Web Application Privacy Flashcards
Failing to suitable design and implement an application, detect a problem, or promptly apply a fix, which is likely to result in a privacy breah. Vulnerability is a key problem in any system that guards or operates on sensitive data.
Wep application vulnerabilities
Failing to prevent the leakage or any information containing or related to user data, or the data itself, to any unauthorized party resulting in loss of data confidentiality.
User-side data leakage
Not informing the affected persons about a possible breach or data leak, resulting in either from intentional or unintentional events; failure to remedy the situation by fixing the cause; not attempting to limit the leaks
Insufficient data breach response
Not providing sufficient information describing how data are processed, such as their collection, storage, and processing. Failure to make this information easily accessble and understandable for non-lawyers
Non-transparent policies, terms, and conditions
Collecting descriptive, demographic, or any other user-related data that are not needed for the system. Applies also to data for which the user did not provide consent.
Collection of data not required for the primary purpose
Providing user data to a third party without obtaining the user’s consent.
Sharing of data with a third party
Using outdated, incorrect, or bogus user data and failing to update or correct data
Outdated personal data
Failing to effectively enforce session termination. May result in the collection of additional user data without the user’s consent or awareness
Missing or insufficient session expiration
Failing to provide data transfers over encrypted and secured channels, excluding the possibility of data leakage.
Insecure data transfer