GDPR
Which cloud services meet GDPR requirements?
AWS, Microsoft Azure and Google Cloud offer services, contractual commitments and security controls that can support GDPR-compliant processing. Compliance depends on the specific service, its configuration and how your organisation uses personal data.
When assessing a cloud service, check:
A data processing agreement (DPA) covering the provider’s responsibilities.
Security controls such as encryption, access restrictions and activity logging.
Support for deletion, retention limits and individuals’ rights requests.
Processing locations, subprocessors and safeguards for international data transfers.
Cloud compliance involves responsibilities for both the provider and its customers, as illustrated by AWS’s shared responsibility guidance. Your organisation must still establish lawful processing purposes, configure appropriate controls and assess the risks of its particular use.
Türkçe
English