TL;DR: Google Drive does not reliably detect, classify, or delete PII in files, images, PDFs, and shared folders, so personal data can persist far longer than policy allows, according to Strac. The governance gap is not storage alone but lifecycle control over where personal data is allowed to remain.
NHIMG editorial — based on content published by Strac: How to Delete PII in Google Drive Automatically
Questions worth separating out
Q: How should security teams automate deletion of personal data in cloud drives?
A: Use content-aware policies that combine OCR, file classification, and remediation rules.
Q: Why do cloud drives create retention risk for personal data?
A: Because storage platforms preserve files by default, while privacy obligations often require data minimisation and timely deletion.
Q: What breaks when PII is only governed by manual review in collaboration tools?
A: Manual review misses volume, unstructured formats, and shadow uploads from HR, support, and operations.
Practitioner guidance
- Define deletion-triggered retention policies Classify which file types and data elements require automatic deletion, then map those rules to retention periods, legal holds, and exception handling for HR, support, and customer-facing folders.
- Extend inspection to unstructured file formats Require OCR and content classification for PDFs, screenshots, scans, and image attachments so PII detection does not depend on filenames or manual review.
- Review delegated access to remediation tools Treat OAuth-connected DLP or deletion engines as NHI workloads, scope their permissions tightly, and verify revocation paths, audit logs, and break-glass procedures.
What's in the full article
Strac's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step Google Drive policy configuration for PII detection and delete actions
- Specific OCR and classifier settings for PDFs, screenshots, and scanned documents
- Examples of alerting and SIEM integration for deletion events and policy matches
- Workflow details for handling public links, external collaborators, and synced folders
👉 Read Strac's guide to automatically deleting PII in Google Drive →
Google Drive PII deletion: are your controls keeping up?
Explore further
Retention control is now an identity-adjacent governance issue. Personal data that remains in cloud storage after it should have been deleted creates a different kind of exposure than a simple permission misconfiguration. The issue is not whether a user could open a file, but whether the organisation has enforced the file's end of life. For IAM and privacy teams, this makes content lifecycle enforcement part of the access governance conversation.
A question worth separating out:
Q: Who is accountable when automated deletion removes regulated files incorrectly?
A: Accountability sits with the data owner, security owner, and privacy function together, because the control changes business records as well as security posture. Organisations need documented policy, exception handling, and audit evidence before automation is enabled. For GDPR and CPRA, the real question is whether deletion rules are defensible, consistent, and logged end to end.
👉 Read our full editorial: Automatic PII deletion in Google Drive is still a governance gap