The EEA section of the notice states that AWS retains contact information, invoices, communication records, account logs, and security-related records after account closure for purposes including tax compliance, dispute resolution, and fraud prevention. No specific retention period is stated for post-closure data.
This analysis describes what AWS's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that account closure does not result in immediate deletion of all personal information for EEA users. The retention is justified on grounds of legal obligation, legitimate interests for dispute resolution, and fraud prevention, which are recognized GDPR lawful bases, but the absence of specified retention periods for each category may create tension with GDPR's storage limitation principle.
Interpretive note: The absence of specific retention periods for individual post-closure data categories creates uncertainty regarding GDPR storage limitation compliance; actual retention schedules may exist in internal records of processing activities not disclosed in the public notice.
Under this provision, EEA users who close their AWS accounts may have contact information, invoices, communication records, and account logs retained for an unspecified additional period for tax, dispute resolution, and fraud prevention purposes. EEA users retain the right to request information about retained data and to request deletion where retention is no longer legally justified.
Cross-platform context
See how other platforms handle Post-Account-Closure Data Retention (EEA) and similar clauses.
Compare across platforms →"After account closure, we may need to keep certain information for an additional period of time for legal and legitimate business purposes. For example, we may retain personal information such as your contact information (for example, name, email address, physical address) and any invoices that AWS has sent to you (for example, record of purchases, applicable discounts, and tax information) for tax and accounting purposes. If applicable, AWS may also retain records of communications with you, as well as relevant logs (for example, a log of your account closure) for dispute resolution purposes. We may further keep records for preventing fraud and ensuring security, for example in case of misuse of our services or violation of our terms.Excerpt from AWS's Privacy Notice
REGULATORY LANDSCAPE: This provision engages GDPR's storage limitation principle under Article 5(1)(e), which requires personal data to be kept for no longer than necessary for the purposes for which it is processed.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that account closure does not result in immediate deletion of all personal information for EEA users. The retention is justified on grounds of legal obligation, legitimate interests for dispute resolution, and fraud prevention, which are recognized GDPR lawful bases, but the absence of specified retention periods for each category may create tension with GDPR's storage limitation principle.
Under this provision, EEA users who close their AWS accounts may have contact information, invoices, communication records, and account logs retained for an unspecified additional period for tax, dispute resolution, and fraud prevention purposes. EEA users retain the right to request information about retained data and to request deletion where retention is no longer legally justified.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS.