Missing Declaration of Voice or Sound Recording Collection in Privacy Policy
Missing Declaration of Voice or Sound Recording Collection in Privacy Policy
Description
If your privacy policy does not mention the collection of your users' voice or sound recordings, but this data type is declared in your Play Data Safety Section, it could leave your users vulnerable to having their personal information collected without their knowledge or consent.
Recommendation
To mitigate the vulnerability of collecting users' voice or sound recordings, ensure that your privacy policy clearly states the purpose of collecting this data, how it will be used, and how it will be protected. Obtain explicit consent from users before collecting any voice or sound recordings, and implement strong security measures to safeguard this sensitive information from unauthorized access or misuse. Regularly review and update your privacy policy to stay compliant with data protection regulations and maintain transparency with your users.
Links
- Android Privacy Guidelines
- Privacy Policies for Mobile Apps
- Apple Privacy Manifest
- CWE-359: Exposure of Private Information ("Privacy Violation")
Standards
- OWASP_MASVS_L1:
- OWASP_MASVS_L2:
- OWASP_MASVS_RESILIENCE:
- CWE_TOP_25:
- GDPR:
- ART_5
- ART_6
- ART_7
- ART_9
- ART_11
- ART_13
- ART_15
- ART_16
- ART_17
- ART_32
- CCPA:
- CCPA_1798_100
- CCPA_1798_105
- CCPA_1798_110
- CCPA_1798_115
- CCPA_1798_120
- CCPA_1798_125
- CCPA_1798_130
- CCPA_1798_135
- CCPA_1798_140
- CCPA_1798_150
- PCI_STANDARDS:
- OWASP_MASVS_v2_1:
- MASVS_PRIVACY_1
- MASVS_PRIVACY_2
- MASVS_PRIVACY_3
- MASVS_PRIVACY_4
- OWASP_ASVS_L1:
- OWASP_ASVS_L2:
- OWASP_ASVS_L3:
- SOC2_CONTROLS:
- CC_2_3
- CC_5_3