Update to the Amazon Acceptable Use Policy
Amazon's Acceptable Use Policy was updated on 6 March 2024, adding Section 5.7 that forces all SP‑API, MWS and related API users to follow the End‑User Data Report Terms. Sellers have a 30‑day compliance window until 5 April 2024 to adjust data retention, scopes and audit logging.
Overview
On 6 March 2024 Amazon refreshed its Acceptable Use Policy (AUP) to incorporate the End‑User Data Report Terms and Conditions. The amendment applies to any seller or developer who accesses Amazon’s APIs for inventory, pricing, or order management, and it creates new compliance obligations that can affect account health if ignored.
Key Points
- Effective date — The policy change became active on 6 March 2024, inserting explicit references to the End‑User Data Report terms.
- Affected sections — Section 5.7 now obligates every API consumer to follow the End‑User Data Report Terms whenever buyer‑derived data is processed.
- Geographic scope — All Amazon marketplaces that permit API interaction—including North America (US, CA, MX), Europe (DE, FR, IT, ES, UK, etc.), and Asia‑Pacific (JP, AU, SG)—are covered by the update.
- Data‑use restrictions — Sellers may no longer resale, share without permission, or retain end‑user information beyond the period required for order fulfillment.
- Enforcement risk — Violations can trigger API credential revocation, temporary suspension of the seller account, or broader penalties across the Amazon ecosystem.
- Compliance window — Existing integrations must be brought into line with the new terms within 30 days of the announcement, i.e., by 5 April 2024.
How the Updated AUP Works
-
Catalog every API interaction — List each system that calls Amazon’s Selling Partner API (SP‑API), MWS, or related endpoints.
- Example: A cloud‑based inventory‑sync service that pulls order details through the Orders API must be recorded in the inventory.
-
Trace buyer‑data pathways — Document the flow of personal information (name, address, email, purchase history) from the moment the API response is received to its final storage or transmission point.
- Example: An order‑fulfillment script writes the buyer’s shipping address to a MySQL table for 90 days to generate packing slips.
Analysis & Recommendations
Why This Matters
Violating the new AUP can lead to API key revocation, temporary seller‑account suspension, or broader penalties across Amazon's ecosystem. The policy caps buyer‑data storage, bans resale and requires explicit consent for any non‑fulfillment use, directly affecting how sellers handle order information.
Key Takeaways
- Effective date: 6 March 2024, with compliance deadline of 5 April 2024 (30 days).
- Section 5.7 now mandates adherence to End‑User Data Report Terms for all buyer‑derived data.
- Data‑use restrictions prohibit resale, sharing without permission, and retention beyond fulfillment needs.
- Violations can trigger API credential revocation, seller‑account suspension, or broader Amazon ecosystem penalties.
Recommended Actions
- →In Seller Central > Account Health > AUP, acknowledge the policy change and upload any required attestations.
- →In Developer Console > SP‑API credentials, replace generic scopes (e.g., orders.read) with limited scopes (e.g., orders.read‑limited) that exclude ...
- →Create an audit‑trail log in CloudWatch or similar that records every API response containing buyer data, including timestamp, service name, and us...
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!