StackLégal

Hosting and network

GDPR AWS

In an indie stack, AWS is used for Cloud infrastructure (compute, storage, databases). Entity cited: Amazon Web Services, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA AWS

Yes. AWS GDPR Data Processing Addendum, incorporated into the AWS Service Terms.

Read the DPA

Stated role

The GDPR DPA states that AWS acts as processor, the customer being able to be controller or processor of Customer Data.

Personal data

The DPA covers personal data uploaded to the services under the customer's AWS accounts. A fixed, more detailed list of categories: not disclosed.

Sub-processors of AWS

Official AWS sub-processor page.

List published by the vendor

Transfers outside the EU

Hosting / location

The customer chooses the processing regions in the AWS network, including regions in the EEA. Once the choice is made, AWS states that it does not transfer that Customer Data outside the selected regions, except as needed to provide the service requested by the customer or to comply with the law or a valid and binding order of a public authority.

EU–United States Data Privacy Framework

Amazon.com, Inc. is registered, EU-U.S. Data Privacy Framework status: Active. Amazon Web Services, Inc. is among the covered entities. United Kingdom extension and Swiss-U.S. DPF: Active.

Data Privacy Framework sheet

Cookies

not disclosed

Typical use, written by StackLégal and not by the vendor: Cloud infrastructure (compute, storage, databases).

History

Last update: October 4, 2026.

  1. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is AWS a processor within the meaning of the GDPR?

The GDPR DPA states that AWS acts as processor, the customer being able to be controller or processor of Customer Data.

What DPA does AWS publish?

Yes. AWS GDPR Data Processing Addendum, incorporated into the AWS Service Terms. https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf

Which further sub-processors does AWS publish?

Official AWS sub-processor page. https://aws.amazon.com/compliance/sub-processors/

Where does AWS state that it processes data, including outside the EU?

The customer chooses the processing regions in the AWS network, including regions in the EEA. Once the choice is made, AWS states that it does not transfer that Customer Data outside the selected regions, except as needed to provide the service requested by the customer or to comply with the law or a valid and binding order of a public authority.

Is AWS registered under the EU–United States Data Privacy Framework?

Amazon.com, Inc. is registered, EU-U.S. Data Privacy Framework status: Active. Amazon Web Services, Inc. is among the covered entities. United Kingdom extension and Swiss-U.S. DPF: Active. https://www.dataprivacyframework.gov/participant/5776

Which personal data does AWS mention?

The DPA covers personal data uploaded to the services under the customer's AWS accounts. A fixed, more detailed list of categories: not disclosed.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets hosting and network

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.