logo

Database

OWASP Top 10 Privacy Risks

Last updated: 2023/09/18
logo

The OWASP Top 10 Privacy Risks Project provides a list for privacy risks in web applications and related countermeasures, furthermore, it covers technological and organizational aspects that focus on real-life risks. The project provides tips on how to implement privacy by design in web applications with the aim of helping developers and web application providers to better understand and improve privacy. The version used in this section is v2.0, 2021.

Control-Requirement Mapping

DefinitionRequirements
P1. Web application vulnerabilities
P2. Operator-sided data leakage
P3. Insufficient data breach response
P4. Consent on everything
P5. Non-transparent policies, terms and conditions
P6. Insufficient deletion of personal data
P7. Insufficient data quality
P8. Missing or insufficient session expiration
P9. Inability of users to access and modify data
P10. Collection of data not required for the user-consented purpose