快工助手跨境电商知识与商机助手

Data security and privacy review

TikTok Shop 官方资料 · TikTok Shop Partner Center 开发者文档 · 适合开发者

stable本次发布有变化全部展示

来自 TikTok Shop 官方资料快照 ·

打开官方原文 ↗
  1. 当前资料结构化阅读页
  2. 固定快照已留存,可追溯
  3. 官方原文可核对
查看技术与溯源信息
平台 / profile
TikTok Shop / profile.tiktok.docs_api
语言
en-US
发布版本
cn-20260909-2
标签
zhuge/sourceplatform/tiktok_shopaudience/developercategory/api_doctopic/compliancetopic/developer

资料正文

§1 Protecting customer and protected data

TikTok Shop requires partners and developers to protect customer, seller, buyer, business, and platform data before they can launch an app that accesses TikTok Shop data. Before launch, prospective and current partners may need to complete the Data Security and Privacy Review (DSPR). This review assesses whether the partner's privacy, security, data-handling, and governance practices meet TikTok Shop requirements before the app accesses Protected Data. This page explains:

  • how DSPR differs from the US Data Security Review;
  • how to start the review;
  • what evidence to prepare;
  • how to interpret common privacy and security requirements.

This page is not legal advice and does not replace the Developer Terms of Service or any market-specific requirements shown in Partner Center.

#

§2 Review names and timelines

Use Data Security and Privacy Review (DSPR) as the umbrella name for the privacy, security, compliance, and data-protection review before launch. Do not treat Data Security and Privacy Review (DSPR) and US Data Security Review as the same review. They are separate review processes with different owners, purposes, forms, and timelines. A US app may be required to complete both reviews before launch.

Review nameWhen it appliesWho evaluates itTypical planning timeNotes
Data Security and Privacy Review (DSPR)Partners or apps that access, process, store, or transmit TikTok Shop Protected Data. Required before App Store launch when Partner Center or the review team requests it.TikTok Shop privacy, security, compliance, or review teams, depending on market and app scope.The DSPR assessment is commonly planned at about 2 weeks after a complete submission. Full compliance and legal review can take 3 or more weeks, especially when follow-up is required.This is a privacy and security maturity review. Start it during onboarding, not at the end of development.
US Data Security Review / US Data Security QuestionnaireDevelopers building apps for the US market.US Data Security team.Typically 10-12 business days after submission.This is a separate US-market data security review. Passing DSPR does not automatically satisfy the US Data Security Review, and passing the US Data Security Review does not automatically satisfy DSPR.

The 2-week DSPR estimate and the 10-12 business day US estimate refer to different reviews. In all cases, Partner Center status and each review team's instructions are the source of truth.

#

§3 Key terms

TermMeaning
Protected DataAny TikTok Shop data or customer-related data that a partner accesses, processes, stores, transmits, or derives through its app or service. This can include seller data, buyer data, order data, product data, authorization data, operational data, support data, business information, system logs, and any personal data received through TikTok Shop APIs or workflows.
DSPRData Security and Privacy Review. The review of a partner's privacy, security, data-handling, and governance practices before launch or before access to protected data is approved.
US Data Security Review / US Data Security QuestionnaireA separate US-market data security review managed by the US Data Security team to assess whether a developer keeps US user data safe and secure.
DPOData Protection Officer. A role required under certain privacy laws or jurisdictions to oversee data-protection compliance.
GDPRGeneral Data Protection Regulation. A European privacy regulation that can apply to personal data processing involving individuals in the European Economic Area.
CPRACalifornia Privacy Rights Act. A California privacy law that can apply to personal data processing involving California residents.
NIDSNetwork Intrusion Detection System. A tool used to monitor network traffic for suspicious activity.
HIPSHost Intrusion Prevention System. A host-level tool used to detect or prevent suspicious activity on endpoints or servers.
MFAMulti-factor Authentication. A login control that requires more than one factor, such as password plus authenticator code or hardware key.
TLSTransport Layer Security. A protocol used to protect data in transit. TikTok Shop expects TLS 1.2 or above for protected data transmission.
#

§4 How to start DSPR

Start the DSPR process as early as possible during developer onboarding. Do not wait until the app is fully built, because launch can be blocked until the review is approved. Use this order:

  1. Complete developer onboarding in Partner Center.
  2. Open the app or service detail page in Partner Center > App & Service.
  3. Check the app launch checklist, My Account, or compliance / legal / data-security review section for a visible DSPR, due diligence, or security questionnaire task.
  4. If a questionnaire is visible, complete and submit it from Partner Center.
  5. If no questionnaire is visible, contact the Partner Development & Management team for your market or submit a Partner Center support ticket and request the correct due diligence / DSPR questionnaire for your app.
  6. For US apps, complete the US Data Security Review / US Data Security Questionnaire separately when instructed by Partner Center, the App Store team, or the US Data Security team.
  7. Monitor the review status and respond to follow-up questions. Incomplete or unclear answers can delay the assessment or result in rejection.

Market contact and support paths:

MarketPrimary pathContact channel
United StatesSupport tickets for USpartner.us@tiktokshop.com when your partner manager or review contact asks for email follow-up.
United KingdomSupport ticketspartner.uk@tiktokshop.com when your partner manager or review contact asks for email follow-up.
Other marketsSupport ticketspartner@tiktokshop.com when your partner manager or review contact asks for email follow-up.
#

§5 Preparation checklist

Prepare the following evidence before submitting DSPR or a market-specific questionnaire.

Requirement itemRequired?Applies toEvidence to prepare
Business and entity detailsRequiredAll partnersCompany name, headquarters location, registration details, business category, level of foreign ownership, and primary contact.
Workforce and system locationsRequiredAll partnersPrimary and alternate workforce locations, production system locations, data storage locations, and remote-access model.
Subcontractor and vendor useRequired if applicablePartners using subcontractors, cloud vendors, processors, or service providersSubcontractor list, data handled by each vendor, data processing agreements, and access controls.
Data inventory and data flowRequiredAll partners accessing Protected DataDiagram or table showing what Protected Data is collected, why it is needed, where it is stored, who can access it, where it is transferred, and when it is deleted.
Privacy roles and responsibilitiesRequiredAll partners; DPO required in certain jurisdictionsNamed privacy owner, escalation contact, DPO details if required, and role responsibilities.
Privacy noticeRequiredAll partners processing personal dataPublic privacy notice describing what data is collected, why it is collected, how it is used, where it is transferred, how it is protected, and how long it is stored.
Data subject rights processRequired where applicable by law or marketEspecially GDPR, CPRA, and other privacy-law contextsProcess for access, download, correction, deletion, and other data-subject requests; response SLA; contact channel.
Data retention and deletionRequiredAll partners processing Protected DataRetention schedule, deletion process, deletion logs, and process for deleting data after seller deauthorization or app disconnection.
Data minimizationRequiredAll partners accessing APIs or Protected DataScope justification, API permission list, business purpose for each data category, and evidence that unnecessary scopes are not requested.
Information security policyRequiredAll partnersSecurity policy or framework, review cadence, senior leadership approval, and ownership.
Network securityRequiredAll partners operating production systemsNetwork diagram, environment segmentation, firewall controls, NIDS/HIPS or equivalent monitoring, and alert process.
Endpoint protectionRequiredAll partners with employee devices, servers, or cloud workloadsAnti-virus, EDR, HIPS, or equivalent tooling; scan cadence; policy update process; remediation evidence.
Security baselinesRequiredAll partnersPassword policy, administrator MFA, screen auto-lock, device hardening, employee security awareness training, and admin-account controls.
Data encryption and key managementRequiredAll partners storing or transmitting Protected DataData-at-rest encryption design, TLS 1.2+ for data in transit, key management process, and cryptographic standard. Use AES-256 or stronger for symmetric encryption. If RSA is used, use RSA-2048 or stronger; do not use RSA-1024 as a security baseline.
Access controlRequiredAll partnersPublished access-control policy, role-based access control, need-to-know and least-privilege controls, system access logs, and at least annual access review evidence.
Vulnerability managementRequiredAll partners operating production systemsVulnerability scan reports, penetration test reports if available, remediation SLA, issue tracker, and retained evidence of fixes.
Incident managementRequiredAll partnersIncident response policy, incident escalation contacts, annual incident drill evidence, incident report template, and post-incident review process.
#

§6 Privacy requirements

Partners must protect personal data throughout the full data lifecycle: collection, storage, processing, transfer, access, retention, and disposal. At minimum, your submission should explain:

  • who owns privacy compliance inside your organization;
  • how your privacy notice explains data collection and processing;
  • how users or sellers can request access, correction, download, deletion, or other rights where required;
  • how long each data category is retained;
  • how data is deleted when a seller revokes authorization, disconnects the app, or no longer needs the service;
  • why each requested API scope and data category is necessary for the service.
#

§7 Security requirements

Partners must implement organizational and technical controls that protect Protected Data and reduce the risk of unauthorized access, disclosure, alteration, or loss. At minimum, your submission should explain:

  • how your information security program is governed and reviewed;
  • how production, staging, and internal networks are segmented;
  • what endpoint protection or workload protection is deployed;
  • how administrator accounts are protected with MFA;
  • how data is encrypted at rest and in transit;
  • how encryption keys and secrets are stored and rotated;
  • how employee and contractor access is granted, reviewed, and removed;
  • how vulnerabilities are detected, prioritized, remediated, and tracked;
  • how incidents are escalated, handled, documented, and reviewed.

Encryption baseline:

  • Data in transit: TLS 1.2 or above.
  • Data at rest: AES-256 or stronger, or an equivalent managed cloud encryption control.
  • RSA, if used for encryption, signing, or key transport: RSA-2048 or stronger. RSA-1024 should not be used as a current security baseline.
#

§8 Review outcomes

OutcomeWhat it meansWhat to do
ApprovedThe submitted questionnaire and evidence passed the review for the requested market or app scope.Continue the app launch path in Partner Center.
Follow-up requestedThe review team needs clarification or additional evidence.Respond with specific evidence, screenshots, policies, diagrams, or updated answers. Incomplete follow-up can extend the timeline.
RejectedThe submission did not satisfy the review requirement or raised unresolved security / privacy concerns.Read the assessor's comments, fix the issue, update the questionnaire or evidence, and resubmit if Partner Center allows resubmission.

If the review remains in progress longer than the applicable planning time, submit a ticket with the app key, service ID, market, questionnaire submission date, current review status, and any reviewer comments.

#

§9 Launch requirement

You cannot launch an app in the TikTok Shop App and Service Store until the required data security, privacy, compliance, and legal review steps for the target market have been approved. There are no exceptions unless Partner Center or the relevant review team explicitly confirms that the requirement does not apply to your app.

#