FinanceGadget
Provider dossier

AWS Bedrock

Data retention, model isolation, sub-processors, and EU AI Act compliance deadlines for Amazon Web Services Bedrock and Titan models.

Terms read 15 August 2026 · tier assessed: AWS Bedrock Enterprise & Cloud Service Terms (AWS Service Terms Section 50) · by Haileslassie Desalegn

Governance and contractual terms

Training use (default)
No. AWS Bedrock explicitly commits in AWS Service Terms Section 50 that customer inputs and outputs are never used to train Amazon Titan foundation models or third-party provider models.
Retention
Ephemeral in-transit processing by default. Prompts and responses are not stored by AWS unless logging or Guardrails features are explicitly enabled by the customer into their own S3 buckets or CloudWatch logs.
Opt-out
Not required — model training on customer data is prohibited by default under Section 50 of the AWS Service Terms.
Data residency
Yes — full in-region processing and storage available across EU regions (eu-central-1 Frankfurt, eu-west-3 Paris, eu-west-1 Ireland).
Sub-processor list
Published on AWS GDPR Center — AWS entities and third-party model providers acting as sub-processors when third-party models are selected.
DPA available
Yes — AWS GDPR Data Processing Addendum (DPA) included automatically in the AWS Service Terms for all AWS EMEA accounts.
Contracting entity
Amazon Web Services, Inc. (Seattle, WA, USA) or Amazon Web Services EMEA SARL (Luxembourg) for EU accounts.
EU contracting entity
Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg.
Governing law
Luxembourg law and Luxembourg courts for AWS EMEA accounts; Washington State law for US accounts.
Certifications
SOC 1 Type II, SOC 2 Type II, SOC 3, ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO/IEC 42001:2023, PCI DSS v4.0.1, C5 (Germany)
AI Act Code of Practice
yes
Vulnerability disclosure
Yes — AWS Security Vulnerability Reporting Program, public security advisories, and dedicated AWS Security Incident Response Team (AWS SIRT).
Documented incidents
No documented unauthorized data exposure incidents specific to AWS Bedrock service infrastructure reported to date.

Model inventory

Listed by the AI Act deadline each model falls under, which depends on when it was placed on the EU market rather than on its capability. No benchmark scores — why not.

Model API identifier EU availability AI Act deadline Covered by DPA
Amazon Titan Text Express / Premier
First-party Amazon Titan model hosted natively in isolated AWS VPC enclave.
amazon.titan-text-express-v1 2023-09-28 (Frankfurt GA) 2 Aug 2027 Yes — covered under standard AWS DPA
Anthropic Claude 3.5 Sonnet / Haiku (Bedrock)
Inference runs strictly within AWS boundaries; no data sent to Anthropic infrastructure.
anthropic.claude-3-5-sonnet-20241022-v2:0 2024-06-20 2 Aug 2026 Yes — processed in AWS regional infrastructure with zero third-party logging

The short answer

AWS Bedrock is Amazon’s managed foundation model service. For enterprise security teams, AWS Bedrock provides a stronger default contractual posture than direct consumer API subscriptions: customer prompts, completion outputs, and embeddings are never used to train Amazon or third-party models by default. All data in transit and at rest remains within the customer’s selected AWS region (such as eu-central-1 Frankfurt), encrypted using customer-managed KMS keys.

Data retention & model training mechanisms

Unlike consumer AI tools where training opt-out toggles must be manually enabled, AWS Bedrock’s terms guarantee that no prompt or output leaves your AWS environment or touches model training pipelines.

Key governance controls:

  • No Model Training: Section 50 of the AWS Service Terms explicitly binds AWS and third-party model providers (Anthropic, Meta, Mistral, Cohere) from using customer content submitted to Bedrock for model improvement.
  • VPC Endpoint Isolation: Bedrock requests can be routed entirely through AWS PrivateLink VPC endpoints, preventing public internet transit.
  • KMS Encryption: Custom fine-tuning datasets and custom model checkpoints are encrypted at rest using your own AWS Key Management Service (KMS) Customer Master Keys (CMKs).

EU AI Act & GDPR Compliance

AWS EMEA SARL (Luxembourg) serves as the contracting entity for EU customers, ensuring that disputes are governed by Luxembourg law. For organizations complying with GDPR and the EU AI Act:

  1. GDPR DPA: Included automatically as part of the AWS Customer Agreement.
  2. Data Residency: Multi-region deployment allows strict pinning to EU data centres (eu-central-1, eu-west-3, eu-west-1).
  3. Sub-processor Accountability: When invoking third-party models on Bedrock, inference executes inside AWS managed infrastructure rather than third-party SaaS servers, preserving single-vendor accountability under AWS sub-processor terms.
Advertisement