Skip to main content

AWS Cloud Security

  • AWS
  • Security, Identity, and Compliance

Privacy Features of AWS Services

AWS is vigilant about your privacy, and we provide the most flexible and secure cloud computing environment available today. With AWS, you own your data, you control its location, and you control who has access to it. We are transparent about how AWS services process the personal data you upload to your AWS account (customer data), and we provide capabilities that allow you to encrypt, delete, and monitor the processing of your customer data.

You can use AWS services with the confidence that your customer data stays in the AWS Region you select. A small number of AWS services involve the transfer of customer data, for example, to develop and improve those services, where you can opt-out of the transfer, or because transfer is an essential part of the service (such as a content delivery service). We prohibit, and our systems are designed to prevent, remote access by AWS personnel to customer data for any purpose, including service maintenance, unless access is requested by you, is required to prevent fraud and abuse, or to comply with law. For more information on how AWS designs its systems to prevent unauthorized access by AWS personnel to customer data, you can learn more on our webpage for Operator Access on AWS.

Below we provide an overview of the key privacy features of AWS Services, which you can use to perform data transfer assessments in accordance with the Schrems II decision of the Court of Justice of the European Union, and the European Data Protection Board Recommendations 01/2020 on measures that supplement transfer tools. For more information, please see our whitepaper on Navigating GDPR Compliance on AWS.

See the AWS Security Documentation for more information about how the AWS services listed below enable customers to encrypt, delete, and monitor the processing of their customer data.

AWS service Customer can encrypt Customer can delete Customer can monitor processing No remote access*
Amazon API Gateway
Amazon AppFlow
Amazon AppStream 2.0
Amazon AppStream 2.0 User Pools
Amazon Athena
Amazon Augmented AI (A2I)
Amazon Aurora
Amazon Bedrock1
Amazon Braket
Amazon Chime
Amazon Cloud Directory
Amazon CloudFront
Amazon CloudWatch
Amazon CloudWatch Logs

Amazon CodeGuru Profiler
Amazon CodeGuru Reviewer
Amazon Cognito
Amazon Comprehend
Amazon Connect2
Amazon Detective
Amazon DocumentDB (with MongoDB compatibility)
Amazon DynamoDB
Amazon Elastic Block Store (Amazon EBS)
Amazon Elastic Compute Cloud (Amazon EC2)
Amazon Elastic Container Registry (Amazon ECR)

Amazon Elastic Container Service (Amazon ECS)
Amazon Elastic File System (Amazon EFS)


Amazon Elastic Kubernetes Service (Amazon EKS)


Amazon ElastiCache for Memcached3 2

Amazon ElastiCache for Redis


Amazon EMR


Amazon EventBridge


Amazon Forecast

Amazon Fraud Detector


Amazon FSx for Lustre

Amazon FSx for ONTAP


Amazon FSx for OpenZFS


Amazon FSx for Windows File Server


Amazon GameLift


Amazon GuardDuty


Amazon Healthlake
Amazon Inspector


Amazon Inspector Classic


Amazon Interactive Video Service (IVS)


Amazon Kendra


Amazon Keyspaces
Amazon Managed Service for Apache Flink for Java Applications


Amazon Managed Service for Apache Flink for SQL Applications


Amazon Kinesis Data Firehose


Amazon Kinesis Data Streams


Amazon Kinesis VideoStreams


Amazon Lex


Amazon Lightsail


Amazon Location Service


Amazon Macie


Amazon Managed Blockchain (AMB)


Amazon Managed Service for Grafana (AMG)


Amazon Managed Service for Prometheus (AMP)


Amazon Managed Streaming for Kafka (MSK)


Amazon Managed Workflows for Apache Airflow (MWAA) 


Amazon MemoryDB for Redis


Amazon MQ


Amazon Neptune


Amazon OpenSearch Service 
Amazon Personalize
Amazon Pinpoint
Amazon Polly
Amazon Q Business
Amazon Q Developer
Amazon QuickSight2
Amazon Redshift
Amazon Rekognition


Amazon Relational Database Service (Amazon RDS)


Amazon SageMaker

Amazon Simple Email Service (Amazon SES)


Amazon Simple Notification Service (Amazon SNS)


Amazon Simple Queue Service (Amazon SQS)
Amazon Simple Storage Service (Amazon S3)


Amazon Simple Storage Service Glacier


Amazon Simple Workflow Service (Amazon SWF)


Amazon Textract


Amazon Timestream


Amazon Transcribe



Amazon Translate


Amazon Virtual Private Cloud (Amazon VPC)


Amazon WorkDocs


Amazon WorkLink


Amazon WorkMail


Amazon WorkSpaces



Amazon WorkSpaces Application Manager (Amazon WAM)


AWS Amplify


AWS App Mesh


AWS App Runner 

AWS Application Discovery Service



AWS Application Migration Service



AWS AppSync



AWS Audit Manager



AWS Backup



AWS Certificate Manager (ACM)



AWS Clean Rooms



AWS Cloud9



AWS CloudFormation



AWS CloudHSM



AWS CloudShell



AWS CloudTrail



AWS CodeArtifact


AWS CodeBuild



AWS CodeCommit



AWS CodeDeploy



AWS CodePipeline



AWS CodeStar



AWS Config



AWS Control Tower



AWS Database Migration Service (AWS DMS) 



AWS Data Exchange



AWS DataSync



AWS Device Farm



AWS Direct Connect



AWS Directory Service



AWS Elastic Beanstalk



AWS Elastic Disaster Recovery



AWS Elastic Transcoder



AWS Elemental MediaConnect



AWS Elemental MediaConvert




AWS Elemental MediaLive




AWS Elemental MediaPackage



AWS Elemental MediaStore



AWS Entity Resolution



AWS Fargate



AWS Firewall Manager



AWS Global Accelerator



AWS Glue



AWS Glue DataBrew



AWS IAM Identity Center



AWS IoT Analytics



AWS IoT Core



AWS IoT Device Management



AWS IoT Events



AWS IoT Greengrass V1




AWS IoT Greengrass V2



AWS IoT SiteWise



AWS IoT Things Graph



AWS IQ



AWS Key Management Service (AWS KMS)



AWS Lake Formation



AWS Lambda



AWS License Manager



AWS Migration Hub



AWS Outposts



AWS Secrets Manager



AWS Security Hub CPSM



AWS Security Hub



AWS Serverless Application Repository




AWS Service Catalog



AWS Snowball Edge




AWS Snowcone



AWS Snowmobile



AWS Step Functions



AWS Storage Gateway for FSx File Gateway



AWS Storage Gateway for S3 File Gateway



AWS Storage Gateway for Tape Gateway



AWS Storage Gateway for Volume Gateway



AWS Supply Chain2


AWS Systems Manager



AWS Transfer Family



AWS Transform



AWS WAF



AWS X-Ray



CloudEndure Disaster Recovery (an AWS Company)



CloudEndure Migration (an AWS Company)



FreeRTOS



Kiro



* Unless access is requested by you, is required to prevent fraud and abuse, or to comply with law.

1 Processing occurs in conjunction with the foundational model (FM) you choose.

2 See the applicable service documentation for information about Amazon Q.

3 Amazon ElastiCache for Memcached supports encryption in transit. By design, Memcached doesn’t provide persistent disk storage, and only stores data in memory for the time needed for customer’s application. ElastiCache also supports memory encryption when choosing Graviton instances of family types r6g and m6g. All data-storing AWS services offer encryption.

Transfers of Customer Data

For a small subset of services it is an essential function of the service that data is transferred from the AWS Region you have selected. For example, if you choose to send messages via Amazon Simple Notification Service to a recipient, the content of those messages will be transferred to the location of the recipients. See below for a list of similar AWS services.

  • Amazon AppStream 2.0 User Pool
  • Amazon Chime
  • Amazon CloudFront
  • Amazon Cognito*
  • AWS IAM Identity Center**
  • Amazon Interactive Video Service (IVS)
  • Amazon Location Service
  • AWS End User Messaging (formerly Amazon Pinpoint)
  • Amazon Simple Email Service
  • Amazon Simple Notification Service
  • Amazon WorkMail
  • AWS Elemental MediaConnect
  • AWS IoT Core***

* In certain circumstances, Amazon Cognito uses Amazon Simple Email Service (Amazon SES) to send user emails and Amazon Simple Notification Service (Amazon SNS) to send user SMS text messages. If Amazon SES is not available in Region, Amazon Cognito calls Amazon SES’ endpoints in a different AWS Region. More information can be found here. Similarly, if Amazon SNS is not available in Region, Amazon Cognito calls Amazon SNS’ endpoints in a different AWS Region. More information can be found here.
** In certain circumstances, AWS IAM Identity Center uses Amazon Simple Email Service (Amazon SES) to send user emails. If Amazon SES is not available in Region, IAM Identity Center calls Amazon SES’ endpoints in a different AWS Region. More information can be found here.
***  To the extent you use the IoT Core for Amazon Sidewalk feature, or the Device Location feature supported by HERE is enabled.

In addition, some of our services use cross-region inference to improve performance or for other technical reasons, such as to help customers scale their generative AI workloads. See here for more information on cross-region inference services and AWS documentation.

Some AWS services can involve the transfer of customer data to develop and improve those services. You can opt out of these transfers by using the opt-out mechanisms indicated in the applicable Service Terms or AWS documentation.

  • Amazon CodeGuru Profiler
  • Amazon Comprehend
  • Amazon Connect*
  • Amazon Fraud Detector
  • Amazon GuardDuty**
  • Amazon Lex
  • Amazon Polly
  • Amazon Q Developer Free Tier
  • Amazon Rekognition
  • Amazon SageMaker Data Agent
  • Amazon Textract
  • Amazon Transcribe
  • Amazon Translate
  • AWS Entity Resolution
  • AWS Security Hub
  • AWS Supply Chain
  • AWS Transform
  • Kiro Free Tier / Individual subscribers

* This entry encompasses, for example, Contact Lens for Amazon Connect, Amazon Connect Customer Profiles, Amazon Connect outbound campaigns, Amazon Q in Connect, and Amazon Connect Forecasting, Capatcity Planning, and Scheduling. See Service Term 54.7.
** This AWS service will involve a transfer to the extent you have enabled the new Amazon GuardDuty Malware Protection feature.

AWS European Sovereign Cloud

For the AWS European Sovereign Cloud, moving data out of your selected AWS Region or remote access by AWS personnel is restricted even further than as described above, as explained in the white paper Overview of the AWS European Sovereign Cloud and the AWS European Sovereign Cloud Addendum.