New processes for reporting security incidents and informing Amazon of organizational changes
On July 3 2024 Amazon added mandatory reporting rules to the Data Protection Policy and Acceptable Use Policy. Sellers must email security incidents to [email protected], receive an automated acknowledgment within two hours, and submit any legal‑entity changes via the Seller Central “Change Notification Form” within five business days, keeping records for 12 months.
Overview
On July 3 2024 Amazon introduced new, mandatory procedures for reporting security breaches and notifying the company of major corporate changes. The revisions are embedded in the Data Protection Policy (DPP) and the Acceptable Use Policy (AUP), and they replace the informal email routes and verbal notices that sellers previously relied on. Sellers and developers who ignore the new channels risk slower incident handling, compliance gaps, and potential penalties.
Key Points
- Dedicated security mailbox — All security‑related reports tied to developer policies must now be sent exclusively to [email protected], eliminating the older ad‑hoc email addresses.
- Organizational change notice — Any modification to a seller’s legal structure—such as a merger, acquisition, or executive turnover—must be filed through the “Change Notification Form” in Seller Central within five business days.
- Policy cross‑reference — The DPP now explicitly links incident reporting to the AUP, so a violation of acceptable‑use rules automatically triggers the security‑reporting workflow.
- Escalation timeline — Amazon will send an automated acknowledgment within two hours of receiving a security email and will launch a formal investigation for high‑severity events within 24 hours.
- Record‑keeping requirement — Sellers must keep copies of every incident report and change‑notification submission for at least 12 months to satisfy audit obligations.
- Case‑ID assignment — Each submission receives a unique case identifier that must be referenced in all subsequent communications, ensuring traceability across the investigation lifecycle.
How the New Reporting Process Works
- Identify the event — Determine whether the situation is a security incident (e.g., exposed credentials, data leakage) or an organizational change (e.g., formation of a new legal entity). Example: A developer discovers that an API key was accidentally pushed to a public GitHub repository.
- Gather required details — Compile timestamps, affected assets, impact assessments, and any immediate remediation steps for security events; for structural changes, collect legal documents, new tax identification numbers, and updated contact information. : The exposed API key report lists the repository URL, date of exposure, and the steps taken to rotate the key and revoke the compromised token.
Analysis & Recommendations
Why This Matters
Failing to use the new mailbox or form can delay incident response, create audit gaps, and lead to penalties. The two‑hour acknowledgment and 24‑hour investigation start tighten security handling, while the 12‑month archive is mandatory for compliance audits.
Key Takeaways
- All security reports must be sent exclusively to [email protected], replacing previous ad‑hoc addresses.
- Organizational changes must be filed through the Seller Central “Change Notification Form” within five business days of the event.
- Amazon sends an automated acknowledgment within two hours and assigns a unique case ID (e.g., SEC‑2024‑00123) to each security email.
- Sellers are required to retain every incident report and change‑notification record for at least 12 months for audit purposes.
Recommended Actions
- →Update SOPs: route every security incident email to [email protected], capture the case ID from the acknowledgment, and log it in your incident t...
- →In Seller Central, go to Compliance > Change Notification Form and submit any merger, acquisition, or executive change within five business days, t...
- →Create a secure, searchable repository (e.g., cloud document store) and store all security emails, case IDs, and change‑notification forms for a mi...
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!