快工助手跨境电商知识与商机助手

US data security review

TikTok Shop 官方资料 · TikTok Shop Partner Center 开发者文档 · 适合开发者

stable本次发布有变化全部展示

来自 TikTok Shop 官方资料快照 ·

打开官方原文 ↗
  1. 当前资料结构化阅读页
  2. 固定快照已留存,可追溯
  3. 官方原文可核对
查看技术与溯源信息
平台 / profile
TikTok Shop / profile.tiktok.docs_api
语言
en-US
发布版本
cn-20260909-2
标签
zhuge/sourceplatform/tiktok_shopaudience/developercategory/api_doctopic/compliancetopic/developer

资料正文

§1 US data security review

The US Data Security Questionnaire is the US-market data security questionnaire used within the broader Data Security and Privacy Review (DSPR), compliance, and legal review path. It is provided and managed by the US Data Security team to confirm that developers keep US user, seller, buyer, business, and platform data safe and secure. All developers building apps for the US market must complete this process during app development when instructed by Partner Center, the App Store team, or the US Data Security team. An app cannot launch in the TikTok Shop US App and Service Store until the required US Data Security Questionnaire and other required launch reviews are approved.

#

§2 How this review relates to DSPR

Use Data Security and Privacy Review (DSPR) as the umbrella name for the privacy, security, data-handling, and governance review before launch. Use US Data Security Questionnaire as the US-market questionnaire managed by the US Data Security team.

ReviewApplies toEvaluatorTypical planning timeLaunch impact
Data Security and Privacy Review (DSPR)Apps or partners that access, process, store, or transmit TikTok Shop Protected Data, or when Partner Center or the review team requests it.TikTok Shop privacy, security, compliance, legal, or review teams, depending on market and app scope.Normally about 2 weeks after a complete submission. Full compliance and legal review can take longer if follow-up is required.Required before launch when requested.
US Data Security QuestionnaireApps built for the US market.US Data Security team.Typically 10-12 business days after submission.Required before an app can launch in the TikTok Shop US App and Service Store.

For US launch, plan for both the general DSPR / compliance review path and the US Data Security Questionnaire. The two timeline estimates are not contradictory if labeled correctly: DSPR is the broader review path, while the US Data Security Questionnaire is the US-specific data security questionnaire within that path. Partner Center status and the review team's instructions are the source of truth for your app.

#

§3 When to start and where to find it

Start the US Data Security Questionnaire as early as possible during app development. Do not wait until the app is ready to publish, because launch can be blocked until the review is approved. Use this path:

  1. Complete developer onboarding in Partner Center.
  2. Open your app or service in Partner Center > App and Service.
  3. Check the app launch checklist, My Account, or the compliance / legal / data-security review section for a visible DSPR, due diligence, security questionnaire, or US Data Security Questionnaire task.
  4. If the questionnaire is visible, complete and submit it from Partner Center.
  5. If no questionnaire is visible but your app targets the US market, contact the US Partner Development and Management team or submit a US Partner Center support ticket and request the correct US data security review entry.
  6. Include your app key, service ID, app name, target market, app category, requested scopes, questionnaire submission date if applicable, and current launch status in the ticket.

Support and contact paths:

MarketPrimary pathContact channel
United StatesSupport tickets for USpartner.us@tiktokshop.com when your partner manager or review contact asks for email follow-up.
Other marketsSupport ticketsUse the contact channel provided by your Partner Development and Management team.
#

§4 Where it fits in the US launch timeline

The US Data Security Questionnaire is part of the US launch review path. It does not replace app review, language listing review, registration review, or other compliance checks.

StepReview or taskNotes
1Registration reviewComplete the initial Partner Center review of your app or service registration and basic information.
2Language listing reviewRequired for public apps for each target market listing.
3App reviewRequired for public apps. Connector apps also require beta testing. Custom apps may require app review depending on category, market, API scope, and seller authorization scale.
4DSPR / compliance and legal reviewComplete the required data security, privacy, compliance, and legal review steps for the target market.
5US Data Security QuestionnaireRequired for US-market apps. This may run in parallel with other review work, but approval is required before US launch.
6Publish and listPublish or list only after all required launch approvals for the app type and target market are complete.

If Partner Center allows parallel submission, you may prepare the language listing, app review materials, DSPR evidence, and US Data Security Questionnaire at the same time. However, final US launch is blocked until every required review is approved.

#

§5 What the questionnaire evaluates

Prepare answers and evidence for the following areas before submitting:

  • Business and entity details, including company name, headquarters, registration details, ownership, and primary contacts.
  • Workforce, production system, and data storage locations.
  • Subcontractors, cloud vendors, processors, and any third parties that can access TikTok Shop data.
  • Data inventory and data flow, including what Protected Data is collected, why it is needed, where it is stored, who can access it, where it is transferred, and when it is deleted.
  • Privacy notice, data-subject request process, retention schedule, and deletion process after seller deauthorization or app disconnection.
  • API scope justification and data minimization controls.
  • Access control, MFA, least privilege, access logging, and access review process.
  • Encryption for data in transit and at rest, key management, and secrets handling.
  • Vulnerability scanning, penetration testing if available, remediation tracking, and evidence retention.
  • Incident response policy, escalation contacts, annual drill evidence, and post-incident review process.
#

§6 Common rejection reasons

The following issues commonly create follow-up questions or rejection risk:

  • Incomplete, vague, or inconsistent questionnaire answers.
  • Missing data inventory, data-flow diagram, or explanation of where US user data is stored and processed.
  • Overbroad API scopes without a clear business purpose for each scope or data category.
  • Privacy notice that does not explain collection, use, transfer, retention, deletion, or seller / user rights.
  • No documented process for access, correction, deletion, or other data-subject requests where required.
  • No clear deletion process after seller deauthorization, shop disconnection, contract termination, or service cancellation.
  • Weak access controls, such as no MFA for administrator access, no least-privilege model, no access logs, or no periodic access review.
  • Insufficient encryption, unclear key management, weak secrets handling, or no evidence of TLS for data in transit.
  • No vulnerability management process, missing scan results, missing remediation SLA, or unresolved high-risk findings.
  • No incident response policy, escalation path, drill evidence, or post-incident review process.
  • Unclear subcontractor, cloud vendor, processor, or offshore access model.
  • Claims that are not supported by policy documents, diagrams, screenshots, system configuration, reports, or other evidence.
#

§7 If you are rejected or receive follow-up questions

If the review team asks follow-up questions or rejects the submission, use this response path:

  1. Read the reviewer comments carefully and identify each privacy, security, or data-handling concern.
  2. Map each concern to a specific update, such as a revised questionnaire answer, data-flow diagram, privacy notice, security policy, access-control evidence, encryption evidence, vulnerability report, or incident response document.
  3. Update the questionnaire and supporting evidence. Keep answers specific and consistent with your actual production architecture and operating process.
  4. Resubmit through Partner Center if resubmission is available.
  5. If the review is blocked or the questionnaire entry is not visible, submit a US support ticket with your app key, service ID, market, questionnaire submission date, current review status, and reviewer comments.
  6. Do not launch the app in the TikTok Shop US App and Service Store until the US Data Security Questionnaire and all other required launch reviews are approved.
#