Sharing Protected Customer Data with a 3rd Party (API 2022-10+)

Our app is currently using the 2022-07 API. We’re using the API to share customer order data with a 3rd party for critical (and non-marketing) purposes.

Because we’re using this version of the API, we’re able to access all of the customer data that we need. Since this version of the API is deprecated, we’ll need to move to a later version of the API.

In later versions of the API, the data that we’re sharing with the 3rd party will be protected.


Our question is this:

What level of compliance do 3rd parties need to have with regards to the data protection requirements?

Any insight here?