View a markdown version of this page

How AWS Can Help - Navigating GDPR Compliance on AWS

How AWS Can Help

Table 1 – How AWS can help you navigate GDPR compliance

Area

Description

AWS Services and Tools

Strong Compliance Framework

Appropriate technical and organizational measures may need to include “the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of the processing systems and services.”

The framework is validated by following certifications and attestations:

SOC 1 / SSAE 16 / ISAE 3402 (formerly SAS 70) / SOC 2 / SOC 3 PCI DSS Level 1 ISO 9001 / ISO 27001 / ISO 27017 / ISO 27018 / ISO 27701 NIST FIPS 140-2 Cloud Computing Compliance Criteria Catalog (C5)

Data Access Control

The controller “…shall implement appropriate technical and organizational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed.”

AWS Identity and Access Management (IAM)

Amazon Cognito

AWS Shield and AWS WAF

AWS Resource Access Manager

Amazon CloudFront

AWS Organizations

AWS CloudTrail

Monitoring, Logging and Records of Processing

“Each controller and, where applicable, the controller’s representative, shall maintain a record of processing activities under its responsibility.” “…the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk […]”

AWS Config

Amazon CloudWatch

AWS Control Tower

Amazon GuardDuty

Amazon Detective

Amazon Inspector

Amazon Macie

AWS Systems Manager

AWS Security Hub

AWS Security Lake

Amazon Security Lake

AWS Tools and SDKs

Protecting your Data on AWS

Organizations must “implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including […] the pseudonymization and encryption of personal data.”

AWS Certificate Manager

AWS CloudHSM

AWS Nitro Systems

Data Protection Impact Assessment (DPIA)

AWS provides services and resources that assist customers in completing their DPIA when using AWS services. The GPDR determines the customer is responsible for determining if a DPIA is required, for choosing an assessment methodology, and for performing the assessment.

AWS Service Terms

AWS Artifact

AWS Compliance Programs

Data Transfer Impact Assessment (DTIA)

The Annex to this whitepaper provides more information for customers that want to perform an assessment on data transfers when using AWS services.

AWS Service Terms

AWS Privacy Features

AWS Sub-Processors webpages

PII Data Discovery

Organizations must identify and classify personal data to implement appropriate protection measures and demonstrate GDPR compliance. AWS provides tools to automatically discover, classify, and monitor personal data across AWS services.

Amazon Macie for automated sensitive data discovery and classification

AWS Glue Data Catalog for data inventory and classification

Amazon EMR for large-scale data processing and analysis

AWS CloudWatch Logs pattern matching for log analysis