Your team has Google Workspace. That’s not the same thing as your team having a well-run Google Workspace.
Here’s a scenario we see a lot: a company moves to Google Workspace, everyone gets an inbox and a Drive folder, and for the first few months it feels like a win. Then six months in, nobody can say who has admin access. A former employee’s account is still active. Two-factor authentication was switched on for some people and not others, because nobody ever went back and checked. The platform is running — it’s just not being managed.
That gap between “having Google Workspace” and “having Google Workspace properly administered” is where most of the risk sits. And for Irish businesses, it’s not just an efficiency problem — it’s a data protection one too.
A Licence Isn’t a Security Policy
Google Workspace ships with sensible defaults, but defaults are a starting point, not a finished configuration. Two-step verification isn’t switched on for every user automatically — an admin has to enforce it at the organisational level.
From Google’s own admin guidanceGoogle recommends enforcing security keys for two-step verification across all organisational units, noting that this approach “reduces the risk of account breach, making it more difficult for an attacker to steal user credentials and gain access to confidential information and private data.”
The same goes for admin privileges, data loss prevention rules, and session controls. None of it configures itself. If nobody in your business owns that configuration, it simply doesn’t happen — and “we use Google Workspace” quietly becomes “we use Google Workspace with the settings nobody ever touched.”
Offboarding Is Where Most of the Real Risk Hides
Here’s the one that catches people out most often: what happens to an account the day someone leaves your organisation. Google’s guidance for administrators lays out a specific sequence:
- Revoke the recovery email and phone number on the account.
- Change the password.
- Reset sign-in cookies.
- Revoke OAuth tokens and any connected third-party apps.
- Only then move or delete the account.
Skip a step, and a departing employee (or whoever gains access to that old recovery email) may still be able to get back in.
Archive, don’t deleteGoogle warns that if you delete a user account outright, you also delete that user’s Workspace data, including anything held for compliance reasons. The safer move for most businesses is to archive or suspend the account first, not delete it on day one. Getting this sequence right, every time, for every leaver, is exactly the kind of process work that falls through the cracks without a dedicated admin process.
Where GDPR Comes Into It
This isn’t only an operational tidiness issue. Under GDPR, your organisation is the data controller for the personal data sitting in your Google Workspace environment — your staff data, your client correspondence, your records. Article 24 of the Regulation puts the responsibility for implementing “appropriate technical and organisational measures” on the controller, not on the software vendor.
The Data Protection Commission’s own guidance on engaging cloud service providers reinforces this: using a SaaS platform like Google Workspace doesn’t transfer your accountability to Google. Google, as the processor, handles its side of the arrangement — but your business is still the one that has to be able to show how access is provisioned, how it’s revoked, and how data is retained. An unmanaged Workspace environment isn’t a compliant one by default. It’s compliant because someone actively made it that way.
What Newtec Actually Does
This is the part of IT that’s easy to postpone because nothing looks broken — until it is. Newtec’s Google Workspace service is built around the full lifecycle, not a one-off setup:
- Managed migration. Moving email, calendar, and contacts across from Exchange or another platform with minimal disruption to your day-to-day operations.
- Security configuration. Two-factor authentication, admin access controls, data loss prevention, and session management, set up deliberately rather than left on default.
- User and access management. Structured onboarding and offboarding, so new starters are provisioned correctly and leavers are cleanly, completely removed.
- Ongoing admin support. Someone actually watching the environment after go-live: configuration changes, licence management, troubleshooting, policy updates.
- GDPR-aligned governance. Retention policies, audit logs, and access controls configured to support your accountability obligations, not just your inbox.
Newtec is an ISO 27001:2022-certified organisation, which means our own information security management practices are independently audited against the international standard — the same standard many of our clients are working toward for their own compliance requirements.
The Difference It Makes
A properly managed Google Workspace environment doesn’t look dramatically different day to day — that’s the point. New starters have what they need on day one. Leavers are removed cleanly, the same way, every time. Security settings are current, not whatever was true when the account was first set up. And if a regulator, a client, or your own leadership team asks how access and data are controlled in your Google environment, there’s a specific answer — not a shrug.
That’s the real value of managed administration: it turns Google Workspace from a tool your business happens to use into infrastructure your business can actually rely on.
Further reading and sources
- Google Workspace Admin Help, Maintain data security after an employee leaves — support.google.com/a/answer/6329207
- Google Workspace Admin Help, Archive former employee accounts — support.google.com/a/answer/9048836
- Google Workspace Admin Help, Monitor the health of your security settings (2-Step Verification) — support.google.com/a/answer/7492006
- Data Protection Commission Ireland, Guidance for Organisations Engaging Cloud Service Providers — dataprotection.ie
- EUR-Lex, Regulation (EU) 2016/679 (GDPR), official consolidated text — eur-lex.europa.eu
- NSAI, ISO/IEC 27001 Information Security Management certification — nsai.ie
Note: all statistics and process claims above are sourced directly from Google’s own Workspace Admin Help documentation, the Irish Data Protection Commission, and the official EUR-Lex text of the GDPR — no third-party or competitor blog content was used.
NEWTEC SERVICES · GOOGLE WORKSPACE ADMINISTRATIONWant to Know Where Your Current Google Workspace Setup Stands?
Speak with a Newtec Google Workspace Specialist and get a clear picture of your security, access, and governance position.
Talk to our team → Shannon: (061) 708-820 · Dublin: (01) 531-3777 · Limerick: (061) 708-821


