4. of Privacy
Your system collects consent but does not document aspects as to how, when, and what consent was provided.
Threat |
|
You have a privacy policy or some terms you ask subjects to accept, but you do not version these documents, so if the policy changes, the conditions that were accepted are no longer in the policy. In addition, you also don’t know what the conditions were when the subjects signed up. |
|
GDPR |
Chapter 2, Art. 5 – 1. (a) Chapter 2, Art. 5 – 1. (b) |
CCPA and HIIPA |
1798.100. General Duties of Businesses that Collect Personal Information |
OECD |
Part 2, 9. Purpose Specification Principle Part 2, 12. Openness Principle |