10. of Privacy
Your system does not implement the erasure or anonymization of personal data once the legal ground for processing has been withdrawn.
Threat |
|
When a subject withdraws consent for their personal data to be processed, you don’t have a process in place to do this and aren’t aware of what data must not be removed because of legal requirements on its retention that conflict with the rights of the subject and what you must remove because there is no legal requirement to retain it and it therefore must be removed. |
|
GDPR |
Chapter 3, Art. 17 |
CCPA and HIIPA |
1798.105. Consumers’ Right to Delete Personal Information |
OECD |
N/A |
Mitigations... |