Privacy Features of AWS Services

AWS is vigilant about your privacy, and we provide the most flexible and secure cloud computing environment available today. With AWS, you own your data, you control its location, and you control who has access to it. We are transparent about how AWS services process the personal data you upload to your AWS account (customer data), and we provide capabilities that allow you to encrypt, delete, and monitor the processing of your customer data.

You can use AWS services with the confidence that your customer data stays in the AWS Region you select. A small number of AWS services involve the transfer of customer data, for example, to develop and improve those services, where you can opt-out of the transfer, or because transfer is an essential part of the service (such as a content delivery service). We prohibit, and our systems are designed to prevent, remote access by AWS personnel to customer data for any purpose, including service maintenance, unless access is requested by you, is required to prevent fraud and abuse, or to comply with law.

Below we provide an overview of the key privacy features of AWS Services which you can use to perform data transfer assessments in accordance with the Schrems II decision of the Court of Justice of the European Union, and the European Data Protection Board Recommendations on measures that supplement transfer tools.  

You can click on the underlined check marks in the below table for AWS documentation about how AWS services enable customers to encrypt, delete, and monitor the processing of their customer data.

AWS service Customer can encrypt Customer can delete Customer can monitor processing No remote access*
Alexa for Business
Amazon API Gateway
Amazon AppFlow
Amazon AppStream 2.0
Amazon AppStream 2.0 User Pools
Amazon Athena
Amazon Augmented AI (A2I)
Amazon Aurora
Amazon Braket
Amazon Chime
Amazon Cloud Directory
Amazon CloudFront
Amazon CloudWatch
Amazon CloudWatch Logs
Amazon CodeGuru Profiler
Amazon CodeGuru Reviewer
Amazon Cognito
Amazon Comprehend
Amazon Connect
Amazon Detective
Amazon DynamoDB
Amazon Elastic Block Store (Amazon EBS)
Amazon Elastic Compute Cloud (Amazon EC2)
Amazon Elastic Container Registry (Amazon ECR)
Amazon Elastic Container Service (Amazon ECS)
Amazon Elastic File System (Amazon EFS)
Amazon Elastic Inference
Amazon Elastic Kubernetes Service (Amazon EKS)
Amazon ElastiCache for Memcached  
Amazon ElastiCache for Redis
Amazon Elasticsearch Service (Amazon ES)
Amazon EMR
Amazon EventBridge
Amazon Forecast
Amazon Fraud Detector
Amazon FSx for Lustre
Amazon FSx for Windows File Server
Amazon GameLift
Amazon GuardDuty
Amazon Honeycode
Amazon Inspector
Amazon Interactive Video Service (IVS)
Amazon Kendra
Amazon Keyspaces
Amazon Kinesis Data Analytics for Java Applications
Amazon Kinesis Data Analytics for SQL Applications
Amazon Kinesis Data Firehose
Amazon Kinesis Data Streams
Amazon Kinesis VideoStreams
Amazon Lex
Amazon Lightsail
Amazon Location Service
Amazon Lookout for Equipment
Amazon Lookout for Metrics
Amazon Lookout for Vision
Amazon Macie
Amazon Managed Blockchain (AMB)
Amazon Managed Service for Grafana (AMG)
Amazon Managed Service for Prometheus (AMP)
Amazon Managed Streaming for Kafka (MSK)
Amazon MQ
Amazon Neptune
Amazon Personalize
Amazon Pinpoint
Amazon Polly
Amazon Quantum Ledger Database (QLDB)
Amazon QuickSight
Amazon Redshift
Amazon Rekognition
Amazon Relation Database Service (Amazon RDS)
Amazon SageMaker
Amazon Simple Email Service (Amazon SES)
Amazon Simple Notification Service (Amazon SNS)
Amazon Simple Queue Service (Amazon SQS)
Amazon Simple Storage Service (Amazon S3)
Amazon Simple Storage Service Glacier
Amazon Simple Workflow Service (Amazon SWF)
Amazon Textract
Amazon Timestream
Amazon Transcribe
Amazon Translate
Amazon Virtual Private Cloud (Amazon VPC)
Amazon WorkDocs
Amazon WorkLink
Amazon WorkMail
Amazon WorkSpaces
Amazon WorkSpaces Application Manager (Amazon WAM)
AWS Amplify
AWS App Mesh
AWS App Runner 
AWS Application Discovery Service
AWS Application Migration Service
AWS AppSync
AWS Audit Manager
AWS Backup
AWS Certificate Manager (ACM)
AWS Cloud9
AWS CloudFormation
AWS CloudHSM
AWS CloudShell
AWS CloudTrail
AWS CodeArtifact
AWS CodeBuild
AWS CodeCommit
AWS CodeDeploy
AWS CodePipeline
AWS CodeStar
AWS Config
AWS Control Tower
AWS Data Exchange
AWS DataSync
AWS Device Farm
AWS Direct Connect
AWS Directory Service
AWS Elastic Beanstalk
AWS Elastic Transcoder
AWS Elemental MediaConnect
AWS Elemental MediaConvert
AWS Elemental MediaLive
AWS Elemental MediaPackage
AWS Elemental MediaStore
AWS Fargate
AWS Firewall Manager
AWS Global Accelerator
AWS Glue
AWS Identity and Access Management (IAM)
AWS Import/Export
AWS IoT Analytics
AWS IoT Core
AWS IoT Device Management
AWS IoT Events
AWS IoT Greengrass V1



AWS IoT Greengrass V2
AWS IoT SiteWise
AWS IoT Things Graph
AWS IQ
AWS Key Management Service (AWS KMS)
AWS Lake Formation
AWS Lambda
AWS License Manager
AWS Migration Hub
AWS OpsWorks for Chef Automate
AWS OpsWorks for Puppet Enterprise
AWS OpsWorks Stacks
AWS Outposts
AWS RoboMaker
AWS Secrets Manager
AWS Security Hub


AWS Server Migration Service (AWS SMS)
AWS Serverless Application Repository
AWS Service Catalog
AWS Single Sign-On (SSO)
AWS Snowball Edge
AWS Snowcone
AWS Snowmobile
AWS Step Functions
AWS Storage Gateway for FSx File Gateway
AWS Storage Gateway for S3 File Gateway
AWS Storage Gateway for Tape Gateway
AWS Storage Gateway for Volume Gateway
AWS Systems Manager
AWS Transfer Family
AWS X-Ray
CloudEndure Disaster Recovery (An AWS Company)
CloudEndure Migration(An AWS Company)
Contact Lens for Amazon Connect
FreeRTOS

*Unless access is requested by you, is required to prevent fraud and abuse, or to comply with law.

AWS services that allow customers to opt-out of transfers of customer data

The following AWS services transfer customer data to develop and improve those services, and you can opt out of that transfer.  

  • Amazon CodeGuru Profiler
  • Amazon Comprehend
  • Amazon Connect Customer Profiles for Identity Resolution
  • Amazon Fraud Detector
  • Amazon Lex
  • Amazon Polly
  • Amazon Rekognition
  • Amazon Textract
  • Amazon Transcribe
  • Amazon Translate
  • Contact Lens for Amazon Connect

AWS services that transfer customer data as an essential function of the service

The following AWS services transfer customer data as an essential function of the service. For example, if you choose to send messages via Amazon Simple Notification Service, the content of those messages will transfer to the location of the recipients.  

  • Alexa for Business
  • Amazon AppStream 2.0 User Pool
  • Amazon Chime
  • Amazon CloudFront
  • AWS Elemental MediaConnect
  • Amazon Location Service
  • Amazon Pinpoint
  • Amazon Simple Email Service
  • Amazon Simple Notification Service
compliance-contactus-icon
Have Questions? Connect with an AWS Business Representative
Exploring compliance roles?
Apply today »
Want AWS Compliance updates?
Follow us on Twitter »