Confidentiality.
WHAT TO ESTABLISH
What data is in each service Who can access it Whether it is encrypted Whether any of it is public
WHAT ENCRYPTION THE PROVIDER OFFERS
Usually encryption at rest and in transit, by default or as an option.
WHAT THAT PROTECTS AGAINST
Physical access to their hardware.
Not against a compromised account of yours.
WHAT PROTECTS AGAINST THAT
Access control and strong authentication.
WHAT TO RESTRICT
Who can export data in bulk Who can change sharing settings Who can access production data
WHAT TO REVIEW
Sharing settings across storage and documents.
Broadly shared and forgotten is extremely common.
WHAT TO DELETE
Data past its purpose.
WHAT TO ENCRYPT YOURSELF
Anything particularly sensitive, before it goes in.
WHAT TO KEEP OUT ENTIRELY
Data you have no business reason to hold.
WHAT TO RECORD
Which services hold what, for your own accounting and obligations.