Amazon Tightens SP-API Data Protection Rules: Broader Confidentiality Requirements Take Effect April 2025
Amazon's revised Data Protection Policy expands SP-API confidentiality requirements beyond customer data to all non-public information, mandating enterprise-grade security controls by April 8, 2025.
Overview
Amazon has rolled out a sweeping revision to Section 3 of its Data Protection Policy for Selling Partner API developers, set to take effect on April 8, 2025. The update significantly expands confidentiality obligations beyond customer data to cover all non-public information exchanged through Amazon's APIs. For solution providers and sellers relying on SP-API integrations, understanding these new requirements is essential — continued use of the API after the effective date constitutes acceptance of the revised terms.
What's Changing
- Wider confidentiality scope — The policy now protects all non-public information shared via the SP-API, including proprietary business data, technical specs, and operational details previously outside formal confidentiality rules.
- Data classification requirements — Developers must categorize all API-received data by sensitivity level and apply appropriate safeguards.
- Physical security mandates — Documented physical protections are now required wherever non-public Amazon data is stored or processed.
- Administrative controls — Background checks, signed confidentiality agreements, designated security officers, and regular security training are all now expected.
- Technical security standards — Network segmentation, encryption (TLS 1.2+ in transit, AES-256 at rest), intrusion detection, penetration testing, and comprehensive audit logging are mandatory.
- Universal MFA enforcement — Every account with access to non-public information must use multi-factor authentication, with no exceptions or shared credentials permitted.
Confidentiality Now Covers Far More Than Customer Data
The most consequential change is the expansion of what counts as protected information. Previously, the DPP focused mainly on consumer personally identifiable information. Under the revised Section 3, confidentiality obligations extend to proprietary business information, technical specifications, and operational data that Amazon shares through its APIs. Catalog structures, fulfillment processes, marketplace operational details — all of it now falls under formal protection requirements. Solution providers must apply the same level of care to this business data that was previously reserved for customer records.
Analysis & Recommendations
Why This Matters
Sellers using third-party tools built on the SP-API could be affected if their solution providers fail to meet the new standards. Developers who build or maintain SP-API integrations face a hard compliance deadline that could disrupt their access if requirements aren't met.
Key Takeaways
- All non-public data from Amazon's APIs — not just customer PII — now falls under formal confidentiality protections
- MFA is mandatory for every account with access to protected information, with no shared credentials allowed
- Physical security, background checks, and designated security officers are now required regardless of company size
- Continued use of the SP-API after April 8, 2025 constitutes automatic acceptance of the new terms
Recommended Actions
- →Audit your current SP-API data handling practices against the new physical, administrative, and technical requirements before April 8
- →Deploy multi-factor authentication on all accounts that interact with non-public Amazon information
- →Request updated security compliance certificates from your cloud hosting provider to document physical safeguard coverage
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!