โ† All providers

Amazon Web Services

Cloud IaaSMedium RiskVerified 2026-03-05
Visit website
Overview
Headquarters๐Ÿ‡บ๐Ÿ‡ธ USSeattle
US IncorporatedYes
CLOUD Act ExposureYes
Regions (10 in 9 countries)
๐Ÿ‡บ๐Ÿ‡ธ US
US East Virginia ยท Ashburn
US West Oregon ยท Portland
๐Ÿ‡ฉ๐Ÿ‡ช DE
EU Frankfurt ยท Frankfurt
๐Ÿ‡ฎ๐Ÿ‡ช IE
EU Ireland ยท Dublin
๐Ÿ‡ฌ๐Ÿ‡ง GB
EU London ยท London
๐Ÿ‡ฏ๐Ÿ‡ต JP
AP Tokyo ยท Tokyo
๐Ÿ‡ธ๐Ÿ‡ฌ SG
AP Singapore ยท Singapore
๐Ÿ‡ฆ๐Ÿ‡บ AU
AP Sydney ยท Sydney
๐Ÿ‡ง๐Ÿ‡ท BR
SA Sao Paulo ยท Sao Paulo
๐Ÿ‡จ๐Ÿ‡ฆ CA
CA Central ยท Montreal
Compliance & Data

Certifications

โœ“ SOC 2โœ“ ISO 27001โœ“ GDPRโœ“ HIPAAโœ“ PCI DSS

Data Types Handled

Application DataLogsPII
Applicable Laws (10)

Applies to businesses meeting revenue or data volume thresholds that handle California residents' data.

Max fine: USD 7,500 per intentional violationvia ๐Ÿ‡บ๐Ÿ‡ธ US
UK GDPRUnited Kingdom

UK has its own adequacy decisions separate from the EU. Transfers from the UK follow UK-specific rules.

Max fine: 4% of global annual turnover or GBP 17.5Mvia ๐Ÿ‡ฌ๐Ÿ‡ง GB

Organizations must obtain meaningful consent and are accountable for personal information transferred to third parties.

Max fine: CAD 100,000 per violationvia ๐Ÿ‡จ๐Ÿ‡ฆ CA
CLOUD ActUnited States

Any US-incorporated provider or subsidiary may be compelled to disclose data regardless of where it is stored.

Max fine: Contempt of court penaltiesvia ๐Ÿ‡บ๐Ÿ‡ธ US

Cross-border transfers require consent or equivalent protection standards recognized by Japan's PPC.

Max fine: JPY 100M for corporate violationsvia ๐Ÿ‡ฏ๐Ÿ‡ต JP

Cross-border transfers require comparable protection standards in the receiving country.

Max fine: SGD 1M or 10% of annual turnovervia ๐Ÿ‡ธ๐Ÿ‡ฌ SG

Cross-border transfers to non-adequate countries require SCCs, BCRs, or other safeguards.

Max fine: 4% of global annual turnover or EUR 20Mvia ๐Ÿ‡ฉ๐Ÿ‡ช DE, ๐Ÿ‡ฎ๐Ÿ‡ช IE

International data transfers require adequate protection or specific legal mechanisms.

Max fine: 2% of revenue in Brazil, up to BRL 50M per violationvia ๐Ÿ‡ง๐Ÿ‡ท BR
FISA Section 702United States

US providers may be subject to surveillance orders targeting non-US persons, creating risk for EU data subjects.

Max fine: Contempt of court penaltiesvia ๐Ÿ‡บ๐Ÿ‡ธ US

Organizations must take reasonable steps to ensure overseas recipients handle personal information in accordance with the APPs.

Max fine: AUD 50M or 30% of adjusted turnover (whichever is greater)via ๐Ÿ‡ฆ๐Ÿ‡บ AU