317 – Allow erasure requests
Summary
The system must allow its users to request erasure of collected data belonging to them.
Description
Systems usually request information from their users, obtain it from third parties or collect it based on their interactions with the application. They should have a mechanism that allows users to request the erasure of this information and guarantees its complete deletion. Furthermore, the erasure should also occur if the user decides to revoke their consent.
Supported In
Advanced: True
References
- GDPR-11_2. Processing which does not require identification
- GDPR-17_1. Right to erasure (‘right to be forgotten')
- SOC2-P4_3. Additional criteria for privacy (related to use, retention, and disposal)
- CCPA-1798_105. Consumer's right to delete personal information
- GLBA-502_B. Obligations with respect to disclosures of personal information – Opt out
- NYDFS-500_13. Limitations on data retention
- PDPO-5_26. Erasure of personal data no longer required
- CMMC-MP_L1-3_8_3. Media disposal
- HITRUST-09_e. Service delivery
- LGPD-16. Termination of Data Processing
- LGPD-18_VI. Data Subjects Rights
- LGPD-60. Final and Transitional Provisions
- OWASPRISKS-P6. Insufficient deletion of personal data
- OWASPRISKS-P9. Inability of users to access and modify data
- ASVS-8_3_2. Sensitive private data
- SIG-P_6. Privacy
- CASA-8_3_2. Sensitive Private Data
Weaknesses
Last updated
2023/09/18