Skip to content

Missing Declaration of Precise Location Collection in Privacy Policy

Missing Declaration of Precise Location Collection in Privacy Policy

Description

If your privacy policy mentions the collection of your users' precise location data in your Play Data Safety Section, this could potentially put your users at risk of having their location information exposed without their consent. It is important to ensure that you are transparent about the collection and use of this sensitive data to protect the privacy and security of your users.

Recommendation

To mitigate the vulnerability of collecting users' precise location data, ensure that your privacy policy clearly outlines the purpose for collecting this information, obtain explicit consent from users before collecting their location data, and implement strong security measures to protect this sensitive information from unauthorized access or misuse. Additionally, regularly review and update your privacy policy to reflect any changes in data collection practices or regulations.

Standards

  • OWASP_MASVS_L1:
  • OWASP_MASVS_L2:
  • OWASP_MASVS_RESILIENCE:
  • CWE_TOP_25:
  • GDPR:
    • ART_5
    • ART_6
    • ART_7
    • ART_9
    • ART_11
    • ART_13
    • ART_15
    • ART_16
    • ART_17
    • ART_32
  • CCPA:
    • CCPA_1798_100
    • CCPA_1798_105
    • CCPA_1798_110
    • CCPA_1798_115
    • CCPA_1798_120
    • CCPA_1798_125
    • CCPA_1798_130
    • CCPA_1798_135
    • CCPA_1798_140
    • CCPA_1798_150
  • PCI_STANDARDS:
  • OWASP_MASVS_v2_1:
    • MASVS_PRIVACY_1
    • MASVS_PRIVACY_2
    • MASVS_PRIVACY_3
    • MASVS_PRIVACY_4
  • OWASP_ASVS_L1:
  • OWASP_ASVS_L2:
  • OWASP_ASVS_L3:
  • SOC2_CONTROLS:
    • CC_2_3
    • CC_5_3