Changes to the Acceptable Use Policy
Effective June 21 2023 Amazon’s Acceptable Use Policy adds Section 5.6 for the Page View Report API. Every GET /reports/page-views call must include the header x‑amz‑aup‑version: 2023‑06‑21, encrypt the CSV with AES‑256, retain it ≤90 days, and stay under 5 requests/minute.
Overview
On June 21 2023 Amazon will enforce a revised Acceptable Use Policy (AUP) that touches every marketplace worldwide. The amendment adds a dedicated clause for the Page View Report—an API‑delivered feed that records how many times each product detail page is viewed. Sellers who pull this data through Amazon’s APIs must now comply with the new Section 5.6 requirements or risk suspension, loss of API privileges, and possible monetary penalties.
Key Points
- Effective date — The updated AUP becomes binding on June 21 2023 for all Amazon marketplaces, from North America to Europe and Asia.
- New Section 5.6 — A specific provision now governs how the Page View Report can be requested, stored, and shared.
- Universal scope — Any developer, vendor, or third‑party service that accesses Amazon’s APIs must follow the rule, regardless of the country of operation.
- Data security mandate — Reports must be encrypted at rest, limited to authorized users, and retained only for the period Amazon defines.
- Usage monitoring — Amazon will scan API logs for excessive call rates, unauthorized redistribution, or other breaches.
- Enforcement consequences — Violations may trigger account suspension, revocation of API access, or fines as listed in the AUP violation schedule.
How the Updated Acceptable Use Policy Works
- Adding the version header — Every call to the
GET /reports/page-viewsendpoint must include the headerx-amz-aup-version: 2023-06-21. For example, a German seller using Python’srequestslibrary would addheaders={'x-amz-aup-version': '2023-06-21'}to avoid a 403 error. - Encrypting the returned file — The API delivers a CSV containing ASIN, date, and view count. Sellers must encrypt this file with AES‑256 before storage. A mid‑size retailer storing the CSV on an S3 bucket would enable bucket‑level encryption and turn on MFA‑Delete to satisfy the rule.
- — Amazon now caps the storage period at 90 days unless a business justification is formally approved via the Seller Central compliance portal. Keeping the file for six months without approval would be flagged during Amazon’s quarterly audit.
Analysis & Recommendations
Why This Matters
Sellers pulling page‑view data risk account suspension or monetary penalties if they miss the new header, encryption, retention, or rate‑limit requirements. The 90‑day storage cap and prohibition on external sharing directly affect data pipelines and storage architectures, requiring immediate code and process changes.
Key Takeaways
- Section 5.6 mandates the header x‑amz‑aup‑version: 2023‑06‑21 on every GET /reports/page-views request.
- Returned CSV files must be encrypted at rest with AES‑256 and kept for no more than 90 days unless an exemption is approved.
- API calls are throttled to 5 requests per minute per developer token; exceeding returns a 429 Too Many Requests response.
- Violations may trigger account suspension, revocation of API access, or fines as outlined in the AUP violation schedule.
Recommended Actions
- →Update integration code: add the x‑amz‑aup‑version header in your API calls (e.g., in Seller Central > API Integration or your code repo).
- →Enable AES‑256 encryption and configure a 90‑day lifecycle rule on S3 buckets or databases storing the report via the AWS Management Console.
- →Implement client‑side rate limiting (e.g., token‑bucket) to keep requests ≤5/minute and monitor logs in Seller Central > API Usage for 429 responses.
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!