AWS DPA automatically ensures GDPR compliance globally, strengthens data protection against government requests, and uses SCCs for international transfers.
AI Analysis
AWS DPA automatically ensures GDPR compliance globally, strengthens data protection against government requests, and uses SCCs for international transfers.
AWS DPA automatically applies globally, ensuring GDPR compliance for all customer data processing.
Strengthened commitments protect customer data from governmental requests, challenging broad demands.
Standard Contractual Clauses (SCCs) are used for lawful international data transfers outside the EU.
A shared responsibility model clarifies roles for secure data transfers, with AWS providing safeguards.
Customers get a 6-step EDPB-based process to assess and secure their data transfers effectively.
Why this score
Automatic GDPR-compliant DPA for all customers globally.+2
Strong commitments to resist governmental data requests.+2
Clear framework with SCCs for international data transfers.+2
What changed
+ # AWS Data Processing Addendum (DPA)
AWS offers a GDPR-compliant AWS Data Processing Addendum (AWS DPA), which enables AWS customers to comply with GDPR contractual obligations. The AWS DPA is incorporated into the AWS Service Terms and applies automatically to all customers globally whenever customers use AWS services to process customer data, regardless of which data protection laws apply to that processing.
Customers can transfer their content from Europe to the US and other countries using AWS, in compliance with EU data protection laws, including the GDPR. For example, where AWS customers choose to transfer customer data outside the EU to a country not recognized by the European Commission as providing an adequate level of protection for personal data subject to the GDPR, AWS uses the Standard Contractual Clauses (SCCs) as a data transfer tool to validate such transfers (unless AWS has adopted an alternative recognized compliance standard for lawful data transfers). The SCCs are part of the AWS Service Terms, are incorporated by reference into the AWS DPA, and apply automatically in case of such a data transfer. As the regulatory and legislative landscape evolves, AWS remains committed to ensuring that customers can continue to benefit from AWS globally.
In February 2021, AWS adopted strengthened contractual commitments for protecting customer data. These commitments apply to all customer data processed by AWS, regardless of whether it is transferred outside the European Economic Area (EEA). These commitments are automatically available to all customers using AWS to process their customer data, without any additional action required, through a Supplementary Addendum to the AWS DPA, which is incorporated in the AWS Service Terms.
The key commitments outlined in the Supplementary Addendum include:
- Redirecting governmental requests for customer data directly to customers whenever possible.
- Promptly notifying customers if AWS is compelled to disclose customer data (unless prohibited by law), allowing customers time to seek protective measures.
- Actively challenging governmental requests that are overly broad, inappropriate, or conflict with EU or applicable EU Member State laws.
- Disclosing only the minimal amount of customer data necessary when legally compelled to do so.
AWS outlines a structured framework to clarify the division of responsibilities in the context of international data transfers under the GDPR. This framework reflects current European regulatory expectations and highlights the shared responsibility model. Under this model, customers are responsible for assessing and implementing the technical and organizational measures needed to secure their data transfers, while AWS remains responsible for maintaining contractual and infrastructure-level safeguards.
The framework includes a practical six-step process based on guidance from the European Data Protection Board (EDPB), which is the independent EU body composed of representatives from national data protection authorities and the European Data Protection Supervisor. The steps help customers: (1) map data transfers; (2) identify the legal transfer mechanism in use (such as SCCs); (3) assess the laws and practices of destination countries; (4) implement supplementary safeguards where necessary; (5) document procedural steps; and (6) reassess risk periodically.
AWS supports customers in this process by offering a set of technical, organizational, and contractual safeguards, such as encryption, data residency controls, and legal commitments to resist overreaching governmental requests. These safeguards help customers meet regulatory expectations and demonstrate accountability. AWS is responsible for implementing and maintaining contractual measures, while customers are responsible for configuring AWS services to reflect their compliance needs and risk posture.
Regional impact
EULow
Individuals benefit from strong GDPR compliance and robust protections against governmental data access, ensuring their data is handled with care.
USLow
While primarily GDPR-focused, the DPA's strong data protection commitments indirectly benefit US individuals by promoting higher data security standards.
GlobalLow
Individuals worldwide benefit from AWS's commitment to strong data protection and resistance to overreaching governmental requests, enhancing trust.