Table of contents
Since 17.01.2025 DORA (Regulation (EU) 2022/2554) applies to payment institutions, e-money institutions, crypto-asset service providers and other financial entities. If the company’s email, documents, calendars and user identities live in Google Workspace, that is an ICT third-party service in DORA’s sense – and very likely one supporting a critical or important function. That creates concrete obligations which are often discovered only at the licence application or the first supervisory review.
What has to be in place
1. Contractual provisions (Article 30)
Article 30 sets out what a contract with an ICT service provider must contain: service description and levels, data processing locations, availability, integrity and confidentiality safeguards, access, recovery and return of data on termination, incident support, cooperation with supervisors, termination rights. For critical functions, additionally full service levels, reporting duties, audit rights and an exit strategy.
You will not rewrite Google’s standard contract. The practical route is Google’s published financial-services terms (Google offers them to Cloud and Workspace customers; check which route is available for your edition and whether it has to be requested through a partner or directly) plus your own mapping table in which each Article 30 item points to a specific place in Google’s contract or documentation.
With the IT provider that configures and monitors your Workspace tenant, the contract is in your hands – and the Article 30 items have to be in it explicitly. What is typically missing: data processing locations, the list of subcontractors, the duty to cooperate with the supervisor, and a deadline for answers to supervisory questions.
2. Register of information (Article 28(3))
Every financial entity must maintain a register of all contractual arrangements with ICT third-party providers, in the templates set by the ESAs. Google Workspace is a set of rows in it: provider, type of service, function supported and its criticality, countries of data storage, subcontractors (Google publishes them), contract dates and notice periods. Your IT provider is also a row in that register, and their subcontractors are further rows.
3. Outsourcing notification to the national supervisor
Alongside DORA, national rules apply – in Latvia, Latvijas Banka’s regulation on the use of outsourced services, which requires assessing and in defined cases notifying outsourcing before it starts. Monitoring of the Workspace tenant by an external provider may qualify as outsourcing. The assessment is yours, but the provider has to give you the facts: exactly what is done, with what access, where, with which subcontractors.
4. Incident classification (Articles 17-19)
An IT provider can detect an event, investigate and escalate. Only the financial entity can classify an incident as major and report it to the supervisor. The contract has to say so clearly: the provider reports to you within a set time with set information; the decision and the reporting remain with you.
5. Evidence (Articles 6 and 9)
The supervisor expects the ICT risk management framework to rest on documented controls. For Workspace that means: a configuration standard (for example the CIS Google Workspace Foundations Benchmark), a control register with status and evidence, an exception log, regular checks and their records.
Typical mistakes
- Workspace is not in the register at all, because “it is only email”.
- The IT provider is in the register, but their subcontractors and tools are not.
- The provider contract has a service description but none of the mandatory Article 30 items.
- The provider “classifies” incidents on the client’s behalf.
- The data region is set, but there is no evidence to show.
This article is an explainer, not a legal opinion. The compliance conclusion belongs to your compliance function and the supervisor; our job is to give them the facts, documents and evidence about the Workspace tenant.
The evidence pack for the supervisor and the IT provider’s disclosure information are part of our security audit for regulated companies.


