Data Protection Compliance

Personal Information Protection Standard

This page provides data protection compliance information for Jinyuandu Trading Co., Ltd. / 晋江度远贸易有限公司 and its internal TikTok Shop operations system.

Compliance package

Version 2.0 of the compliance package includes our Information Security Standard, Personal Information Protection Standard, questionnaire-to-evidence matrix, security baseline, access control policy and implementation evidence, incident response and breach notification procedure, data request and deletion procedure, and internal approval record.

Download Data Protection Compliance Package

Information security standard

Our internal security standard defines least privilege, account lifecycle controls, endpoint security baselines, secure authorization, incident response, and six-month management reviews. Controls that are not implemented or cannot be evidenced are not represented as operational.

Data storage and processing

TikTok Shop data is stored and processed only in the United States. Our system does not store TikTok Shop user data in China.

Access control

TikTok Shop data access is restricted to authorized internal staff through role-based and store-level permissions. Administrative access is limited to authorized management personnel. Disabled accounts and invalidated sessions cannot remain active.

Incident response and deletion

The package defines incident reporting, containment, evidence preservation, notification assessment, recovery, post-incident review, verified data requests, authorization revocation, and contract-termination deletion records.

Policy review

Our internal personal data protection policy is reviewed every 6 months and updated when business, system, or compliance requirements change.

Review note

The following note can be used with our TikTok Shop developer application reassessment:

Dear TikTok Shop Review Team, in response to the GSO request for evidence, we have attached our revised Information Security and Data Protection Evidence Package v2.0. The package contains a page-level questionnaire evidence matrix, approved standards, implementation excerpts, incident response and notification procedures, data request and deletion procedures, management approval records, and independently verifiable public policy URLs. Controls not implemented or not evidenced remain marked No. Please use Section 2 as the reviewer index and reassess our application. Thank you.

Download the resubmission note