Skip to main content

V8.3 — Sensitive Private Data

Sensitive Private Data: 8 L3 requirement(s). V8.3.1: Verify that sensitive data is sent to the server in the HTTP message body or headers, and that query string parameters f... V8.3.2: Verify that users have a method to remove or export their data on demand. V8.3.3: Verify that users are provided clear language regarding collection and use of supplied personal information and that use... ... and 5 more.

PropertyValue
SectionV8.3
Ownerplatform

Mapped Controls

ControlTitle
SID-DATA-06PII Field Encryption for User Records
SID-PRIV-01Minimal Disclosure Enforcement
SID-PRIV-03Right-to-Erasure Bulk Deletion API

Source: OWASP Application Security Verification Standard 4.0.3