5. of minimization
We send personal data to an API, even though we believe it is not really being used for anything.
Threat |
|
One of the third-party APIs you rely on includes fields that don’t seem relevant or necessary for the API to elaborate the analysis you’re asking, but you’re including it because it is a required field. |
|
GDPR |
Chapter 2, Art. 5 – 1 (a) Chapter 2, Art. 5 – 1 (b) Chapter 2, Art. 5 – 1 (c) |
CCPA and CPRA |
CCPA 1798.100. General Duties of Businesses that Collect Personal Information (a)(1) |
OECD |
Part 2, 9. Purpose Specification Principle Part 2, 10. Use Limitation Principle |
... |