2. of Transfer II
The application uses an API, which makes it our data processor, but we don’t know whether this is reflected in our API contract.
Threat |
|
In the code of your application, you are calling a third-party service for the company you use to handle your deliveries and sending them the name and address of your customer. However, you don’t know whether your customer was made aware that someone else would see their personal data. |
|
GDPR |
Chapter 3, Art. 13 – 1. (e) |
CCPA & CPRA |
CCPA 1798.100. General Duties of Businesses that Collect Personal Information (d) CPRA SEC. 3. Purpose and Intent. (A)(1) |
OECD |
Paragraph 15(a)(i) |