The short answer
Yes, Google Drive is safe enough for client documents, on two conditions: the files live in the firm's Google Workspace account, not in staff members' personal Gmail, and the settings are locked down. Google's servers are rarely the weak point. What usually leaks is the way a firm uses them: links anyone can open, former staff who still have access, and copies sitting on laptops.
This guide is for law firms, notaries, tax advisers, accountants and agencies that are staying on Google Drive. Everything said here about Google's products was checked against Google's official documentation on 26 September 2026. Features and editions change, so follow the links again before you change a setting.
What Google already protects
To be fair to Google, the basics are done well.
- Encryption. All files uploaded to Drive or created in Docs, Sheets and Slides are encrypted in transit and at rest with AES 256-bit encryption.
- Advertising. Google says it does not use Drive content for advertising, and accesses private content only with your permission or where the law requires it.
- Everyday threats. Google Accounts come with built-in protection against spam, phishing and malware (source).
- Clear roles in Workspace. For Workspace customers, the Cloud Data Processing Addendum names Google as processor and the customer as controller of the personal data stored.
So the question "is Google Drive safe from hackers" is rarely settled in Google's data centres. It is settled in your firm's own accounts and settings.
Where firms usually slip
- Client files in personal Gmail. A personal account has no admin console. The firm cannot lock its sharing settings, cannot see a log and cannot recover the files when the person leaves.
- "Anyone with the link". With this option, whoever holds the link can open the file without signing in to a Google Account. The link is easy to forward on WhatsApp, and once it has been forwarded you no longer know who holds it.
- Former staff. Files in My Drive belong to whoever created them. If an account is deleted without a transfer of ownership, untransferred files are deleted too.
- Sharing to personal accounts. Someone shares a client folder with their own Gmail to work from home. That folder is now outside the firm's control.
- No trail. For a file not owned by a work or school account, no one can see its view history.
- Copies on laptops. Drive for desktop has a "Mirror files" mode that keeps a full copy on the computer. When an admin wipes the account from a device, only streamed content is removed; mirrored content stays.
- Third-party apps. An app granted access to Drive can read files within that permission, and the permission is often given in one click and forgotten.
Personal Drive versus Google Workspace
How safe Drive is depends heavily on the account and the edition. As at 26 September 2026:
| Feature | Personal Google Account | Google Workspace |
|---|---|---|
| External sharing controls in an admin console | None | Every edition |
| Drive log events (view, download, share, delete) | None | Every edition, kept for 6 months |
| Shared drives, owned by the organisation | None | Business Starter and up, with fewer controls on Starter |
| Wipe the account from a device | None | Business Starter and up |
| Security investigation tool | None | Enterprise Standard, Enterprise Plus and some other editions |
| DLP for Drive | None | Enterprise Standard, Enterprise Plus, Frontline Standard and Plus, Education, Enterprise Essentials Plus |
| Choice of data region | None | Business Standard and up; the only choices are the United States, Europe or no preference |
| Client-side encryption | None | Enterprise Plus, Frontline Plus, Education Standard and Plus |
Client-side encryption means Google's servers cannot decrypt the files, but it needs an external key service and an identity provider. For a small firm it is usually more than is needed.
14 steps to harden Google Drive
Most of these are done by an admin in the Google Admin console. Menu names follow Google's English documentation.
- Move every client file into the firm's Workspace account. No client documents in personal Gmail, with no exceptions.
- Enforce 2-Step Verification for every account. For partners and admins, choose "Only security key", which now accepts passkeys as well.
- One shared drive per client or matter. Files in a shared drive belong to the organisation and stay when someone leaves.
- Make "Restricted" the default general access for new files, through the General access setting in Sharing options.
- Switch off "Anyone with the link" for the organisational units that handle client work, by unticking the option that lets users make files visible to anyone with the link.
- Restrict sharing outside the firm. If your clients are companies, use Allowlisted Domains. Bear in mind that an allowlist blocks personal accounts, so for individual clients on Gmail, a warning is the practical choice.
- Turn on the external-sharing warning and the external file marker. Staff are warned before sharing outside the domain, and files owned by outsiders are flagged.
- Set an expiry date on outsiders' access. In the Share dialog, choose Add expiration (eligible work or school accounts only).
- Stop viewers and commenters downloading, printing and copying final drafts sent outside the firm.
- Configure Drive for desktop. Point staff to "Stream files" and restrict "Mirror files" by admin policy, because mirrored copies are not removed when a laptop goes missing.
- Lock down third-party apps. Under Security > Access and data control > API controls, mark apps as Trusted, Limited or Blocked and restrict access to the Drive service.
- Write a leavers' procedure. On the last day: suspend the account, transfer file ownership to a partner, remove the person from shared drives, then delete the account.
- Check the Drive audit log monthly. Entries are kept for six months and admins cannot extend that. If you need a longer record, keep your own copy, for example through the BigQuery export.
- For the most sensitive documents, use DLP or client-side encryption if your edition includes them. DLP can block external sharing or disable downloads for files containing sensitive data.
A quarterly access review
Settings that are right today drift within three months. Set aside an hour each quarter:
- Compare each shared drive's members with the matter team. Remove anyone no longer involved.
- In the Drive audit log, look for sharing and visibility changes over the last three months, especially public links and sharing to outside domains.
- Confirm that leavers' accounts are suspended or deleted and their files transferred.
- Review the list of third-party apps accessing firm data.
- Check which devices are still syncing with staff accounts.
- Write the result on one page: the date, who checked, and what changed.
That one page matters. When a client or an auditor asks, you have evidence rather than a verbal assurance.
The Indonesian PDP Law angle
For client documents, your firm is usually the personal data controller. Several duties in Law No. 27 of 2022 bear directly on how you use Drive:
- Article 35: technical and operational measures to protect personal data.
- Article 36: keeping personal data confidential.
- Article 37: supervising everyone involved in processing, your own staff included.
- Article 39: preventing unauthorised access to personal data.
- Article 31: recording all processing activities.
- Article 46: after a failure of personal data protection, notifying the data subjects and the supervisory authority in writing within 3 x 24 hours.
Article 51(3) adds that processing by a processor remains the controller's responsibility. Storing files with Google does not hand that responsibility to Google. One more point: Workspace data regions do not yet offer Indonesia, so the rules on transfers abroad in Article 56 apply as well.
This is general information, not legal advice.
When Drive is enough, and when it is not
It is enough if your firm is on Workspace, the 14 steps above are in place, the quarterly review actually happens, and no client has yet asked for data stored in Indonesia or for access records older than six months.
It is not enough when:
- Some client documents are still in personal accounts and hard to move.
- A client or contract requires the data to be stored in Indonesia.
- You need DLP or client-side encryption and your Workspace edition does not include it.
- Clients send ID cards and tax numbers over WhatsApp because they have no Google Account to upload with.
- Nobody has time to review the log before entries age out after six months.
In that situation many firms do not leave Drive; they add a layer on top. folders.id can sync chosen folders from Google Drive, one way or both ways, so the team keeps working in Drive. Files uploaded to folders.id are stored with an Indonesian object-storage provider.