In summary
The customer selects the AWS region in which it stores its customer data. In accordance with the AWS Data Processing Addendum
(AWS DPA), AWS will not transfer customer data outside the customer’s selected AWS region unless it is necessary to provide or maintain the AWS services initiated by the customer, or as necessary to comply with the law or a valid and binding order. Where the customer instructs the AWS services to transfer customer data to third countries, AWS uses the SCCs as a data transfer tool under Chapter V of the GDPR to validate such transfers (unless AWS has adopted an alternative recognized compliance standard for lawful data transfers). The SCCs are part of the AWS Service Terms
, are incorporated by reference into the AWS DPA, and apply automatically in case of a data transfer. AWS takes and makes available additional technical, organizational, and contractual supplementary measures to protect customer data and supplement the SCCs.