Skip to main content
Amazon logo

Amazon

GDPR evidence

amazon.comCloud and hostingLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Amazon and GDPR

CertReports found no public GDPR evidence for Amazon as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: UK Extension Certification, EU-US Certification, SW-US Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
21 Oct 2016
Expires or valid through
2 Jan 2027
Scope
In general, the personal information we collect enables us to provide goods and services to customers, users, vendors, and sellers and helps us to personalize and improve the customer experience through Amazon products, services, stores, website and physical locations, devices and applications. The personal information we process includes information customers provide us in relation to our services, information we automatically collect about customers’ use of our services, and information we receive from other sources, such as updated delivery and address information from our carriers.  We use the information for different purposes depending upon the goods or services being provided. Among other things, these purposes may include the following: handling orders; delivering products and services; processing payments; processing for other purposes as required by our services; communicating with customers, users, vendors, and sellers about orders, products, services, and promotional offers; updating our records and generally maintaining customer, user, vendor, and seller accounts; providing voice, image, and camera services; displaying content; and recommending merchandise and services that might be of interest to our customers, users, vendors, or sellers. We also use this information to prevent or detect fraud or abuses on our web sites, and enable third parties to carry out technical, logistical, or other functions on our behalf. We disclose personal information to subsidiaries Amazon.com controls that are subject to practices at least as protective as Amazon.com, as well as third parties who provide services, products, applications, or skills we make available to customers, and for protection of Amazon and others.  We also may disclose personal information in connection with the sale or purchase of a business or service or to ad companies to serve you with more useful and relevant Amazon ads and to measure their effectiveness.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Amazon.com, Inc.: Active: UK Extension Certification, EU-US Certification, SW-US Certification
Live pagesha256 edda881c6e
VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
7 Apr 2018
Expires or valid through
3 Apr 2027
Scope
Ring LLC and its subsidiary Ring Protect Inc. (collectively, “Ring”) collect personal data about consumers, potential consumers, website visitors, business customer representatives, vendor representatives, business partners, employees, and prospective employees located in the EU, UK and Switzerland. The types of relevant personal data Ring collects, and the purposes for such collection, are described in Ring’s Privacy Notice, available at https://eu.ring.com/pages/privacy-notice. Ring may disclose the relevant personal data to recipients such as (1) its affiliates and subsidiaries, (2) third-party processors the company has retained to perform services on its behalf and pursuant to its instructions, and as otherwise described in the Privacy Notice.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Ring LLC: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 aee2cb0d93
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Amazon GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Cloud and hosting category) whose GDPR row is verified or vendor-stated, ranked by similarity.