The Data Protection Assessment is an annual requirement for apps accessing certain types of data. The questions in the assessment are designed to determine whether developers are complying with our Platform Terms as it relates to the use, sharing and protection of Platform Data.
“Platform Data” means any information, data, or other content you obtain from us, through Platform or through your App, whether directly or indirectly and whether before, on, or after the date you agree to these Terms, including data anonymized, aggregated, or derived from such data. Platform Data includes app tokens, page tokens, access tokens, app secrets, and user tokens.
All data you receive from Meta through the app is considered Platform Data. For example, UserID, User email and User friends are all Platform Data.
Make sure you are reachable:
Review the questions in the Data Protection Assessment and engage with your teams on how best to answer these questions.
If you are an administrator for an app that requires Data Protection Assessment, you will receive notifications on your My Apps page, the App Dashboard, Alert Inbox, and the email associated with your developer account.
You will receive a notification to prepare for the assessment by completing the following steps:
a. Make sure you are reachable:
b. Review the questions in the Data Protection Assessment and engage with your teams on how best to answer these questions.
c. Review our Platform Terms, and our Developer Policies.
If you are the administrator for an app that requires Data Protection Assessment, you will be notified in the following ways:
Yes. If you need clarification about the questions asked in the Data Protection Assessment, you can reach out to Meta directly.
Meta has published Data Security Requirements on our developer documentation site, but this content is only available to users who are logged into their Facebook account. If you aren’t able to open this page and access the documentation, make sure that you:
You have 60 calendar days from first notification to complete the Data Protection Assessment.
This is an annual requirement.
Yes. The form will auto-save so you will be able to pick up where you left off.
Here are the definitions for all the scenarios of your assessment:
Unfortunately, you will not be able to download your answers from the previous assessment, as we have changed the questionnaire to provide more clarity. After you submit your answers for this assessment, you will be able to view and download your submission as a PDF.
If based on your response, Meta reviewers need more information, we will reach out with clarifying questions and you will be notified in the following ways:
The notifications you received (described above) will have a link to the assessment, where you will see information at the top of the page that provides details on what additional information Meta reviewers are looking for. Please respond in the form and upload documentation if needed. Make sure you click ‘Submit’ after you have completed your response.
This is an opportunity for you to work with Meta reviewers who need to be absolutely certain before making a decision on whether or not the app is complying with our Platform Terms.
If you receive a ‘More information needed’ request, you will have 5 business days to respond. If you do not respond within the initial 5-day window, you will receive two auto-extensions for a total of 15 business days.
Yes. Depending on the violation, different restrictions could be placed against the app.
Yes, if a violation is detected based on your responses to the assessment, Meta reviewers will notify you through the following methods:
Failure to respond is considered a Platform Term violation.
For each violation, if the deadline to respond is within 3 days, a 'Request extension’ button will appear. You can request two extensions equal to the length of the warning period (which will vary depending on violation) that will be automatically approved.
If a violation is found and the app has been restricted, you will be able to resolve the violation by providing a response with submitting evidence showing the violation has been remediated. Once a response has been submitted, a Meta reviewer will review this and respond directly in the ‘Resolve violations’ form.