Main menu (IT)

Amazon Web Services - Sensitive Data Guidance

AWS has a core set of secure services, but it is up to each user to implement appropriate security controls and to comply with applicable University policies, notably policies relating to the protection of University data and Level 1 data policies

Third-party content that is available through AWS are generally governed by separate contract terms and conditions, including separate fees and charges. AWS may not have tested or screened third-party content.

Sensitive Data Guidance 
Data TypeData UseComments


Credit Card 

(PCI-DSS)

Not permitted. Not acceptable for PCI-DSS data. 

Export Control 

ConsultConsult with Information Security

Electronic Protected Health Information

(ePHI) subject to HIPAA

ConsultHIPAA Business Associate Agreement has been signed. Consult with Information Security

Human Subject Research

ConsultConsult with Information Security

Intellectual Property 

ConsultConsult with Information Security

IT Security Information

PermittedWhen appropriately configured. 

Other Sensitive Institutional Information 

(e.g. Fundraising, Attorney/Client Privileges)

ConsultConsult with Information Security

Personally Identifiable Information (PII)


ConsultWhen appropriately configured; consult with Information Security

Public Information


Permitted 


Research Data 

(Animal General, Non-Humanoid Subject Research)

PermittedConsult with Information Security and office of research. 
 
Student Education Records

(FERPA)

Permitted Excluding student health records. Consult with Information Security