Serving users who are bound by professional secrecy (doctors/lawyers etc.)

0

With our product we may process sensitive information of users, which may constitute a professional secret within the meaning of Section 203 of the German Criminal Code ("third-party secrets"). Examples of such users are doctors or lawyers, whose client data is protected by confidentiality. AWS is a sub-processor for us. We have to oblige all our sub-processors to maintain confidentiality with regard to such data. Do we need to sign additional agreements with AWS, or is the standard data processing agreement enough?

1개 답변
0

Hi,

Your question is answered in this documentation: https://docs.aws.amazon.com/whitepapers/latest/navigating-gdpr-compliance/aws-data-processing-addendum-dpa.html

AWS offers a GDPR-compliant AWS Global Data Processing Addendum (GDPR DPA), which 
enables customers to comply with GDPR contractual obligations. The AWS GDPR DPA is 
incorporated into the AWS Service Terms and applies automatically to all customers globally 
who require it to comply with the GDPR whenever customers use AWS services to process personal 
data, regardless of which data protection laws apply to that processing.

And also: https://docs.aws.amazon.com/whitepapers/latest/navigating-gdpr-compliance/the-role-of-aws-under-the-gdpr.html

Best,

Didier

profile pictureAWS
전문가
답변함 한 달 전
profile picture
전문가
검토됨 한 달 전
profile pictureAWS
전문가
검토됨 한 달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠