Skip to main content

AWS Cloud Security

  • AWSβ€Ί
  • Security, Identity, and Compliance

Privacy Features of AWS Services

AWS is vigilant about your privacy, and we provide the most flexible and secure cloud computing environment available today. With AWS, you own your data, you control its location, and you control who has access to it. We are transparent about how AWS services process the personal data you upload to your AWS account (customer data), and we provide capabilities that allow you to encrypt, delete, and monitor the processing of your customer data.

You can use AWS services with the confidence that your customer data stays in the AWS Region you select. A small number of AWS services involve the transfer of customer data, for example, to develop and improve those services, where you can opt-out of the transfer, or because transfer is an essential part of the service (such as a content delivery service). We prohibit, and our systems are designed to prevent, remote access by AWS personnel to customer data for any purpose, including service maintenance, unless access is requested by you, is required to prevent fraud and abuse, or to comply with law. For more information on how AWS designs its systems to prevent unauthorized access by AWS personnel to customer data, you can learn more on our webpage for Operator Access on AWS.

Below we provide an overview of the key privacy features of AWS Services, which you can use to perform data transfer assessments in accordance with the Schrems II decision of the Court of Justice of the European Union, and the European Data Protection Board Recommendations 01/2020 on measures that supplement transfer tools. For more information, please see our whitepaper on Navigating GDPR Compliance on AWS.

See the AWS Security Documentation for more information about how the AWS services listed below enable customers to encrypt, delete, and monitor the processing of their customer data.

AWS service Customer can encrypt Customer can delete Customer can monitor processing No remote access*
Amazon API Gateway βœ“ βœ“ βœ“ βœ“
Amazon AppFlow βœ“ βœ“ βœ“ βœ“
Amazon AppStream 2.0 βœ“ βœ“ βœ“ βœ“
Amazon AppStream 2.0 User Pools βœ“ βœ“ βœ“ βœ“
Amazon Athena βœ“ βœ“ βœ“ βœ“
Amazon Augmented AI (A2I) βœ“ βœ“
βœ“ βœ“
Amazon Aurora βœ“ βœ“ βœ“ βœ“
Amazon Bedrock1 βœ“ βœ“ βœ“ βœ“
Amazon Braket βœ“ βœ“ βœ“ βœ“
Amazon Chime βœ“ βœ“ βœ“ βœ“
Amazon Cloud Directory βœ“ βœ“ βœ“ βœ“
Amazon CloudFront βœ“ βœ“ βœ“ βœ“
Amazon CloudWatch βœ“ βœ“ βœ“ βœ“
Amazon CloudWatch Logs
βœ“ βœ“ βœ“ βœ“
Amazon CodeGuru Profiler βœ“ βœ“ βœ“ βœ“
Amazon CodeGuru Reviewer βœ“ βœ“ βœ“ βœ“
Amazon Cognito βœ“ βœ“ βœ“ βœ“
Amazon Comprehend βœ“ βœ“ βœ“ βœ“
Amazon Connect2 βœ“ βœ“ βœ“ βœ“
Amazon Detective βœ“ βœ“ βœ“ βœ“
Amazon DocumentDB (with MongoDB compatibility) βœ“ βœ“ βœ“ βœ“
Amazon DynamoDB βœ“ βœ“ βœ“ βœ“
Amazon Elastic Block Store (Amazon EBS) βœ“ βœ“ βœ“ βœ“
Amazon Elastic Compute Cloud (Amazon EC2) βœ“ βœ“ βœ“ βœ“
Amazon Elastic Container Registry (Amazon ECR) βœ“ βœ“ βœ“
βœ“
Amazon Elastic Container Service (Amazon ECS) βœ“ βœ“ βœ“ βœ“
Amazon Elastic File System (Amazon EFS) βœ“ βœ“
βœ“
βœ“
Amazon Elastic Kubernetes Service (Amazon EKS) βœ“ βœ“
βœ“
βœ“
Amazon ElastiCache for Memcached3 βœ“2 βœ“ βœ“
βœ“
Amazon ElastiCache for Redis βœ“ βœ“
βœ“
βœ“
Amazon EMR βœ“ βœ“
βœ“
βœ“
Amazon EventBridge βœ“ βœ“
βœ“
βœ“
Amazon Forecast βœ“ βœ“
βœ“
βœ“
Amazon Fraud Detector βœ“ βœ“
βœ“
βœ“
Amazon FSx for Lustre βœ“ βœ“ βœ“
βœ“
Amazon FSx for ONTAP βœ“ βœ“
βœ“
βœ“
Amazon FSx for OpenZFS βœ“ βœ“
βœ“
βœ“
Amazon FSx for Windows File Server βœ“ βœ“
βœ“
βœ“
Amazon GameLift βœ“ βœ“
βœ“
βœ“
Amazon GuardDuty βœ“ βœ“
βœ“
βœ“
Amazon Healthlake βœ“ βœ“ βœ“ βœ“
Amazon Inspector βœ“ βœ“
βœ“
βœ“
Amazon Inspector Classic βœ“ βœ“
βœ“
βœ“
Amazon Interactive Video Service (IVS) βœ“ βœ“
βœ“
βœ“
Amazon Kendra βœ“ βœ“
βœ“
βœ“
Amazon Keyspaces βœ“ βœ“ βœ“ βœ“
Amazon Managed Service for Apache Flink for Java Applications βœ“ βœ“
βœ“
βœ“
Amazon Managed Service for Apache Flink for SQL Applications βœ“ βœ“
βœ“
βœ“
Amazon Kinesis Data Firehose βœ“ βœ“
βœ“
βœ“
Amazon Kinesis Data Streams βœ“ βœ“
βœ“
βœ“
Amazon Kinesis VideoStreams βœ“ βœ“
βœ“
βœ“
Amazon Lex βœ“ βœ“
βœ“
βœ“
Amazon Lightsail βœ“ βœ“
βœ“
βœ“
Amazon Location Service βœ“ βœ“
βœ“
βœ“
Amazon Macie βœ“ βœ“
βœ“
βœ“
Amazon Managed Blockchain (AMB) βœ“ βœ“
βœ“
βœ“
Amazon Managed Service for Grafana (AMG) βœ“ βœ“
βœ“
βœ“
Amazon Managed Service for Prometheus (AMP) βœ“ βœ“
βœ“
βœ“
Amazon Managed Streaming for Kafka (MSK) βœ“ βœ“
βœ“
βœ“
Amazon Managed Workflows for Apache Airflow (MWAA)  βœ“ βœ“
βœ“
βœ“
Amazon MemoryDB for Redis βœ“ βœ“
βœ“
βœ“
Amazon MQ βœ“ βœ“
βœ“
βœ“
Amazon Neptune βœ“ βœ“
βœ“
βœ“
Amazon OpenSearch Service  βœ“ βœ“ βœ“ βœ“
Amazon Personalize βœ“ βœ“ βœ“ βœ“
Amazon Pinpoint βœ“ βœ“ βœ“ βœ“
Amazon Polly βœ“ βœ“ βœ“ βœ“
Amazon Q Business βœ“ βœ“ βœ“ βœ“
Amazon Q Developer βœ“ βœ“ βœ“ βœ“
Amazon QuickSight2 βœ“ βœ“ βœ“ βœ“
Amazon Redshift βœ“ βœ“ βœ“ βœ“
Amazon Rekognition βœ“ βœ“
βœ“
βœ“
Amazon Relational Database Service (Amazon RDS) βœ“ βœ“
βœ“
βœ“
Amazon SageMaker βœ“ βœ“
βœ“
βœ“
Amazon Simple Email Service (Amazon SES) βœ“ βœ“
βœ“
βœ“
Amazon Simple Notification Service (Amazon SNS) βœ“ βœ“
βœ“
βœ“
Amazon Simple Queue Service (Amazon SQS) βœ“ βœ“ βœ“ βœ“
Amazon Simple Storage Service (Amazon S3) βœ“ βœ“
βœ“
βœ“
Amazon Simple Storage Service Glacier βœ“ βœ“
βœ“
βœ“
Amazon Simple Workflow Service (Amazon SWF) βœ“ βœ“
βœ“
βœ“
Amazon Textract βœ“ βœ“
βœ“
βœ“
Amazon Timestream βœ“ βœ“
βœ“
βœ“
Amazon Transcribe
βœ“ βœ“
βœ“
βœ“
Amazon Translate βœ“ βœ“
βœ“
βœ“
Amazon Virtual Private Cloud (Amazon VPC) βœ“ βœ“
βœ“
βœ“
Amazon WorkDocs βœ“ βœ“
βœ“
βœ“
Amazon WorkLink βœ“ βœ“
βœ“
βœ“
Amazon WorkMail βœ“ βœ“
βœ“
βœ“
Amazon WorkSpaces
βœ“ βœ“
βœ“
βœ“
Amazon WorkSpaces Application Manager (Amazon WAM) βœ“ βœ“
βœ“
βœ“
AWS Amplify βœ“ βœ“
βœ“
βœ“
AWS App Mesh βœ“ βœ“
βœ“
βœ“
AWS App Runner  βœ“ βœ“ βœ“
βœ“
AWS Application Discovery Service βœ“
βœ“
βœ“
βœ“
AWS Application Migration Service βœ“
βœ“
βœ“
βœ“
AWS AppSync βœ“
βœ“
βœ“
βœ“
AWS Audit Manager βœ“
βœ“
βœ“
βœ“
AWS Backup βœ“
βœ“
βœ“
βœ“
AWS Certificate Manager (ACM) βœ“
βœ“
βœ“
βœ“
AWS Clean Rooms βœ“
βœ“
βœ“
βœ“
AWS Cloud9 βœ“
βœ“
βœ“
βœ“
AWS CloudFormation βœ“
βœ“
βœ“
βœ“
AWS CloudHSM βœ“
βœ“
βœ“
βœ“
AWS CloudShell βœ“
βœ“
βœ“
βœ“
AWS CloudTrail βœ“
βœ“
βœ“
βœ“
AWS CodeArtifact βœ“
βœ“
βœ“
βœ“
AWS CodeBuild βœ“
βœ“
βœ“
βœ“
AWS CodeCommit βœ“
βœ“
βœ“
βœ“
AWS CodeDeploy βœ“
βœ“
βœ“
βœ“
AWS CodePipeline βœ“
βœ“
βœ“
βœ“
AWS CodeStar βœ“
βœ“
βœ“
βœ“
AWS Config βœ“
βœ“
βœ“
βœ“
AWS Control Tower βœ“
βœ“
βœ“
βœ“
AWS Database Migration Service (AWS DMS)  βœ“
βœ“
βœ“
βœ“
AWS Data Exchange βœ“
βœ“
βœ“
βœ“
AWS DataSync βœ“
βœ“
βœ“
βœ“
AWS Device Farm βœ“
βœ“
βœ“
βœ“
AWS Direct Connect βœ“
βœ“
βœ“
βœ“
AWS Directory Service βœ“
βœ“
βœ“
βœ“
AWS Elastic Beanstalk βœ“
βœ“
βœ“
βœ“
AWS Elastic Disaster Recovery βœ“
βœ“
βœ“
βœ“
AWS Elastic Transcoder βœ“
βœ“
βœ“
βœ“
AWS Elemental MediaConnect βœ“
βœ“
βœ“
βœ“
AWS Elemental MediaConvert
βœ“
βœ“
βœ“
βœ“
AWS Elemental MediaLive
βœ“
βœ“
βœ“
βœ“
AWS Elemental MediaPackage βœ“
βœ“
βœ“
βœ“
AWS Elemental MediaStore βœ“
βœ“
βœ“
βœ“
AWS Entity Resolution βœ“
βœ“
βœ“
βœ“
AWS Fargate βœ“
βœ“
βœ“
βœ“
AWS Firewall Manager βœ“
βœ“
βœ“
βœ“
AWS Global Accelerator βœ“
βœ“
βœ“
βœ“
AWS Glue βœ“
βœ“
βœ“
βœ“
AWS Glue DataBrew βœ“
βœ“
βœ“
βœ“
AWS IAM Identity Center βœ“
βœ“
βœ“
βœ“
AWS IoT Analytics βœ“
βœ“
βœ“
βœ“
AWS IoT Core βœ“
βœ“
βœ“
βœ“
AWS IoT Device Management βœ“
βœ“
βœ“
βœ“
AWS IoT Events βœ“
βœ“
βœ“
βœ“
AWS IoT Greengrass V1
βœ“
βœ“
βœ“
βœ“
AWS IoT Greengrass V2 βœ“
βœ“
βœ“
βœ“
AWS IoT SiteWise βœ“
βœ“
βœ“
βœ“
AWS IoT Things Graph βœ“
βœ“
βœ“
βœ“
AWS IQ βœ“
βœ“
βœ“
βœ“
AWS Key Management Service (AWS KMS) βœ“
βœ“
βœ“
βœ“
AWS Lake Formation βœ“
βœ“
βœ“
βœ“
AWS Lambda βœ“
βœ“
βœ“
βœ“
AWS License Manager βœ“
βœ“
βœ“
βœ“
AWS Migration Hub βœ“
βœ“
βœ“
βœ“
AWS Outposts βœ“
βœ“
βœ“
βœ“
AWS Secrets Manager βœ“
βœ“
βœ“
βœ“
AWS Security Hub CPSM βœ“
βœ“
βœ“
βœ“
AWS Security Hub βœ“
βœ“
βœ“
βœ“
AWS Serverless Application Repository
βœ“
βœ“
βœ“
βœ“
AWS Service Catalog βœ“
βœ“
βœ“
βœ“
AWS Snowball Edge
βœ“
βœ“
βœ“
βœ“
AWS Snowcone βœ“
βœ“
βœ“
βœ“
AWS Snowmobile βœ“
βœ“
βœ“
βœ“
AWS Step Functions βœ“
βœ“
βœ“
βœ“
AWS Storage Gateway for FSx File Gateway βœ“
βœ“
βœ“
βœ“
AWS Storage Gateway for S3 File Gateway βœ“
βœ“
βœ“
βœ“
AWS Storage Gateway for Tape Gateway βœ“
βœ“
βœ“
βœ“
AWS Storage Gateway for Volume Gateway βœ“
βœ“
βœ“
βœ“
AWS Supply Chain2 βœ“
βœ“ βœ“
βœ“
AWS Systems Manager βœ“
βœ“
βœ“
βœ“
AWS Transfer Family βœ“
βœ“
βœ“
βœ“
AWS Transform βœ“
βœ“
βœ“
βœ“
AWS WAF βœ“
βœ“
βœ“
βœ“
AWS X-Ray βœ“
βœ“
βœ“
βœ“
CloudEndure Disaster Recovery (an AWS Company) βœ“
βœ“
βœ“
βœ“
CloudEndure Migration (an AWS Company) βœ“
βœ“
βœ“
βœ“
FreeRTOS βœ“
βœ“
βœ“
βœ“
Kiro βœ“
βœ“
βœ“
βœ“

* Unless access is requested by you, is required to prevent fraud and abuse, or to comply with law.

1 Processing occurs in conjunction with the foundational model (FM) you choose.

2 See the applicable service documentation for information about Amazon Q.

3 Amazon ElastiCache for Memcached supports encryption in transit. By design, Memcached doesn’t provide persistent disk storage, and only stores data in memory for the time needed for customer’s application. ElastiCache also supports memory encryption when choosing Graviton instances of family types r6g and m6g. All data-storing AWS services offer encryption.

Transfers of Customer Data

For a small subset of services it is an essential function of the service that data is transferred from the AWS Region you have selected. For example, if you choose to send messages via Amazon Simple Notification Service to a recipient, the content of those messages will be transferred to the location of the recipients. See below for a list of similar AWS services.

  • Amazon AppStream 2.0 User Pool
  • Amazon Chime
  • Amazon CloudFront
  • Amazon Cognito*
  • AWS IAM Identity Center**
  • Amazon Interactive Video Service (IVS)
  • Amazon Location Service
  • AWS End User Messaging (formerly Amazon Pinpoint)
  • Amazon Simple Email Service
  • Amazon Simple Notification Service
  • Amazon WorkMail
  • AWS Elemental MediaConnect
  • AWS IoT Core***

* In certain circumstances, Amazon Cognito uses Amazon Simple Email Service (Amazon SES) to send user emails and Amazon Simple Notification Service (Amazon SNS) to send user SMS text messages. If Amazon SES is not available in Region, Amazon Cognito calls Amazon SES’ endpoints in a different AWS Region. More information can be found here. Similarly, if Amazon SNS is not available in Region, Amazon Cognito calls Amazon SNS’ endpoints in a different AWS Region. More information can be found here.
** In certain circumstances, AWS IAM Identity Center uses Amazon Simple Email Service (Amazon SES) to send user emails. If Amazon SES is not available in Region, IAM Identity Center calls Amazon SES’ endpoints in a different AWS Region. More information can be found here.
***  To the extent you use the IoT Core for Amazon Sidewalk feature, or the Device Location feature supported by HERE is enabled.

In addition, some of our services use cross-region inference to improve performance or for other technical reasons, such as to help customers scale their generative AI workloads. See here for more information on cross-region inference services and AWS documentation.

Some AWS services can involve the transfer of customer data to develop and improve those services. You can opt out of these transfers by using the opt-out mechanisms indicated in the applicable Service Terms or AWS documentation.

  • Amazon CodeGuru Profiler
  • Amazon Comprehend
  • Amazon Connect*
  • Amazon Fraud Detector
  • Amazon GuardDuty**
  • Amazon Lex
  • Amazon Polly
  • Amazon Q Developer Free Tier
  • Amazon Rekognition
  • Amazon SageMaker Data Agent
  • Amazon Textract
  • Amazon Transcribe
  • Amazon Translate
  • AWS Entity Resolution
  • AWS Security Hub
  • AWS Supply Chain
  • AWS Transform
  • Kiro Free Tier / Individual subscribers

* This entry encompasses, for example, Contact Lens for Amazon Connect, Amazon Connect Customer Profiles, Amazon Connect outbound campaigns, Amazon Q in Connect, and Amazon Connect Forecasting, Capatcity Planning, and Scheduling. See Service Term 54.7.
** This AWS service will involve a transfer to the extent you have enabled the new Amazon GuardDuty Malware Protection feature.

AWS European Sovereign Cloud

For the AWS European Sovereign Cloud, moving data out of your selected AWS Region or remote access by AWS personnel is restricted even further than as described above, as explained in the white paper Overview of the AWS European Sovereign Cloud and the AWS European Sovereign Cloud Addendum.