Blog/Featured
Featured

GDPR and personal data: how to reach compliance with the AWS Cloud?

Since it came into force in May 2018, the General Data Protection Regulation (GDPR

Premaccess3 September 20205 min read
GDPR and personal data: how to reach compliance with the AWS Cloud?

Since it came into force in May 2018, the General Data Protection Regulation (GDPR, “General Data Protection Regulation”, RGPD in French) has demanded more rigour and transparency in the processing of personal data on digital platforms (websites, applications, etc.).

Whatever your line of business (large company, public organisation…), you end up processing personal data through your information systems. But are you correctly applying the “best practices” for the security and retention of data?

If you have deployed your infrastructure on a public Cloud (AWS, Google Cloud, Azure, etc.), the shared responsibility principle applies when implementing that compliance.

In plain terms: the Cloud provider is responsible for the security of the Cloud. As a user, you are responsible for the processing of the data, for your security and for your compliance within that space.

GDPR and personal data: how to reach compliance with the AWS Cloud?

Well aware of how difficult that is, the Cloud providers have created a number of tools to let you stay compliant. AWS is one of them.

Who has to apply the GDPR? What do we mean by personal data? How do you encrypt it? How do you put monitoring and access control in place? In this article, find all the information you need to get a clearer view of this broad subject, along with the services available at AWS to be “GDPR friendly”.

TABLE OF CONTENTS

  • Who is concerned by the GDPR? What is personal data?
  • GDPR & personal data: the fundamental rights of users and your obligations
  • Does the AWS Cloud comply with the GDPR?
  • What services does AWS offer to help you comply with the GDPR?
  • AWS also offers 4 particularly useful services to support you towards that “GDPR friendly” goal

Who is concerned by the GDPR? What is personal data?

First of all, let us restate what this regulation is and what personal data is.

The General Data Protection Regulation

It governs the processing of personal data on the territory of the European Union. It strengthens citizens' control over the use that may be made of data concerning them. It harmonises the subject across Europe.

Any organisation, public or private, that processes personal data on its own behalf or not, is concerned by this text as soon as:

  • it is established on the territory of the European Union,
  • and/or its business directly targets European residents.

Personal data

This is information from which an individual can be identified or is identifiable.

GDPR and personal data: how to reach compliance with the AWS Cloud?

A person can be identified:

  • directly (for example: surname, first name)
  • or indirectly (identifier, customer number, telephone number…).

Identification can be carried out:

  • from a single piece of data (social security number…)
  • from cross-referencing a set of data.

The protection of this sensitive data rests on 5 broad principles that apply on any medium, digital or not:

  • The purpose principle: collection has a clearly defined aim.
  • The proportionality and relevance principle: we only collect the data we need.
  • The limited retention period principle : it is not possible to keep information about natural persons for an indefinite period. A precise retention period must be set, according to the type of information recorded and the purpose of the file.
  • The security and confidentiality principle: you must guarantee the security and confidentiality of the information you hold. In particular, you must ensure that only authorised people have access to that information.
  • Individuals' rights and the consent principle : the people concerned must be informed of the way their data is processed and they must be able to give their consent.

GDPR & personal data: the fundamental rights of users and your obligations

We can name 4 of them:

Right to data portability:

Individuals have the right to copy all the personal data you hold about them. That data must be provided in a way that makes it easy to reuse.

Right to be forgotten:

This gives individuals the right to request the erasure of certain personal data, so as to make it inaccessible to third parties.

Data protection by design:

From the initial design phase of a service, you must comply with the rules, recommendations and guidelines relating to data protection.

Notification in the event of a data breach:

In the event of a data breach, you must notify the relevant supervisory authority within 72 hours. If there is a high risk to the rights and freedoms of individuals, you must also inform them.

GDPR and personal data: how to reach compliance with the AWS Cloud?

Does the AWS Cloud comply with the GDPR?

YES

When this European regulation came into force, in 2018, AWS carried out a GDPR compliance audit certifying that all of its services and features do meet the highest standards for confidentiality and the protection of personal data.

This Cloud provider also holds certifications: ISO 27017, dedicated to Cloud computing security, and ISO 27018, dedicated to the protection of personal data in the Cloud.

Would you like advice on this subject… Contact us.

What services does AWS offer to help you comply with the GDPR?

Depending on your needs, here are several services and features made available to you by AWS to meet the requirements of the European text.

GDPR and personal data: how to reach compliance with the AWS Cloud?

Encrypt your data

  • Encryption of your data at rest with AES256 (EBS/S3/Glacier/RDS)
  • Centralised key management via Key Management Service (per AWS region)
  • IPsec tunnels to AWS with VPN gateways
  • Dedicated HSM modules in the Cloud with AWS CloudHSM

Access control: restrict access to AWS resources to authorised administrators, users and applications

GDPR and personal data: how to reach compliance with the AWS Cloud?

Monitoring and log files: get an overview of the activity on your AWS resources

GDPR and personal data: how to reach compliance with the AWS Cloud?
  • Resource management and configuration with AWS Config
  • Compliance audits and security analyses with AWS CloudTrail
  • Identification of configuration problems with AWS Trusted Advisor
  • Fine-grained log files of access to Amazon S3 objects
  • Detailed information on network flows via Amazon VPC-FlowLogs
  • Rule-based configuration checks and actions with AWS Config Rules
  • Filtering and monitoring of HTTP access to applications with the WAF functions of AWS CloudFront

AWS also offers 4 particularly useful services to support you towards that “GDPR friendly” goal:

  • Amazon GuardDuty is a managed threat detection service that continuously monitors for malicious or unauthorised behaviour.
  • Amazon Macie uses machine learning to monitor and protect the data stored in Amazon S3.
  • Amazon Inspector is an automated security assessment service. It helps strengthen the security and compliance of your applications deployed on AWS.
  • AWS Config Rules is a monitoring service. It checks that Cloud resources comply with security rules.

Finally, if you want to go further still on this subject, AWS has published a white paper titled “Navigating GDPR Compliance on AWS”. It explains how to map the requirements of the GDPR to each AWS service, with a focus on those covering monitoring, data access and key management.

As decision-makers, project manager or CIO, if you want to know whether you are compliant with the GDPR, or to bring yourself into compliance, do not hesitate to contact the Premaccess team. As an AWS expert, it will advise you and offer you tailor-made support suited to your needs.

Would you like advice on your compliance in the Cloud… Contact us.

Going further

Does this concern you? Have a look at our cloud security and compliance offer, or talk to an expert (reply within 24 business hours).

P
PremaccessCloud experts · Franco-Swiss since 2007
/ Also worth reading