Data Protection Policy

Offer a wide range of services to help businesses establish.

The Data Protection Policy (“DPP”) governs the receipt, storage, usage, transfer, and disposal of Information, including the data vended and retrieved through the Amazon Services API (including the Marketplace Web Service API). This policy is applicable to all systems that store, process, or otherwise handle data vended and retrieved from the Amazon Services API.

This Policy supplements the Amazon Services API Developer Agreement and the Acceptable Use Policy. Failure to comply may result in suspension or termination of Amazon Services API access.

1. General Security Requirements

Consistent with industry-leading security, Developers will maintain physical, administrative, and technical safeguards, and other security measures to maintain the security and confidentiality of Information accessed, collected, used, stored, or transmitted by a Developer.

1.1 Network Protection

Developers must implement network protection controls including network firewalls and network access control lists to deny access to unauthorized IP addresses. Developers must implement network segmentation, anti-virus and anti-malware software on end-user devices. Developers must restrict public access only to approved users and carry out data protection and IT security training for everyone with system access.

1.2 Access Management

Developers must establish a formal user access registration process to assign access rights for all user types and services by ensuring that a unique ID is assigned to each person with computer access to Information.

Developers must not create or use generic, shared, or default login credentials or user accounts and must prevent user accounts from being shared. Developers must ensure that access is granted only to required users and must review access permissions regularly.

1.3 Least Privilege Principle

Developers must implement fine-grained access control mechanisms to allow granting rights to any party using the Application and the Application’s authorized operators following the principle of least privilege. Access to Information must be granted on a “need-to-know” basis.

1.4 Credential Management

Developers must establish minimum password requirements for personnel and systems with access to Information. Passwords must meet required security standards including a minimum length of twelve (12) characters, uppercase and lowercase letters, numbers, and special characters.

Developers must ensure Multi-Factor Authentication (MFA) is required for all user accounts. API keys provided by Amazon must be encrypted and accessible only by authorized employees.

1.5 Encryption in Transit

Developers must encrypt all Information in transit with secure protocols such as TLS 1.2+, SFTP, and SSH-2. Security controls must be enforced across all applicable internal and external endpoints.

1.6 Risk Management and Incident Response Plan

Developers must have a risk assessment and management process reviewed by senior management annually. This process must include assessment of potential threats, vulnerabilities, likelihood, and impact.

Developers must create and maintain plans to detect and handle Security Incidents, including incident response roles, procedures, escalation paths, and corrective actions.

1.7 Request for Deletion

Developers must permanently and securely delete Information upon and in accordance with Amazon’s notice requiring deletion within 30 days of Amazon’s requests unless the data is necessary to meet legal requirements, including tax or regulatory requirements.

Secure deletion must occur in accordance with industry-standard sanitization processes such as NIST 800-88. Developers must also permanently and securely delete all live (online or network accessible) instances of Information 90 days after Amazon’s notice.

1.8 Data Attribution

Developers must store Information in a separate database or implement a mechanism to tag and identify the origin of all data in any database that contains Information.

2. Additional Security Requirements Specific to Personally Identifiable Information

The following additional Security Requirements must be met for Personally Identifiable Information (“PII”). PII is granted to Developers for select tax and merchant fulfilled shipping purposes, on a must-have basis.

If an Amazon Services API contains PII, or PII is combined with non-PII, then the entire data store must comply with the following requirements.

2.1 Data Retention

Developers will retain PII for no longer than 30 days after order delivery and only for the purpose necessary to fulfill orders, calculate and remit taxes, produce tax invoices and other legally required documents, and meet legal requirements.

Developers may retain data for over 30 days after order delivery only if required by law and only for the purposes of complying with that law. PII must not be transmitted or stored unprotected.

2.2 Data Governance

Developers must create, document, and abide by privacy and data handling policies that govern appropriate conduct and technical controls applied in managing and protecting information assets.

A record of data processing activities such as specific data fields and how they are collected, processed, stored, used, shared, and disposed for all PII should be maintained to establish accountability and compliance with regulations.

Developers must establish and abide by privacy policies for customer consent and data rights to access, rectify, erase, or stop sharing and processing information where applicable.

2.3 Asset Management

Developers must maintain baseline standard configuration for information systems and keep inventory of software and physical assets with access to PII.

Physical assets that store, process, or otherwise handle PII must comply with all requirements set forth in this policy. Developers must not store PII in removable media, personal devices, or unsecured public cloud applications unless encrypted using appropriate security standards.

2.4 Encryption at Rest

Developers must encrypt all PII at rest using at least AES-128 or RSA with 2048-bit key size or higher.

Cryptographic materials and capabilities used for encryption of PII must only be accessible to the Developer’s processes and services.

2.5 Secure Coding Practices

Developers must not hardcode sensitive credentials in their code, including encryption keys, secret access keys, or passwords. Sensitive credentials must not be exposed in public code repositories.

Developers must maintain separate test and production environments.

2.6 Logging and Monitoring

Developers must gather logs to detect security-related events including successful or failed events, date and time, access attempts, data changes, and system errors.

Developers must implement logging mechanisms across all channels providing access to Information, including service APIs, storage-layer APIs, and administrative dashboards.

Logs must have access controls to prevent unauthorized access and tampering throughout their lifecycle. Unless otherwise required by applicable law, logs must be retained for at least 90 days for reference in case of a Security Incident.

2.7 Vulnerability Management

Developers must create and maintain a plan and/or runbook to detect and remediate vulnerabilities. Developers must protect physical hardware containing PII from technical vulnerabilities by performing vulnerability scans and remediating appropriately.

Developers must conduct vulnerability scanning at least every 180 days, penetration testing at least every 365 days, and scan code for vulnerabilities prior to each release.

Developers must control changes to storage hardware by testing, verifying changes, approving changes, and restricting access to authorized personnel only. Developers must maintain appropriate procedures to restore availability and access to PII in a timely manner in the event of a physical or technical incident.

3. Audit and Assessment

Developers must maintain all appropriate books and records reasonably required to verify compliance with the Acceptable Use Policy, Data Protection Policy, and Amazon Services API Developer Agreement during the period of this agreement and for 12 months thereafter.

Upon Amazon’s written request, Developers must certify in writing to Amazon that they are in compliance with these policies.

Upon request, Amazon may, or may have an independent certified public accounting firm selected by Amazon, audit, assess, and inspect the books, records, facilities, operations, and security of all systems involved with a Developer’s Application in the retrieval, storage, or processing of Information.

Developers must cooperate with Amazon or Amazon’s auditor in connection with any audit or assessment. If deficiencies, breaches, or failures to comply are identified, Developers must take all necessary actions to remediate those deficiencies within an agreed-upon timeframe.

Upon request, Developers must provide remediation evidence in the form requested by Amazon, which may include policies, documents, screenshots, or screen sharing of application or infrastructure changes.

4. Definitions

Amazon Services API

Means any application programming interface (API) offered by Amazon for the purpose of helping Amazon Authorized Users to programmatically exchange data.

API Materials

Means Materials made available in connection with the Amazon Services API, including APIs, documentation, specifications, software libraries, software development kits, and other supporting materials, regardless of format.

Application

Means a software application or website that interfaces with the Amazon Services API or the API Materials.

Authorized User

Means a user of Amazon’s systems or services who has been specifically authorized by Amazon to use the applicable systems or services.

Customer

Means any person or entity who has purchased items or services from Amazon’s public-facing websites.

Developer

Means any person or entity, including you if applicable, that uses the Amazon Services API or the API Materials for a Permitted Use on behalf of an Authorized User.