All AWS Services GDPR ready
Today, I’m very pleased to announce that AWS services comply with the General Data Protection Regulation (GDPR). This means that, in addition to benefiting from all of the measures that AWS already takes to maintain services security, customers can deploy AWS services as a key part of their GDPR compliance plans.
This announcement confirms we have completed the entirety of our GDPR service readiness audit, validating that all generally available services and features adhere to the high privacy bar and data protection standards required of data processors by the GDPR. We completed this work two months ahead of the May 25, 2018 enforcement deadline in order to give customers and APN partners an environment in which they can confidently build their own GDPR-compliant products, services, and solutions.
AWS’s GDPR service readiness is only part of the story; we are continuing to work alongside our customers and the AWS Partner Network (APN) to help on their journey toward GDPR compliance. Along with this announcement, I’d like to highlight the following examples of ways AWS can help you accelerate your own GDPR compliance efforts.
Security of Personal Data
During our GDPR service readiness audit, our security and compliance experts confirmed that AWS has in place effective technical and organizational measures for data processors to secure personal data in accordance with the GDPR. Security remains our highest priority, and we continue to innovate and invest in a high bar for security and compliance across all global operations. Our industry-leading functionality provides the foundation for our long list of internationally-recognized certifications and accreditations, demonstrating compliance with rigorous international standards, such as ISO 27001 for technical measures, ISO 27017 for cloud security, ISO 27018 for cloud privacy, SOC 1, SOC 2 and SOC 3, PCI DSS Level 1, and EU-specific certifications such as BSI’s Common Cloud Computing Controls Catalogue (C5). AWS continues to pursue the certifications that assist our customers.
Compliance-enabling Services
Many requirements under the GDPR focus on ensuring effective control and protection of personal data. AWS services give you the capability to implement your own security measures in the ways you need in order to enable your compliance with the GDPR, including specific measures such as:
- Encryption of personal data
- Ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services
- Ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
- Processes for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of processing
This is an advanced set of security and compliance services that are designed specifically to handle the requirements of the GDPR. There are numerous AWS services that have particular significance for customers focusing on GDPR compliance, including:
- Amazon GuardDuty – a security service featuring intelligent threat detection and continuous monitoring
- Amazon Macie – a machine learning tool to assist discovery and securing of personal data stored in Amazon S3
- Amazon Inspector – an automated security assessment service to help keep applications in conformity with best security practices
- AWS Config Rules – a monitoring service that dynamically checks cloud resources for compliance with security rules
Additionally, we have published a whitepaper, “Navigating GDPR Compliance on AWS,” dedicated to this topic. This paper details how to tie GDPR concepts to specific AWS services, including those relating to monitoring, data access, and key management. Furthermore, our GDPR Center will give you access to the up-to-date resources you need to tackle requirements that directly support your GDPR efforts.
Compliant DPA
We offer a GDPR-compliant Data Processing Addendum (DPA), enabling you to comply with GDPR contractual obligations.
Conformity with a Code of Conduct
GDPR introduces adherence to a “code of conduct” as a mechanism for demonstrating sufficient guarantees of requirements that the GDPR places on data processors. In this context, we previously announced compliance with the CISPE Code of Conduct. The CISPE Code of Conduct provides customers with additional assurances regarding their ability to fully control their data in a safe, secure, and compliant environment when they use services from providers like AWS. More detail about the CISPE Code of Conduct can be found at: https://aws.amazon.com/compliance/cispe/
Training and Summits
We can provide you with training on navigating GDPR compliance using AWS services via our Professional Services team. This team has a GDPR workshop offering, which is a two-day facilitated session customized to your specific needs and challenges. We are also providing GDPR presentations during our AWS Summits in European countries, as well as San Francisco and Tokyo.
Additional Resources
Finally, we have teams of compliance, data protection, and security experts, as well as the APN, helping customers across Europe prepare for running regulated workloads in the cloud as the GDPR becomes enforceable. For additional information on this, please contact your AWS Account Manager.
As we move towards May 25 and beyond, we’ll be posting a series of blogs to dive deeper into GDPR-related concepts along with how AWS can help. Please visit our for more information. We’re excited about being your partner in fully addressing this important regulation.
-Chad Woolf
Vice President, AWS Security Assurance
Interested in additional AWS Security news? Follow the AWS Security Blog on Twitter.
相關推薦
All AWS Services GDPR ready
Today, I’m very pleased to announce that AWS services comply with the General Data Protection Regulation (GDPR). This means that, in addition to b
Go Serverless! Let’s create a File Sharing application based on AWS services
Let’s start illustrating the services that are utilized according to design choices.Amazon S3“Amazon S3 is an object storage service created to memorize an
Resolve Errors Accessing AWS Services
Amazon Web Services is Hiring. Amazon Web Services (AWS) is a dynamic, growing business unit within Amazon.com. We are currently hiring So
AWS Services and Pre
Amazon Web Services is Hiring. Amazon Web Services (AWS) is a dynamic, growing business unit within Amazon.com. We are currently hiring So
Resolve Security Group and ACL Issues When Connecting To AWS Services
To enable the connection to a service running on an instance, the associated network ACL must allow both inbound traffic on the port that the s
Provision AWS Services Through Kubernetes Using the AWS Service Broker
IMPORTANT NOTE – Oct 12, 2018 The steps described in this post are no longer accurate, please refer to the AWS Service Broker Git
Find Out the Status of AWS Services
Amazon Web Services is Hiring. Amazon Web Services (AWS) is a dynamic, growing business unit within Amazon.com. We are currently hiring So
Learning Amazon Web Services (AWS) for Developers Amazon Web Services AWS開發者教程 Lynda課程中文字幕
Learning Amazon Web Services (AWS) for Developers 中文字幕 Amazon Web Services AWS開發者教程 中文字幕Learning Amazon Web Services (AWS) for Developers 亞馬遜
Android Studio在啟動時gradle的問題:Download https://services.gradle.org/distributions/gradle-4.6-all.zip
Android Studio在啟動時一直在下載gradle的問題:Download https://services.gradle.org/distributions/gradle-4.6-all.zip 時如何解決? 首先在底部會出現載入的程序,如果有錯誤,在這裡
AWS wants to be Your AI and IoT Services Supplier
"Is this the party to whom I am speaking?" Amazon Go cashierless stores ("Let's go shoplifting!") With years of AI and IoT experience under its belt, Amazo
Optimizing Kafka: Hardware Selection Within AWS (Amazon Web Services)
Accelerating Kafka in AWSUsing Kafka for building real-time data pipelines and now experiencing growing pains at scale? Then no doubt — like Branch — you a
Ready for the Next Storm | AWS News Blog
Amazon Web Services is Hiring. Amazon Web Services (AWS) is a dynamic, growing business unit within Amazon.com. We are currently hiring
Amazon Web Services (AWS)
Simple websites typically consist of a single web server which runs either a Content Management System (CMS), such as WordPress, an eCommerc
https://services.gradle.org/distributions/gradle-2.14.1-all.zip
有時候在開啟Github上的專案時會出現這個問題,看看怎麼解決 我們在我們的專案中找到這個檔案然後修改畫紅線的地方,如果不知道怎麼修改就看看沒有問題的專案寫的是多少,就改成多少就沒問題了。我這裡將3。3改成了2.14.1就沒問題了。
adnroid studio卡在Gradle:Download https://services.gradle.org/distributions/gradle-3.2-all.zip解決辦法
標題中出現的錯誤提示是來源於gradle-wrapper.properties檔案中的 https\://services.gradle.org/distributions/gradle-3.2-all.zip 完整的如圖 解決辦法是先用下載工具先下載https:
Alfresco Process Services on AWS
Use this Quick Start to deploy an Alfresco Process Services server cluster on the AWS Cloud. Alfresco Process Services is an Enterprise
AWS Marketplace: Alfresco Content Services (ECM)
Product Overview Alfresco is an enterprise open-source software company focuse
AWS Marketplace customer case studies all
The healthcare division of Philips provides solutions for diagnostic, treatment and preventative care in the U.S. The division uses data
Alfresco Content Services on AWS
Use this Quick Start to deploy an Alfresco Content Services server cluster on the AWS Cloud. Alfresco Content Services is an Enterprise
Cloud Economics – Amazon Web Services (AWS)AWS
Most likely, your organization is not in the business of running data centers, yet a significant amount of time and money is spent doing ju