来自 TikTok Shop 官方资料快照 ·
- 当前资料结构化阅读页
- 固定快照已留存,可追溯
- 官方原文可核对
资料正文
§1 Protecting customer and protected data
TikTok Shop requires partners and developers to protect customer, seller, buyer, business, and platform data before they can launch an app that accesses TikTok Shop data. Before launch, prospective and current partners may need to complete the Data Security and Privacy Review (DSPR). This review assesses whether the partner's privacy, security, data-handling, and governance practices meet TikTok Shop requirements before the app accesses Protected Data. This page explains:
- how DSPR differs from the US Data Security Review;
- how to start the review;
- what evidence to prepare;
- how to interpret common privacy and security requirements.
This page is not legal advice and does not replace the Developer Terms of Service or any market-specific requirements shown in Partner Center.
§2 Review names and timelines
Use Data Security and Privacy Review (DSPR) as the umbrella name for the privacy, security, compliance, and data-protection review before launch. Do not treat Data Security and Privacy Review (DSPR) and US Data Security Review as the same review. They are separate review processes with different owners, purposes, forms, and timelines. A US app may be required to complete both reviews before launch.
| Review name | When it applies | Who evaluates it | Typical planning time | Notes |
|---|---|---|---|---|
| Data Security and Privacy Review (DSPR) | Partners or apps that access, process, store, or transmit TikTok Shop Protected Data. Required before App Store launch when Partner Center or the review team requests it. | TikTok Shop privacy, security, compliance, or review teams, depending on market and app scope. | The DSPR assessment is commonly planned at about 2 weeks after a complete submission. Full compliance and legal review can take 3 or more weeks, especially when follow-up is required. | This is a privacy and security maturity review. Start it during onboarding, not at the end of development. |
| US Data Security Review / US Data Security Questionnaire | Developers building apps for the US market. | US Data Security team. | Typically 10-12 business days after submission. | This is a separate US-market data security review. Passing DSPR does not automatically satisfy the US Data Security Review, and passing the US Data Security Review does not automatically satisfy DSPR. |
The 2-week DSPR estimate and the 10-12 business day US estimate refer to different reviews. In all cases, Partner Center status and each review team's instructions are the source of truth.
§3 Key terms
| Term | Meaning |
|---|---|
| Protected Data | Any TikTok Shop data or customer-related data that a partner accesses, processes, stores, transmits, or derives through its app or service. This can include seller data, buyer data, order data, product data, authorization data, operational data, support data, business information, system logs, and any personal data received through TikTok Shop APIs or workflows. |
| DSPR | Data Security and Privacy Review. The review of a partner's privacy, security, data-handling, and governance practices before launch or before access to protected data is approved. |
| US Data Security Review / US Data Security Questionnaire | A separate US-market data security review managed by the US Data Security team to assess whether a developer keeps US user data safe and secure. |
| DPO | Data Protection Officer. A role required under certain privacy laws or jurisdictions to oversee data-protection compliance. |
| GDPR | General Data Protection Regulation. A European privacy regulation that can apply to personal data processing involving individuals in the European Economic Area. |
| CPRA | California Privacy Rights Act. A California privacy law that can apply to personal data processing involving California residents. |
| NIDS | Network Intrusion Detection System. A tool used to monitor network traffic for suspicious activity. |
| HIPS | Host Intrusion Prevention System. A host-level tool used to detect or prevent suspicious activity on endpoints or servers. |
| MFA | Multi-factor Authentication. A login control that requires more than one factor, such as password plus authenticator code or hardware key. |
| TLS | Transport Layer Security. A protocol used to protect data in transit. TikTok Shop expects TLS 1.2 or above for protected data transmission. |
§4 How to start DSPR
Start the DSPR process as early as possible during developer onboarding. Do not wait until the app is fully built, because launch can be blocked until the review is approved. Use this order:
- Complete developer onboarding in Partner Center.
- Open the app or service detail page in Partner Center > App & Service.
- Check the app launch checklist, My Account, or compliance / legal / data-security review section for a visible DSPR, due diligence, or security questionnaire task.
- If a questionnaire is visible, complete and submit it from Partner Center.
- If no questionnaire is visible, contact the Partner Development & Management team for your market or submit a Partner Center support ticket and request the correct due diligence / DSPR questionnaire for your app.
- For US apps, complete the US Data Security Review / US Data Security Questionnaire separately when instructed by Partner Center, the App Store team, or the US Data Security team.
- Monitor the review status and respond to follow-up questions. Incomplete or unclear answers can delay the assessment or result in rejection.
Market contact and support paths:
| Market | Primary path | Contact channel |
|---|---|---|
| United States | Support tickets for US | partner.us@tiktokshop.com when your partner manager or review contact asks for email follow-up. |
| United Kingdom | Support tickets | partner.uk@tiktokshop.com when your partner manager or review contact asks for email follow-up. |
| Other markets | Support tickets | partner@tiktokshop.com when your partner manager or review contact asks for email follow-up. |
§5 Preparation checklist
Prepare the following evidence before submitting DSPR or a market-specific questionnaire.
| Requirement item | Required? | Applies to | Evidence to prepare |
|---|---|---|---|
| Business and entity details | Required | All partners | Company name, headquarters location, registration details, business category, level of foreign ownership, and primary contact. |
| Workforce and system locations | Required | All partners | Primary and alternate workforce locations, production system locations, data storage locations, and remote-access model. |
| Subcontractor and vendor use | Required if applicable | Partners using subcontractors, cloud vendors, processors, or service providers | Subcontractor list, data handled by each vendor, data processing agreements, and access controls. |
| Data inventory and data flow | Required | All partners accessing Protected Data | Diagram or table showing what Protected Data is collected, why it is needed, where it is stored, who can access it, where it is transferred, and when it is deleted. |
| Privacy roles and responsibilities | Required | All partners; DPO required in certain jurisdictions | Named privacy owner, escalation contact, DPO details if required, and role responsibilities. |
| Privacy notice | Required | All partners processing personal data | Public privacy notice describing what data is collected, why it is collected, how it is used, where it is transferred, how it is protected, and how long it is stored. |
| Data subject rights process | Required where applicable by law or market | Especially GDPR, CPRA, and other privacy-law contexts | Process for access, download, correction, deletion, and other data-subject requests; response SLA; contact channel. |
| Data retention and deletion | Required | All partners processing Protected Data | Retention schedule, deletion process, deletion logs, and process for deleting data after seller deauthorization or app disconnection. |
| Data minimization | Required | All partners accessing APIs or Protected Data | Scope justification, API permission list, business purpose for each data category, and evidence that unnecessary scopes are not requested. |
| Information security policy | Required | All partners | Security policy or framework, review cadence, senior leadership approval, and ownership. |
| Network security | Required | All partners operating production systems | Network diagram, environment segmentation, firewall controls, NIDS/HIPS or equivalent monitoring, and alert process. |
| Endpoint protection | Required | All partners with employee devices, servers, or cloud workloads | Anti-virus, EDR, HIPS, or equivalent tooling; scan cadence; policy update process; remediation evidence. |
| Security baselines | Required | All partners | Password policy, administrator MFA, screen auto-lock, device hardening, employee security awareness training, and admin-account controls. |
| Data encryption and key management | Required | All partners storing or transmitting Protected Data | Data-at-rest encryption design, TLS 1.2+ for data in transit, key management process, and cryptographic standard. Use AES-256 or stronger for symmetric encryption. If RSA is used, use RSA-2048 or stronger; do not use RSA-1024 as a security baseline. |
| Access control | Required | All partners | Published access-control policy, role-based access control, need-to-know and least-privilege controls, system access logs, and at least annual access review evidence. |
| Vulnerability management | Required | All partners operating production systems | Vulnerability scan reports, penetration test reports if available, remediation SLA, issue tracker, and retained evidence of fixes. |
| Incident management | Required | All partners | Incident response policy, incident escalation contacts, annual incident drill evidence, incident report template, and post-incident review process. |
§6 Privacy requirements
Partners must protect personal data throughout the full data lifecycle: collection, storage, processing, transfer, access, retention, and disposal. At minimum, your submission should explain:
- who owns privacy compliance inside your organization;
- how your privacy notice explains data collection and processing;
- how users or sellers can request access, correction, download, deletion, or other rights where required;
- how long each data category is retained;
- how data is deleted when a seller revokes authorization, disconnects the app, or no longer needs the service;
- why each requested API scope and data category is necessary for the service.
§7 Security requirements
Partners must implement organizational and technical controls that protect Protected Data and reduce the risk of unauthorized access, disclosure, alteration, or loss. At minimum, your submission should explain:
- how your information security program is governed and reviewed;
- how production, staging, and internal networks are segmented;
- what endpoint protection or workload protection is deployed;
- how administrator accounts are protected with MFA;
- how data is encrypted at rest and in transit;
- how encryption keys and secrets are stored and rotated;
- how employee and contractor access is granted, reviewed, and removed;
- how vulnerabilities are detected, prioritized, remediated, and tracked;
- how incidents are escalated, handled, documented, and reviewed.
Encryption baseline:
- Data in transit: TLS 1.2 or above.
- Data at rest: AES-256 or stronger, or an equivalent managed cloud encryption control.
- RSA, if used for encryption, signing, or key transport: RSA-2048 or stronger. RSA-1024 should not be used as a current security baseline.
§8 Review outcomes
| Outcome | What it means | What to do |
|---|---|---|
| Approved | The submitted questionnaire and evidence passed the review for the requested market or app scope. | Continue the app launch path in Partner Center. |
| Follow-up requested | The review team needs clarification or additional evidence. | Respond with specific evidence, screenshots, policies, diagrams, or updated answers. Incomplete follow-up can extend the timeline. |
| Rejected | The submission did not satisfy the review requirement or raised unresolved security / privacy concerns. | Read the assessor's comments, fix the issue, update the questionnaire or evidence, and resubmit if Partner Center allows resubmission. |
If the review remains in progress longer than the applicable planning time, submit a ticket with the app key, service ID, market, questionnaire submission date, current review status, and any reviewer comments.
§9 Launch requirement
You cannot launch an app in the TikTok Shop App and Service Store until the required data security, privacy, compliance, and legal review steps for the target market have been approved. There are no exceptions unless Partner Center or the relevant review team explicitly confirms that the requirement does not apply to your app.
