2. of minimization
We put absolutely everything in the audit log so that we can positively audit all personal data activities.
Threat |
|
Audit logs should contain enough information to identify who or what performed actions, when they did so, and what was impacted. You’re logging more than is needed, which is wasteful of resources, goes against the principle of minimization, and leaves you more exposed. |
|
GDPR |
Chapter 2, Art. 5–1 (f) Chapter 2, Art. 5–2 Chapter 4, Art. 32–1 |
CCPA and CPRA |
N/A |
OECD |
Part 3, 15. A Data Controller Should (iv) Part 3, 15. A Data Controller Should (vi) |
Mitigations |
...