Skip to content

Missing Mention of User Data Correction Rights in Privacy Policy

Missing Mention of User Data Correction Rights in Privacy Policy

Description

The application does not mention users' right to correct inaccuracies within their data in its privacy policy, leaving users vulnerable to potential inaccuracies in their personal information.

Recommendation

To mitigate this vulnerability, ensure that your privacy policy clearly outlines the process for users to correct any inaccuracies within their data, including providing a designated contact person or form for users to submit correction requests. Regularly review and update your privacy policy to reflect any changes in data correction procedures and communicate these updates to users. Additionally, implement data validation measures to minimize inaccuracies in user data from the outset.

Standards

  • OWASP_MASVS_L1:
  • OWASP_MASVS_L2:
  • OWASP_MASVS_RESILIENCE:
  • CWE_TOP_25:
  • GDPR:
    • ART_5
    • ART_6
    • ART_7
    • ART_9
    • ART_11
    • ART_13
    • ART_15
    • ART_16
    • ART_17
    • ART_32
  • CCPA:
    • CCPA_1798_100
    • CCPA_1798_105
    • CCPA_1798_110
    • CCPA_1798_115
    • CCPA_1798_120
    • CCPA_1798_125
    • CCPA_1798_130
    • CCPA_1798_135
    • CCPA_1798_140
    • CCPA_1798_150
  • PCI_STANDARDS:
  • OWASP_MASVS_v2_1:
    • MASVS_PRIVACY_1
    • MASVS_PRIVACY_2
    • MASVS_PRIVACY_3
    • MASVS_PRIVACY_4
  • OWASP_ASVS_L1:
  • OWASP_ASVS_L2:
  • OWASP_ASVS_L3:
  • SOC2_CONTROLS:
    • CC_2_3
    • CC_5_3