Amazon
Last Reviewed: 01 Jun 2026
At a Glance
AWS's DPA addresses the key GDPR requirements, covering EU, UK, Swiss and US requirements with SCCs and processor-only restrictions in place. Audit rights are structured: customers access certifications and SOC reports rather than direct on-site inspections, but all material provisions are satisfied.
Company & Product Details
HQ
United States
Products
AWS cloud infrastructure / hosting services
Product description
Cloud infrastructure, storage, compute, database and related managed services.
What data is being processed?
Customer Data uploaded to AWS accounts. This can include any categories of personal data depending on the customer workload and services used.
Document Details
Date of DPA
27 Jul 2023
Additional date information
No explicit date is stated within the document text. Date derived from PDF metadata (CreationDate: 2023-07-27). Previously stored date was 2026-03-16, which appears inconsistent with the current PDF at the stored URL; that date may have been sourced from the AWS Service Terms page or a prior version of the document.
What jurisdictions are covered?
EU GDPR, UK GDPR, Swiss FADP, CCPA/CPRA (via incorporated terms/addenda).
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
Customer Selected Customer can select AWS Region(s), including EEA Regions. Sub-processors may process from other locations used to provide or maintain the services.
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Technical and organisational measures are described in the DPA, AWS Security Standards and audit materials. Includes network/facility security, access controls, regular testing and external certifications/reports (ISO 27001/27017/27018/27701 and SOC 1/2/3).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Without undue delay after AWS becomes aware of a Security Incident.
What happens to the data on termination?
Customers may request return or deletion of Customer Data at any time up to the termination date and for 90 days following the termination date, using AWS Service Controls. No later than the end of this 90-day period, Customer must close all AWS accounts containing Customer Data. There is no additional service-level deletion timeline specified in this DPA beyond the 90-day post-termination window; Customer is responsible for initiating return or deletion requests (clause 14).