ABCDEFGHIJKLMNOPQRSTUVWXYZAAAB
1
Preliminary results for the OWASP Top 10 Privacy Risks 2021
2
No.TitleFrequencyImpactRiskRanking 2014DescriptionComment
3
P1Web Application Vulnerabilities22.85.601
Vulnerability is a key problem in any system that guards or operates on sensitive user data. Failure to suitably design and implement an application, detect a problem or promptly apply a fix (patch) is likely to result in a privacy breach. This risk also encompasses the OWASP Top 10 List of web application vulnerabilities and the risks resulting from them.
4
P2Operator-sided Data Leakage1.922.85.382
Failure to prevent the leakage of any information containing or related to user data, or the data itself, to any unauthorized party resulting in loss of data confidentiality. Introduced either due to intentional malicious breach or unintentional mistake e.g. caused by insufficient access management controls, insecure storage, duplication of data or a lack of awareness.
5
P3Insufficient Data Breach Response2.242.45.383
Not informing the affected persons (data subjects) about a possible breach or data leak, resulting either from intentional or unintentional events; failure to remedy the situation by fixing the cause; not attempting to limit the leaks.
6
P4Consent on Everything / Problems with getting Consent2.3724.74New / 17
Aggregation or inappropriate use of consent to legitimate processing. Consent is "on everything" and not collected separately for each purpose (e.g. use of website and profiling for advertising)
7
P5
Non-transparent Policies, Agreements, Terms and Conditions
2.3224.645
Not providing sufficient information to describing how data is processed, such as its collection, storage, and processing. Failure to make this information easily-accessible and understandable for non-lawyers.
8
P6Insufficient Deletion of User Data2.2724.544
Failure to effectively and/or timely delete personal data after termination of the specified purpose or upon request.
9
P7Insufficient Data Quality1.892.44.54
New (formerly #8 as "Outdated personal data")
The use of outdated, incorrect or bogus user data. Failure to update or correct the data.
10
P8Missing or Insufficient Session Expiration1.882.44.519
Failure to effectively enforce session termination. May result in collection of additional user-data without the user’s consent or awareness.
11
P9Inability of users to access and modify data2.022.24.4413
Users do not have the ability to access, change or delete data related to them.
12
P10
Collection of data not required for the user-consented purpose
2.1724.346
Collecting descriptive, demographic or any other user-related data that are not needed for the purposes of the system. Applies primarily to data for which the user did not provide consent.
13
P11Insufficient Data Structure Model to handle user rights2.1124.22New
14
P12Sharing of Data with 3rd Party2.0524.107
15
P13Inappropriate Policies, Terms and Conditions1.852.24.0711
16
P14Insecure Data Transfer1.672.44.0110
17
P15Transfer or Processing through 3rd Party2.151.83.8712
18
P16Misleading Content21.83.6016
19
P17Collection without Consent2.231.63.5714
20
P18Data Aggregation and Profiling2.061.63.3019
21
P19Secondary Use2.011.42.8118
22
P20Form field design issues1.8511.8520
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100