来自 TikTok Shop 官方资料快照 ·
- 当前资料结构化阅读页
- 固定快照已留存,可追溯
- 官方原文可核对
资料正文
§1 US data security review
The US Data Security Questionnaire is the US-market data security questionnaire used within the broader Data Security and Privacy Review (DSPR), compliance, and legal review path. It is provided and managed by the US Data Security team to confirm that developers keep US user, seller, buyer, business, and platform data safe and secure. All developers building apps for the US market must complete this process during app development when instructed by Partner Center, the App Store team, or the US Data Security team. An app cannot launch in the TikTok Shop US App and Service Store until the required US Data Security Questionnaire and other required launch reviews are approved.
§2 How this review relates to DSPR
Use Data Security and Privacy Review (DSPR) as the umbrella name for the privacy, security, data-handling, and governance review before launch. Use US Data Security Questionnaire as the US-market questionnaire managed by the US Data Security team.
| Review | Applies to | Evaluator | Typical planning time | Launch impact |
|---|---|---|---|---|
| Data Security and Privacy Review (DSPR) | Apps or partners that access, process, store, or transmit TikTok Shop Protected Data, or when Partner Center or the review team requests it. | TikTok Shop privacy, security, compliance, legal, or review teams, depending on market and app scope. | Normally about 2 weeks after a complete submission. Full compliance and legal review can take longer if follow-up is required. | Required before launch when requested. |
| US Data Security Questionnaire | Apps built for the US market. | US Data Security team. | Typically 10-12 business days after submission. | Required before an app can launch in the TikTok Shop US App and Service Store. |
For US launch, plan for both the general DSPR / compliance review path and the US Data Security Questionnaire. The two timeline estimates are not contradictory if labeled correctly: DSPR is the broader review path, while the US Data Security Questionnaire is the US-specific data security questionnaire within that path. Partner Center status and the review team's instructions are the source of truth for your app.
§3 When to start and where to find it
Start the US Data Security Questionnaire as early as possible during app development. Do not wait until the app is ready to publish, because launch can be blocked until the review is approved. Use this path:
- Complete developer onboarding in Partner Center.
- Open your app or service in Partner Center > App and Service.
- Check the app launch checklist, My Account, or the compliance / legal / data-security review section for a visible DSPR, due diligence, security questionnaire, or US Data Security Questionnaire task.
- If the questionnaire is visible, complete and submit it from Partner Center.
- If no questionnaire is visible but your app targets the US market, contact the US Partner Development and Management team or submit a US Partner Center support ticket and request the correct US data security review entry.
- Include your app key, service ID, app name, target market, app category, requested scopes, questionnaire submission date if applicable, and current launch status in the ticket.
Support and contact paths:
| Market | Primary path | Contact channel |
|---|---|---|
| United States | Support tickets for US | partner.us@tiktokshop.com when your partner manager or review contact asks for email follow-up. |
| Other markets | Support tickets | Use the contact channel provided by your Partner Development and Management team. |
§4 Where it fits in the US launch timeline
The US Data Security Questionnaire is part of the US launch review path. It does not replace app review, language listing review, registration review, or other compliance checks.
| Step | Review or task | Notes |
|---|---|---|
| 1 | Registration review | Complete the initial Partner Center review of your app or service registration and basic information. |
| 2 | Language listing review | Required for public apps for each target market listing. |
| 3 | App review | Required for public apps. Connector apps also require beta testing. Custom apps may require app review depending on category, market, API scope, and seller authorization scale. |
| 4 | DSPR / compliance and legal review | Complete the required data security, privacy, compliance, and legal review steps for the target market. |
| 5 | US Data Security Questionnaire | Required for US-market apps. This may run in parallel with other review work, but approval is required before US launch. |
| 6 | Publish and list | Publish or list only after all required launch approvals for the app type and target market are complete. |
If Partner Center allows parallel submission, you may prepare the language listing, app review materials, DSPR evidence, and US Data Security Questionnaire at the same time. However, final US launch is blocked until every required review is approved.
§5 What the questionnaire evaluates
Prepare answers and evidence for the following areas before submitting:
- Business and entity details, including company name, headquarters, registration details, ownership, and primary contacts.
- Workforce, production system, and data storage locations.
- Subcontractors, cloud vendors, processors, and any third parties that can access TikTok Shop data.
- Data inventory and data flow, including what Protected Data is collected, why it is needed, where it is stored, who can access it, where it is transferred, and when it is deleted.
- Privacy notice, data-subject request process, retention schedule, and deletion process after seller deauthorization or app disconnection.
- API scope justification and data minimization controls.
- Access control, MFA, least privilege, access logging, and access review process.
- Encryption for data in transit and at rest, key management, and secrets handling.
- Vulnerability scanning, penetration testing if available, remediation tracking, and evidence retention.
- Incident response policy, escalation contacts, annual drill evidence, and post-incident review process.
§6 Common rejection reasons
The following issues commonly create follow-up questions or rejection risk:
- Incomplete, vague, or inconsistent questionnaire answers.
- Missing data inventory, data-flow diagram, or explanation of where US user data is stored and processed.
- Overbroad API scopes without a clear business purpose for each scope or data category.
- Privacy notice that does not explain collection, use, transfer, retention, deletion, or seller / user rights.
- No documented process for access, correction, deletion, or other data-subject requests where required.
- No clear deletion process after seller deauthorization, shop disconnection, contract termination, or service cancellation.
- Weak access controls, such as no MFA for administrator access, no least-privilege model, no access logs, or no periodic access review.
- Insufficient encryption, unclear key management, weak secrets handling, or no evidence of TLS for data in transit.
- No vulnerability management process, missing scan results, missing remediation SLA, or unresolved high-risk findings.
- No incident response policy, escalation path, drill evidence, or post-incident review process.
- Unclear subcontractor, cloud vendor, processor, or offshore access model.
- Claims that are not supported by policy documents, diagrams, screenshots, system configuration, reports, or other evidence.
§7 If you are rejected or receive follow-up questions
If the review team asks follow-up questions or rejects the submission, use this response path:
- Read the reviewer comments carefully and identify each privacy, security, or data-handling concern.
- Map each concern to a specific update, such as a revised questionnaire answer, data-flow diagram, privacy notice, security policy, access-control evidence, encryption evidence, vulnerability report, or incident response document.
- Update the questionnaire and supporting evidence. Keep answers specific and consistent with your actual production architecture and operating process.
- Resubmit through Partner Center if resubmission is available.
- If the review is blocked or the questionnaire entry is not visible, submit a US support ticket with your app key, service ID, market, questionnaire submission date, current review status, and reviewer comments.
- Do not launch the app in the TikTok Shop US App and Service Store until the US Data Security Questionnaire and all other required launch reviews are approved.
