36 Disable Google Takeout
draft
Google Takeout gives every user a one-click bulk archive of their mailbox, Drive and other service data. Turning it off removes that self-service export path — the fastest way for a compromised account, or a departing employee, to walk out with everything at once. It applies per OU, and the shared 'Data export permission' toggle covers the jointly-controlled core services while nine other services each carry a switch of their own.
Documentation: Allow or block Google Takeout
Caveats
- Takeout off does not stop data leaving — a user can still download from Drive, sync with Drive for desktop, or forward mail. It removes the bulk one-click archive, nothing more.
- A configuration-group policy can override the OU setting — a user in the right OU can still export if a group they belong to carries a more permissive Takeout policy.
- Changes can take up to 24 hours to propagate — and an export already queued before the change may still complete.
Setup steps
- open ↗
https://admin.google.com/ac/managedsettings/850805570439 · captured 2026-07-15
Data › Data import & export › Google Takeout- OU
root / high-risk OU
-
Data › Data import & export › Google Takeout › User access to Takeout for Google services- Data export permission
Don't allow for everyone
-
Data › Data import & export › Google Takeout › Services with individual controlsYouTube, Google Photos, Blogger, Google Play, Google Pay, Location History, Google Maps, Google Books, Play Console = OFF
-
How to verify
-
As a test user, open takeout.google.com — the covered services must refuse export ("service not available"). User-visible, no admin access needed.
draft v0.0.3 Prevent policy #15 · #4 ↗