You are here:
Automatic Re-Encryption of Data
If you enable automatic key rotation for your AWS Key Management Service (KMS) key, AWS rotates the root key material annually. During the root key rotation, the system rotates your data key, which is used to encrypt and re-encrypt the data.
If you use an alias Amazon Resource Name (ARN) to encrypt your data, Einstein automatically re-encrypts the data during the annual key rotation. If you encrypt your data by using an AWS KMS ARN, and not an alias ARN, manually reconfigure the new key every year.
When you re-encrypt your data automatically by using the same AWS KMS key, the system uses an existing unchanged root key and the automatically rotated data keys to re-encrypt the data.

