7. of Privacy
Your system is not following through on personal data deletion in integrated third parties.
Threat |
|
You have outsourced some of your data processing to a partner company, perhaps for accounting or order fulfillment reasons, but if a customer asks to be removed from your systems, you do not ask the partner company to do the same. |
|
GDPR |
Part 3, Art. 17–2 Part 3, Art. 19 |
CCPA and HIIPA |
1798.105. Consumers’ Right to Delete Personal Information (c) (1) |
OECD |
N/A |
Mitigations |
|
|