AWS · AWS Customer Agreement · View original document ↗

Data Privacy and AWS's Role as Data Processor

High severity Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity AWS recorded 2 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for AWS Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.

This analysis describes what AWS's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The clause creates a framework for data residency control and establishes AWS's data access limitations and non-disclosure obligations as operational requirements. It specifies the conditions under which AWS may deviate from customer region selections, creating a clear procedure for compliance-driven data transfers.

Consumer impact (what this means for users)

Customers retain authority to specify storage regions, and the terms restrict AWS access to content maintenance and legal compliance purposes. The provision establishes that content relocation occurs only upon legal requirement, subject to Section 4.2 exceptions.

How other platforms handle this

Adyen Medium

In providing the services, Adyen will process personal data in accordance with its Privacy Policy and applicable data protection laws, including the General Data Protection Regulation. You are responsible for ensuring that you have the necessary consents and legal bases to share personal data with A...

Smartsheet Medium

When we provide the Service to our customers, we act as a data processor on behalf of those customers. Our customers are the data controllers, meaning that they determine the purposes and means of the processing of personal data that is submitted into the Service. If you are an end user of a custome...

Cloudflare Medium

Cloudflare's current Privacy Policy is incorporated into this Agreement by this reference and is located at https://www.cloudflare.com/privacypolicy/. In addition, by using the Services, you acknowledge and agree that internet transmissions are never completely private or secure.

See all platforms with this clause type →

Monitoring

AWS has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
You may specify the AWS regions in which Your Content will be stored. You consent to the storage of Your Content in, and transfer of Your Content into, the AWS regions you select. We will not access or use Your Content except as necessary to maintain or provide the Service Offerings, or as necessary to comply with the law or a binding order of a governmental body. We will not (a) disclose Your Content to any government or third party or (b) subject to Section 4.2, move Your Content from the regions selected by you; in each case except as necessary to comply with the law or a binding order of a governmental body.

— Excerpt from AWS's AWS Customer Agreement

Applicable regulations

CCPA/CPRA
California, USA
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union

Provision details

Document information
Document
AWS Customer Agreement
Entity
AWS
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 9, 2026
Record ID
CA-P-005992
Document ID
CA-D-00674
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
6d114216458bb84e7194307cffc74be1120fd6e465c1ce76a207512b61effe42
Analysis generated
May 8, 2026 03:04 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: AWS
Document: AWS Customer Agreement
Record ID: CA-P-005992
Captured: 2026-05-08 03:04:08 UTC
SHA-256: 6d114216458bb84e…
URL: https://conductatlas.com/platform/aws/aws-customer-agreement/data-privacy-and-awss-role-as-data-processor/
Accessed: May 20, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does AWS's Data Privacy and AWS's Role as Data Processor clause do?

The clause creates a framework for data residency control and establishes AWS's data access limitations and non-disclosure obligations as operational requirements. It specifies the conditions under which AWS may deviate from customer region selections, creating a clear procedure for compliance-driven data transfers.

How does this clause affect you?

Customers retain authority to specify storage regions, and the terms restrict AWS access to content maintenance and legal compliance purposes. The provision establishes that content relocation occurs only upon legal requirement, subject to Section 4.2 exceptions.

Is ConductAtlas affiliated with AWS?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS.