OWASP Top 10 Privacy Risks

OWASP Top 10 Privacy Risks - An OWASP lab project

About OWASP Top 10 Privacy Risks

Top 10 Privacy Risks

The following table shows version 2.0 of the OWASP Top 10 Privacy Risks and compares it to the ranking of 2014. 2021 2014 Title P1 1 Web Application Vulnerabilities P2 2 Operator-sided Data Leakage P3 3 Insufficient Data Breach Response P4 New Consent on Everything P5 5 Non-transparent Policies, Terms and Conditions P6 4 Insufficient Deletion of User Data P7 New Insufficient Data Quality P8 9 Missing or Insufficient Session Expiration P9 13 Inability of Users to Access and Modify Data P10 6 Collection of Data Not Required for the User-Consented Purpose Detailed information is provided in the Top 10 Privacy Risks tab.

Licensing

OWASP Top 10 Privacy Risks Project is free to use. It is licensed under the Creative Commons CC-BY-SA v3.0 License.
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.