GLOSSARY / Compliance & Risk

GDPR

The UK/EU General Data Protection Regulation, governing how personal data is collected, stored, processed, and protected, including where that data resides in the cloud.

west Back to Glossary

Definition

policy

GDPR (General Data Protection Regulation) sets requirements for how personal data is collected, processed, and protected, including data residency, breach notification timelines, and the right to erasure. For AWS-hosted systems, GDPR compliance touches architectural decisions directly: which region data is stored in, how backups and disaster recovery copies are encrypted and retained, and whether a recovery process could inadvertently restore data that should have been deleted.

In Practice

A disaster recovery plan that replicates customer data to a backup region outside the UK/EU without addressing data residency requirements can solve an availability problem while creating a compliance one.