Protecting data is our ongoing commitment to EU customers

Latest news and updates

Protect your data

Earning customer trust is the foundation of our business at AWS and we know you trust us to protect your most critical and sensitive assets: your data. We work closely with you to understand your data protection needs, and offer the most comprehensive set of services, tooling, and resources to help protect your data. To do this, we provide technical, operational, and contractual measures needed to protect your data. With AWS, you manage the privacy controls of your data, control how your data is used, determine who has access, and how it is encrypted. We underpin these capabilities with the most flexible and secure cloud computing environment available today.

Veolia Group Delivers Innovation and Enhanced Security on AWS

Organisations using AWS technology can comply with EU regulations

With AWS, you can improve your ability to meet core security and EU data privacy compliance requirements, such as handling data subject requests, managing personal data breach notifications, performing data protection impact assessments, and setting technical and organisational measures with respect to the processing of your data. We also provide you with guidance to maintain compliance, plus we offer a large network of AWS partners who can help manage your compliance for you. We support industry initiatives such as GAIA-X to define standards for the next generation of data infrastructure. We supported GAIA-X from the start and contributed to technical working groups during its’ formation. We support the Cloud Infrastructure Services Providers in Europe (CISPE) Code of Conduct. We help you meet European laws and standards and achieve the highest levels of security, privacy, and resilience.

Flemish Government

The IT Shared Service Centre of the Flemish Government uses AWS to help citizens maintain control of their data and digitally access government services.

SecureAppbox

SecureAppbox helps organisations manage sensitive data and comply with General Data Protection Regulation (GDPR).

Our commitments to protect EU customer data

Data control

With AWS, you control your data by using powerful AWS services and tools that allow you to determine where your data is, how it is secured, and who has access to it. Services such as AWS Identity and Access Management (IAM) allow you to securely manage access to AWS services and resources. Powerful AWS services, such as AWS CloudTrail and Amazon Macie enable governance, compliance, detection, and auditing, while AWS CloudHSM and AWS Key Management Service (KMS) allow you to securely generate and manage encryption keys.

Data privacy

We continuously raise the bar on privacy safeguards with services and features that let you to implement your own privacy controls, including advanced access control, encryption, and logging features. We make it easy to encrypt data in transit and at rest using keys either managed by AWS or fully managed by you. You can bring your own keys that were generated and managed outside of AWS. We implement consistent and scalable processes to manage privacy, including how data is collected, used, accessed, stored, and deleted. We provide a wide variety of best practice documents, training, and guidance that you can leverage to protect your data, such as the Security Pillar of the AWS Well-Architected Framework. We only process customer data – that is any personal data you upload to your AWS account - under your documented instructions and do not access, use, or share your content without your agreement, as described in our AWS Customer Agreement and AWS GDPR Data Processing Addendum (AWS GDPR DPA). Thousands of customers who are subject to GDPR use AWS services for these types of workloads. We have achieved internationally-recognized certifications and accreditations, demonstrating compliance with rigorous international standards, such as ISO 27017 for cloud security, ISO 27701 for privacy information management, and ISO 27018 for cloud privacy. We do not use customer data or derive information from it for marketing or advertising purposes.
 
Learn more at our Data Privacy Centre.

Data sovereignty

You can choose to store your customer data in any one or more of our European Regions, including in France, Germany, Ireland, Italy, Sweden; and in Spain from 2022. You can also use AWS services with the confidence that customer data stays in the AWS Region you select.  A small number of AWS services involve the transfer of data, for example, to develop and improve those services, where you can opt-out of the transfer, or because transfer is an essential part of the service (such as a content delivery service). We prohibit -- and our systems are designed to prevent -- remote access by AWS personnel to customer data for any purpose, including service maintenance, unless that access is requested by you or unless access is required to prevent fraud and abuse, or to comply with law. We are committed to important EU privacy, portability, and digital sovereignty programmes -- including Cloud Infrastructure Services Providers in Europe (CISPECode of Conduct, the European Commission Standard Contractual Clauses (SCC), the SWIPO Infrastructure as a Service (IaaS) Code of Conduct, and GAIA-X.

Our contracts are written in plain, straightforward language and include commitments that go beyond those available from other cloud providers to protect customer data. Our strengthened commitments to you build on our long track record of challenging law enforcement requests. If we receive a law enforcement request for customer data from government bodies, whether inside or outside the European Economic Area (EEA), we commit to challenge requests that are overbroad, or where we have any appropriate grounds to do so, including where the request conflicts with EU law, as described in our supplementary addendum to the AWS GDPR DPA. We also provide a bi-annual Information Request Report describing the types and number of information requests AWS receives from law enforcement.

We are transparent about our commitments to protect our EU customers’ data. Our GDPR Data Processing Addendum, including Standard Contractual Clauses, automatically applies for our customers who are subject to General Data Protection Regulation (GDPR). As part of our continued commitments, we offer Privacy Features of AWS Services resources to help you to determine whether the maintenance and provision of our services to you may involve customer data being transferred outside of the AWS Region in which you chose to store customer data. These resources make it easier for you to comply (and demonstrate compliance) with regulations, including GDPR. They also help you complete your data transfer assessments in accordance with recommendations from the European Data Protection Board (EDPB) on transferring personal data in compliance with “Schrems II”. You can select to use AWS services that only store and process customer data in the EU. Links are available on our GDPR Center.

Security

At AWS, security is our top priority and security in the cloud is a shared responsibility between AWS and our customer. You can improve your ability to meet core security, confidentiality, and compliance requirements with our comprehensive services, whether that's through Amazon GuardDuty or our AWS Nitro System, the underlying platform for our EC2 instances. In addition, services such as AWS CloudHSM and AWS Key Management Service, allow you to securely generate and manage encryption keys, and AWS Config and AWS CloudTrail deliver monitoring and logging capabilities for compliance and audits.

We comply with internationally recognized standards such as Cloud Computing Compliance Controls Catalog (C5) and Esquema Nacional de Seguridad (ENS). We also achieved certifications including PCI-DSS, Hébergement de Données de Santé (HDS, France), and TISAX (EU Automotive), helping satisfy compliance requirements for regulatory agencies across the EU. Financial services providers, healthcare providers, and governmental agencies are among the customers, who trust us with some of their most sensitive information.

We invest in the economic, technological, environmental, and social fabric of the EU

We work with our EU customers to securely bring their most sensitive and regulated data to the cloud. Thousands of the EU's fastest growing start-ups, largest enterprises, and governments are using AWS to innovate faster and to better serve their customers and EU citizens.
 
Our products and services positively transform the everyday lives of people in the EU by enabling the democratisation of technology, empowering scientific discovery, helping communities recover from COVID-19, and more. We drive economic development through investing in infrastructure, jobs, and skills in communities and countries across the EU. We also support a vast ecosystem of startups, SMBs, large enterprises, government organisations, and partners who use AWS to help you grow your business and serve customers in Europe and around the world. We made a commitment to achieving net zero carbon by 2040 and are on a path to powering our operations with 100% renewable energy by 2025. We support the EU’s Green Deal and help our customers achieve their own sustainability targets.
Siemens

Siemens

Siemens uses an array of AWS services to carry on that tradition of transformation—bringing IOT to railways and factories, developing intelligent infrastructure for buildings and distributed energy systems, implementing Artificial Intelligence into its cybersecurity platform, and more.

SNCF Réseau

SNCF Réseau

SNCF Réseau determined that the breadth of AWS managed services met the company’s expectations for accelerating the implementation of its Smart Data strategy—a sweeping new approach to collecting and quickly analysing data relevant to the maintenance of SNCF rails using smart sensors in near real time.

EU customers rely on AWS to innovate and grow

  • Public Sector
  • Healthcare
  • Media and Entertainment
  • Energy
  • Retail and Manufacturing
  • Finance
  • Public Sector
  • Argo Software
    MADI SOFT
    PEGASO
    INAF
    CRUI
    Politecnico di Milano
    INAF
    Politecnico di Torino
  • Healthcare
  • a2a
    ItaliAssistenza
    a2a
    Dante labs
    a2a
    Bayer
    a2a
    Munich Leukemia Lab
  • Media and Entertainment
  • Arneg
    quadronica
    Casa.it
    tre altamira
    Vini Franchetti
    Unox
    milestone
    NVP
  • Energy
  • amiu
    ICA
    City of Cagliari
    Open Content
    Consortium of Trentino Municipalities
    Studio Storti
  • Retail and Manufacturing
  • Banca Progetto
    Nexi
    Credimi
    Satispay
    Reale Mutua
    Nexi
  • Finance
  • Centro Medico Santagostino
    Elco
    Dante labs
    GEK
    Dedalus
    GPI
Data Privacy Center

Data Privacy Center

At AWS, we earn trust by working to meet our customers’ privacy needs and being transparent in our privacy commitments.

GDPR Center

GDPR Center

AWS is committed to offering services and resources to our customers to help them comply with the GDPR requirements.

Data transfer blog

Confidential computing: an AWS perspective

We’ve made many long-term investments in purpose-built technologies and systems to keep raising the bar of security and confidentiality for our customers.

Privacy Features of AWS Services

Privacy Features of AWS Services

We are transparent about how AWS services process the presonal data you upload to your AWS account and we provide capabilities that allow you to encrypt, delete, and monitor the processing of your customer data.

Data Protection

Data Protection

Earning customer trust is the foundation of our business at AWS and we know you trust us to protect your most critical and sensitive assets: your data.