TikTok for Developers

Developer Docs

Last updated October 8, 2026

U.S. Launch Approval Process

To launch your app to the U.S., you must complete the U.S. launch approval request and data security agreement. These steps are only accessible from your organization page on the Developer Portal after you've completed received approval for the general launch approval request.

U.S. launch approval request

The U.S. launch approval request is a separate compliance step for developers who intend to launch their mini game or mini drama in the United States. It is reviewed by the TikTok U.S. Data Security Inc. (USDS) Third-Party Risk Management (TPRM) team.

Note: The U.S. launch approval request form becomes available only after you have submitted the general launch approval request.

To access the U.S. launch approval request on the Developer Portal:

  1. Go to the Business tab of your organization page.
  2. Click the Pre-launch tasks tab to find the request form.

U.S. launch approval questions

The U.S. launch approval request form includes the following questions:

  1. Where is your company headquartered?
  2. Where is your company legally registered?
  3. Add your company's majority stakeholders (Only those with a controlling interest of 20% or more qualify as majority stakeholders.)
  4. Will any non-public U.S. user data, including PII, private account details, or e-commerce data, be stored, processed, or accessed from any of the following countries? Select all countries that apply.
    1. China (including Hong Kong and Macau)
    2. Russia
    3. Iran
    4. North Korea
    5. Cuba
    6. Venezuela
    7. None of the above
  5. Do any internal engineering teams or 4th-parties, such as subcontractors, subprocessors, or affiliates, that develop, compile, or contribute executable code for this service operate, reside, or maintain headquarters in any of the following countries?
    1. China (including Hong Kong and Macau)
    2. Russia
    3. Iran
    4. North Korea
    5. Cuba
    6. Venezuela
    7. None of the above
  6. TikTok representative contact
  7. Final attestation: As a condition for partnering with TikTok USDS JV, vendors must comply with strict geographic restrictions related to Countries of Concern. Select each statement that you can formally confirm.
    1. Data handling: I confirm that non-public U.S. user data will not be accessed, processed, collected, or stored in a Country of Concern by our personnel, systems, or 4th-party subprocessors.
    2. Service and development: I confirm that no internal engineering team, 4th-party, or core component, such as hardware or software, used to develop or support this engagement originates from, operates in, or provides services from a Country of Concern.
    3. Ownership and control: I confirm that our company headquarters and place of legal organization are not in a Country of Concern. I also confirm that no ultimate beneficial owner holding 20% or more equity, or key executive, resides in or is affiliated with a Country of Concern.

Follow-up information request

If your response to the U.S. launch approval request indicates potential risks, you will receive a request for additional information. The follow-up request will ask you to choose one of two options:

Option A: Technical Remediation Confirmation

If your organization can fully isolate relevant data, systems, and personnel from Countries of Concern, please provide all required evidence below.

  • Data Architecture & Localization Diagram: Technical documentation proving all U.S. data is permanently ring-fenced and stored exclusively in non-restricted jurisdictions.
  • IAM Policies & Access Control Lists (ACLs): System configuration exports confirming logical access strictly blocks authenticated credentials, IP ranges, or support personnel operating from Countries of Concern.
  • 4th-Party Subprocessor Attestation: Formal confirmation that no 4th-party subprocessor or subcontractor will handle, store, or access this data from a Country of Concern.
  • Corporate Attestation: An executive declaration certifying complete geographic and operational segregation from restricted jurisdictions.

Option B: Detailed Operational Disclosure

If your organization or 4th-party sub-processors cannot immediately relocate storage, processing, or access out of a Country of Concern, you must provide a detailed disclosure addressing all points below for risk evaluation:

  • Entity & Personnel Identification: Technical documentation proving all U.S. data is permanently ring-fenced and stored exclusively in non-restricted jurisdictions.
  • Exact Data Scope: Detail every specific data element involved (e.g., raw IP addresses, user identifiers, device metadata, system logs, hashed identifiers, or aggregated performance metrics).
  • Nature of Activity: Formal confirmation that no 4th-party sub-processor or subcontractor will handle, store, or access this data from a Country of Concern.
  • Business & Technical Justification: Provide the explicit business and technical reason why this data must be stored, processed, or accessed from this specific location rather than a non-restricted jurisdiction.
  • Integrity & Isolation Safeguards: Outline all active technical controls (e.g., end-to-end encryption with non-CoC key management, jump-box logging, zero-trust network access) used to prevent unauthorized access or data exfiltration.

The follow-up request includes a document upload component (PDF, images, Word documents, etc.; up to 10 files) and an optional text box for explanation.

Review statuses

  • Approved: You may launch your app in U.S. regions. You must sign a data security agreement for the approval to take effect.
  • Rejected: You will not be allowed to resubmit online. The rejection reason will be displayed in the Developer Portal. Contact the TikTok Operations team if you need further assistance.

U.S. Data Security Agreement

After your U.S. launch approval request has been approved, you must sign a data security agreement for the data scope to take effect. The agreement will be available for signing in the Pre-launch tasks of your organization page.

Compliance review definitions and requirements

More information about the compliance review's key risk areas is listed below.

Ultimate Beneficial Ownership (UBO)

UBO refers to the individuals or entities who ultimately own or control your company. Even if ownership is indirect or layered through holding companies, the ultimate decision makers must be disclosed.

Note: Vendors with a UBO holding 20% or greater ownership interest located in a restricted country may not access, process, or store TikTok USDS protected data.

Headquarters and workforce locations

Your personnel who support TikTok U.S. users—whether employees, contractors, or subcontractors—must not be based in a restricted country. This restriction applies regardless of employment classification or whether the personnel support us directly or indirectly.

Service and support location restrictions

All technical support and operational services related to TikTok USDS must be performed outside restricted countries. This includes the following:

  • Hosting environments
  • Development teams
  • Customer support personnel

Failure to comply with this requirement may lead to disqualification or reassessment of the vendor relationship.

Data handling locations

TikTok USDS data cannot be accessed, processed, modified, or stored in a restricted country. Please confirm your cloud and infrastructure configurations before completing the questionnaire, especially if your services use auto-scaling or globally distributed environments.

Fourth-party disclosure requirements

If your organization relies on other entities (cloud providers, IT subcontractors, for example) to support your TikTok USDS engagement, those are considered fourth parties. Disclosure is required if these parties engage in the following:

  • Host, transmit, or process USDS data
  • Provide core infrastructure for your services
  • Offer necessary services for your operational delivery to TikTok
TikTok for Developers