AWS shares hashed contact information and cookie-based identifiers with advertising partners to enable personalized advertising on third-party websites and to measure advertising effectiveness. The notice states that directly identifying information such as name is not shared in this context.
This analysis describes what AWS's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes transmission of derived personal identifiers to advertising partners for cross-context behavioral advertising purposes. Under CPRA, sharing personal information for cross-context behavioral advertising may constitute regulated sharing regardless of whether it is characterized as a sale, and the EEA section of the notice relies on legitimate interests as the legal basis for this processing under GDPR.
Interpretive note: Whether the hashed identifier and cookie sharing practice constitutes regulated sharing under CPRA or requires consent rather than legitimate interests under GDPR depends on jurisdiction-specific enforcement interpretation and regulatory guidance.
Under this provision, AWS transmits hashed email addresses and cookie identifiers to advertising partners, enabling personalized advertising on third-party sites. US users can opt out via the 'Your Privacy Choices' link in the AWS site footer; EEA users can withdraw consent via Cookie Preferences or submit the Your Privacy Choices form.
Cross-platform context
See how other platforms handle Advertising Data Sharing via Hashed Identifiers and similar clauses.
Compare across platforms →"To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners. We don't share your name or other information that directly identifies you when we do this. Instead, we use an identifier like a cookie or a unique code derived from your contact information (such as a hashed email address).Excerpt from AWS's Privacy Notice
REGULATORY LANDSCAPE: This provision implicates CPRA's definition of sharing for cross-context behavioral advertising, which applies regardless of monetary consideration, and may require evaluation under GDPR Article 6 regarding the lawful basis of legitimate interests for …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision authorizes transmission of derived personal identifiers to advertising partners for cross-context behavioral advertising purposes. Under CPRA, sharing personal information for cross-context behavioral advertising may constitute regulated sharing regardless of whether it is characterized as a sale, and the EEA section of the notice relies on legitimate interests as the legal basis for this processing under GDPR.
Under this provision, AWS transmits hashed email addresses and cookie identifiers to advertising partners, enabling personalized advertising on third-party sites. US users can opt out via the 'Your Privacy Choices' link in the AWS site footer; EEA users can withdraw consent via Cookie Preferences or submit the Your Privacy Choices form.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS.