Update: Amazon API Services Developer Agreement, Data Protection Policy, and Acceptable Use Policy
From June 12 2024 Amazon will enforce new API Service Developer Agreement, Data Protection Policy and Acceptable Use Policy. All API calls must use TLS 1.2+ and purge order‑related data within 30 days, with a 5 % quarterly audit that can suspend keys.
Overview
Starting June 12 2024, Amazon will enforce updated versions of its Services API Developer Agreement, Data Protection Policy, and Acceptable Use Policy. The revisions raise the bar for security, tighten rules around data retention, and broaden the list of prohibited activities. Any seller or third‑party provider that calls Amazon APIs after that date must confirm compliance, or risk losing access to critical integration points.
Key Points
- Effective date — All developers are automatically bound by the new terms from June 12 2024; any API request made after that day signals acceptance of the revised agreements.
- Encryption requirement — Applications that currently move or store buyer information without modern encryption must adopt TLS 1.2 or higher and enable encryption at rest for stored records.
- Data‑minimization rule — The updated Data Protection Policy obliges developers to keep only the data needed for a specific transaction and to purge it within 30 days of order fulfillment unless a documented exception applies.
- New prohibited uses — The Acceptable Use Policy now bans automated scraping of competitor listings and the use of API output for external price‑monitoring services that are not authorized by Amazon.
- Quarterly compliance sampling — Amazon will randomly audit 5 % of active API keys each quarter; any key that fails the audit will be suspended until the issue is corrected.
How the Updates Work
-
Policy publication and acknowledgment — Amazon posts the revised documents on its developer portal; each registered developer must log in, review the changes, and click an “I Agree” button before any API call is processed after June 12. Example: A third‑party inventory‑sync platform displays a pop‑up on July 1 prompting its admin to accept the new terms before the next synchronization can run.
-
Technical compliance checks — When an API request reaches Amazon’s gateway, the system inspects the TLS version, validates required security headers, and, if the developer has enabled IP‑restriction, confirms the call originates from an approved address range.
Analysis & Recommendations
Why This Matters
Non‑compliant sellers risk losing API connectivity, which halts inventory sync, order processing and price updates. The 30‑day deletion rule and TLS 1.2 mandate require immediate code and infrastructure changes before the June 12 deadline.
Key Takeaways
- Effective date is June 12 2024; any API request after that signals acceptance of the new terms.
- TLS 1.2 or higher and encryption at rest are mandatory; calls using TLS 1.0/1.1 receive a 403 response.
- Data must be deleted within 30 days of order fulfillment unless an exception is documented.
Recommended Actions
- →Log into the Amazon Developer Portal > Agreements page and click “I Agree” to the revised documents before making any API calls.
- →Upgrade your server or SDK to support TLS 1.2+ and verify the setting in Seller Central > Settings > Security.
- →Implement a nightly job that reads the “retention‑deadline” flag from API responses and deletes records older than 30 days; document the process fo...
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!