nigerian firm.
Google Workspace or Microsoft 365?
Both meet the security bar for a Nigerian financial or legal firm. That is the honest answer; so the decision turns on other things: your existing estate, your users’ habits, your compliance position and your budget. It does not turn on which platform is “more secure”.
Frequently asked questions
Is Google Workspace secure enough for a Nigerian bank? For email, documents and collaboration, yes. Use an Enterprise edition and configure DLP, data regions and access controls. Payment transaction data must stay in Nigeria under the CBN directive, so keep it out of Workspace.
Where is Google Workspace data stored for Nigerian customers? In the United States or Europe. Google has no Nigerian data region. Residency controls let you choose between those two locations for covered data at rest.
Does Google Workspace comply with the NDPA? No platform is “NDPA compliant” on its own. Google supplies the certifications, contract terms and technical controls. Registration, DPIAs, a lawful transfer basis and internal policy stay your responsibility.
Does the CBN 2027 directive mean we cannot use Google Workspace? No. It applies to payment transaction data generated in Nigeria. Email, documents and collaboration data fall outside it. You do need controls that stop payment data being exported into Drive or Sheets.
Which Google Workspace plan does a law firm need? Business Plus at minimum. That is where Vault becomes available, which gives you retention, legal hold and eDiscovery. Larger firms, or firms with strict client security requirements, should look at Enterprise Standard or Plus.
Can Google read our documents? Under standard encryption, Google holds the keys and can technically access content. Its own access controls and Access Transparency logging apply. With client-side encryption on Enterprise Plus, encryption happens before data reaches Google, and you control the keys.





