Data Protocol Docs Logo

guide

Evidence Guide: Data Protection Assessment

Check out the Meta Channel

In partnership withpartner logo

30 min read

Share this doc:


Depending on factors like what types of Platform Data you collect, Meta may ask about your security practices when you complete the Data Protection Assessment (DPA). Certain questions will also require you to upload supporting evidence.

Meta will request procedure or policy evidence, implementation evidence, or both. Evidence-related issues are some of the most common challenges developers face when completing the DPA. Those issues often arise because developers have submitted incomplete or insufficient evidence.

As you prepare for the DPA, use this guide to help you submit evidence that will meet Meta's requirements. Meta may ask about the following security practices:

lightbulb icon

Keep in mind: Any evidence that does not currently exist will require time and resources to create or compile. Review these requirements early so you can prepare and submit acceptable evidence before your DPA is due.

Protecting Platform Data with encryption at rest

Meta's requirement:

You are required to protect the Platform Data you store in a cloud, server, or data center environment with encryption at rest, or with an acceptable alternative.


  1. How do I meet this requirement?

To meet Meta's requirement for encrypting data at rest, you must:

  • Enable either application-level (e.g., software encrypts/decrypts specific columns in a database) or full-disk encryption
  • Apply encryption at rest comprehensively in the cloud/server environment, including both primary storage and backups
lightbulb icon

Meta recommends that you use industry-standard encryption (e.g., AES, BitLocker, Blowfish, TDES, RSA), but does not require any particular algorithm or key length.


  1. What should I do to prepare evidence?


  1. What if I don't encrypt data at rest?


Share this doc:


Your privacy matters.

By clicking "Accept All", you are agreeing to Data Protocol's Cookie Policy.