Queen of Privacy
Your system processes personal data in a way that is not described in the privacy notice.
Threat |
|
You perform profiling of your customers based on their purchases; however, you only have consent to use their data for the purpose of fulfilling their orders. |
|
GDPR |
Chapter 2, Art. 5–1 (b) Chapter 2, Art. 5–1 (c) |
CCPA and HIIPA |
1798.121. Consumers’ Right to Limit Use and Disclosure of Sensitive Personal Information |
OECD |
Part 2, 9. Purpose Specification Principle Part 2, 10. Use Limitation Principle Part 2, 13. Individual Participation Principle pt. (d) |
Mitigations |
|