Ailance Alt TM Logo
Ailance Alt TM Logo

Data protection at AWS

AWS and data protection with GDPR

Are Amazon servers GDPR-compliant?

Cloud-Cloud computing is becoming increasingly popular. The leading providers in this market are all based in the U.S., including Amazon Web Services (AWS). Will personal data transferred by German and European companies to the United States, a legal basis is always required for such transfers. After the European Court of Justice, in its ruling of July 16, 2020, ruled on the so-called Privacy Shield has declared invalid, the following are generally used for data transfer Standard contractual clauses are used. However, these alone are not sufficient.

In its ruling, the ECJ emphasized the controller's responsibility to assess whether the rights of data subjects in the USA (or other third countries) are protected with the conclusion of the Standard contractual clauses in fact enjoy a level of protection equivalent to that in the EU. In practice, European supervisory authorities expect supplementary measures such as a Anonymization or Encryption of the data to be transferred. Whether and how AWS Data protection This blog post explores how the company takes this seriously and supports its customers in implementing it.

 

AWS

 

Amazon Web Services (AWS) is a U.S.-based Cloud-computing provider. It was founded in 2006 as a subsidiary of the online retailer Amazon.com. Since then, AWS has been growing rapidly. In 2017, Gartner named AWS the leading international provider in the Cloud Computing. A few years ago, AWS had a turnover of 46 billion dollars.

 

 

AWS and data protection

 

As a US company, Amazon Web Services, like comparable services, has been criticized for years with regard to data protection. To compensate for this problem, AWS offers so-called regions, which in turn are divided into availability zones and correspond to physical locations for the storage of data. For example, the regions Ireland (eu-west-1) and Frankfurt am Main (eu-central-1) can be selected so that instances are only executed there. The problem with this is that data located in the EU Server do not protect against access by US authorities in the context of the Cloud Acts. This is a problem for AWS and data protection in Germany.

Amazon offers its customers preconfigured Standard contractual clauses and also refers to a Data Processing Addendum. However, both documents are designed according to a „high-level approach.“ They assist the customer in implementing the Standard contractual clauses does not really meet the requirements for a transfer impact assessment. For example, the following description of the categories of data processed, taken from the addendum—„Customer Data uploaded to the Services under the Customer’s AWS accounts“—is, of course, far too superficial to provide an adequate Transfer Impact Assessment to carry out.

To enhance data protection, Amazon offers developers the option to re-encrypt data stored on AWS themselves—even when using an official software development kit. Large customers are offered the option to use hardware encryption with custom components.

 

Conclusion
According to AWS’s own statement, requests from U.S. authorities are always carefully reviewed and, if necessary, rejected. Furthermore, with regard to data protection, Amazon AWS emphasizes that data encrypted by the customer is only disclosed to U.S. authorities in its encrypted form.

For AWS services with Encryption AWS's own KMS service is used, which ensures that AWS itself has no way of decrypting the plaintext.

This suggests that it is possible to use AWS in compliance with data protection regulations, but only if data is actually encrypted and any residual risks have been deemed acceptable as part of the Transfer Impact Assessment.

Do you need assistance with conducting a professional data transfer impact assessment? Please feel free to contact us. We look forward to supporting you with our many years of expertise in data protection.

Picture of Marcus Belke

Marcus Belke

Marcus Belke is the CEO of 2B Advice GmbH. He drives innovation in data protection compliance and risk management and is responsible for the further development of Ailance, the next-generation compliance platform.

Share this post:

Data protection at AWS