FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Hosting
  4. AWS
A

AWS

OtherWebsite

Related services

A

actionhero.js

actionhero.js is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. actionhero.js integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, actionhero.js helps organizations maintain robust websites that meet user expectations and technical requirements.

Other

Adminer

Adminer is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Adminer supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Adminer ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Akka HTTP

Akka HTTP is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Akka HTTP integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Akka HTTP helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
A

Alibaba Cloud Object Storage Service

Alibaba Cloud Object Storage Service is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Object Storage Service provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Object Storage Service ensures optimal.

Other

AlmaLinux

AlmaLinux is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AlmaLinux supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AlmaLinux ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

AlternC

AlternC is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AlternC supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AlternC ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Amazon Web Services (AWS) do?

Amazon Web Services is the worldwide leading cloud infrastructure platform, offering compute, storage, content delivery (CloudFront), databases, machine learning and hundreds of additional services. Many European websites rely on AWS through CloudFront for static assets, S3 for media storage, EC2 or Lambda for application hosting, and CloudWatch or QuickSight for analytics. Because AWS is operated by Amazon Web Services Inc., a US controlled company, every European deployment must address international data transfers and document a clear legal basis under the GDPR.

What Amazon Web Services does and how it appears on a website

Amazon Web Services (AWS) is the worldwide leading cloud platform operated by Amazon Web Services Inc., a subsidiary of Amazon.com Inc. registered in Seattle, Washington. On a European website, AWS most often appears in three forms: Amazon CloudFront serving images, scripts and HTML from edge locations close to the visitor, Amazon S3 storing static assets and uploaded media, and Amazon EC2 or AWS Lambda running the backend application. Additional features such as Amazon Cognito (authentication), Amazon Pinpoint (push and email), AWS WAF (security filtering) and Amazon Rekognition (image analysis) may also process personal data.

Even when an EU region is selected, AWS remains under US jurisdiction. Support staff in the United States may access infrastructure to troubleshoot incidents, IAM and billing run through global endpoints, and some managed services replicate metadata across regions. This dual European and US footprint is the central GDPR question for any AWS deployment.

Cookies and data collected by AWS

AWS itself does not deploy marketing cookies. The infrastructure layer sets a small number of technical cookies, mainly AWSALB and AWSALBCORS used by the Application Load Balancer to keep a session attached to the same backend, AWSELB used by the older Classic Load Balancer, and similar identifiers when sticky sessions are enabled. CloudFront does not set cookies by default but it processes the visitor IP address, the User-Agent header, the requested URL and TLS metadata. Logs may be retained in Amazon S3 buckets configured by the website operator.

When higher level services are layered on AWS, such as Amazon Pinpoint analytics, AWS Personalize or Amazon Connect, additional identifiers and profile data are processed. The website operator remains the data controller and is responsible for documenting every cookie or local storage entry triggered by AWS components.

GDPR and ePrivacy implications

Amazon Web Services Inc. acts as a processor when it hosts a European website, and the controller is the website operator. A signed AWS Data Processing Addendum (DPA) is required and is available in the AWS Artifact portal. The DPA incorporates the European Commission Standard Contractual Clauses and the UK addendum, lists sub-processors, and describes security controls aligned with ISO 27001, ISO 27018, SOC 2 and the EU Cloud Code of Conduct.

Under the ePrivacy Directive transposed into national law (TTDSG in Germany, LCEN in France, LSSI-CE in Spain), every non-strictly-necessary cookie or similar identifier set through an AWS component requires informed, freely given consent before being stored on the visitor device. Load balancing cookies are typically considered strictly necessary and are exempt, but cookies set by analytics, personalization or advertising features built on AWS are not.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers and the EU-US Data Privacy Framework

Amazon Web Services Inc. is certified under the EU-US Data Privacy Framework, which the European Commission recognised in adequacy decision 2023/1795. This means transfers of personal data from the EU to AWS in the US benefit from an adequacy basis, complemented by Standard Contractual Clauses for any country outside the framework. Following the Schrems II ruling, supplementary measures such as customer managed encryption keys (AWS KMS with imported keys), strict IAM policies and detailed transfer impact assessments are strongly recommended.

Operators handling sensitive workloads can pin services to EU regions, enable AWS Nitro Enclaves, and contractually exclude US support access via the AWS European Sovereign Cloud roadmap announced for the Brandenburg region.

Consent and legal basis

For pure infrastructure use (hosting, CDN cache, security filtering), Article 6(1)(f) legitimate interest is the standard legal basis, supported by a documented legitimate interest assessment. For any AWS feature that profiles users, runs analytics, or feeds advertising, prior opt-in consent gathered through a compliant Consent Management Platform is mandatory before triggering the AWS SDK or pixel calls.

Practical compliance steps

Sign the AWS DPA, restrict workloads to EU regions whenever business requirements allow, enable encryption at rest and in transit with customer managed keys, limit IAM access to named roles, configure logging retention to the minimum necessary, list AWS and its relevant sub-processors in the privacy notice, document the transfer impact assessment, and integrate every AWS triggered cookie or pixel into the Consent Management Platform so it only loads after explicit opt-in when consent is required.

GDPR consent category

Other

Websites using Amazon Web Services (AWS) must obtain user consent under GDPR regulations.

Legal basisLegitimate interest under Article 6(1)(f) GDPR for core hosting and security (load balancers, CDN cache) when properly documented. Consent under Article 6(1)(a) is required when AWS components serve tracking, analytics or advertising features and store identifiers on the user device.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, EU-US Data Privacy Framework, Schrems II case law, German TTDSG / TDDDG, French Data Protection Act

DPIA considerations

A Data Protection Impact Assessment is recommended when AWS hosts personal data at scale, when the workload involves special category data, or when CloudFront, AWS WAF and CloudWatch are combined with user identifiers. The DPIA must cover region selection, encryption at rest and in transit, IAM access controls, sub-processor list, retention rules and the response plan for US government access requests.

Sample consent text

We use Amazon Web Services to host and deliver this website, including content delivery through Amazon CloudFront. AWS may set technical cookies for load balancing and may process your IP address. Some traffic is routed through US infrastructure under the EU-US Data Privacy Framework and Standard Contractual Clauses. By clicking Accept, you allow this processing for the analytics and personalization features powered by AWS.

Technical details

Tracking methodCloud infrastructure with session cookies for load balancing and content delivery
Server locationGlobal, multi-region, customer configurable. EU regions include Frankfurt, Ireland, Paris, Stockholm, Milan, Madrid and Zurich. US regions remain the default for many features.
Data transferred outside the EUOperated by Amazon Web Services Inc. (United States). Even when an EU region is selected, support access, billing data, IAM and several global services route through US infrastructure. Transfers rely on Standard Contractual Clauses and the EU-US Data Privacy Framework certification.

Third-party domains contacted

amazonaws.comcloudfront.netawsstatic.coms3.amazonaws.com

Cookies placed

NameTypeDurationPurpose
AWSALBHTTP cookie7 daysApplication Load Balancer sticky session: keeps a visitor on the same backend instance during a session.
AWSALBCORSHTTP cookie7 daysSame as AWSALB but compatible with cross-origin requests using the SameSite=None attribute.
AWSELBHTTP cookieSessionClassic Load Balancer sticky session, legacy equivalent of AWSALB.
AWSELBCORSHTTP cookieSessionClassic Load Balancer sticky session in cross-origin context.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does AWS set on a website?

AWS only sets a few technical cookies. The Application Load Balancer can place AWSALB and AWSALBCORS (7 days) to keep a visitor on the same backend, and the older Classic Load Balancer uses AWSELB and AWSELBCORS. CloudFront does not set any cookie by default, but when signed cookies are configured for restricted content it can store CloudFront-Key-Pair-Id and CloudFront-Policy. Higher level AWS services such as Pinpoint or Personalize set their own additional identifiers.

Do I need user consent to use AWS on my website?

For pure infrastructure use, such as CloudFront caching static assets or an Application Load Balancer keeping a session, the load balancing cookies are typically strictly necessary and exempt from prior consent under the ePrivacy Directive. Consent is required as soon as AWS components serve analytics, advertising, personalization or profiling features.

What is the legal basis for processing through AWS?

Legitimate interest under Article 6(1)(f) GDPR is the most common basis for infrastructure hosting and security, supported by a documented legitimate interest assessment. Consent under Article 6(1)(a) is required for marketing and profiling. Contractual necessity under Article 6(1)(b) can apply when AWS hosts a service the visitor explicitly subscribed to.

Does AWS transfer data to the United States?

Yes. Even when an EU region is selected, support staff, IAM and several global services may access data from the United States. Amazon Web Services Inc. is certified under the EU-US Data Privacy Framework recognised by the European Commission, and AWS provides Standard Contractual Clauses with its Data Processing Addendum. Supplementary measures such as customer managed encryption keys are strongly recommended after Schrems II.

Do I need a DPIA when I use AWS?

A Data Protection Impact Assessment is recommended whenever AWS hosts personal data at scale, processes special category data, or combines security, content delivery and analytics components linked to user identifiers. The DPIA should document region choice, encryption, IAM controls, retention, sub-processors and the response to US government access requests.

How do I implement AWS compliantly on a European website?

Sign the AWS DPA in AWS Artifact, restrict workloads to EU regions when business needs allow, enable encryption at rest and in transit with customer managed keys, scope IAM policies to named roles, retain logs only as long as required, and integrate every AWS triggered cookie or pixel into the Consent Management Platform so it loads only after explicit opt-in when consent is needed.

Are there GDPR friendly alternatives to AWS?

For pure CDN needs, Bunny CDN, KeyCDN and Scaleway Edge are EU based options. For object storage, Scaleway, OVHcloud and Hetzner offer S3 compatible services in EU regions. For compute and serverless, OVHcloud, Scaleway, Hetzner and the upcoming AWS European Sovereign Cloud are viable. The right alternative depends on workload, certifications required and SLAs.

How do I update my cookie policy after deploying AWS?

List AWS as a processor in the privacy notice, name CloudFront and any other AWS service in use, describe the technical cookies set (AWSALB, AWSALBCORS, AWSELB), mention the EU-US Data Privacy Framework and the use of Standard Contractual Clauses, link to the AWS DPA and provide a contact point for data subject requests.