5. of Privacy
Personal data in your system is missing pointers to data subjects; hence, the data is forgotten when the owner is deleted or makes an access request.
Threat |
|
You’re collecting data, but that data isn’t connected to the subject’s user or ID, so when a subject is removed from the system, some of their data can become orphaned. It may also be impossible to retrieve a subject’s data to show them exactly what data you have stored on them if they ask. |
|
GDPR |
Chapter 2, Art. 5 – 1. (e) Chapter 3, Art. 15 Chapter 3, Art. 16 Chapter 3, Art. 17 |
CCPA and HIIPA |
1798.105. Consumers’ Right to Delete Personal Information 1798.110. Consumers’ Right to Know What Personal Information Is Being Collected... |