{"schema":"https://policywatcher.online/schemas/evidence-packet/v1","schemaVersion":"1.0.0","mappingVersion":"2026-07-29.1","changeId":"5ba2f740-f2df-442d-af42-b68f291f9bc9","screeningDate":"2026-07-06T22:22:37.332Z","publicationGate":"published","company":{"id":"edaffd5f-94d3-483c-8ae1-b5ae272d33ec","name":"Amazon","slug":"amazon","industry":"E-Commerce"},"policy":{"id":"c26029b3-e270-443d-b93c-18ef3688295a","name":"AWS Data Processing Addendum","type":"dpa","jurisdiction":"Global","sourceUrl":"https://docs.aws.amazon.com/whitepapers/latest/navigating-gdpr-compliance/aws-data-processing-addendum-dpa.html"},"sourceConfidence":{"state":"review-required","lastCheckedAt":"2026-07-06T09:39:08.880Z","retrievalChannel":"other","dataStatus":"Available","publicSnapshotEvidence":true,"limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"snapshots":{"old":null,"current":{"version":1,"sha256":"f2252a5b890943c3c0bd2133d7cdded29fafacff96aea55a01dd3bfd1e3b91ee","capturedAt":"2026-07-06T22:22:37.328Z"}},"assessment":{"summary":"AWS DPA automatically ensures GDPR compliance globally, strengthens data protection against government requests, and uses SCCs for international transfers.","overallRisk":"Low","overallScore":9,"previousPublicChange":null,"scoreDelta":null,"direction":"baseline","reasons":[{"icon":"info","textEn":"Automatic GDPR-compliant DPA for all customers globally.","textIt":"DPA conforme al GDPR automatico per tutti i clienti globali.","deltaScore":2,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"info","textEn":"Strong commitments to resist governmental data requests.","textIt":"Forti impegni a resistere alle richieste governative di dati.","deltaScore":2,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"info","textEn":"Clear framework with SCCs for international data transfers.","textIt":"Chiaro framework con SCC per i trasferimenti internazionali di dati.","deltaScore":2,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"}],"keyPoints":[{"textEn":"AWS DPA automatically applies globally, ensuring GDPR compliance for all customer data processing.","textIt":"Il DPA di AWS si applica automaticamente a livello globale, garantendo la conformità al GDPR per il trattamento dei dati dei clienti.","sentiment":"positive"},{"textEn":"Strengthened commitments protect customer data from governmental requests, challenging broad demands.","textIt":"Impegni rafforzati proteggono i dati dei clienti dalle richieste governative, contestando quelle eccessive.","sentiment":"positive"},{"textEn":"Standard Contractual Clauses (SCCs) are used for lawful international data transfers outside the EU.","textIt":"Le Clausole Contrattuali Standard (SCC) sono utilizzate per trasferimenti internazionali di dati legali al di fuori dell'UE.","sentiment":"positive"},{"textEn":"A shared responsibility model clarifies roles for secure data transfers, with AWS providing safeguards.","textIt":"Un modello di responsabilità condivisa chiarisce i ruoli per trasferimenti sicuri, con AWS che fornisce garanzie.","sentiment":"positive"},{"textEn":"Customers get a 6-step EDPB-based process to assess and secure their data transfers effectively.","textIt":"I clienti ricevono un processo in 6 fasi basato sull'EDPB per valutare e proteggere efficacemente i loro trasferimenti di dati.","sentiment":"positive"}],"regionImpacts":[{"region":"EU","perspective":"Enterprise","riskLevel":"Low","impactAnalysisEn":"Enterprises gain a clear framework for GDPR compliance, including SCCs for international transfers and a shared responsibility model, simplifying their obligations.","complianceNoteEn":"GDPR Art 28, SCCs"},{"region":"EU","perspective":"Individual","riskLevel":"Low","impactAnalysisEn":"Individuals benefit from strong GDPR compliance and robust protections against governmental data access, ensuring their data is handled with care.","complianceNoteEn":"GDPR Art 46, EDPB Guidance"},{"region":"Global","perspective":"Enterprise","riskLevel":"Low","impactAnalysisEn":"Global enterprises receive a standardized, automatically applied DPA that helps manage compliance across diverse jurisdictions, reducing operational complexity.","complianceNoteEn":"Cross-border Operations"},{"region":"Global","perspective":"Individual","riskLevel":"Low","impactAnalysisEn":"Individuals worldwide benefit from AWS's commitment to strong data protection and resistance to overreaching governmental requests, enhancing trust.","complianceNoteEn":"Global Data Protection"},{"region":"US","perspective":"Enterprise","riskLevel":"Low","impactAnalysisEn":"US enterprises operating globally can leverage this DPA to meet international compliance standards, especially for data processed for EU customers.","complianceNoteEn":"Global Compliance"},{"region":"US","perspective":"Individual","riskLevel":"Low","impactAnalysisEn":"While primarily GDPR-focused, the DPA's strong data protection commitments indirectly benefit US individuals by promoting higher data security standards.","complianceNoteEn":"CCPA/CPRA (indirect)"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts.","mappings":[{"framework":{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 (EU AI Act)","shortName":"EU AI Act","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","referenceVersion":"Official Journal text, 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?","kpiFields":["kpiAiTrainingOptOut","kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness"]},"status":"not-assessed","assessedCount":0,"mappedFieldCount":4,"evidence":[]},{"framework":{"id":"iso-42001","name":"ISO/IEC 42001:2023","shortName":"ISO/IEC 42001","referenceUrl":"https://www.iso.org/standard/42001","referenceVersion":"ISO/IEC 42001:2023 overview","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?","kpiFields":["kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit","kpiRegulatoryCompliance"]},"status":"mapped","assessedCount":2,"mappedFieldCount":4,"evidence":[{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"},{"field":"kpiRegulatoryCompliance","label":"Regulatory compliance","value":"Comprehensive"}]},{"framework":{"id":"nist-ai-rmf","name":"NIST AI Risk Management Framework 1.0","shortName":"NIST AI RMF","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?","kpiFields":["kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness","kpiContentModeration"]},"status":"not-assessed","assessedCount":0,"mappedFieldCount":4,"evidence":[]},{"framework":{"id":"oecd-ai-principles","name":"OECD AI Principles","shortName":"OECD AI Principles","referenceUrl":"https://oecd.ai/en/ai-principles","referenceVersion":"OECD AI Principles, updated 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?","kpiFields":["kpiConsentMechanism","kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit"]},"status":"mapped","assessedCount":1,"mappedFieldCount":4,"evidence":[{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"}]}]},"humanReviewQuestions":["Does the original AWS Data Processing Addendum source still match the recorded public snapshot version 1?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"methodologyUrl":"https://policywatcher.online/methodology/confidence","changeUrl":"https://policywatcher.online/change/5ba2f740-f2df-442d-af42-b68f291f9bc9","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged.","contentDigest":"627b88f7859ec5450fda1d11099df67234ec18f31d64b7097d8d37b728f43b03"}