Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision discloses that AWS serves as the infrastructure sub-processor for all Twilio services, processing all personal data contained in communications sent through or uploaded to Twilio services for hosting and storage purposes, with processing located in the USA subject to regional selection.
This analysis describes what Segment's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
AWS is disclosed as the infrastructure sub-processor for all Twilio services, meaning essentially all personal data processed through Twilio and Segment products is hosted and stored by AWS, making the AWS sub-processor relationship foundational to the entire data processing chain described in this document.
Under this provision, personal data from all Twilio services is processed by AWS as an infrastructure and storage sub-processor, with the processing location defaulting to the USA unless the customer selects Regional Twilio processing. AWS's compliance documentation (GDPR Centre, Supplementary Measures Addendum) is linked externally for additional security information.
Cross-platform context
See how other platforms handle AWS as Universal Infrastructure Sub-Processor and similar clauses.
Compare across platforms →Monitoring
Segment has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"AWS All services Personal data contained in communications sent through or uploaded to the services. Infrastructure Provider providing hosting services and storage. USA*Excerpt from Segment's Sub-Processors
1) REGULATORY LANDSCAPE: The AWS sub-processor relationship engages GDPR Article 28 and GDPR Chapter V for EU personal data processed on US AWS infrastructure. The document links to AWS Supplementary Measures Addenda and GDPR Centre as the transfer mechanism documentation. AWS participates in the EU-US Data Privacy Framework, which may serve as the primary transfer mechanism; compliance teams should verify the current status of applicable mechanisms. 2) GOVERNANCE EXPOSURE: Medium. AWS is a well-documented and widely used cloud infrastructure provider with publicly available compliance documentation. However, the universal scope of AWS's role (all services) means that any AWS-level security incident, compliance issue, or transfer mechanism invalidation would affect the entire Twilio service portfolio simultaneously. 3) JURISDICTION FLAGS: EU and EEA customers face standard Chapter V transfer exposure for US-based AWS processing. Customers selecting Regional Twilio with Ireland region processing should confirm that AWS's EU-based infrastructure is used for that region and that the fraud exception does not route data outside the selected region to non-EU AWS infrastructure. Australian region customers should verify equivalent AWS compliance. 4) CONTRACT AND VENDOR IMPLICATIONS: Customers with AWS-specific vendor risk requirements should confirm that Twilio's AWS sub-processor relationship is covered by their DPA and that the linked supplementary measures documentation is current and accessible. Organizations with their own AWS enterprise agreements should note that this AWS relationship is Twilio's, not the customer's direct relationship. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should incorporate the AWS sub-processing relationship into their records of processing activities and data protection impact assessments for Twilio-dependent services. Teams should monitor the AWS Supplementary Measures Addendum linked by Twilio for updates, and confirm that the transfer mechanism remains valid under current EU-US data transfer frameworks.
AWS is disclosed as the infrastructure sub-processor for all Twilio services, meaning essentially all personal data processed through Twilio and Segment products is hosted and stored by AWS, making the AWS sub-processor relationship foundational to the entire data processing chain described in this document.
Under this provision, personal data from all Twilio services is processed by AWS as an infrastructure and storage sub-processor, with the processing location defaulting to the USA unless the customer selects Regional Twilio processing. AWS's compliance documentation (GDPR Centre, Supplementary Measures Addendum) is linked externally for additional security information.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Segment.