Important: Updates to the Amazon API Services Developer Agreement, Data Protection Policy (DPP), and Acceptable Use Policy (AUP)
Effective 22 August 2022 Amazon’s API Services Developer Agreement, Data Protection Policy and Acceptable Use Policy take effect. Developers must rotate API secret keys every 90 days, obtain documented buyer consent and encrypt PII at rest, and limit automated calls to 10 per minute.
Overview
Amazon is updating three foundational policy documents that dictate how developers and sellers interact with its API services: the Amazon API Services Developer Agreement, the Data Protection Policy (DPP), and the Acceptable Use Policy (AUP). The revisions become enforceable on 22 August 2022, giving the marketplace roughly a month for users to review and adjust their integrations. Sellers who rely on Amazon APIs must understand the new security, privacy, and usage rules to keep their storefronts operational and avoid interruptions.
Key Points
- Effective date — All three policies take effect on 22 August 2022, creating a short compliance window for existing integrations.
- Credential rotation — The revised Developer Agreement now obligates developers to rotate API secret keys at least once every 90 days, tightening protection against credential leakage.
- Explicit consent & encryption — The DPP requires documented buyer consent before any personally identifiable information (PII) is stored, and it mandates encryption of that data while at rest.
- Usage restrictions — The updated AUP bans high‑frequency price‑scraping bots and bulk order‑placement scripts that could manipulate marketplace dynamics.
- Compliance audits — Amazon will perform periodic checks; applications that fail to meet the new standards risk suspension or revocation of API access.
- Unified documentation — All three policies are now housed in a single searchable “API Governance” portal, simplifying reference for developers.
How the Updates Work
- Credential rotation schedule — Developers must create a process that generates a new access key, updates every integration point, and disables the old key before the 90‑day deadline. For example, a seller using the MWS Orders API could schedule a Lambda function to issue a fresh key, rewrite the configuration file, and retire the previous key automatically each quarter.
- Buyer consent capture — Any system that records buyer email, shipping address, or purchase history must first obtain a clear opt‑in from the user. A typical implementation adds a mandatory checkbox to a third‑party order‑management dashboard; the checkbox state is stored alongside the data in an encrypted MySQL column, ensuring both consent and protection are recorded.
Analysis & Recommendations
Why This Matters
Non‑compliance can lead to suspension or revocation of API credentials, disrupting order, inventory and pricing integrations. Rotating keys every 90 days reduces credential leakage risk, while mandatory consent and encryption protect buyer data and meet legal obligations. The new 10‑requests‑per‑minute cap forces sellers to redesign high‑frequency bots to avoid penalties.
Key Takeaways
- All three policies become enforceable on 22 August 2022.
- API secret keys must be rotated at least once every 90 days.
- The DPP now requires documented buyer consent and encryption of PII at rest.
- The AUP caps automated product‑listing queries at 10 requests per minute and bans high‑frequency price‑scraping bots.
Recommended Actions
- →Audit API keys in Seller Central > Developer Central > MWS Access Keys, list keys older than 90 days, generate new keys, update all integration con...
- →Add a mandatory opt‑in checkbox to any buyer‑data capture form, store the consent flag in an encrypted database column, and log the timestamp for e...
- →Modify price‑monitoring scripts to enforce a 6‑second delay between calls or integrate a rate‑limiting library so total calls stay ≤10 per minute.
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!