Version 2.0 of the OWASP Top 10 Privacy Risks list from 2021. Further information and related countermeasures will be provided soon. The type shows if a risk is rather organizational, technical, or both. #|Type|Title|Frequency|Impact|Description P1||Web Application Vulnerabilities|High|Very high|Vulnerability is a key problem in any system that guards or operates on sensitive user data. Failure to suitably design and implement an application, detect a problem or promptly apply a fix (patch) is likely to result in a privacy breach. This risk also encompasses the OWASP Top 10 List of web application vulnerabilities and the risks resulting from them. P2||Operator-sided Data Leakage|High|Very high|Failure to prevent the leakage of any information containing or related to user data, or the data itself, to any unauthorized party resulting in loss of data confidentiality. Introduced either due to intentional malicious breach or unintentional mistake e.g. caused by insufficient access management controls, insecure storage, duplication of data or a lack of awareness. P3||Insufficient Data Breach Response|High|Very high|Not informing the affected persons (data subjects) about a possible breach or data leak, resulting either from intentional or unintentional events; failure to remedy the situation by fixing the cause; not attempting to limit the leaks. P4||Consent on Everything|Very high|High|Aggregation or inappropriate use of consent to legitimate processing. Consent is "on everything" and not collected separately for each purpose (e.g. use of website and profiling for advertising). P5||Non-transparent Policies, Terms and Conditions|Very high|High|Not providing sufficient information to describing how data is processed, such as its collection, storage, and processing. Failure to make this information easily-accessible and understandable for non-lawyers. P6||Insufficient Deletion of Personal Data|High|High|Failure to effectively and/or timely delete personal data after termination of the specified purpose or upon request. P7||Insufficient Data Quality|Medium|Very high|The use of outdated, incorrect or bogus user data. Failure to update or correct the data. P8||Missing or insufficient Session Expiration|Medium|Very high|Failure to effectively enforce session termination. May result in collection of additional user-data without the user’s consent or awareness. P9||Inability of users to access and modify data|High|High|Users do not have the ability to access, change or delete data related to them. P10||Collection of data not required for the user-consented purpose|High|High|Collecting descriptive, demographic or any other user-related data that are not needed for the purposes of the system. Applies also to data for which the user did not provide consent. Note: The values between 0 to 3 used for frequency and impact rating were replaced by a textual description: 0-1.5: Low, 1.5-1.9: Medium, 1.9-2.3: High, > 2.3: Very high