Security policies and responsibilities in IBM Cloud

Customer data security is paramount. The following information outlines some of the ways that customer data is protected when using IBM watsonx and what you are expected to do to help in these efforts.

Customer responsibility

Clients are responsible for ensuring their own compliance with various laws and regulations, including the European Union General Data Protection Regulation (GDPR). Clients are solely responsible for obtaining advice of competent legal counsel as to the identification and interpretation of any relevant laws and regulations that may affect the clients’ business and any actions the clients may need to take to comply with such laws and regulations. The products, services, and other capabilities described herein are not suitable for all customer situations and may have restricted availability. IBM does not provide legal, accounting, or auditing advice or represent or warrant that its services or products will ensure that clients are in compliance with any law or regulation.

IBM's commitment to GDPR

Learn more about IBM's own GDPR readiness journey and our GDPR capabilities and offerings to support your compliance journey.

Content and Data Protection

The Data Processing and Protection data sheet (Data Sheet) provides information specific to the IBM Cloud Service regarding the type of Content enabled to be processed, the processing activities involved, the data protection features, and specifics on retention and return of Content. Any details or clarifications and terms, including customer responsibilities, around use of the Cloud Service and data protection features, if any, are set forth in this section. There may be more than one Data Sheet applicable to a customer's use of the IBM Cloud Service based upon options selected by customer. The Data Sheet may only be available in English and not available in local languages. Despite any practices of local law or custom, the parties agree that they understand English and it is an appropriate language regarding acquisition and use of the IBM Cloud Services. The following Data Sheets apply to the IBM Cloud Service and its available options. Customer acknowledges that i) IBM may modify Data Sheets from time to time at IBM's sole discretion and ii) such modifications will supersede prior versions. The intent of any modification to Data Sheet(s) will be to

  1. improve or clarify existing commitments,
  2. maintain alignment to current adopted standards and applicable laws, or
  3. provide additional commitments. No modification to Data Sheets will materially degrade the data protection of a IBM Cloud Service.

See the Learn more section for links to some of the data sheets that you can view.

You, the customer, are responsible to take necessary actions to order, enable, or use available data protection features for a IBM Cloud Service and accept responsibility for use of the IBM Cloud Services if you fail to take such actions, including meeting any data protection or other legal requirements regarding Content. IBM's Data Processing Addendum (DPA) and DPA Exhibits apply and are referenced in as part of the Agreement, if and to the extent the European General Data Protection Regulation (EU/2016/679) (GDPR) applies to personal data contained in Content. The applicable Data Sheets for this IBM Cloud Service will serve as the DPA Exhibits. If the DPA applies, IBM's obligation to provide notice of changes to Subprocessors and Customer's right to object to such changes will apply as set out in DPA.

Options for permanently deleting personal data

Learn more