AWS says customers don’t have to use Privacy Shield

Europe at night

Amazon Web Services (AWS) said customers do not have to rely on the new EU-US data transfer agreement, Privacy Shield, despite committing to supporting it.

The cloud giant’s announcement comes after Europe’s data watchdogs expressed their misgivings over the framework, which was only approved last month by the EU, suggesting it could challenge the legislation in a year.

However, AWS said it welcomed Privacy Shield, and would support it.

Stephen Schmidt, AWS’s CISO, said in a blog post: “The new EU-US Privacy Shield does not impact AWS customers for two reasons. First, customers using AWS have full control of the movement of their data and have always had the choice of the region in which their data is kept. AWS customers choose the AWS region where their data will be stored and can be assured that their data will remain there unless moved by them.”

Second, customers can send personal data outside the EU to US datacentres by relying on AWS’s Model Clauses.

However, the legal status of Model Clauses is subject to a legal challenge from data privacy campaigner Max Schrems, who is questioning whether or not they guarantee EU data’s privacy when transferred to the US.

It was Schrems who ultimately brought down Privacy Shield’s predecessor, Safe Harbour, when he took Facebook to court over allegedly passing EU data to US spy agencies – something Facebook denied. The European Court of Justice eventually declared Safe Harbour invalid.

Schmidt confirmed Amazon is taking the “necessary steps” to certify under Privacy Shield – other companies like Workday have already certified.

European data authorities are concerned about various aspects of Privacy Shield, which they will challenge in a year, such as the neutrality of a US-appointed Ombudsperson, who is meant to look into EU citizens’ complaints over data misuse. The Article 29 Working Party is also concerned that US assurances it will not perform mass surveillance on EU data is not backed up by legislation.

However, Schmidt said: “At AWS, security is our top priority, and we will continue to work vigilantly to ensure that our customers are able to continue to enjoy the benefits of AWS securely, compliantly, and without disruption in Europe and around the world."

Latest in Privacy
23andMe logo and branding pictured on a sign outside the company headquarters in Sunnyvale, California.
Millions of 23andMe users’ genetic data could be up for grabs – and experts worry it’s a looming privacy nightmare
VPN concept image showing a desktop computer connected to a VPN with interlinked data points.
So long, Defender VPN: Microsoft is scrapping the free-to-use privacy tool over low uptake
Electronic network data security, data protection and electronic technology, financial network security
UK businesses patchy at complying with data privacy rules
LinkedIn log an branding pictured at the company office in Singapore on Thursday, Oct. 17, 2024
LinkedIn faces lawsuit amid claims it shared users' private messages to train AI models
Female data privacy professional working on a desktop computer in an office space.
Data privacy professionals are severely underfunded – and it’s only going to get worse
Workplace surveillance and monitoring concept image showing a CCTV camera with an open place office space in the background.
Your office is now absolutely riddled with surveillance equipment
Latest in News
Flexible work concept image showing woman working in office environment side by side with woman working from home.
IT professionals aren’t budging on flexible work demands – and more than half say they’ll quit if employers don’t meet expectations
Phishing concept image showing an email symbol with fishing hook.
Have I Been Pwned owner Troy Hunt’s mailing list compromised in phishing attack
Cybersecurity team members discussing strategy in an open plan office space, with male and female practitioners standing and others sitting at desks.
UK tech firms have a chance to trial a four-day week this year – here's how other pilot schemes fared
Cyber security concept image showing a digitized padlock sitting on a blue colored circuit board.
LevelBlue launches new partner program that’s “built for the future”
23andMe logo and branding pictured on a sign outside the company headquarters in Sunnyvale, California.
Millions of 23andMe users’ genetic data could be up for grabs – and experts worry it’s a looming privacy nightmare
Microsoft Copilot logo and branding pictured on a smartphone screen.
Microsoft launches new security AI agents to help overworked cyber professionals