AWS · AWS Privacy Notice · View original document ↗

International Data Transfers

Medium severity Medium confidence Explicitdocumentlanguage Common · 54 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for AWS Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

The notice states that personal information may be transferred to and processed in countries outside the user's country of residence, including countries with data protection standards that differ from those of the user's home jurisdiction.

This analysis describes what AWS's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses that personal data may be transferred internationally without specifying the transfer mechanisms used to ensure adequate protection for EU or other regulated transfers. This language is relevant to GDPR Chapter V compliance and may require evaluation of whether Standard Contractual Clauses, adequacy decisions, or other safeguards are in place.

Interpretive note: The notice does not specify the transfer mechanisms or safeguards used for international data transfers, creating ambiguity about GDPR Chapter V compliance for EU resident data.

Consumer impact (what this means for users)

Under this provision, personal information collected from users including EU and EEA residents may be transferred to countries outside their jurisdiction for processing. The notice does not specify which transfer mechanisms are used to protect data during cross-border transfers.

How other platforms handle this

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Medium Medium

Your personal information may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where the privacy laws may not be as protective as those in your jurisdiction.

Grindr Medium

Your personal information may be transferred to, stored, and processed in the United States or other countries outside of your country of residence, which may have data protection laws that are different from those in your country.

See all platforms with this clause type →

Monitoring

AWS has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Your personal information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country.

— Excerpt from AWS's AWS Privacy Notice

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1. REGULATORY LANDSCAPE: GDPR Chapter V restricts transfers of personal data to third countries without adequate protections. Following Schrems II, reliance on Standard Contractual Clauses requires supplementary measures assessment. The UK GDPR imposes parallel requirements for UK resident data. Transfer of data to the United States from the EU is currently covered by the EU-US Data Privacy Framework where applicable, but the adequacy of this framework has been subject to ongoing legal scrutiny. 2. GOVERNANCE EXPOSURE: Medium. The notice's disclosure of international transfers without specifying the applicable transfer mechanism or safeguards creates a documentation gap that may complicate regulatory inquiries or audits by EU data protection authorities. 3. JURISDICTION FLAGS: EU/EEA and UK residents face the highest exposure given the requirements of GDPR and UK GDPR for documented transfer mechanisms. Brazilian users may also have relevant rights under LGPD. Users in jurisdictions with data localization requirements face additional considerations. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers with EU operations should assess whether AWS's international transfer disclosures align with their own GDPR compliance frameworks, particularly where employee data may be collected through the AWS website. Data processing agreements should address transfer mechanisms explicitly. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should request documentation from AWS identifying the specific transfer mechanisms in place for international data flows, including whether EU-US Data Privacy Framework certification, Standard Contractual Clauses, or other safeguards are relied upon. This documentation should be retained as part of the organization's vendor assessment record.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over representations made by US companies regarding international data transfer safeguards, including Safe Harbor and Privacy Shield successor frameworks.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
AWS Privacy Notice
Entity
AWS
Document last updated
May 5, 2026
Tracking information
First tracked
May 21, 2026
Last verified
May 21, 2026
Record ID
CA-P-008664
Document ID
CA-D-00649
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
2fb04590268699fa6374538d0098cfcad9b058336d2e7bc7903257ea53ab35fa
Analysis generated
May 21, 2026 04:45 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: AWS
Document: AWS Privacy Notice
Record ID: CA-P-008664
Captured: 2026-05-21 04:45:41 UTC
SHA-256: 2fb04590268699fa…
URL: https://conductatlas.com/platform/aws/aws-privacy-notice/international-data-transfers/
Accessed: June 27, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does AWS's International Data Transfers clause do?

This provision discloses that personal data may be transferred internationally without specifying the transfer mechanisms used to ensure adequate protection for EU or other regulated transfers. This language is relevant to GDPR Chapter V compliance and may require evaluation of whether Standard Contractual Clauses, adequacy decisions, or other safeguards are in place.

How does this clause affect you?

Under this provision, personal information collected from users including EU and EEA residents may be transferred to countries outside their jurisdiction for processing. The notice does not specify which transfer mechanisms are used to protect data during cross-border transfers.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 54 platforms. See the full comparison.

Is ConductAtlas affiliated with AWS?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS.