Google claim, with some credibility, not to offer up personal information via email. Instead, ads are placed, but user identification is not provided. (The extent to which this information can be de-anonymised is something I'd like to see.)
But the data remain, on Google's servers, encrypted to keys Google itself has, and susceptible to exfiltration by various account attacks.
The problems of the Podesta attack mentioned in the article are several. Google are addressing part, but not all, of that attack.
1. Podesta was sent a phishing message that was not detected and blocked entirely.
2. His multi-member email management team failed to appropriately respond to that message. This isn't a case of Podesta alone falling for this, he had help.
3. His password was obtained.
4. The password, and it alone, was sufficient to access Podesta's account.
5. Unusual access patterns were not detected and blocked by Google. (Google are actually fairly good at doing this -- to the extent I've been repeatedly locked out of accounts.)
6. Given account access, substantially all of Podesta's email was successfully copied to the attacker's systems.
7. That email was immediately readable to the attackers, as it was not encrypted to keys Podesta alone controlled (and independent of his already-compromised password).
That's seven points of failure, any one of which could have prevented the attack.