Skip to main content

How does amaise meet data protection requirements (GDPR, nDSG, US)?

Written by amaise Support

How does amaise meet data protection requirements (GDPR, nDSG, US)?

amaise meets the data protection requirements of the relevant jurisdictions. Since the core principles — purpose limitation, data minimization, transparency, security, and data subject rights — largely align internationally, all customers benefit from the same high standards.

EU — GDPR:

  • Data processing agreement (DPA) compliant with Art. 28 GDPR

  • Notification obligation within 72 hours (Art. 33/34)

  • Data residency in the EU (AWS Frankfurt) or Switzerland

  • Details: see GDPR compliance

Switzerland — nDSG (effective since September 1, 2023):

  • Data residency in Switzerland (AWS Zurich, Azure OpenAI Switzerland North)

  • Tenant-specific encryption (dedicated KMS key per tenant)

  • Documented data deletion (8-step process at contract termination)

  • Compliance with Art. 321 StGB (professional secrecy: medical confidentiality, attorney-client privilege)

  • Notification to the FDPIC according to nDSG Art. 24

  • Processing record according to nDSG Art. 12

USA:

  • Data residency in the USA (AWS Ohio)

  • Compliance with applicable state privacy laws (e.g., CCPA/CPRA)

  • Security controls aligned with HIPAA requirements for healthcare customers

  • Industry-specific compliance available on request

EPO / International organizations:

  • amaise supports the requirements of international organizations and can address specific compliance needs on a customer basis.

For specific compliance inquiries, please contact us at [email protected].

Did this answer your question?