Google Cloud
Fair 1.7 Easy 5.0 Secure 3.3
| Pillar | Criterion | Score | Evidence |
|---|---|---|---|
| Easy | Day-one UX Can non-technical staff use it without a project? | 5 | Staff usually already know Gmail and Drive. Source |
| Easy | Operate Admin burden, updates, backups and language coverage. | 5 | Google operates the stack; almost no local admin load. Source |
| Easy | Integrate SSO, mail/CalDAV, APIs and common NGO connectors. | 5 | SSO, mail and a huge integration marketplace. Source |
| Fair | Lock-in / exit Can you leave with your data in open formats, at known cost? | 2 | Takeout exists; formats and APIs still centre on Google. Source |
| Fair | Sovereignty EU legal entity, EU hosting, and exposure to extra-EU lawful access? | 1 | US company; CLOUD Act / FISA exposure even with EU data regions. Source |
| Fair | Openness Open source or open standards? Are independent implementations possible? | 2 | Closed source; some standard protocols, many proprietary APIs. Source |
| Secure | IT security Authentication, encryption, patch cadence and independent audit. | 4 | Mature security programme and encryption in transit/rest. Source |
| Secure | User security 2FA, roles, phishing resistance and safe defaults. | 4 | Strong 2FA and admin roles; phishing of Google login remains common. Source |
| Secure | Personal data GDPR fit: DPA, residency, sub-processors and Schrems II posture. | 2 | DPA available; Schrems II / US cloud remains the hard GDPR question. Source |