2. of Retention/Removal
Users’ file uploads containing personal data are saved to temporary files on the frontend.
Threat |
|
You’ve implemented hot-desking in your office since moving to a hybrid working model, and when your staff uploads personal data to the HR system, that personal data is stored on the local system temporarily but never cleaned up. This has made it possible for their colleague to read the files they uploaded because this computer is now shared. |
|
GDPR |
Chapter 4, Art. 32 – 1 (b) Chapter 1, Art. 4 – (12) Chapter 2, Art. 5 – 1 (f) |
CCPA & CPRA |
CCPA 1798.100. General Duties of Businesses that Collect Personal Information (e) |
OECD |
Part 2, 11. Security Safeguards... |