01
Accountability
Role map
Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.
- Name workload, platform, security, account and data owners.
- Separate organisation, account, role, service and support access.
- Record AWS and other managed-service roles from current agreements and architecture.
02
Collection surfaces
Collection and notice touchpoints
Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.
- Application APIs, databases, object storage, queues and logs.
- Developer access, support cases, observability and data pipelines.
- Backups, snapshots, replication, analytics and cross-account sharing.
03
Purpose discipline
Purpose and data minimisation checks
Every field and copy should have a named operating reason, accountable owner and review event.
- Map data classes to only required services, fields, logs and regions.
- Avoid personal data in resource names, tags and verbose logs.
- Limit non-production copies and broad data-lake ingestion.
04
Choice evidence
Consent and preference evidence
When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.
- Carry collection and purpose evidence from the application layer.
- Do not treat an IAM permission as a data principal’s consent.
- Ensure downstream analytics uses match the recorded purpose.
05
Least privilege
Access control and privileged roles
Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.
- Review root use, IAM Identity Center, roles, policies, keys and cross-account trust.
- Separate control-plane and data-plane access.
- Exercise key rotation, session revocation and departure.
06
Lifecycle
Retention, deletion, backup and export behaviour
A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.
- Define deletion for live stores, versions, replicas, caches, snapshots and backups.
- Test restore paths so deleted data is not silently reintroduced.
- Record region, archive and retention configuration by service.
07
Service chain
Processor, sub-processor and contract checks
Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.
- Retrieve current AWS terms, DPA, service terms and sub-processor information.
- Inventory managed services, SaaS tools, support access and cross-account parties.
- Record exit, deletion, incident and assistance expectations.
08
Detection + response
Logs, monitoring and breach evidence
Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.
- Confirm CloudTrail event coverage, trails or event stores, region scope and retention.
- Include data events where the risk and service require them.
- Protect logs and connect detections to the investigation workflow.
09
Request workflow
Rights-request search, export, correction and erasure workflow
- 01
Translate a verified person identifier into application and storage keys.
- 02
Search live services and owned data pipelines.
- 03
Apply exceptions and execute application-controlled correction or deletion.
- 04
Track versions, replicas, snapshots, backups and downstream confirmations.
10
Bounded configuration
Configuration checklist
Every relevant service and region has an owner and data class.
- Admin path
- Verify in the current admin console
- Evidence to save
- Architecture inventory and review date.
Human, service and cross-account access are least-privileged.
- Admin path
- Verify in the current admin console
- Evidence to save
- Role/policy review and exceptions.
Required control- and data-plane events are retained deliberately.
- Admin path
- Verify in the current admin console
- Evidence to save
- Trail/event-store configuration and event sample.
Versions, replicas and restore paths follow a documented lifecycle.
- Admin path
- Verify in the current admin console
- Evidence to save
- Backup map and restore/deletion exercise.
No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.
11
Retrievable proof
Evidence to save
Service, region and data-class map
IAM and cross-account review
CloudTrail coverage and sample
Encryption/key ownership record
Snapshot and backup lifecycle
Rights-search and restore exercise
Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.
12
Do not overclaim
Known limitations and questions for the vendor
Known limitations
- CloudTrail event history is not the same as a configured long-term trail or event data store.
- Service-specific logging and deletion behaviour varies.
- Application identifiers and business logic remain the organisation’s responsibility.
Questions to resolve
- Which accounts, services and regions hold each data class?
- Are required data events enabled?
- Which snapshots and replicas can restore deleted records?
- Which external accounts and support paths can access data?
13
Traceable record
Official vendor sources, DPDP sources and corrections
Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.
Official vendor documentation
Official DPDP record
- Act No. 22 of 2023Ministry of Law and Justice, Government of India · checked 2026-09-27 ↗
- G.S.R. 843(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 846(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 892(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.
Report or inspect a correctionAmazon Web Services and AWS are trademarks of Amazon.com, Inc. or its affiliates. References are nominative and do not imply endorsement. No affiliation or endorsement is implied.