AWS Bedrock (EU)
Amazon Web Services EMEA SARL · LU · Last reviewed: 2026-08-24
Data Protection Contracts
67/100AWS provides a publicly available Art. 28 GDPR data processing agreement covering documented instructions, confidentiality, sub-processor obligations, audit rights and assistance with data subject requests.
jaSource: AWS GDPR Data Processing Addendum, §2 (Documented Instructions), §3 (Confidentiality of Customer Data), §6 (Sub-processing), §7 (Data Subject Requests), §10-11 (Certifications und Audits) (reviewed 2026-07-23)
The AWS DPA incorporates the EU Standard Contractual Clauses and distinguishes controller-to-processor from processor-to-processor clauses depending on the customer's role.
jaSource: AWS GDPR Data Processing Addendum, §12.2 Application of Standard Contractual Clauses, §12.2.1 und §12.2.2; §12.3 lässt alternativ Binding Corporate Rules zu. (reviewed 2026-07-23)
AWS notifies security incidents 'without undue delay' but states no specific deadline. Unsuccessful attack attempts are expressly excluded from the notification duty.
neinSource: AWS GDPR Data Processing Addendum, §9.1 — 'AWS will notify Customer of a Security Incident without undue delay after becoming aware'; §9.3 Unsuccessful Security Incidents (Ausnahme für Port-Scans, DoS-Versuche und ähnliche Vorfälle ohne unbefugten Zugriff). (reviewed 2026-07-23)
Data Residency & Sovereignty
33/100AWS lets the customer choose the processing region, including regions in the EEA, and generally does not transfer data out of the chosen region, with exceptions for service delivery and legal orders. For the Anthropic models Kontinent additionally uses EU inference profiles, which may serve from EU regions other than Frankfurt.
teilweiseSource: AWS GDPR Data Processing Addendum + AWS Bedrock Inference Profiles (geprüft 03.08.2026), §12.1 Regions — 'AWS will not transfer Customer Data from Customer's selected Region(s) except as necessary to provide the Services initiated by Customer, or as necessary to comply with the law or valid and binding order of a governmental body.' Kontinent bindet eu-central-1 ein und verwendet ausschließlich eu-Inferenzprofile; global-Profile werden bewusst nicht genutzt. (reviewed 2026-07-23)
AWS maintains a public sub-processor list, announces additions 30 days in advance and grants an objection right (terminate, stop using the service, or move the data to another region). The list is not limited to the EU and includes group entities outside it.
teilweiseSource: AWS GDPR Data Processing Addendum + AWS Sub-processors (Liste, Stand 23.07.2026), §6.1 Authorized Sub-processors (öffentliche Liste, 30 Tage Vorlauf, Widerspruchsoptionen) und §6.2 (Flow-down der DPA-Pflichten, AWS bleibt verantwortlich). (reviewed 2026-07-23)
The contracting entity is Amazon Web Services EMEA SARL, based in Luxembourg and therefore an EU legal entity. It belongs to the US group Amazon.com, Inc., so ownership sits outside the EU.
neinSource: AWS Customer Agreement + AWS GDPR Data Processing Addendum, Vertragspartner für Kunden im EWR ist AWS EMEA SARL (Luxemburg); Konzernmutter Amazon.com, Inc. (Seattle, USA). (reviewed 2026-07-23)
Data Use
67/100For certain models Bedrock stores inputs and outputs for up to 30 days, solely for abuse detection, and AWS may review flagged content on that basis. There is therefore no zero-retention commitment across all models. Beyond that, the DPA obliges AWS to process customer data only to provide the services.
teilweiseSource: AWS Service Terms (Stand 29.07.2026) + AWS GDPR Data Processing Addendum, Service Terms §50.12.2 Abuse Detection — 'Amazon Bedrock stores Service inputs and outputs for up to 30 days (unless otherwise required by law) solely to detect activity that violates our, or third-party model providers, terms of service or use policies'; DPA §3 Confidentiality of Customer Data. (reviewed 2026-07-29)
AWS contractually does not use Bedrock content to develop its own services or AI technologies. The service terms list exhaustively which AI services such use applies to, and Amazon Bedrock is expressly not among them.
jaSource: AWS Service Terms (Stand 29.07.2026), §50.3 zählt die betroffenen Dienste auf (CodeGuru Profiler, Comprehend, Lex, Polly, Rekognition, Textract, Transcribe, Translate, Transform, FinOps Agent, Kiro Free Tier) und stellt klar: 'This Section does not apply to ... any AI Service that is not listed in the first sentence of this Section 50.3.' Bedrock ist nach §50.1 ein AI Service, aber in §50.3 nicht gelistet. (reviewed 2026-07-29)
No objection to use for training or service improvement is needed for Bedrock, because such use is excluded from the outset. For the 30-day abuse-detection retention, however, the service terms provide no opt-out. Transfer of content to Anthropic for abuse detection happens only with explicit consent.
teilweiseSource: AWS Service Terms (Stand 29.07.2026), §50.3 (AI-services-opt-out-Policy über AWS Organizations, für Bedrock mangels Listung gegenstandslos), §50.12.2 (Missbrauchserkennung ohne Opt-out), §50.12.2.2 (Übermittlung an Anthropic nur per Opt-in-Mechanismus). (reviewed 2026-07-29)
Certifications
75/100AWS holds ISO 27001, 27017, 27018 and 27701 certifications and provides the certificates on request. Its security measures are audited at least annually by independent third parties against ISO 27001.
jaSource: AWS GDPR Data Processing Addendum, §10.1(i) AWS ISO-Certification and SOC Reports; §10.2 AWS Audits (mindestens jährlich, unabhängige Dritte, nach ISO 27001). (reviewed 2026-07-23)
AWS provides SOC 1, SOC 2 and SOC 3 reports, but the full reports only on request and only under a non-disclosure agreement. No BSI C5 attestation for Bedrock is evidenced to Kontinent.
teilweiseSource: AWS GDPR Data Processing Addendum, §10.1(ii) SOC 1/2/3 Reports, verfügbar 'upon Customer's request, and provided that the parties have an applicable NDA in place'; §10.3 Audit Reports ebenfalls NDA-gebunden. (reviewed 2026-07-23)
AI Act Readiness
100/100For its own Nova models, where Amazon is itself a provider within the meaning of the AI Act, the Article 53 documentation is in place: a public summary of training content in the AI Office's official template, a detailed service card covering intended use, limitations, safety and evaluation, and a named contact point for rightsholders under the Copyright Chapter of the Code of Practice. For the older Nova models placed on the market before 2 August 2025 only the service card exists so far — there the training content summary is not due until 2 August 2027. The remaining models served through Bedrock come from third parties, each responsible for its own documentation.
jaSource: Public Summary of Training Content: Amazon Nova 2 Lite, Version 1.0 vom 27.07.2026 + AWS AI Service Card Amazon Nova 2 Lite (abgerufen 24.08.2026), Zusammenfassung der Trainingsinhalte in der Vorlage des KI-Büros: Abschnitt 1.1 Anbieter 'Amazon Media EU S.à r.l., Luxemburg — provider established in the Union', Abschnitt 1.2 'Date of placement of the model on the Union market: December 2, 2025', Abschnitt 1.3 Modalitäten und Größenklassen der Trainingsdaten je Text, Bild, Audio und Video. Service Card, Abschnitt 'Intellectual Property': Kontaktstelle gpai-models@amazon.com für Beschwerden zu den 'commitments under the Copyright Chapter of the Code of Practice for General-Purpose AI Models under the EU AI Act'. Gegenprobe: Für nova-micro-lite-pro (in Verkehr 05.12.2024) existiert eine Service Card, aber keine Zusammenfassung der Trainingsinhalte — Frist nach Art. 111 Abs. 3 KI-VO läuft bis 02.08.2027. (reviewed 2026-08-24)
Amazon appears on the signatory list of the EU General-Purpose AI Code of Practice.
jaSource: EU-Signatarliste GPAI Code of Practice — 00_Uebergreifend/EU_GPAI-CoP-Signatarliste_2026-07-27.pdf, Signatarliste, Abschnitt 'Signatories of the code of practice': Amazon gelistet. Das Kriterium wird — wie bei allen 15 Zeilen — auf der Anbieterebene beantwortet: unterzeichnet dieses Unternehmen den Kodex. Hinweis fuer die Modellebene: ueber Bedrock fuehren wir ausserdem Modelle von Alibaba/Qwen, MiniMax und NVIDIA, die laut Signatarliste NICHT unterzeichnet haben (siehe Art-53-Register_Modellanbieter_2026-08-14.md, Gruppe C). Nicht unterzeichnet heisst nicht 'nicht konform' — der Kodex ist freiwillig, Art. 53 gilt unabhaengig davon. (reviewed 2026-08-24)
Contract Quality & Transparency
67/100AWS publishes its customer agreement, data processing agreement and sub-processor list in full and retrievable without any contractual relationship. The certificates and audit reports themselves are available only under a non-disclosure agreement.
jaSource: AWS Customer Agreement, AWS GDPR DPA, AWS Sub-processors (alle öffentlich, archiviert 23.07.2026), Alle drei Dokumente öffentlich abrufbar und in der Compliance-Ablage archiviert; Einschränkung nach §10.1/§10.3 DPA für Zertifikate und Audit-Reports. (reviewed 2026-07-23)
AWS publishes a service level agreement for Amazon Bedrock committing to 99.9 % availability per AWS region and monthly billing cycle. Falling below it triggers a graduated service credit claim; the credits are the sole and exclusive remedy.
jaSource: Service Level Agreement für Amazon Bedrock (Stand 04.10.2023, abgerufen 24.08.2026), Dienstverpflichtung — 99,9 % monatlicher Verfügbarkeitsprozentsatz je AWS-Region; Dienstgutschriften gestaffelt 10 % (unter 99,9 %), 25 % (unter 99,0 %), 100 % (unter 95,0 %); Antragsfrist bis zum Ende des zweiten Abrechnungszyklus nach dem Vorfall; Gutschrift als einzige und ausschließliche Abhilfe. (reviewed 2026-08-24)
Liability is capped for both parties at the fees paid for the service giving rise to the claim during the preceding twelve months. Only the indemnification obligations sit outside the cap — among them an uncapped indemnity against intellectual property claims directed at the output of the Nova models. Elevated limits for breaches of confidentiality, data protection damage, intent or gross negligence are absent entirely, liability for the value of customer content is expressly excluded, and the general indemnification duty falls one-sidedly on the customer.
neinSource: AWS Customer Agreement (abgelegt 23.07.2026), §9.1(B) — Ausschluss der Haftung für 'THE VALUE OF YOUR CONTENT'; §9.2 Damages Cap — Deckel auf die in zwölf Monaten gezahlten Entgelte des verursachenden Dienstes, Ausnahmen nur für 'PAYMENT OBLIGATIONS UNDER SECTION 7' und für Haftung, die nach anwendbarem Recht nicht begrenzt werden kann — also keine erhöhte Grenze für Vertraulichkeit, Datenschutz, Vorsatz oder grobe Fahrlässigkeit; §7.1 einseitige, ungedeckelte Freistellungspflicht des Kunden; §7.2(a) beidseitige Schutzrechtsfreistellung, ergänzt um die ungedeckelte IP-Freistellung für Nova-Ausgaben nach AWS Service Terms §50.10. (reviewed 2026-08-24)
Do you represent AWS Bedrock (EU) and think something is inaccurate? Write to legal@kontinent.ai. We check every report and correct verified errors with full transparency.
Report error