6. of Privacy
Your system collects more personal data than is strictly necessary to fulfill the intended purpose.
Threat |
|
You might be storing information about the age, date of birth, or gender of your customers, but the only use you have for this data is to profile them, for which you haven’t asked their permission. |
|
GDPR |
Chapter 2, Art. 5 – 1. (c) |
CCPA and HIIPA |
1798.100. General Duties of Businesses That Collect Personal Information (a) (1) and (2) |
OECD |
Part 2, 8. Data Quality Principle |
Mitigations |
|
|