{"schema":"https://policywatcher.online/schemas/evidence-packet/v1","schemaVersion":"1.0.0","mappingVersion":"2026-07-29.1","changeId":"ecc39763-b2f3-40c2-ac76-9f0844adb261","screeningDate":"2026-07-24T20:57:29.404Z","publicationGate":"published","company":{"id":"3e20dca5-ce3f-4e7e-930c-7aa4753a789d","name":"Google","slug":"google","industry":"Tech Giant"},"policy":{"id":"11539eab-9c04-4d21-8496-ac21de3bc7e2","name":"Privacy Policy","type":"privacy","jurisdiction":"US","sourceUrl":"https://policies.google.com/privacy"},"sourceConfidence":{"state":"review-required","lastCheckedAt":"2026-07-06T03:59:34.659Z","retrievalChannel":"seeded","dataStatus":"Available","publicSnapshotEvidence":true,"limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"snapshots":{"old":{"version":1,"sha256":"8a70bdc1fa80efce5dfbc4342c511a2f1f5cfd194fb1b7e48868da91ccd3d903","capturedAt":"2026-07-06T07:19:28.291Z"},"current":{"version":2,"sha256":"61d74aa5731363bb1caa708128349f2d4096a6b1ebbce23bf55268c71461a29a","capturedAt":"2026-07-24T20:57:29.396Z"}},"assessment":{"summary":"The policy update adds new table of contents sections, hinting at future clarity on data transfers and definitions, but core data practices remain consistent.","overallRisk":"Medium","overallScore":6,"previousPublicChange":null,"scoreDelta":null,"direction":"baseline","reasons":[{"icon":"warning","textEn":"Extensive data collection for personalized services and advertising.","textIt":"Ampia raccolta dati per servizi personalizzati e pubblicità.","deltaScore":0,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"warning","textEn":"Broad third-party sharing for processing and legal reasons.","textIt":"Ampia condivisione con terze parti per elaborazione e motivi legali.","deltaScore":0,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"info","textEn":"Lack of explicit AI-specific data governance details in this general policy.","textIt":"Mancanza di dettagli specifici sulla governance dei dati AI in questa policy generale.","deltaScore":0,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"}],"keyPoints":[{"textEn":"New table of contents entries added, including 'Data transfer frameworks' and 'Key terms'.","textIt":"Aggiunte nuove voci nell'indice, inclusi 'Framework di trasferimento dati' e 'Termini chiave'.","sentiment":"positive"},{"textEn":"No immediate changes to data collection, usage, or sharing clauses in the provided text.","textIt":"Nessuna modifica immediata alle clausole di raccolta, utilizzo o condivisione dei dati nel testo fornito.","sentiment":"neutral"},{"textEn":"Users retain access to comprehensive privacy controls for managing personal data.","textIt":"Gli utenti mantengono l'accesso a controlli privacy completi per la gestione dei dati personali.","sentiment":"positive"}],"regionImpacts":[{"region":"EU","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Enterprises using Google services should continue to ensure their own compliance with GDPR and the upcoming AI Act. The new 'Data transfer frameworks' section may offer future clarity on data flows.","complianceNoteEn":"GDPR, AI Act Relevance"},{"region":"EU","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"The policy maintains existing data collection and processing practices. Individuals in the EU still benefit from GDPR rights, which Google acknowledges in its 'European requirements' section.","complianceNoteEn":"GDPR Rights Acknowledged"},{"region":"Global","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Global enterprises must continue to assess Google's data practices against diverse international regulations. The new TOC entries suggest potential future clarity on cross-border data transfers.","complianceNoteEn":"International Regulations"},{"region":"Global","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"Globally, individuals can manage their privacy settings through Google Account controls. The policy's general approach to data collection and use remains consistent across regions.","complianceNoteEn":"Consistent Controls"},{"region":"US","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"US enterprises should continue to align their use of Google services with state privacy laws. The policy's general nature means specific AI governance details are not yet present for emerging regulations.","complianceNoteEn":"State Privacy Laws"},{"region":"US","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"US individuals retain controls over data, similar to the previous policy. State-specific privacy laws like CCPA/CPRA offer additional rights, which Google generally supports through its privacy dashboard.","complianceNoteEn":"CCPA/CPRA Rights"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts.","mappings":[{"framework":{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 (EU AI Act)","shortName":"EU AI Act","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","referenceVersion":"Official Journal text, 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?","kpiFields":["kpiAiTrainingOptOut","kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAiTrainingOptOut","label":"AI training opt-out","value":"Not Available"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Mentioned"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Partial"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"}]},{"framework":{"id":"iso-42001","name":"ISO/IEC 42001:2023","shortName":"ISO/IEC 42001","referenceUrl":"https://www.iso.org/standard/42001","referenceVersion":"ISO/IEC 42001:2023 overview","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?","kpiFields":["kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit","kpiRegulatoryCompliance"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Mentioned"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"},{"field":"kpiRegulatoryCompliance","label":"Regulatory compliance","value":"Comprehensive"}]},{"framework":{"id":"nist-ai-rmf","name":"NIST AI Risk Management Framework 1.0","shortName":"NIST AI RMF","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?","kpiFields":["kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness","kpiContentModeration"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Mentioned"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Partial"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiContentModeration","label":"Content moderation","value":"Opaque"}]},{"framework":{"id":"oecd-ai-principles","name":"OECD AI Principles","shortName":"OECD AI Principles","referenceUrl":"https://oecd.ai/en/ai-principles","referenceVersion":"OECD AI Principles, updated 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?","kpiFields":["kpiConsentMechanism","kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiConsentMechanism","label":"Consent mechanism","value":"Opt-Out"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Mentioned"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"}]}]},"humanReviewQuestions":["Does the original Privacy Policy source still match the recorded public snapshot version 2?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"methodologyUrl":"https://policywatcher.online/methodology/confidence","changeUrl":"https://policywatcher.online/change/ecc39763-b2f3-40c2-ac76-9f0844adb261","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged.","contentDigest":"b958f469a9df13ae0bafc3e5488e1f5bffe4af5f28c591250dbad0c46e54b43d"}