Skip to content

GDPR, international data transfer

0

Hello,

While trying to build a Privacy Policy, after reading your Privacy Policy here, it was not clear which is the international data transfer mechanism for countries that are not specified in your Privacy Policy. Please specify which of the following applies:
Standard data protection clauses (SCCs);
Binding corporate rules (BCRs);
Codes of conduct;
Certification mechanisms;
Ad hoc contractual clauses;

Thank you,

asked a year ago449 views

1 Answer
0
Accepted Answer

When it comes to international data transfers under GDPR, AWS provides several mechanisms to ensure compliance, particularly for countries not explicitly mentioned in their Privacy Policy.

The primary mechanism AWS offers for international data transfers is the Standard Contractual Clauses (SCCs). These are included in the AWS Data Processing Addendum (DPA), which automatically applies to all customers worldwide who need it to comply with GDPR when using AWS services to process personal data.

Following the invalidation of the EU-US Privacy Shield by the Court of Justice of the European Union (CJEU), AWS customers and partners can continue to rely on these SCCs included in the AWS DPA for transferring their data from Europe to the US and other countries in compliance with EU data protection laws, including GDPR.

AWS has also strengthened its contractual commitments to protect customer data. These enhanced commitments apply to all customer data subject to GDPR, regardless of whether it is transferred outside the European Economic Area (EEA) or not. These additional protections are available to all AWS customers through a supplementary addendum to the AWS GDPR DPA.

It's important to note that AWS recommends building environments that avoid third-country transfers altogether as a default, unless there is a specific need and a legal ground to do so. This approach aligns with GDPR's strict rules on transferring personal data outside the EU/EEA.

For the most up-to-date and specific information regarding AWS's data transfer mechanisms, especially for countries not explicitly mentioned in their Privacy Policy, it would be advisable to consult the AWS GDPR center or contact AWS directly. They can provide the most current and accurate information tailored to your specific use case and the countries involved in your data transfers.
Sources
AWS Data Processing Addendum (DPA) - Navigating GDPR Compliance on AWS
EU data concern | AWS re:Post
Knowit’s ADAM Guide to GDPR Compliance on AWS | AWS Partner Network (APN) Blog

answered a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.