3. of Transfer
We provide an API that ingests personal data, but we do not know whether we are a data processor or a data controller, and it’s not defined in our contracts.
Threat |
|
You’ve exposed an API that processes personal data, but you aren’t certain where this data comes from: is it from the subject, or is it from someone else who has collected the data from the subject? Who are the consumers of your API and do your contracts cater to those different types of consumers? |
|
GDPR |
Chapter 1, Art 4. – (7) and (8) Chapter 4, Art 24. Chapter 4, Art 28. Chapter 4, Art 29. |
CCPA & CPRA |
CCPA 1798.140. Definitions (ag) |
OECD |
N/A |