E-commerce · Amazon SP-API · Restricted Data Access

Get approved for Amazon SP-API restricted roles

Amazon does not gate restricted roles on how good your software is. It gates them on compliance. We rebuild the exact security and data-handling documentation Amazon scores, aligned into one consistent file, so the reason behind your refusal is gone.

Direct-to-Consumer Shipping Tax Invoicing Tax Remittance Professional Services
Amazon does not approve an application because it is well written. It approves because the application demonstrates compliance. The most common rejection comes back as one line: “security and compliance documentation did not meet requirements.” That single line is exactly what we rebuild.
40+
developer & restricted-role accesses since 2018
87%
of our customers got the access they applied for (since 2018)
48h
to deliver your complete compliance file
1st
try approval on a public app, the hardest tier
What restricted roles are

The roles that unlock buyer PII on SP-API

Restricted roles are elevated Selling Partner API permissions that give an approved developer access to Personally Identifiable Information, names, shipping addresses, contact details and order data. Amazon treats this as highly sensitive personal and financial data, so it gates each role behind a Restricted Data Access (RDA) review, and grants it only when your use case and your security posture both check out.

The four restricted (PII) roles

Direct-to-Consumer Shipping

Unlocks the buyer PII you need to ship directly: recipient name, shipping address and contact details, and for Amazon Custom, customer-uploaded photos, personalization text, names and dates. Used to generate carrier-compliant shipping labels, rates and tracking.

For sellers, fulfilment, shipping and Amazon Custom software Direct-to-Consumer Shipping role guide →

Tax Invoicing

Unlocks the order and customer data needed to generate compliant tax invoices (VAT / GST) from Amazon order data, for accounting and tax-compliance workflows where they are enabled for authorized users.

For invoicing, ERP and accounting integrations Tax Invoicing role guide →

Tax Remittance

Unlocks the data needed to calculate tax obligations and produce filing-ready outputs that support a merchant's tax-remittance workflow, in line with local tax regulations.

For tax-engine and compliance tools Tax Remittance role guide →

Professional Services

Unlocks the buyer PII needed to deliver an add-on service in person, assembly, installation, repair or maintenance: the customer's name, service (home) address, contact number and appointment details. Used to schedule jobs, assign technicians and manage appointments through Amazon's Services API.

For installers, assemblers and field-service software Professional Services role guide →

Amazon's four restricted (PII) roles are Direct-to-Consumer Shipping, Professional Services, Tax Invoicing and Tax Remittance. Each is judged on its own justification, they are not interchangeable, and the reviewer weighs the roles you request against your use case and Amazon's official role definitions together. We also prepare related roles such as Buyer Communication and Buyer Solicitation on request.

So why do most applications come back rejected, often with no real explanation? Almost never because of the product. Almost always because of the file.
The real reason

Why restricted-role applications get rejected

Amazon rarely tells you what went wrong. The decision almost always comes down to one phrase, your security and compliance documentation did not meet requirements. In practice, that means one or more of these:

  • Documentary inconsistency, the application answers, the privacy policy and the security procedures contradict each other.
  • Generic, copy-paste answers and vague wording that prove nothing.
  • Weak or missing justification for why each role and the PII are truly needed.
  • No field-level data inventory showing which PII is used, where and why.
  • PII retention that is not capped or not provably automated, no enforced 30-day deletion.
  • Logs that store customer PII, or no evidence of access reviews and offboarding.
  • Any hint of credential harvesting, asking for Seller Central passwords or keys is an automatic refusal.
  • Any hint of cross-seller data aggregation or resale of Amazon-derived data.
  • A public website that does not match the roles you request, overclaiming, or missing the capability entirely.
  • An incomplete Data Handling & Privacy Policy that does not meet Amazon's restricted-roles standard.

Amazon reviews evidence, not promises. We remove every one of these reasons, so there is no compliance ground left to refuse you on.

To remove those reasons, you have to know exactly what the reviewer scores. We speak Amazon's assessment language, point by point.
Behind the review

What Amazon actually scores

A restricted-role review is a security and data-protection assessment. We align your file to every control Amazon evaluates, and tell you in plain language what to have in place. We never need access to your systems to do it. These controls map to Amazon's Acceptable Use Policy (AUP), Data Protection Policy (DPP) and Key Security Control Guidance, as published as of June 2026.

Data handling & retention

PII kept no longer than 30 days after delivery, used only to fulfil orders or as required by law, then securely deleted (per NIST 800-88).

Encryption

TLS 1.2 or higher in transit (TLS 1.3 recommended); AES-128 or higher at rest (AES-256 recommended) with RSA-2048 or higher; a key management system (KMS) with at least annual key rotation, and encrypted backups.

Access control

Least-privilege access, unique per-employee IDs, multi-factor authentication, quarterly access reviews and prompt offboarding.

Logging & monitoring

Activity logs kept for at least 12 months with alerting, keeping customer PII out of logs unless legally required.

Incident response

A written runbook with roles and escalation, and notification to Amazon within 24 hours of a suspected breach.

Authentication

Amazon's official OAuth, Login with Amazon (LWA), only. You never request, accept or store a seller's Seller Central or Vendor Central credentials.

Two sellers can request the same role and face two very different reviews. Which path you are on decides how heavy the file has to be.
Two paths

Private application or public application?

It depends on who uses your software. We prepare both, and we tell you which one fits before you spend a euro.

Private app

Software for your own company

For a tool used only inside your own business, on your own seller account. The review is documentary, built on two things: your application answers and your public Data Handling & Privacy Policy. It removes the heaviest requirements that exist to police multi-seller platforms, which makes it a genuinely simpler case.

  • Single-seller, internal use
  • Reviewed on answers + your policy page
  • The 650 EUR standard file
Public app

Software you offer to many sellers

For SaaS, ERP, WMS, OMS and integrators offering a tool to multiple Amazon sellers. Far harder: a business-criteria review, additional security questions, and a live security-architecture review with an Amazon solution architect, as a Data Security Assessment (DSA) across twelve domains (listed below). We have taken a public app through it and passed on the first attempt.

  • Multi-seller software / developers
  • Business review + security assessment + live call
  • A larger engagement, quoted after a call

The 12 domains of Amazon's Data Security Assessment (DSA)

If your app is public, Amazon's mandatory Data Security Assessment (DSA) is run by an Amazon-authorised agent at no cost, and evaluates these twelve domains. We prepare your evidence for every one of them.

  1. Business & system overview
  2. Security governance
  3. Infrastructure security
  4. Data protection
  5. Network security & vulnerability management
  6. Application security
  7. Identity & access management
  8. Security monitoring & incident response
  9. Privacy
  10. Data handling & management
  11. Third-party integration
  12. Customer support

The assessment takes about a month and roughly 8 hours of your team's time (around 4–6 hours of written responses, a 2-hour call, and about 2 hours of follow-up). Private, single-seller apps do not go through the DSA.

What you get

A complete compliance file, ready to submit

Not advice and not a template. Three finished, copy-paste-ready deliverables, plus everything around them, aligned to Amazon's Acceptable Use Policy (AUP), Data Protection Policy (DPP) and Developer Agreement.

Application answers, ready to submit

Every answer Amazon asks for, written for you: the questionnaire plus the free-form security and architecture responses, within Amazon's character limits.

A publishable Data Handling & Privacy Policy

A ready-to-publish policy page for your website, covering collection, processing, storage, use, sharing and disposal. One of the two things Amazon checks for a private app.

A plain-language implementation checklist

Every control Amazon requires, written so your IT lead can put it in place point by point, with no guesswork about what "compliant" means.

Role-by-role justification

A tailored purpose, legal basis and retention period for each restricted role you request, because Amazon judges each one separately.

Incident-response plan

A runbook covering roles, incident types, escalation and the 24-hour notification to Amazon, ready to attach and to follow.

Follow-up handling

We answer Amazon's follow-up questions, and if the first attempt is declined we revise the file on their feedback, across up to three attempts.

The market is full of providers who write answers. We build a complete file where every element is consistent with the others and aligned to Amazon's official policies. That overall consistency is what removes the risk of follow-up requests and refusal.
One question we hear before every engagement: how much of this lands on our developers? Less than you think, and we never touch your systems.

A clear division of labour

We are a marketplace-compliance firm, not a development agency. We do not need access to your application, your source code, your servers or your Amazon account. We prepare the documentation and the application; your own IT lead implements the checklist on your infrastructure.

Knowing exactly what Amazon expects, and how to present it, is our field. Implementing it on your systems is where your IT lead is strongest. Most of the checklist is documentation and configuration. The few items that can need a developer, an automated 30-day deletion routine, keeping PII out of logs, connecting through Amazon's OAuth instead of storing credentials, are small tasks, not a rewrite.

Anyone can fill in the same Amazon form. The difference is who fills the silences Amazon never spells out. On your own versus with a team that has been through this review dozens of times, the gap looks like this.
Going it alone vs. with Fenchell

Same review. Very different odds.

A restricted-role application is won on compliance and consistency, the parts most applicants underestimate until Amazon comes back with questions, or with nothing at all.

The application On your own With Fenchell
Building the case
Every application answer written for you
A role-by-role justification for the PII you request
A Data Handling & Privacy Policy that meets Amazon's standard
One consistent story across the whole file
Meeting the security bar
A plain-language checklist of every control Amazon scores
An incident-response plan ready to attach
When Amazon pushes back
Follow-up questions answered for you
The file revised across up to 3 attempts
Your options

DIY, a dev agency, or a compliance firm

There are three ways to approach a restricted-role application, and only one is built for this exact problem.

Do it yourself

Free, but you learn Amazon's compliance bar by being rejected. Most teams underestimate the documentary consistency and the security evidence, and lose weeks to repeated refusals.

A development agency

Strong at code, but this is rarely a coding problem. Agencies bill hours to build features Amazon never asked for, while the real blocker, the compliance file, stays unaddressed.

A compliance firm (Fenchell)

We bill an outcome, not time. You get the exact compliance file Amazon scores, answers, policy page and checklist, aligned to its policies, with no access to your systems.

How it works

From rejected to ready, in three moves

We start from a short form, build your complete compliance file, and stay with you through Amazon's review.

Your move · 10 minutes

You complete a short form

Tell us which roles you want, whether your software is for your own company or for many sellers, any previous attempt, and how your business works. A screenshot of your current Amazon application page and a look at your website are all we need to start.

Our move · 48 hours

We build your compliance file

We review your case the way an Amazon reviewer does and assemble the complete file: every application answer, your Data Handling & Privacy Policy page, your implementation checklist, and a justification for each role.

What we check while we write
  • That every document tells exactly the same story
  • That each role is justified and the PII is tightly scoped
Submit & follow-up

You implement, submit, and we back you

Your IT lead implements the checklist and publishes the policy page, you submit the prepared answers, and we handle Amazon's follow-up questions, revising the file across up to three attempts if needed.

Our commitments

Six commitments, every single time

What you can hold us to from the first message to the last day of follow-up.

Advice included

Guidance tailored to your account, your software and your roles is part of the service, not an add-on.

48-hour delivery

Your complete compliance file is delivered within 48 hours of payment reaching us.

Obtained or refunded

If the access is not obtained, you are refunded subject to the terms of our T&Cs.

Up to 3 attempts

If Amazon declines, we revise the file on their feedback across up to three submission attempts.

No system access

We never need your code, servers or Amazon login. We prepare the file; your team keeps full control.

A dedicated team

Our team is on your case Monday to Friday, 9am–6pm EEST, throughout the process.

You have seen the roles, the reasons, the file and the process. The only thing left is your application. Ten minutes of context from you, and our team takes it from there.
Start your application

Tell us about your case

Share which restricted roles you want, whether your app is private or public, and how your business works. We review it the way Amazon will, and come back with your complete compliance file.

48-hour delivery No system access needed Up to 3 submission attempts
Preparing the file is the work. Standing behind it is the part most providers skip. Here is what our track record and our guarantee mean for you.
Results & guarantee

A process we have run, refined, and won with

Real client outcomes since 2018, and a refund policy that puts the risk on us, not on you. As an Amazon Marketplace EU Agency Partner with a dedicated Key Account Manager, and a verifiable member of Amazon's Service Provider Network (SPN), we work inside Amazon's own partner ecosystem.

Developer & restricted-role accesses since 2018 40+

Developer accesses and restricted roles unlocked for real clients through our structured, document-backed process.

Customers who got the access they applied for 87%

Of our customers obtained their access. Amazon keeps the final decision, so outcomes are never guaranteed, which is why the risk sits with us.

A public app approved first try

We prepared a multi-channel e-commerce platform for the hardest tier, a public application with a full security assessment, and it passed on the first attempt.

Obtained or refunded

A full refund if a technical issue occurred on our side, and a partial refund if Amazon questions your business legitimacy, per our T&Cs.

Best Service. “Getting approved for access to the Amazon API was a real challenge for us. Fenchel and their team stepped in, audited our functionality, and helped us understand precisely what Amazon's software review team was looking for — which made all the difference.”
Verified client review · unprompted · March 2026
4.8/5 Rated by 250 verified clients on eKomi · Fenchell across all services

Frequently asked questions

Refund policy: refunds are handled according to the terms of our T&Cs, a full refund if a technical issue occurred on our side, and a partial (50%) refund if Amazon questions your business legitimacy. We never promise approval, because Amazon keeps the final decision.
What are Amazon SP-API restricted roles?
Restricted roles are elevated Selling Partner API permissions that grant access to buyer Personally Identifiable Information (PII), names, shipping addresses, contact details and order data. They include Direct-to-Consumer Shipping, Tax Invoicing and Tax Remittance. Because they expose sensitive data, Amazon only grants them after a Restricted Data Access (RDA) review, and for software offered to many sellers, a third-party Data Security Assessment (DSA).
Why was my Amazon restricted-role application rejected?
By far the most common reason is that your security and compliance documentation did not meet requirements. Amazon does not reject because your product is weak; it rejects when the application does not demonstrate compliance, or when the application answers, the privacy policy and the security procedures contradict each other. Reviewers look for contradictions, vague wording, generic copy-paste answers, weak justifications and incomplete policies.
Does Amazon approve an application because it is well written?
No. Amazon approves because the application demonstrates compliance: a valid business justification for each role, a credible security architecture, and documentary consistency across the whole file. Good writing alone is not enough, every document has to tell the same story and align with Amazon's policies.
Which restricted roles do you cover?
We prepare applications for the PII-bearing restricted roles, most often Direct-to-Consumer Shipping, Tax Invoicing and Tax Remittance, plus Professional Services for in-person add-on services such as assembly and installation. We also handle related roles such as Buyer Communication and Buyer Solicitation. Each role is justified on its own terms, because the reviewer weighs the roles you request against your use case and Amazon's policies together.
What is the difference between a private and a public application?
A private application is for software used only inside your own company (a single seller). The review is documentary, your application answers and your public Data Handling & Privacy Policy, and is genuinely simpler. A public application is for software you offer to many sellers (SaaS, ERP, WMS, integrators); it is far harder and adds a business-criteria review, additional security questions, and a live security-architecture review with an Amazon solution architect, a Data Security Assessment (DSA) across twelve assessment domains.
Do you need access to our code, servers or Amazon account?
No. We are a marketplace-compliance firm, not a development agency. We prepare the documentation and the application Amazon requires; your own IT lead implements the checklist on your infrastructure. Knowing exactly what Amazon expects and how to present it is our field; implementing it on your systems is where your IT lead is strongest.
Will getting approved require changing our source code?
Rarely. The large majority of what Amazon evaluates is documentation, security procedures and infrastructure configuration. The few items that can need a small development task are an automated routine that deletes customer data within 30 days of shipment, making sure logs do not store customer PII, and connecting through Amazon's official OAuth instead of storing credentials. None of these is a rewrite; a developer usually handles them in a few days.
How long can we keep customer PII under Amazon's policy?
The standard, safe position is to keep PII no longer than 30 days after order delivery, and only to fulfil orders or as required by law. Data must then be securely deleted (for example per NIST 800-88), PII must be removed within 30 days of an Amazon deletion request, and all live copies removed within 90 days of an Amazon notice.
What encryption and security does Amazon expect?
TLS 1.2 or higher for data in transit (TLS 1.3 recommended) and AES-128 or higher at rest (AES-256 recommended), with RSA-2048 or higher, managed with a key management system (KMS) and at least annual key rotation. Credentials are never hardcoded or stored, access is least-privilege with multi-factor authentication and quarterly reviews, logs are PII-free and retained 12+ months with alerting, and an incident-response runbook notifies Amazon within 24 hours of a breach.
What exactly do you deliver?
Three things, ready to use: every application answer written and ready to submit (the questionnaire plus the free-form security and architecture responses); a publishable Data Handling & Privacy Policy page for your website; and a plain-language implementation checklist of every control Amazon requires. You also get a role-by-role justification, an incident-response plan, and handling of Amazon's follow-up questions.
How long does it take and how does pricing work?
The standard restricted-role file is a one-time fee of 650 EUR, delivered within 48 hours of payment. After that, submission timing depends on how fast your team implements the checklist, and Amazon controls its own review time. Public apps offered to many sellers are a larger engagement and are quoted after a short call. Support covers up to 3 submission attempts.
What if Amazon rejects it, or asks more questions? Can you guarantee approval?
We never promise approval, because Amazon keeps the final decision. What we do is rebuild the exact point Amazon scores, your security and compliance documentation, so the previous reason for refusal is removed. Follow-up questions are included, we revise on Amazon's feedback across up to 3 attempts, and refunds follow our T&Cs: a full refund for a technical issue on our side, a partial refund if Amazon questions your business legitimacy.
Do we need an EU company to apply?
Not strictly, but a properly established company with a clean public presence and a real data-handling policy makes approval easier, and a compliant EU structure helps with VAT and data-protection expectations. We help you set up a compliant Bulgarian company, 100% remotely, and can align your structure, your VAT and your Amazon application so they all support each other.
What are the 12 domains of Amazon's Data Security Assessment?
For public apps, Amazon's Data Security Assessment (DSA) evaluates twelve domains: (1) business and system overview, (2) security governance, (3) infrastructure security, (4) data protection, (5) network security and vulnerability management, (6) application security, (7) identity and access management, (8) security monitoring and incident response, (9) privacy, (10) data handling and management, (11) third-party integration, and (12) customer support. The assessment is run by an Amazon-authorised agent at no cost; we prepare your evidence for every domain.
How long does Amazon take to review a restricted-role application?
Amazon controls its own timing, so there is no guaranteed deadline. For a public app, the Data Security Assessment typically takes about a month of elapsed time and roughly 8 hours of your team's effort (around 4 to 6 hours of written responses, a 2-hour call, and about 2 hours of follow-up). A private (documentary) application is usually quicker. We deliver your complete file within 48 hours, so the only variable left is Amazon's review and how fast your team implements the checklist.

Remove the reason behind your refusal

Start the form and we will confirm your roles, your path and your next steps. The standard restricted-role file is 650 €, delivered in 48 hours, obtained or refunded subject to our T&Cs. Building software for many sellers? Book a call for a tailored scope.

Content reviewed by Loïc Segui (COO & CTO), Fenchell's Marketplace Compliance Team · last updated 29 June 2026. We never promise approval: even when your file is prepared correctly, Amazon retains the right not to grant restricted access without justification. The figures shown on this page (accesses obtained, success rate) are based on real client cases and do not constitute a guarantee of outcome; results vary depending on your situation and Amazon's decision. Fenchell Capital OOD, Bulgarian firm based in Plovdiv (EIK 207945095).

Start my application