Strong Compliance Framework and Security Standards
The GDPR requires both controllers and processors to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These may include “…the ability to ensure the ongoing confidentiality, integrity, availability and resilience of the processing systems and services,” (Article 32(1)(b) of the GDPR) as well as reliable data restoration, testing, and overall risk management processes.
To support customers in meeting these obligations, AWS maintains a broad compliance framework grounded in international and regional standards. The following sections describe key components of this framework:
AWS Compliance Programs, which include third-party certifications and independent audit reports available through AWS Artifact
. ISO/IEC 27701 certification, which extends AWS's existing security certifications to cover privacy-specific requirements aligned with the GDPR.
Cloud Computing Compliance Criteria Catalogue (C5), a German federal standard that provides structured assurance for operational and cybersecurity practices in cloud environments.
The CISPE Code of Conduct, a GDPR-approved pan-European compliance framework specifically for cloud infrastructure providers, under which over 100 AWS services have been independently certified.
Together, these programs and commitments provide customers with validated evidence of the technical and organizational measures AWS has implemented and form a reliable foundation to support their own GDPR compliance efforts. Each of these elements is detailed in the sections below.