Amazon

Last Reviewed: 01 Jun 2026

GDPR Addressed

At a Glance

AWS's DPA addresses the key GDPR requirements, covering EU, UK, Swiss and US requirements with SCCs and processor-only restrictions in place. Audit rights are structured: customers access certifications and SOC reports rather than direct on-site inspections, but all material provisions are satisfied.

Company & Product Details

HQ

United States

Products

AWS cloud infrastructure / hosting services

Product description

Cloud infrastructure, storage, compute, database and related managed services.

What data is being processed?

Customer Data uploaded to AWS accounts. This can include any categories of personal data depending on the customer workload and services used.

Document Details

Date of DPA

27 Jul 2023

Additional date information

No explicit date is stated within the document text. Date derived from PDF metadata (CreationDate: 2023-07-27). Previously stored date was 2026-03-16, which appears inconsistent with the current PDF at the stored URL; that date may have been sourced from the AWS Service Terms page or a prior version of the document.

What jurisdictions are covered?

EU GDPR, UK GDPR, Swiss FADP, CCPA/CPRA (via incorporated terms/addenda).

Is the DPA incorporated into service or customer agreements?

Yes
The DPA, supplementary addendum, SCCs, UK addendum, Swiss addendum and CCPA terms are incorporated into the AWS Service Terms.

Location & Transfers

Where is data held or processed?

Customer Selected Customer can select AWS Region(s), including EEA Regions. Sub-processors may process from other locations used to provide or maintain the services.

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
AWS Service Terms incorporate EU SCCs (controller-to-processor and processor-to-processor), the AWS UK GDPR Addendum, the AWS Swiss Addendum and AWS CCPA Terms. See: https://aws.amazon.com/service-terms/

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Technical and organisational measures are described in the DPA, AWS Security Standards and audit materials. Includes network/facility security, access controls, regular testing and external certifications/reports (ISO 27001/27017/27018/27701 and SOC 1/2/3).

Non Processor Data Use

Does the company process data solely as a processor?

Yes
The DPA explicitly restricts AWS to acting solely as a data processor on Customer documented instructions. AWS will not access, use, or disclose Customer Data except as necessary to maintain or provide the Services, or to comply with law or a valid governmental order. No language granting AWS independent controller rights or the ability to use Customer Data for its own purposes was found in the document (clauses 1.1, 3).

Subprocessing

General authorization

General
AWS publishes a sub-processor list and gives at least 30 days' notice before engaging a new sub-processor: https://aws.amazon.com/compliance/sub-processors/

Do all the DPA terms flow down to sub-processors?

Yes
To the extent a sub-processor performs the same processing services, AWS must impose the same contractual obligations and remains responsible.

Is data only processed on the instruction of the controller?

Yes
The DPA and Agreement (including customer instructions via configuration tools / console / APIs) constitute documented instructions.

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
AWS provides assistance mainly through Service Controls and by forwarding identified data subject requests.

Does the contract include staff confidentiality clauses?

Yes
AWS imposes appropriate contractual obligations on personnel, including confidentiality, data protection and data security obligations.

Are there audit rights for the data?

Structured
AWS provides certifications, SOC reports and audit reports under NDA and uses external annual audits. Customer audit rights are channelled through AWS' audit framework rather than broad open-ended inspection rights.

Is there assistance with DPIA requests?

Yes
AWS assists with data protection impact assessments and prior consultation by providing information made available under the DPA audit / compliance provisions.

How much notice is provided for data breaches?

Without undue delay after AWS becomes aware of a Security Incident.

What happens to the data on termination?

Customers may request return or deletion of Customer Data at any time up to the termination date and for 90 days following the termination date, using AWS Service Controls. No later than the end of this 90-day period, Customer must close all AWS accounts containing Customer Data. There is no additional service-level deletion timeline specified in this DPA beyond the 90-day post-termination window; Customer is responsible for initiating return or deletion requests (clause 14).