If you are in the EU, UK, or California, you have legal rights to see what data AWS holds about you, correct mistakes, request deletion, and in California, opt out of your data being sold or shared for advertising purposes.
This analysis describes what AWS's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
These rights are legally enforceable under GDPR and CCPA, meaning AWS is required to respond to valid requests within defined timeframes, giving you meaningful control over your personal information if you choose to exercise these rights.
Interpretive note: The exact verbatim text was not available in the truncated document; the scope of rights available to users outside the EU and California, and the specific request mechanisms, could not be confirmed from the truncated source.
EU and California residents can formally request that AWS disclose, correct, or delete their personal information, and California residents can opt out of data sharing for behavioral advertising purposes, providing concrete mechanisms to exercise privacy rights.
Cross-platform context
See how other platforms handle Data Subject Rights (EU and California) and similar clauses.
Compare across platforms →Monitoring
AWS has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.
"Depending on your location, you may have certain rights regarding your personal information, including the right to access, correct, or delete your personal information, the right to restrict or object to our processing of your personal information, and the right to data portability. California residents may also have the right to opt out of the sale or sharing of their personal information.— Excerpt from AWS's AWS Privacy Notice
REGULATORY LANDSCAPE: GDPR Articles 15 through 22 grant EU and EEA data subjects rights of access, rectification, erasure, restriction, portability, and objection, with defined response timeframes. CCPA and CPRA grant California residents rights of access, deletion, correction, portability, and opt-out from sale or sharing, enforced by the California Privacy Protection Agency and the California Attorney General. The UK GDPR mirrors EU rights for UK data subjects. AWS as a data controller for marketing and website data is directly obligated to respond to these requests. GOVERNANCE EXPOSURE: Medium. AWS's obligations as a data controller for its own marketing and website operations are distinct from its role as a data processor for customer workloads. Enterprise customers whose employees or end users submit rights requests directly to AWS may find those requests redirected, as AWS's processing of customer-uploaded data is governed by separate DPA terms. This distinction should be clearly understood in vendor contracts. JURISDICTION FLAGS: EU and EEA residents have the most comprehensive enforceable rights framework. California residents have CCPA and CPRA rights. UK residents have UK GDPR rights. Other jurisdictions such as Brazil under LGPD and Canada under PIPEDA may have analogous rights that are not explicitly addressed in this policy, creating potential gaps for global users. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should confirm that their AWS DPA addresses data subject rights requests for customer-processed data, including response timeframes and assistance obligations, and that internal processes are in place to route and fulfill requests within statutory deadlines. COMPLIANCE CONSIDERATIONS: Legal teams should verify that AWS's data subject request intake process is functional and responsive, document the response timelines committed to in the policy, and ensure internal data mapping is sufficient to fulfill access and portability requests within GDPR's 30-day and CCPA's 45-day response windows.
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.
Professional Governance Intelligence
Need to monitor specific governance provisions?
Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
These rights are legally enforceable under GDPR and CCPA, meaning AWS is required to respond to valid requests within defined timeframes, giving you meaningful control over your personal information if you choose to exercise these rights.
EU and California residents can formally request that AWS disclose, correct, or delete their personal information, and California residents can opt out of data sharing for behavioral advertising purposes, providing concrete mechanisms to exercise privacy rights.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS.