Telemetry, AI enrichment, and transfers: what productivity suites do with your documents
Analysis of American suite collection practices (Google, Microsoft): telemetry, AI training, CLOUD Act, and what GDPR and the Data Act change for European companies.

Last January, a CIO showed us their processing register. Line "Messaging": purpose "internal communication", legal basis "contract", processor "Google Ireland Limited". Nothing unusual. Then the question: "Does Gemini read our quotes?", and the register no longer answered.
This article sets the terms of the debate, without panic marketing. Sources cited: vendor documentation, European texts, CNIL decisions.
Three distinct flows (too often confused)
| Flow | Example | Typical purpose |
|---|---|---|
| Product telemetry | Client version, latency, crashes | Improve the service |
| Usage signals | Clicks, reading time, searches | Personalization, internal analytics |
| AI enrichment | Mail/doc content to summarize, classify, suggest | Copilot / Gemini features |
GDPR applies to all three once personal data is processed. But business impact differs: a crash log is one thing; a model trained on client contracts is another.
Google Workspace: what the contracts say
Google distinguishes:
- Workspace Core services (Gmail, Drive, Calendar…) covered by the DPA and standard contractual clauses.
- Additional services or AI features that may have different terms of use.
Sensitive point since 2024-2025: Gemini features. Google states it does not use Workspace content to train models without consent on Business/Enterprise plans, but wording changes by version and options enabled by the admin. Read the box you check in the admin console, not a tech influencer's Twitter summary.
Product telemetry is largely described in privacy policies: interaction events, device information, diagnostics. Admins can limit some sharing (Chrome policies, Workspace settings), never reset everything to zero while keeping a functional cloud service.
Microsoft 365: Copilot and the data boundary
Microsoft follows a similar logic with Microsoft 365 Copilot:
- Commercial promise: no training of the foundation model on tenant data for paid Copilot.
- Operational reality: content transits Azure services for inference; Copilot telemetry metadata exists for billing and support.
Admins enable Copilot per user. License cost is significant (often +€20-30/user/month beyond M365). Many European companies enable without updating the GDPR register, a classic audit gap.
CLOUD Act: why American DPOs worry French DPOs
The CLOUD Act (2018) allows US authorities to request data from US providers, including stored outside the United States, under certain conditions.
Suites sign post-Schrems II SCCs (standard contractual clauses). European companies add transfer impact assessments (TIAs). That does not remove US law, it documents residual risk.
For a hospital, local government, or defense mid-cap: that residual risk is often unacceptable. Hence the return of sovereign mail projects, not by dogma, by requirements.
GDPR: concrete obligations for your register
If you use Google or Microsoft, your register should mention at minimum:
- Processor and further processors (Google / Microsoft list updated quarterly).
- Distinct purposes: messaging, storage, generative AI (if enabled).
- Retention periods, often dictated by your policies, not vendor defaults.
- Transfers outside the EU and safeguards (SCCs, TIA).
- Data subject rights: access, deletion, real procedure, not "contact Google."
CNIL regularly reminds that choosing a cloud tool does not exempt the controller. In an audit, "Google handles it" does not hold.
Data Act and AI Act: what is coming
The Data Act (progressively applicable 2025-2027) strengthens portability and access to data generated by connected products, with implications for exports and cloud suite interoperability.
The AI Act classifies AI systems by risk. Automatic mail sorting for HR or health can become "high risk" depending on context. If your suite applies a "rejected candidate" label via LLM, you are no longer in gadget notification territory.
These texts push toward more transparency on which model, which data, which logic. Giants publish sheets, often long, sometimes contradicting real UX.
Summary table
| Feature | Google Workspace | Microsoft 365 | UltiSuite (France cloud / on-premise) |
|---|---|---|---|
| Product usage telemetry | Yes | Yes | Local logs (admin) |
| AI on mail/doc content | Gemini (admin option) | Copilot (license option) | UltiAI per plan (Plus, Boost, Scale) or LLM of choice |
| Model training on your data | No (Business+ plans, per DPA) | No (commercial Copilot) | You control, no training by default |
| Primary vendor jurisdiction | USA | USA | France (cloud) or your jurisdiction (on-premise) |
| Full data export | Takeout / API | eDiscovery / Graph | Account export + admin access (on-premise) |
| Disable AI collection | Partial (admin console) | Per-user Copilot | Disable (admin) or LLM not connected |
UltiSuite is not magic: if you plug an American cloud LLM into your mail rules, you recreate the same transfer. The difference: you hold the switch, not a hidden default option to "improve the experience."
Commercial claims worth skepticism
Phrases we often read on product pages:
- "Enterprise-grade security" without threat model detail.
- "Your data stays your data", legally true, operationally vague on who can access it on the vendor side.
- "Responsible AI", marketing until the technical sheet explains retention, logs, and real opt-out.
Our advice: demand an up-to-date subprocessor list, the AI annex if you enable Gemini/Copilot, and have your DPO sign the transfer analysis before deployment, not after 2,000 accounts are created.
What to do concretely?
If you stay on Google/Microsoft
- Disable AI features until the register is updated.
- Limit heavy clients (full Drive sync on sensitive endpoints).
- Use separate accounts for highly confidential data.
- Negotiate clauses with a lawyer, click-wrap contracts are not neutral.
If you migrate to a sovereign suite
- Start with mail (MX), that is where the most sensitive metadata leaks.
- Keep historical drive read-only for a while.
- Document physical hosting (country, host, backups).
Our SMB comparison details TCO. The mail sorting guide shows how to automate without sending every message to a third party.
Sober conclusion
Nobody reads your mail to write a novel. But the cloud industry built revenue on data centralization and, now, AI. Every new "intelligent" feature is a new processing to declare.
The European stake is not boycotting American tech, it is choosing consciously what transits through them, what stays with you, and aligning contracts with that reality.
Related articles
More reading in the Sovereignty category.
