AWS Data Processing Addendum (DPA)
AWS offers a GDPR-compliant AWS Data Processing Addendum
Customers can transfer their content from Europe to the US and other countries using AWS, in compliance with EU data protection laws, including the GDPR. For example, where AWS customers choose to transfer customer data outside the EU to a country not recognized by the European Commission as providing an adequate level of protection for personal data subject to the GDPR, AWS uses the Standard Contractual Clauses (SCCs) as a data transfer tool to validate such transfers (unless AWS has adopted an alternative recognized compliance standard for lawful data transfers). The SCCs are part of the AWS Service Terms, are incorporated by reference into the AWS DPA, and apply automatically in case of such a data transfer. As the regulatory and legislative landscape evolves, AWS remains committed to ensuring that customers can continue to benefit from AWS globally.
In February 2021, AWS adopted strengthened contractual commitments for protecting customer data. These commitments apply to all customer data processed by AWS, regardless of whether it is transferred outside the European Economic Area (EEA). These commitments are automatically available to all customers using AWS to process their customer data, without any additional action required, through a Supplementary Addendum
The key commitments outlined in the Supplementary Addendum include:
Redirecting governmental requests for customer data directly to customers whenever possible.
Promptly notifying customers if AWS is compelled to disclose customer data (unless prohibited by law), allowing customers time to seek protective measures.
Actively challenging governmental requests that are overly broad, inappropriate, or conflict with EU or applicable EU Member State laws.
Disclosing only the minimal amount of customer data necessary when legally compelled to do so.
AWS outlines a structured framework to clarify the division of responsibilities in the context of international data transfers under the GDPR. This framework reflects current European regulatory expectations and highlights the shared responsibility model. Under this model, customers are responsible for assessing and implementing the technical and organizational measures needed to secure their data transfers, while AWS remains responsible for maintaining contractual and infrastructure-level safeguards.
The framework includes a practical six-step process based on guidance from the European Data Protection Board (EDPB), which is the independent EU body composed of representatives from national data protection authorities and the European Data Protection Supervisor. The steps help customers: (1) map data transfers; (2) identify the legal transfer mechanism in use (such as SCCs); (3) assess the laws and practices of destination countries; (4) implement supplementary safeguards where necessary; (5) document procedural steps; and (6) reassess risk periodically.
AWS supports customers in this process by offering a set of technical, organizational, and contractual safeguards, such as encryption, data residency controls, and legal commitments to resist overreaching governmental requests. These safeguards help customers meet regulatory expectations and demonstrate accountability. AWS is responsible for implementing and maintaining contractual measures, while customers are responsible for configuring AWS services to reflect their compliance needs and risk posture.