8. of Privacy
Your system collects personal data without being able to name the specified, explicit, and legitimate purpose it is used for.
Threat |
|
You have many applications that all use the same database and perform different tasks, but you do not track which elements of the collected data they use. So, if a subject asks how you process their data, you’re not able to tell them with any certainty. |
|
GDPR |
Part 2, Art. 5–1. (b) Part 2, Art. 5–1. (c) |
CCPA and HIIPA |
1798.100. General Duties of Businesses that Collect Personal Information (c) |
OECD |
Part 2, 8. Data Quality Principle |
Mitigations |
|
... |