At AWS, our highest priority is securing our customers’ data, and we implement rigorous contractual, technical, and organizational measures to protect data confidentiality, integrity, and availability regardless of which AWS Region a customer has selected.
AWS complies with ISO 27018, a code of practice that focuses on protection of personal data in the cloud. It extends ISO information security standard 27001 to cover the regulatory requirements for the protection of personally identifiable information (PII) or personal data for the public cloud computing environment and specifies implementation guidance based on ISO 27002 controls that is applicable to PII processed by public cloud service providers. For more information, or to view the AWS ISO 27018 Certification, see the AWS ISO 27018 Compliance webpage.
Additionally, AWS publishes a SOC 2 Type II Privacy report, based on the SOC 2 Privacy Trust Criteria developed by the American Institute of CPAs (AICPA), which establishes criteria for evaluating controls related to how personal data is collected, used, retained, disclosed, and disposed to meet the entity’s objectives. The AWS SOC 2 Type II Privacy report provides third-party attestation of our systems and the suitability of the design of our privacy controls. The scope of the privacy report includes information about how we handle the content that you upload to AWS and how it is protected in all of the services and locations that are in scope for the latest AWS SOC reports. The SOC 2 Type II Privacy report can be downloaded through AWS Artifact in the AWS Management Console.