Skip to main content
Skip to main content
Oracle Threat Matrix · v4.0

2000-Point Compliance Registry

Every regulatory check AIfa Works runs across client engagements — with direct links to the governing law, maximum fine exposure, and enforcement consequence.

Governing Laws & Maximum Exposure

FrameworkGoverning LawMax Fine
ADA / WCAGADA Title III / European Accessibility Act (EAA) / Ontario AODA

$75,000–$150,000 (ADA) / €100,000 (EAA) / $100,000 per day (AODA)
HIPAA / MedicalHIPAA Privacy Rule / Washington My Health My Data Act (MHMDA)

$50,000–$1,500,000 per year / $7,500 per MHMDA violation
CCPA / CPRACalifornia Consumer Privacy Act (CCPA/CPRA) / California Age-Appropriate Design Code (AB 2273)

$2,500–$7,500 per violation / $7,500 per child (AB 2273)
FTC EnforcementFederal Trade Commission Act

Section 5 (Deceptive Practices & Dark Patterns)

Up to $50,120 per violation (adjusted annually)
TCPA / TelecomTelephone Consumer Protection Act (TCPA) / CAN-SPAM Act / FTSA

$500–$1,500 per call/text (TCPA) / $50,120 per CAN-SPAM email
GDPREU GDPR / UK GDPR / ePrivacy Directive

Up to €20,000,000 / £17.5M or 4% of global annual turnover
PCI-DSS / SecurityPCI DSS v4.0

PCI Security Standards Council Requirements

$5,000–$100,000 per month; merchant card processing suspension
State Privacy LawsUS State Privacy Acts (VA VCDPA, TX TDPSA, CO CPA) / NY DFS / NY SHIELD

$2,500–$7,500 per violation (States) / up to $250,000 (NY DFS)
Financial / CorporateEU DORA / Gramm-Leach-Bliley Act (GLBA) / Corporate Transparency Act (CTA)

$500/day late (FinCEN BOI) / up to $100,000 (GLBA) / 1% daily global turnover (DORA)
Digital OperationsCanada PIPEDA & Law 25 / Brazil LGPD / Australia Privacy Act / Singapore PDPA / EU AI Act & DSA

$100,000 CAD (PIPEDA) / $25M CAD (Quebec) / 2% revenue (LGPD) / $50M AUD (APPs) / €35M or 7% revenue (AI Act)

Showing 2000 of 2000 checks

#CodeCheck
001ADA-001

Missing ALT Tags on Images

002ADA-002

Missing ARIA Labels on Interactive Elements

003ADA-003

Insufficient Color Contrast Ratio

004ADA-004

No Skip Navigation Link

005ADA-005

Keyboard-Inaccessible Interactive Elements

006ADA-006

Missing Form Field Labels

007ADA-007

Broken Heading Hierarchy

008ADA-008

Missing HTML Lang Attribute

009ADA-009

ADA Overlay Widget Installed

010ADA-010

Inaccessible Careers/Job Application Portal

011HIPAA-001

Meta Pixel on Medical Booking Pages

012HIPAA-002

Google Analytics on Patient Portal Without BAA

013HIPAA-003

Missing Good Faith Estimate Page

014HIPAA-004

Social Media Pixels on Health Service Pages

015HIPAA-005

No BAA with Form SaaS Provider

016HIPAA-006

Medical Chatbot Collecting Symptoms Without Consent

017HIPAA-007

Unencrypted Patient Intake Forms

018HIPAA-008

Missing Patient PHI Access Request Link

019HIPAA-009

Telehealth Across State Lines Without License Filter

020HIPAA-010

Health Tracking Without MHMDA Consent

021CCPA-001

Missing "Do Not Sell or Share" Footer Link

022CCPA-002

Email Discount Popup Without Financial Incentive Notice

023CCPA-003

Third-Party Trackers Firing Before Cookie Consent

024CCPA-004

Missing or Inadequate Privacy Policy

025CCPA-005

Careers Page Missing Applicant Privacy Notice

026CCPA-006

No Data Deletion Request Mechanism

027CCPA-007

Third-Party Data Sharing Without Disclosure

028CCPA-008

Missing Cookie Consent Banner for California Users

029CCPA-009

Auto-Opt-In to Marketing Communications

030CCPA-010

Operating as Data Broker Without Registration

031FTC-001

Fake Countdown Timer (Dark Pattern)

032FTC-002

Deceptive Crossed-Out "Original" Price

033FTC-003

Fake Social Proof Counter

034FTC-004

Unverified Customer Reviews

035FTC-005

Subscription Cancellation Harder Than Signup

036FTC-006

Missing Affiliate Disclosure

037FTC-007

Undisclosed Compensated Testimonials

038FTC-008

Unsubstantiated Environmental Claims

039FTC-009

Free Trial Auto-Converting Without Disclosure

040FTC-010

Bait-and-Switch Pricing

041TCPA-001

Contact Form Missing SMS Consent Checkbox

042TCPA-002

Marketing SMS Sent After 8 PM Local Time

043TCPA-003

No STOP Mechanism in Marketing SMS

044TCPA-004

Marketing Emails Without Physical Address

045TCPA-005

Marketing Emails Without Unsubscribe Link

046TCPA-006

Abandoned Cart SMS Without Prior Written Consent

047TCPA-007

Auto-Dialer Without Express TCPA Consent

048TCPA-008

Missing A2P 10DLC Campaign Registration

049TCPA-009

Bulk SMS Without STOP Keyword Handler

050TCPA-010

Pre-Recorded Voice Messages Without Opt-In

051GDPR-001

Meta Pixel Fires Before Cookie Consent

052GDPR-002

No Cookie Consent Banner for EU Visitors

053GDPR-003

Google Analytics Without GDPR Consent

054GDPR-004

No Data Processing Agreement with Processors

055GDPR-005

No 72-Hour Breach Notification Process

056GDPR-006

Cross-Border Data Transfer Without Safeguards

057GDPR-007

YouTube Embed Leaking Video Viewing Data

058GDPR-008

No "Right to Be Forgotten" Mechanism

059GDPR-009

No Data Retention Policy Published

060GDPR-010

Consent Banner Uses Pre-Checked Boxes

061PCI-001

Missing Content-Security-Policy Header

062PCI-002

API Keys Exposed in Frontend Source

063PCI-003

Payment Form Without Tokenization

064PCI-004

Missing HTTPS on Form or Payment Pages

065PCI-005

Mixed Content on HTTPS Pages

066PCI-006

Open Directory Listing

067PCI-007

XML-RPC Endpoint Enabled

068PCI-008

Outdated CMS with Known CVEs

069PCI-009

Third-Party Scripts Without SRI

070PCI-010

Forms Without CAPTCHA Protection

071STATE-001

CIPA: Chatbot Recording Without Consent

072STATE-002

BIPA: Virtual Try-On Without Biometric Consent

073STATE-003

Utah AI Act: AI Chatbot Not Disclosing AI Identity

074STATE-004

CA BOT Act: AI Using Human Name Without Disclosure

075STATE-005

Proposition 65: Missing Toxic Substance Warning

076STATE-006

CA Auto-Renewal: No Reminder Before Annual Charge

077STATE-007

Inadequate Age-Gate for Restricted Products

078STATE-008

SB 478: Hidden Service Fees at Checkout

079STATE-009

NY SHIELD Act: Inadequate Data Security

080STATE-010

Job Postings Without Salary Range

081FIN-001

GLBA: Sensitive Financial Docs via Unsecured Email

082FIN-002

FinCEN BOI: Missing Beneficial Ownership Report

083FIN-003

FINRA: Personal Email for Investment Communications

084FIN-004

Missing Contractor License Number on Website

085FIN-005

No DMCA Agent or Takedown Policy

086FIN-006

Missing Arbitration Clause in Terms of Service

087FIN-007

Return Policy Not Prominently Displayed

088FIN-008

Credit Card Surcharge Without Advance Notice

089FIN-009

SEC Form CRS Missing for Investment Advisors

090FIN-010

Insurance Lead Generation Without Required Disclosures

091OPS-001

Missing DMARC Record

092OPS-002

Missing SPF Record

093OPS-003

Broken Outbound Links to Expired Domains

094OPS-004

Orphaned Tracking Scripts from Discontinued Services

095OPS-005

Missing DKIM Email Authentication

096OPS-006

Outdated Copyright Year in Footer

097OPS-007

Missing robots.txt and Sitemap

098OPS-008

Poor Mobile Tap Targets

099OPS-009

Contact Form Without Rate Limiting

100OPS-010

Missing or Expired SSL Certificate

101ADA-101

Missing Accessibility Information on Products/Services

102ADA-102

Non-Compliant Public Feedback Processes

103COP-101

Illegal Personal Information Collection from Children

104PIP-101

Lack of Mandated Privacy Officer Contact Info

105PIP-102

Vague Purposes for Personal Data Collection

106LGP-101

No Appointed Data Protection Officer (DPO)

107LGP-102

Absence of a Valid Legal Basis for Processing

108POP-101

Direct Marketing Without Opt-In Consent

109POP-102

Unlawful Cross-Border Data Transfer Disclosures

110APP-101

Non-Compliant Overseas Data Disclosure Statement

111APP-102

Lack of Anonymous/Pseudonymous Interaction Option

112PDP-101

Failure to Provide Request for Access/Correction Info

113PDP-102

Unreasonable Terms forcing Personal Data Consent

114AIA-101

Unmarked Generative AI Output / Deepfakes

115AIA-102

Lack of Disclosure on AI User Interaction

116DSA-101

Deceptive UI Patterns (Dark Patterns) in Design

117DSA-102

Lack of Single Point of Contact for Authorities

118DMA-101

Unlawful Data Combination Across Services

119STA-101

Deceptive Design Encouraging Child Data Sharing

120STA-102

Absence of Consumer Appeal Rights Process

121STA-103

Lack of Sensitive Data Processing Opt-In

122NYD-101

Lack of Cybersecurity Multi-Factor Auth (MFA)

123NYD-102

Failure to Implement Safeguards for Private Data

124QBL-101

No Privacy Impact Assessment (PIA) for Transfer

125DOR-101

Inadequate ICT Third-Party Risk Disclosures

126VPPA-001

Video Tracking Pixel Fires Without VPPA Consent

127EAA-001

No Accessibility Statement Published Under European Accessibility Act

128NIS2-001

No Security.txt or Vulnerability Disclosure Policy (NIS2)

129HBNR-001

Health Data Shared Without FTC Health Breach Notification Compliance

130CKWL-001

Cookie Wall Blocks Access Without Valid Reject Option

131CTDP-001

Minor\'s Data Used for Targeted Advertising Without Opt-In (CTDPA)

132OCPA-001

Website Does Not Honor Global Privacy Control Signal (Oregon CPA)

133COAI-001

High-Risk AI System Without Public Transparency Disclosure (Colorado AI Act)

134JPAP-001

Cookie Data Shared With Third Parties Without Japan APPI Disclosure

135KRPI-001

Non-Essential Cookies Set Before Consent for South Korean Users

136FERP-001

Education Website Tracking Pixels Transmitting Student Data

137ESIG-001

E-Sign Consent Flow Lacks Required ESIGN Act Disclosures

138IDDP-001

Privacy Notice Not Available in Required Languages (India DPDP Act)

139FACT-001

Full Credit Card Number Shown on Electronic Receipt (FACTA Violation)

140DLDP-001

No Clear Opt-Out Mechanism for Delaware Consumers (DPDPA)

141THPD-001

Non-Essential Cookies Firing Without Opt-In Consent (Thailand PDPA)

142SEC-001

SEC Registrant Missing Cybersecurity Governance Disclosure

143TRKV-001

Missing Data Controller Registration Notice (Turkey KVKK)

144NZPR-001

Cross-Border Data Transfer Without NZ Privacy Act IPP 12 Compliance

145MNDP-001

Privacy Notice Missing Data Retention Periods (Minnesota MCDPA)

146EIDS-001

Very Large Online Platform Not Prepared for EUDI Wallet Acceptance

147AMLK-001

AML/KYC Customer Identification Notice Missing on Financial Site

148CTHL-001

Geofencing Near Health Facility for Data Collection (CT SB 3)

149IDDG-001

Missing Grievance Redressal Mechanism for Indian Data Principals

150CBAC-001

Cookie Consent Banner Uses Asymmetric Accept/Reject Design

151CUBI-001

Biometric Capture Without Prior Notification and Consent (Texas CUBI)

152EUAI-003

Missing Machine-Readable Metadata/Watermark in AI-Generated Content (EU AI Act)

153QC25-002

Missing Data Protection Officer (DPO) Contact Details on Website (Quebec Act 25)

154COPA-001

Failure to Recognize Global Privacy Control (GPC) Opt-Out Signal (Colorado CPA)

155MHMDA-002

Missing Consumer Health Privacy Policy Link on Homepage (WA MHMDA)

156CNPI-001

Missing Separate Consent for Sensitive Personal Information Processing (China PIPL)

157DSA-001

Dark Patterns in User Interfaces (EU DSA Article 25)

158KRPA-001

Bundling Consent for Third-Party Data Transfers (South Korea PIPA)

159UKOSA-001

Inadequate Age Verification for Regulated Content (UK OSA)

160EUAI-004

Missing Emotion Recognition / Biometric Categorization Disclosure (EU AI Act)

161CAAD-002

Default Geolocation Disabled for Under-18 Users (CA AADC)

162BIPA-002

Missing Biometric Retention and Destruction Policy (BIPA)

163ORPA-001

Missing Opt-In Consent for Sensitive Data Processing (Oregon OCPA)

164VCDP-002

Geofencing Around Healthcare Facilities for Data Collection (VCDPA)

165TDPS-001

Sensitive Data Consent Violation (Texas TDPSA)

166MTDP-001

Missing Parent Consent Verification for Minors under 13 (Montana MCDPA)

167FDBR-001

Failure to Disclose Facial Recognition Surveillance (Florida FDBR)

168NJPA-001

Missing Privacy Disclosures for Children's Data (New Jersey Privacy Act)

169NEDP-001

Inadequate Notice of Consumer Profiling (Nebraska NDPA)

170NHPA-001

Missing Direct Marketing Opt-Out Link (New Hampshire Privacy Act)

171GDPR-011

Inaccessible Format for Data Portability Requests (GDPR)

172GDPR-012

Non-Layered Privacy Policy Information Structure (GDPR)

173DSA-002

Missing Ad Repository and Transparency Log (EU DSA)

174DSA-003

Missing Single Point of Contact for Authorities (EU DSA)

175DMA-001

Involuntary Gatekeeper Data Bundling (EU DMA)

176EUDAT-001

Smart Contract Access Lack of Deactivation Capability (EU Data Act)

177GDPR-013

Missing Consent Status Logging and Audit Trails (GDPR)

178EPRIV-002

Pre-Consent Cookie & Tracker Execution (ePrivacy)

179DORA-002

Lack of Operational Resilience Disclosures (EU DORA)

180GDPR-014

Missing Retention Timelines in Privacy Disclosures (GDPR)

181AUPA-002

Data Disposal Standards Infraction (Australia Privacy Act)

182SGPD-001

Missing Consent Withdrawal Mechanism (Singapore PDPA)

183SGPD-002

Missing Data Protection Officer Visibility (Singapore PDPA)

184DPDP-002

Missing Right to Nominate Representative Notice (India DPDP Act)

185DPDP-003

Missing Consent Manager Interface Integration (India DPDP Act)

186JPAP-002

Missing Disclosures for Handling Anonymized Data (Japan APPI)

187NZPR-002

Missing Contact Link for Privacy Officer (New Zealand Privacy Act)

188THPD-002

Missing DPO Contact Details in Consent Flows (Thailand PDPA)

189VNDP-001

Missing Local Data Protection Officer for Sensitive Data (Vietnam Decree 13)

190PHDP-001

Bundled Consent for Profiling and Automated Decision-Making (Philippines DPA)

191LGPD-002

Missing Data Subject Rights Portal Link (Brazil LGPD)

192POPI-001

Missing Prior Authorization for Processing Credit Data (South Africa POPIA)

193SAPD-001

Missing Opt-in Consent for Direct Marketing (Saudi Arabia PDPL)

194ILPA-001

Failure to Disclose Database Registration Status (Israel Privacy Act)

195DIFC-001

Missing Separate Consent for Direct Marketing (Dubai DIFC)

196NDPA-001

Missing Cross-Border Data Transfer Disclosures (Nigeria NDPA)

197KEDP-001

Unauthorized Cross-Border Transfer of Health Data (Kenya DPA)

198EGDP-001

Lack of License for Electronic Marketing Messages (Egypt DPA)

199MRDP-001

Unauthorized International Data Transfer (Morocco CNDP Law 09-08)

200LGPD-003

Inadequate Security Standards Disclosures (Brazil LGPD)

201FTCS-001

Insecure Transmission of Financial Customer Info (FTC Safeguards)

202GLBA-002

Missing Privacy Notice Delivery Link (GLBA)

203CTAC-001

Lack of Corporate Transparency Disclosures (CTA)

204SEC-002

Missing Electronic Record Archiving Verification (SEC Rule 17a-4)

205DORA-003

Lack of ICT Risk Management System Disclosures (EU DORA)

206FTCR-001

Missing Identity Theft Prevention Disclosures (FTC Red Flags)

207FINRA-001

Missing BrokerCheck Link and Regulatory Disclosures (FINRA)

208PCI-011

Unmonitored Third-Party Scripts on Checkout Page (PCI-DSS v4.0)

209PCI-012

Missing Subresource Integrity (SRI) on Payment Gateway (PCI-DSS v4.0)

210TILA-001

Non-Prominent APR Disclosure in Loan Ads (TILA)

211FTCD-001

Deceptive Cancellation Flow / Roach Motel (FTC Section 5)

212FTCD-002

Deceptive Urgency & Fake Countdown Timers (FTC Section 5)

213FTCD-003

Confirmshaming in Opt-Out Modals (FTC Section 5)

214W3CR-001

Missing Smart Contract Auditing Disclosures on dApp (SEC Framework)

215W3CR-002

Blind Signing Vulnerability in Web3 dApp Interface (NIST SP 800-95)

216DSA-004

Missing Recommender System Algorithmic Transparency (EU DSA)

217EUAI-005

Missing High-Risk AI System Logging Capability (EU AI Act)

218UKCR-001

Auto-Renewal Terms Without Plain Language Summary (UK CRA)

219PIPD-002

Inadequate Third-Party Processor Disclosures (Canada PIPEDA)

220TDDD-001

Analytics Cookie Consent Bypass (Germany TDDDG)

221TXSC-001

Social Media Chat Enabled by Default for Minors (Texas SCOPE)

222UTSM-001

Missing Age Verification for Social Platforms (Utah SMRA)

223FLDB-001

Missing Age Gate for Restricted Social Platform (Florida FDBR)

224CTDP-002

Geofencing Around Mental Health Centers (Connecticut SB 3)

225VCDP-003

Missing Consent Verification for Child Sensitive Data (Virginia VCDPA)

226CAAD-003

Profiling Enabled by Default for Minor Accounts (CA AADC)

227MDAD-001

Missing Child Impact Assessment Disclosures (Maryland AADCA)

228COPA-002

Missing Parental Consent for Child Personal Data (Colorado CPA)

229INDP-001

Missing Opt-In Consent for Child Sensitive Data (Indiana CDPA)

230TNIP-001

Missing Privacy Policy Rights Appeals Process (Tennessee TIPA)

231TCPA-011

Inaccessible or Delayed Email Unsubscribe Mechanism (CAN-SPAM)

232TCPA-012

Missing Valid Sender Identity and Postal Address (CAN-SPAM)

233TCPA-013

Missing Written Consent for Marketing Robocalls (TCPA)

234EAA-003

E-Commerce Shopping Cart Keyboard Navigation Barriers (EAA)

235EAA-004

Lack of Alternative Media Formats in E-Commerce (EAA)

236AODA-002

Inaccessible Document Downloads (Ontario AODA)

237ADA-237

Keyboard Focus Trap in Modal Dialogues (ADA Title III)

238ADA-103

Inaccessible Media Players (ADA Title III)

239EPRIV-003

Consent Bypass on Mobile Responsive Layouts (ePrivacy)

240FTCE-011

Fake AI Testimonials and Reviews (FTC Consumer Review Rule)

241HIPAA-011

Social Media Chat Leakage of Patient PHI (HIPAA)

242HIPAA-012

Unsecure Transmission of Patient Records via SMS/Email (HIPAA)

243PCI-013

Insecure Storage of Credit Card Data in LocalStorage (PCI-DSS v4.0)

244PCI-014

Insecure Payment Scripts Execution on Checkout Pages (PCI-DSS v4.0)

245MHMDA-003

Lack of Health Provider Verification for Sensitive Data (WA MHMDA)

246NIST-001

Missing Web Portal Authentication Session Timeouts (NIST SP 800-53)

247SOC2-001

Missing System Availability Disclosures (SOC 2 Type II)

248CYIN-001

Undisclosed End-of-Life Software Platforms (Cyber Insurance)

249DORA-004

Missing ICT Incident Reporting Capability (EU DORA)

250FTCS-002

Missing Customer Portal Session Limits (FTC Safeguards)

251DEPD-001

Missing Consumer Data Portability Format Option (Delaware DPDPA)

252MAPD-001

Sale of Sensitive Personal Data Prohibited (Maryland MODPA)

253KYPD-001

Missing Consumer Right of Access Disclosure (Kentucky KCDPA)

254RIPD-001

Failure to Disclose Third-Party Sales in Privacy Notice (Rhode Island RIDTPPA)

255IAPD-001

Missing Consumer Right to Opt-Out of Data Sale (Iowa ICDPA)

256FTCH-001

Unlawful Sharing of Health Metrics with Trackers (FTC Health Breach Rule)

257NYDF-001

Missing Multi-Factor Authentication on Financial Portals (NYDFS)

258BIPA-003

Missing Written Release for Biometric Collection (Illinois BIPA)

259AADA-001

Keyboard Focus Obscured by Sticky Elements (WCAG 2.2)

260AADA-002

Insufficient Target Size for Interactive Elements (WCAG 2.2)

261EUAI-006

Missing Human Oversight Disclosures for High-Risk AI (EU AI Act)

262EUAI-007

Lack of Post-Market Monitoring Plans for AI Systems (EU AI Act)

263DSA-005

Missing Non-Profiling Option for Recommender Systems (EU DSA)

264DSA-006

Missing Age Verification for Minor Protection (EU DSA)

265NIS2-002

Missing Incident Notification and Contact Channels (NIS2)

266GDPR-015

Missing Right to Restrict Processing Action Path (GDPR)

267EPRIV-004

Cookie Lifespan Exceeds Maximum Limits (ePrivacy Guidelines)

268GDPR-016

Missing Records of Processing Activities Disclosure summary (GDPR)

269EIDS-002

Lack of Qualified Electronic Signatures Support (eIDAS 2.0)

270GDPR-017

Missing Data Protection Impact Assessment (DPIA) Disclosures (GDPR)

271ARPD-001

Missing Right to Rectification Portal (Argentina Law 25.326)

272COPD-001

Bundled Consent for Commercial Messaging (Colombia Law 1581)

273MXPD-001

Missing Separate ARCO Rights Actions (Mexico LFPDPPP)

274CHPD-001

Missing Cross-Border Transfer Disclosures (Switzerland FADP)

275POPI-002

Default Opt-in Marketing Violation (South Africa POPIA)

276TRKV-002

Unauthorized Cross-Border Transfer without Adequate Safeguards (Turkey KVKK)

277AUPA-003

Missing Privacy Policy Contact and Access Procedure Details (Australia APP 1)

278SGPD-003

Lack of Data Access and Correction Request Tracking System (Singapore PDPA)

279THPD-003

Cross-Border Transfer to Non-Adequate Countries without Consent (Thailand PDPA)

280PHDP-002

Inadequate Disclosure of Right to Object to Processing (Philippines DPA)

281FTCD-004

Deceptive Subscription Price Increases Without Consent (FTC)

282FTCD-005

Pre-ticked Optional Add-on Items at Checkout (FTC)

283TCPA-014

Failure to Maintain Internal Do Not Call (DNC) Registry (TCPA)

284TCPA-015

Unsubscribe Requests Require Fees or Logins (CAN-SPAM)

285EAA-005

Inaccessible Digital Invoice/Receipt Outputs for E-Commerce (EAA)

286AODA-003

Missing Accessibility Feedback Submission Channel (Ontario AODA)

287ADA-104

Text Scaling Breaks Page Layout at 200% (ADA Title III)

288ADA-105

Inability to Adjust or Extend Form Session Limits (ADA Title III)

289EPRIV-005

Consent Banner Cookie Settings Block Keyboard Users

290FTCE-012

Unlabeled Affiliate Links and Sponsored Content (FTC Endorsement Guides)

291W3CR-003

Missing Risks Disclosure for Token Transactions in dApp (SEC)

292W3CR-004

dApp Fails to Validate API Endpoint Integrity (NIST SP 1800-34)

293PCI-015

Front-end Execution of Scripts from Non-Authorized Domains (PCI-DSS v4.0)

294PCI-016

Customer Portal Session Replay Scripts Enabled on Password Inputs (PCI-DSS)

295CYIN-002

Missing Incident Response Plan Reference (Cyber Insurance)

296DORA-005

ICT Systems Major Incident Log Reporting Lack (EU DORA)

297FTCS-003

Missing Risk Assessment Log Disclosures (FTC Safeguards)

298SOC2-002

Inadequate Access Revocation Notification (SOC 2 Type II)

299NIST-002

Lack of User Account Management Audit Logs (NIST SP 800-53)

300HIPAA-013

Missing Identity Verification Prior to Accessing PHI (HIPAA)

301MCDP-002

Missing Consumer Right to Correct Inaccurate Personal Data (Minnesota MCDPA)

302TXSC-002

Inadequate Advertising Restrictions on Social Platforms for Minors (Texas SCOPE)

303UTSM-002

Default DM Block Between Minors and Non-Parents (Utah SMRA)

304FLDB-002

Search Results Bias Disclosure Failure (Florida FDBR)

305CTDP-003

Profiling Minors for Commercial Purposes (Connecticut SB 3)

306CAAD-004

Non-Obvious Interactive Dark Patterns Targeting Children (CA AADC)

307MDAD-002

Default Tracking Active for Children (Maryland MODPA)

308INDP-002

Lack of Sensitive Data Processing Disclosures (Indiana CDPA)

309TNIP-002

Inadequate Response Time for Data Rights Requests (Tennessee TIPA)

310NHPA-002

Missing Right to Deletion Actions for New Hampshire Consumers (NHPA)

311AADA-003

Redundant Data Entry Required in Multi-step Forms (WCAG 2.2)

312AADA-004

Inaccessible Authentication via Cognitive Function Tests (WCAG 2.2)

313AADA-005

Inconsistent Location of Help and Support Contacts (WCAG 2.2)

314AADA-006

Dragging Movements Required Without Single-pointer Alternatives (WCAG 2.2)

315AADA-007

Horizontal Scrolling Triggered on Desktop Layouts (WCAG 2.1)

316AADA-008

Text Spacing Adjustments Lead to Overlapping Text (WCAG 2.1)

317AADA-009

Unstoppable Auto-playing Media and Carousels (WCAG 2.1)

318AADA-010

Missing Input Placeholders or Context Clues (WCAG 2.1)

319AADA-011

Status Messages Not Announced by Screen Readers (WCAG 2.1)

320AADA-012

Illogical Tab Navigation Order (WCAG 2.1)

321GDPR-018

Encryption Standards for Collected Data Not Disclosed (GDPR)

322GDPR-019

Missing Adequacy Decision Disclosures for External Transfers (GDPR)

323GDPR-020

Lack of Data Breach Mitigation Instructions for Users (GDPR)

324PIPD-003

Missing Specific Storage Location Disclosures (Canada PIPEDA)

325PIPD-004

Missing Data Access Request Processing Costs Notice (Canada PIPEDA)

326JPAP-003

Failure to Disclose Purposes of Shared Cookie Identifiers (Japan APPI)

327NZPR-003

Unlawful Retention of Personal Data Beyond Needed Duration (New Zealand Privacy Act)

328THPD-004

Inadequate Disclosure of Right to Request Data Deletion (Thailand PDPA)

329PHDP-003

Failure to Disclose Procedures for Filing Complaints with DPA (Philippines DPA)

330LGPD-004

Privacy Policy Updates Not Prominently Notified (Brazil LGPD)

331GLBA-003

Missing Consumer Right to Opt-Out of Sharing with Non-Affiliates (GLBA)

332SEC-003

Missing Administrative Policies Safeguarding Customer Information Disclosures (SEC)

333PCI-017

Inventory of External Software Components Missing (PCI-DSS v4.0)

334PCI-018

Failure to Document Cryptographic Key Management (PCI-DSS v4.0)

335CYIN-003

Lack of Vulnerability Disclosure Program Notice (Cyber Insurance)

336DORA-006

Lack of Third-Party ICT Provider Criticality Level Disclosures (EU DORA)

337FTCS-004

Missing Employee Security Training Reference (FTC Safeguards)

338SOC2-003

Inadequate Patch Management Disclosures (SOC 2 Type II)

339NIST-003

Lack of Web Traffic and Intrusion Monitoring Disclosures (NIST SP 800-53)

340HIPAA-014

Inadequate Cybersecurity Risk Analysis Disclosures (HIPAA Security Rule)

341MDAD-003

Profiling Children for Targeted Ads (Maryland MODPA)

342TXSC-003

Collection of Minor Location History Without Parent Verification (Texas SCOPE)

343UTSM-003

Algorithmic Recommendations to Minors (Utah SMRA)

344FLDB-003

Missing Personal Data Sales Clear Opt-out Link (Florida FDBR)

345CTDP-004

Geolocation Data Selling Without Consent (Connecticut SB 3)

346CAAD-005

Absence of Child Safety Impact Assessment Rationale Disclosures (CA AADC)

347BIPA-004

Selling Biometric Identifiers Prohibited (Illinois BIPA)

348HIPAA-015

Inadequate De-identification of Patient Research Records (HIPAA Privacy)

349DORA-007

Missing Contractual Clause Safeguard Summaries (EU DORA)

350FTCS-005

Missing Incident Response Policy Summary (FTC Safeguards)

351ADA-106

Focus Appearance (Minimum) Violation

352ADA-107

Focus Obscured by Sticky Elements

353ADA-108

Dragging Movements Lack Click Alternatives

354ADA-109

Sub-Minimum Interactive Target Size

355ADA-110

Redundant Form Data Entry Requirement

356ADA-111

Inaccessible Multi-Factor Authentication

357ADA-112

Focus Obscured (Enhanced Level)

358ADA-113

Cognitive Authentication Exclusion (Enhanced)

359ADA-114

Missing Accessible Video Transcripts

360ADA-115

Missing Captions for Pre-recorded Media

361HIPAA-016

Insecure Patient Appointment Forms

362HIPAA-017

Unauthorized Marketing Pixels on Booking Screens

363HIPAA-018

Lack of Portal Access Activity Logging

364HIPAA-019

Undated Notice of Privacy Practices

365HIPAA-020

Non-Compliant Health Data Deletion Process

366HIPAA-021

Missing MHMDA Consumer Health Opt-In

367HIPAA-022

Insecure Storage of Prescription Uploads

368HIPAA-023

Lack of Patient Portal Automatic Logoff

369HIPAA-024

Shared Patient Portal Administrative Credentials

370HIPAA-025

De-identification Failures in Portal Reports

371CCPA-011

Dark Patterns in Consent Opt-Out Links

372CCPA-012

Lack of Global Privacy Control (GPC) Verification Logs

373CCPA-013

Missing Notice of Financial Incentive

374CCPA-014

Non-Compliant Employee & Applicant Privacy Notice

375CCPA-015

Missing Sensitive Data Retention Periods

376CCPA-016

Lack of Portal for Right to Correct

377CCPA-017

Implicit Sensitive Geolocation Tracking

378CCPA-018

Incomplete Authorized Agent Procedural Disclosure

379CCPA-019

Missing Privacy Request Annual Metrics

380CCPA-020

Default Profiling of Under-18 Consumers

381FTC-011

Subscription Deceptive Auto-Renewal Obstacles

382FTC-012

Fake Scarcity Countdown Timers

383FTC-013

Pre-Checked Optional Marketing Consents

384FTC-014

Fake Review Data Embedded in Client Bundles

385FTC-015

Deceptive Checkout Junk Fees

386FTC-016

Automatic E-Commerce Shopping Cart Additions

387FTC-017

Lack of Multi-Factor Authentication for Financial Portals

388FTC-018

Invalid Parental Consent Process on Child Portals

389FTC-019

Ad Pixel Data Sharing on Health Searches

390FTC-020

Unlabelled Sponsored Content

391TCPA-016

Pre-Checked SMS Consent Inputs

392TCPA-017

Incomplete SMS Opt-In Statutory Terms

393TCPA-018

Missing Mobile Carrier Disclosures

394TCPA-019

Non-Compliant SMS Unsubscribe System

395TCPA-020

Missing Physical Address in Outbound Emails

396TCPA-021

Broken Unsubscribe Mechanisms in Mail Footers

397TCPA-022

Excessive Delays in Email Unsubscribe Processing

398TCPA-023

Robocalls and Automatic Texting Without Written Consent

399TCPA-024

Lack of Preserved Do Not Call Request Records

400TCPA-025

Out-of-Hours Automated Text Dispatching

401GDPR-021

Pre-Ticked Non-Essential Cookies on Load

402GDPR-022

Unequal Reject and Accept Banner Layouts

403GDPR-023

Missing DPO Public Contact Details

404GDPR-024

Failing to Disclose DPAs with Cloud Subprocessors

405GDPR-025

Lack of Secure SAR Request Channels

406GDPR-026

Unjustified Erasure Request Rejections

407GDPR-027

Privacy Settings Enabled by Default

408GDPR-028

Insecure Email Contact Form Submissions

409GDPR-029

Failure to Execute Required DPIAs

410GDPR-030

Cross-Border Transfers without Standard Clauses

411PCI-019

CVV Data Retention in Database

412PCI-020

Weak TLS Cipher Suite Configurations

413PCI-021

Missing CSP Headers on Payments Checkouts

414PCI-022

Lack of External Javascript Script Audits

415PCI-023

Missing Payment Form Tampering Monitoring

416PCI-024

Default Administrative Panel Credentials

417PCI-025

Shared Payment Operator Sessions

418PCI-026

Known CVE Vulnerabilities in Payment Stack

419PCI-027

Unencrypted Storage of Primary Account Numbers

420PCI-028

Missing Penetration Testing Attestation

421STATE-011

Texas TDPSA Small Business Sensitive Consent

422STATE-012

Virginia VCDPA Rights Appeal Escalation

423STATE-013

Missing Colorado CPA Universal Opt-Out Recognition

424STATE-014

Delaware DPDPA Non-Consensual Health Transfers

425STATE-015

Oregon OCPA Incomplete Third-Party Listing

426STATE-016

New Jersey NJPA Sensitive Selling Disclosures

427STATE-017

Utah UCPA Incomplete Rights Disclosures

428STATE-018

New Hampshire NHPA Privacy Officer Designation

429STATE-019

Montana MTCDPA Child Processing Opt-In

430STATE-020

Nebraska NEDPA Incomplete Response Timelines

431FIN-011

Missing DORA ICT Incident Notification Disclosures

432FIN-012

GLBA Customer Files Cleartext Encryption Failures

433FIN-013

CTA Beneficial Owner Portal Reporting Failures

434FIN-014

Inadequate SEC 10-K Material Threat Disclosures

435FIN-015

FINRA Rule 2210 Deceptive Yield Claims

436FIN-016

Missing SOX Internal Control Assessment Disclosures

437FIN-017

DORA Third-Party Risk Registers Exclusions

438FIN-018

GLBA Incomplete Annual Opt-Out Option Notifications

439FIN-019

FINRA Rule 4511 Non-WORM Log Format

440FIN-020

CFTC Rule 1.31 Electronic History Deletions

441OPS-011

AI Sentiment Analysis Warnings Missing

442OPS-012

Prohibited AI Biometric Categorization Systems

443OPS-013

Missing AI Image & Text Metadata Watermarks

444OPS-014

EU DSA Algorithmic Feed Disclosures

445OPS-015

EU DSA Missing Advertisements Repository

446OPS-016

Lack of Shadow Banning Redress Portal

447OPS-017

Failing to Accept eIDAS 2.0 Wallets

448OPS-018

Missing CRA Vulnerability Reporting Gateway

449OPS-019

Missing DPO ANPD Registry for Brazilian Portals

450OPS-020

Lack of Guardian Consent Verification for India DPDP

451UAEPD-001

Lack of Explicit Consent for Cross-Border Data Transfers

452UAEPD-002

Missing Local Data Protection Officer (DPO) Contact Details

453UAEPD-003

Non-Compliant UAE Child Consent Flow

454UAEPD-004

Failure to Maintain UAE Data Processing Registers

455UAEPD-005

Inadequate Data Breach Notification Timelines for UAE

456UAEPD-006

Lack of Direct Opt-Out for Marketing Profiling in UAE

457SDPD-001

Missing Registration on Saudi National Data Portal

458SDPD-002

Lack of Explicit Consent for Direct Marketing in KSA

459SDPD-003

Illegal Storage of Sensitive Personal Data Outside KSA

460SDPD-004

Failure to Disclose Processing Purpose to KSA Consumers

461SDPD-005

Non-Compliant Data Erasure Response Timeframe in KSA

462SDPD-006

Lack of Explicit Opt-In for Tracking KSA Citizens

463ILPA-002

Missing Database Registration under Israeli Law

464ILPA-003

Failure to Disclose Duty of Delivery under Israeli Law

465ILPA-004

Non-Compliant Cross-Border Data Transfers from Israel

466ILPA-005

Lack of Data Security Audits under Israeli Regulations

467ILPA-006

Illegal Direct Mailing Advertising without Registration in Israel

468TRKV-003

Missing Explicit Consent for Cookie Tracking in Turkey

469TRKV-004

Missing Registration on Turkish VERBIS Database Registry

470TRKV-005

Inadequate Data Breach Reporting Windows for Turkey

471TRKV-006

Missing Turkish Privacy Policy Clarification Text

472TRKV-007

Illegal Cross-Border Transfers without Turkish Board Consent

473CHFADP-001

Lack of Explicit Disclosures for Automated Decisions in Switzerland

474CHFADP-002

Missing Representative for Foreign Controllers in Switzerland

475CHFADP-003

Failure to Disclose Swiss Processing Register entries

476CHFADP-004

Inadequate Data Transfer Exclusions for Switzerland

477CHFADP-005

Lack of Explicit Consent for Swiss Sensitive Data

478CHFADP-006

Lack of Swiss Data Breach Reporting (Rapid Windows)

479UKGDPR-001

Lack of UK GDPR Addendum for Data Transfers

480UKGDPR-002

Missing UK ICO Fee Registration

481UKGDPR-003

Missing UK Representative under UK GDPR

482UKGDPR-004

Non-Compliant Children's Data Processing under UK Age-Appropriate Code

483UKOSA-002

Lack of Age Verification Mechanisms for Harmful Content (UK OSA)

484UKOSA-003

Missing UK Online Safety Reporting Channels

485AUSPA-001

Failure to Honor Australia Privacy Act Erasure Requests

486AUSPA-002

Non-Compliant Cross-Border Disclosures for Australia

487AUSPA-003

Lack of Explicit Opt-In for Marketing Cookies in Australia

488AUSPA-004

Missing Australia Privacy Policy Disclosure of Third Party Hosting Locations

489AUSPA-005

Australia Spam Act Opt-Out Violation

490AUSPA-006

Illegal Direct Marketing without Opt-Out under APP 7

491AUSPA-007

Lack of Data Quality Verifications for Australian Records

492NZPR-004

Failure to Disclose NZ Privacy Officer Details

493NZPR-005

Lack of Immediate Breach Notification for New Zealand

494NZPR-006

Missing NZ Consumer Access Portal (IPP 6)

495NZPR-007

Illegal Storage of NZ Records in Non-Adequate Jurisdictions (IPP 12)

496NZPR-008

Collection of Excessive Personal Data from NZ Residents

497SGPD-004

Lack of Mandatory DPO Contact Disclosures in Singapore

498SGPD-005

Failure to Document Deemed Consent Rules for Singapore

499SGPD-006

Non-Compliant Data Portability Actions under Singapore PDPA

500SGPD-007

Inadequate Singapore Breach Notification Timeline (3 Calendar Days)

501SGPD-008

Singapore Do Not Call (DNC) Registry Violations

502MYPD-001

Lack of Dual-Language Privacy Notice under Malaysian PDPA

503MYPD-002

Illegal Cross-Border Transfers under Malaysian PDPA

504MYPD-003

Lack of Verification Controls for Data Correctness in Malaysia

505MYPD-004

Non-Compliant Processing of Sensitive Personal Data in Malaysia

506THPD-005

Failure to Disclose Thai DPO Contact Protocols

507THPD-006

Missing Thai Consent Revocation Interface

508THPD-007

Illegal Cross-Border Transfers of Thai Personal Data

509THPD-008

Missing Thai Data Processing Register Entries

510THPD-009

Collection of Thai Sensitive Personal Data without Explicit Consent

511VNDP-002

Lack of Prior Impact Assessment for Vietnam Data Transfers

512VNDP-003

Non-Compliant Processing of Children's Data in Vietnam

513VNDP-004

Lack of Localized Server Presence for Vietnam Operations

514VNDP-005

Failure to Disclose DPO Details under Vietnam Decree 13

515VNDP-006

Lack of Verified Data Security Assessments in Vietnam

516DPDP-004

Missing Multi-Language Privacy Notices for India

517DPDP-005

Lack of Localized Dispute Redressal Channels for India

518DPDP-006

Incomplete Purpose-Specification Form Notices in India

519DPDP-007

Failure to Disclose DPO and Consent Manager Contacts in India

520DPDP-008

Non-Compliant Processing of Children's Tracking Cookies in India

521DPDP-009

Lack of Data Erasure Controls on Vendor Subprocessors in India

522JPAP-004

Lack of Cross-Border Information Disclosures under Japanese APPI

523JPAP-005

Incomplete Disclosure of Database Safety Measures in Japan

524JPAP-006

Lack of Consent for Pseudo-Personally Identifiable Information in Japan

525JPAP-007

Non-Compliant Processing of Personally Referable Information in Japan

526JPAP-008

Lack of Data Breach Notification System for PPC Japan

527JPAP-009

Illegal Direct Marketing over Phone without Verification in Japan

528SKPA-001

Lack of Multi-Option Form Consent Separations in South Korea

529SKPA-002

Non-Compliant Resident Registration Number Processing in S. Korea

530SKPA-003

Lack of Native Language DPO Disclosures in South Korea

531SKPA-004

Missing Cross-Border Transfer Disclosures under Korean PIPA

532SKPA-005

South Korea PIPC Breach Notification Violations

533LGPD-005

Missing Brazilian DPO Registry with ANPD

534LGPD-006

Lack of Explicit Consent for Processing Sensitive Brazilian Records

535LGPD-007

Non-Compliant Data Portability Path under Brazilian LGPD

536LGPD-008

Failure to Document Brazilian Processing Legal Bases

537LGPD-009

Failure to Honor Immediate Erasure Requests in Brazil

538POPI-003

Missing Registration of South African Information Officer

539POPI-004

Lack of Direct Consent for Unsolicited Electronic Marketing in SA

540POPI-005

Insecure Storage of South African Identity Numbers

541POPI-006

Failure to Audit South African Processing Purpose Boundaries

542POPI-007

Failure to File PAIA Manual on Corporate Portals

543NDPA-002

Lack of Mandated Audit Disclosures under Nigerian NDPA

544NDPA-003

Lack of Explicit Consent for Direct Marketing in Nigeria

545NDPA-004

Illegal Storage of Nigerian Data Outside Nigeria

546NDPA-005

Missing Information Security Audits under Nigerian Law

547MXPD-002

Missing Mexican Privacy Notice Structure (Aviso de Privacidad)

548MXPD-003

Lack of Explicit Opt-In for Sensitive Data in Mexico

549MXPD-004

Failure to Document ARCO Rights Redress Pathways in Mexico

550MXPD-005

Insecure Security Disclosures for Mexican Customer Data

551ARGPD-001

Failure to Register Databases with AAIP (Argentina)

552ARGPD-002

Lack of Explicit ARCO Rights Redress Channels under Argentine Law

553ARGPD-003

Missing Local Security Safeguards for Argentine Data Subject Repositories

554ARGPD-004

Illegal Direct Marketing without Opt-Out Verification under Argentine Law

555ARGPD-005

Lack of Adequate Third-Country Transfer Safeguards for Argentine Citizens

556COLPD-001

Missing Mandatory Registration of Databases in Colombia (RNBD)

557COLPD-002

Absence of Explicit Prior Consent for Colombian Residents

558COLPD-003

Lack of Compliant Grievance Handling Channels under Colombian Law

559COLPD-004

Failure to Audit Cross-Border Data Flow Protocols under Colombian Law

560COLPD-005

Unlawful Processing of Minors' Personal Data without Parental Representation in Colombia

561CHLPD-001

Failure to Honor Erasure or Correction Requests for Chilean Citizens

562CHLPD-002

Illegal Processing of Sensitive Personal Information without Written Authorization in Chile

563CHLPD-003

Lack of Proper Security Disclosures for Chilean Resident Data Repositories

564CHLPD-004

Non-Compliant Email Direct Marketing without Opt-Out under Chilean Law

565CHLPD-005

Inadequate Transfer Contracts for Processing Chilean Resident Personal Data

566PERPD-001

Failure to Register Personal Data Banks in Peru (RNDP)

567PERPD-002

Incomplete Disclosures of International Transfers of Peruvian Data

568PERPD-003

Missing Direct and Immediate ARCO Rights Procedures under Peruvian Law

569PERPD-004

Failure to Obtain Clear, Prior Consent for Tracking Cookies in Peru

570PERPD-005

Inadequate Legal Representation for Data Processing in Peru by Foreign Entities

571URYPD-001

Missing Registration of Data Processing Activity with URCDP (Uruguay)

572URYPD-002

Failure to Document and Notify Security Breaches in Uruguay within 24 Hours

573URYPD-003

Missing Uruguayan Local Representative Designation for Foreign Controllers

574URYPD-004

Non-Compliant Processing of Biometric or Sensitive Data in Uruguay

575URYPD-005

Lack of Explicit Portability Actions for Uruguay Residents

576ECUPD-001

Inadequate Consent Interfaces for Ecuadorian Residents (LOPDP)

577ECUPD-002

Lack of Localized Redress Pathways for Ecuadorian Protection Agency

578ECUPD-003

Failure to Execute Data Protection Impact Assessments (DPIA) in Ecuador

579ECUPD-004

Illegal Marketing Communications without Verified Consent in Ecuador

580ECUPD-005

Lack of Security and Integrity Measures for Ecuador Databases

581CRIAP-001

Failure to Register Databases with PRODHAB (Costa Rica)

582CRIAP-002

Incomplete Informational Self-Determination Disclosures in Costa Rica

583CRIAP-003

Lack of Verification Protocols for Costa Rican Sensitive Data Processing

584CRIAP-004

Unlawful Transfer of Costa Rican Data to Non-Adequate Third Countries

585CRIAP-005

Absence of Simplified Revocation Mechanisms for Costa Rican Users

586PANPD-001

Failure to Inform Panama Citizens of Controller Identity (Ley 81)

587PANPD-002

Lack of ARCO Rights Enforcement Pathways in Panama

588PANPD-003

Absence of Consent Legal Basis for Financial Profiling in Panama

589PANPD-004

Missing Security Breach Notification Protocols to ANTAI (Panama)

590PANPD-005

Unlawful Storage of Panamanian Personal Data in Non-Adequate Servers

591KENPD-001

Failure to Register as a Data Controller with Kenyan ODPC

592KENPD-002

Absence of Local Representative for Foreign Controllers in Kenya

593KENPD-003

Inadequate Consent Controls for Direct Marketing under Kenya Law

594KENPD-004

Lack of Data Protection Impact Assessment (DPIA) for Kenya Operations

595KENPD-005

Failure to Meet the 72-Hour Data Breach Reporting Window to Kenyan ODPC

596EGYPD-001

Failure to Obtain License for Electronic Marketing in Egypt

597EGYPD-002

Inadequate Privacy Notice Disclosures for Egyptian Citizens

598EGYPD-003

Lack of Mandated Data Protection Officer (DPO) in Egypt

599EGYPD-004

Failure to Report Personal Data Breaches within 72 Hours in Egypt

600EGYPD-005

Unlawful Cross-Border Transfer of Egyptian Citizens' Data

601MARPD-001

Failure to File Prior Declaration or Authorization with Moroccan CNDP

602MARPD-002

Lack of Clear Disclosures of Recipient Categories in Morocco

603MARPD-003

Absence of Explicit Consent for Direct Marketing in Morocco

604MARPD-004

Failure to Implement Technical Safeguards for Moroccan Data Integrity

605MARPD-005

Non-Compliant Cross-Border Transfers of Moroccan Personal Data

606QATPD-001

Inadequate Verification of Consent for Children's Data in Qatar

607QATPD-002

Failure to Document Processing Audits for Qatar Regulator

608QATPD-003

Incomplete Security Measures and Disclosures for Qatari Residents

609QATPD-004

Missing Direct Request Handling Channels for Qatari Subjects

610QATPD-005

Failure to Disclose Cross-Border Processing Locations to Qatari Subjects

611BHRPD-001

Lack of Written Consent for Sensitive Data in Bahrain

612BHRPD-002

Failure to Appoint a Local Representative in Bahrain

613BHRPD-003

Non-Compliant Direct Marketing Communications in Bahrain

614BHRPD-004

Failure to Record Processing Registrations with Bahrain Authority

615BHRPD-005

Inadequate Transfer Protocols for Exporting Bahraini Citizen Data

616OMNPD-001

Failure to Appoint a Data Protection Officer (DPO) in Oman

617OMNPD-002

Missing Explicit Consent for Sensitive Health or Biometrics in Oman

618OMNPD-003

Lack of Verified Dispute Resolution Procedures for Omani Subjects

619OMNPD-004

Absence of Adequate Cross-Border Transfer Guarantees for Omani Data

620OMNPD-005

Failure to Respond to Omani Consumer Requests within Legal Timeline

621HKGPD-001

Failure to Disclose Intended Direct Marketing to Hong Kong Residents

622HKGPD-002

Lack of Separated Consent for Third-Party Marketing in Hong Kong

623HKGPD-003

Non-Compliant Data Retention Disclosures for Hong Kong Customers

624HKGPD-004

Insecure Data Deletion and Destruction Protocols in Hong Kong

625HKGPD-005

Lack of Data Access and Correction Interfaces for Hong Kong Subjects

626TWNPD-001

Incomplete Informational Disclosures under Taiwan PDPA

627TWNPD-002

Unlawful Collection of Sensitive Personal Data without Written Consent in Taiwan

628TWNPD-003

Lack of Auditable Safety Maintenance Plan in Taiwan

629TWNPD-004

Missing Incident Notification Protocols to Taiwanese Citizens

630TWNPD-005

Inadequate Safeguards for Direct Marketing to Taiwan Residents

631PHLPD-001

Missing Registration of Data Processing Systems with Philippines NPC

632PHLPD-002

Failure to Designate a Data Protection Officer in the Philippines

633PHLPD-003

Inadequate Privacy Notice Disclosures for Philippine Residents

634PHLPD-004

Lack of Systemic Breach Notification System to NPC within 72 Hours

635PHLPD-005

Incomplete Consent Forms for Processing Sensitive Information in the Philippines

636IDNPD-001

Lack of Documented Legal Basis for Indonesian Operations

637IDNPD-002

Failure to Appoint a Local Data Protection Officer in Indonesia

638IDNPD-003

Missing Age and Parental Verification Controls for Children in Indonesia

639IDNPD-004

Lack of Explicit Incident Notification System in Indonesia within 72 Hours

640IDNPD-005

Non-Compliant Data Erasure Mechanisms for Indonesian Personal Data

641KAZPD-001

Failure to Register Databases containing Kazakhstan Resident Data

642KAZPD-002

Non-Compliant Cross-Border Transfers without Confirming Adequacy in Kazakhstan

643KAZPD-003

Incomplete Consent Gathering Systems for Kazakhstan Residents

644KAZPD-004

Failure to Localize Server Storage within the Republic of Kazakhstan

645KAZPD-005

Lack of Standard Redress and Deletion Protocols for Kazakhstan Citizens

646UKRPD-001

Missing Notification of Data Processing to Ukrainian Commissioner

647UKRPD-002

Inadequate Privacy Policy Disclosures regarding Third-Party Recipients in Ukraine

648UKRPD-003

Failure to Obtain Consent for Marketing and Cookie Tracking in Ukraine

649UKRPD-004

Lack of Security and Access Logs under Ukrainian Law

650UKRPD-005

Incomplete Redress and Erasure Access Procedures for Ukrainian Subjects

651CANPD-001

Lack of Explicit Opt-In Consent for Sensitive Data under PIPEDA

652CANPD-002

Missing Privacy Officer Contact Information under PIPEDA

653CANPD-003

Inadequate Access and Rectification Procedures under PIPEDA

654CANPD-004

Non-Compliant Breach Reporting Procedures under Canadian Law

655CANPD-005

Incomplete Third-Party Transfer Agreements for Canadian Data

656BOLPD-001

Failure to Honor Constitutional Right of Habeas Data in Bolivia

657BOLPD-002

Lack of User Redress Protocols for Personal Data in Bolivia

658BOLPD-003

Unlawful Processing of Communication Logs in Bolivia

659BOLPD-004

Incomplete Disclosures of Third-Party Recipients of Bolivian Data

660BOLPD-005

Insecure Storage of Bolivian Data Subject Registries

661PRYPD-001

Unlawful Financial Credit History Processing in Paraguay

662PRYPD-002

Absence of Direct Correction Pathways under Paraguay Law

663PRYPD-003

Lack of Organizational Safety Measures for Paraguay Records

664PRYPD-004

Illegal Direct Marketing over Electronic Channels in Paraguay

665PRYPD-005

Inadequate Contracts with Subprocessors of Paraguayan Data

666VENPD-001

Lack of Compliance with Habeas Data Principles in Venezuela

667VENPD-002

Failure to Document Safety Controls for Venezuelan Data Transmission

668VENPD-003

Missing Consent Disclosures for Venezuelan Subject Repositories

669VENPD-004

Lack of Easy Access Request Interfaces for Venezuelan Users

670VENPD-005

Non-Compliant Retention Policies for Venezuelan Customer Records

671GTMIP-001

Inadequate Informational Notice under Guatemala Law

672GTMIP-002

Failure to Honor Habeas Data Correction Rights in Guatemala

673GTMIP-003

Insecure Storage of Guatemalan Personal Data Registries

674GTMIP-004

Lack of Explicit Consent for Sharing Guatemalan Resident Data

675GTMIP-005

Absence of Free Marketing Consent Revocation Channels in Guatemala

676DOMPD-001

Processing Dominican Data without Prior Consent

677DOMPD-002

Incomplete Disclosures of Dominican Controller Identity

678DOMPD-003

Inadequate Habeas Data Request Procedures under Dominican Law

679DOMPD-004

Unlawful Cross-Border Transfers of Dominican Citizen Data

680DOMPD-005

Insecure Security Disclosures for Dominican Personal Data Banks

681SLVPD-001

Lack of Consent for Commercial Emails in El Salvador

682SLVPD-002

Inadequate Data Handling Disclosures in Salvadoran Privacy Notice

683SLVPD-003

Insecure Transaction Logging for Salvadoran Customers

684SLVPD-004

Insecure Database Records for Salvadoran Consumers

685SLVPD-005

Incomplete Deletion Options for Salvadoran User Databases

686HNDPD-001

Missing Collection Disclosures for Honduras Residents

687HNDPD-002

Lack of Block and Deletion Pathways in Honduras Databases

688HNDPD-003

Unlawful Third-Party Transfers without Consent in Honduras

689HNDPD-004

Insecure Storage of Honduran Personal Registries

690HNDPD-005

Absence of Free Marketing Opt-Out Channels for Honduras

691NICPD-001

Failure to Register Databases with Regulator in Nicaragua

692NICPD-002

Lack of Explicit Consent for Sensitive Data in Nicaragua

693NICPD-003

Inadequate Redress Pathways for ARCO Rights in Nicaragua

694NICPD-004

Non-Compliant Cross-Border Transfers of Nicaraguan Data

695NICPD-005

Failure to Report Database Security Breaches in Nicaragua

696GHAPD-001

Failure to Register as a Data Controller with Ghana DPC

697GHAPD-002

Processing Ghanaian Sensitive Personal Data without Authorization

698GHAPD-003

Inadequate Notice regarding Right to Object to Marketing in Ghana

699GHAPD-004

Non-Compliant International Transfers of Ghanaian Data

700GHAPD-005

Missing Security Breach Notification Systems under Ghana Law

701UGAPD-001

Failure to Register with Uganda Data Protection Office

702UGAPD-002

Collecting Ugandan Citizen Data without Prior Consent

703UGAPD-003

Inadequate Procedures to Handle Subject Rights in Uganda

704UGAPD-004

Illegal Direct Marketing without Opt-Out in Uganda

705UGAPD-005

Non-Compliant Storage of Ugandan Records in Non-Adequate Countries

706RWAPD-001

Processing Personal Data without Registration in Rwanda

707RWAPD-002

Lack of Explicit Consent for Sensitive Data in Rwanda

708RWAPD-003

Missing Local Data Protection Officer Contacts for Rwanda Operations

709RWAPD-004

Inadequate Data Breach Reporting Procedures to Rwanda Authority

710RWAPD-005

Unlawful Cross-Border Transfers of Rwandan Resident Records

711ZIMPD-001

Processing Zimbabwe Data without Registration

712ZIMPD-002

Lack of Consent for Automated Decision-Making in Zimbabwe

713ZIMPD-003

Inadequate Security Measures for Zimbabwean Databases

714ZIMPD-004

Missing Data Access Request Procedures for Zimbabwe Citizens

715ZIMPD-005

Non-Compliant Direct Marketing Communications to Zimbabwe Residents

716AOGPD-001

Processing Angolan Personal Data without Notification to APD

717AOGPD-002

Lack of Explicit Consent for Sensitive Data in Angola

718AOGPD-003

Incomplete Disclosures of Recipient Categories in Angola

719AOGPD-004

Inadequate Technical Security for Angolan Personal Databases

720AOGPD-005

Unlawful Cross-Border Transfers of Angolan Personal Data

721ALGPD-001

Failure to Register Data Processing Systems with Algerian ANPDP

722ALGPD-002

Lack of Explicit Prior Consent for Personal Data in Algeria

723ALGPD-003

Inadequate Procedures to Honor Access and Deletion in Algeria

724ALGPD-004

Non-Compliant International Transfers of Algerian Records

725ALGPD-005

Absence of Breach Notification Protocols to Algerian Authority

726JORPD-001

Processing Jordan Personal Data without Consent

727JORPD-002

Lack of Data Protection Officer (DPO) for Jordan Operations

728JORPD-003

Inadequate Disclosures of Data Retention in Jordan Privacy Notices

729JORPD-004

Non-Compliant Cross-Border Transfers of Jordanian Data

730JORPD-005

Incomplete Options to Execute Access and Rectification for Jordan Citizens

731KWTDP-001

Lack of Documented CITRA Compliance for Kuwait Operations

732KWTDP-002

Missing Explicit Consent for Marketing Communications in Kuwait

733KWTDP-003

Inadequate Security Safeguards for Kuwaiti Databases

734KWTDP-004

Absence of Incident Reporting Procedures to CITRA in Kuwait

735KWTDP-005

Failure to Provide Simplified Deletion for Kuwaiti Consumers

736UZBPD-001

Processing Uzbekistan Resident Data without Explicit Consent

737UZBPD-002

Failure to Localize Server Databases within Uzbekistan

738UZBPD-003

Inadequate Notices for Data Access and Correction in Uzbekistan

739UZBPD-004

Non-Compliant International Transfers of Uzbekistani Data

740UZBPD-005

Failure to Register Personal Databases with Uzbek State Register

741GEOPD-001

Failure to Notify State Inspector Service in Georgia

742GEOPD-002

Lack of Explicit Consent for Sensitive Data in Georgia

743GEOPD-003

Inadequate Disclosures of Processors and Vendors in Georgia

744GEOPD-004

Lack of Security Audits and Permission Levels under Georgian Law

745GEOPD-005

Non-Compliant Blocking and Deletion Procedures in Georgia

746ARMPD-001

Failure to Comply with Armenia Law on Personal Data Protection

747ARMPD-002

Absence of Consent for Automated Profiling in Armenia

748ARMPD-003

Incomplete Disclosures of International Transfer Locations for Armenia

749ARMPD-004

Lack of Security Plans for Armenian Personal Data Banks

750ARMPD-005

Inadequate Procedures for Access and Rectification in Armenia

751SWSPD-001

Lack of Explicit Consent for High-Risk Profiling under Swiss FADP

752SWSPD-002

Incomplete Privacy Notice Disclosures under Swiss FADP

753SWSPD-003

Missing Representative Contact Info for Foreign Controllers under FADP

754SWSPD-004

Non-Compliant Cross-Border Swiss Data Transfer

755SWSPD-005

Inadequate Subject Rights Access Channels under Swiss FADP

756SAUPD-001

Lack of Explicit Consent for Sensitive Data under Saudi PDPL

757SAUPD-002

Missing Bilingual Privacy Notice under Saudi PDPL Requirements

758SAUPD-003

Non-Compliant Direct Marketing Communications in Saudi Arabia

759SAUPD-004

Unauthorized Cross-Border Transfer of Saudi Personal Data

760SAUPD-005

Failure to Document Subject Redress Pathways under Saudi Law

761ISRPA-001

Unregistered Sensitive Database Processing in Israel

762ISRPA-002

Missing Disclosure of Collection Voluntariness under Israeli Law

763ISRPA-003

Inadequate Access Controls and Security Logs under Israeli Regulations

764ISRPA-004

Non-Compliant Direct Mail Marketing Registry in Israel

765ISRPA-005

Lack of Direct Access and Rectification Procedures in Israel

766LKAPD-001

Lack of Consent for Processing Sensitive Data in Sri Lanka

767LKAPD-002

Excessive Retention of Personal Data in Sri Lanka

768LKAPD-003

Failure to Designate or Disclose DPO Contact Info in Sri Lanka

769LKAPD-004

Failure to Provide Free Subject Access Rights in Sri Lanka

770LKAPD-005

Non-Compliant Cross-Border Transfer of Sri Lankan Data

771MUSPD-001

Lack of Lawful Processing Basis for Sensitive Data in Mauritius

772MUSPD-002

Incomplete Cross-Border Transfer Disclosures in Mauritius

773MUSPD-003

Lack of Direct Consent Withdrawal Methods in Mauritius

774MUSPD-004

Non-Compliant 72-Hour Breach Reporting in Mauritius

775MUSPD-005

Inadequate Erasure and Rectification Channels in Mauritius

776TZNPD-001

Processing Personal Data without Commission Registration in Tanzania

777TZNPD-002

Non-Compliant Direct Marketing Communications in Tanzania

778TZNPD-003

Inadequate Access and Rectification Procedures in Tanzania

779TZNPD-004

Non-Compliant Cross-Border Data Transfers from Tanzania

780TZNPD-005

Failure to Document Security Breach Notification Protocols in Tanzania

781BTPD-001

Processing Sensitive Personal Data without Consent in Botswana

782BTPD-002

Lack of Authorization for Non-Adequate Cross-Border Transfer from Botswana

783BTPD-003

Inadequate Safeguards for Sensitive Database Files in Botswana

784BTPD-004

Missing Subject Access and Restriction Methods in Botswana

785BTPD-005

Lack of Direct Consent Withdrawal Pathways in Botswana

786ZMBPD-001

Processing Sensitive Personal Data without Written Consent in Zambia

787ZMBPD-002

Processing Personal Data without Controller Registration in Zambia

788ZMBPD-003

Failure to Appoint or Disclose DPO under Zambian Law

789ZMBPD-004

Non-Compliant Data Retention Cycles in Zambia

790ZMBPD-005

Non-Compliant Cross-Border Transfer of Zambian Data

791JAMPD-001

Failure to Register with Information Commissioner in Jamaica

792JAMPD-002

Missing Data Protection Officer Contacts under Jamaican Law

793JAMPD-003

Lack of Subject Profiling Opt-Out under Jamaican Law

794JAMPD-004

Lack of Formal Data Processor Agreements under Jamaican Law

795JAMPD-005

Non-Compliant Cross-Border Transfers from Jamaica

796BRBPD-001

Unregistered Processing of Personal Data in Barbados

797BRBPD-002

Inadequate Security Safeguards for Barbadian Data

798BRBPD-003

Missing Disclosures in Privacy Notice under Barbados Law

799BRBPD-004

Lack of Direct Objection Mechanisms in Barbados

800BRBPD-005

Non-Compliant 72-Hour Breach Reporting in Barbados

801BHSPD-001

Unregistered Processing of Personal Data in Bahamas

802BHSPD-002

Inadequate Security Safeguards for Bahamian Data

803BHSPD-003

Lack of Rectification and Deletion Rights in Bahamas

804BHSPD-004

Non-Compliant Direct Marketing Opt-Out in Bahamas

805BHSPD-005

Excessive Data Retention Limits under Bahamas Law

806TTOPD-001

Unregistered Sensitive Database Processing in Trinidad & Tobago

807TTOPD-002

Inadequate Data Security Safeguards in Trinidad & Tobago

808TTOPD-003

Non-Compliant 30-Day Access Request Timelines in Trinidad & Tobago

809TTOPD-004

Non-Adequate Cross-Border Transfer from Trinidad & Tobago

810TTOPD-005

Secondary Purpose Processing without Consent in Trinidad & Tobago

811MCOPD-001

Failure to Notify CCIN of Processing in Monaco

812MCOPD-002

Missing Local Representative contacts for Foreign Controllers in Monaco

813MCOPD-003

Inadequate Cookie Consent and Opt-Out Options in Monaco

814MCOPD-004

Unauthorized Export of Personal Data from Monaco

815MCOPD-005

Inadequate Channels to Execute Rights of Opposition in Monaco

816ADPD-001

Lack of Lawful Processing Basis under Andorra Law 29/2021

817ADPD-002

Missing DPO Designation or Registration in Andorra

818ADPD-003

Inadequate Privacy Notice Disclosures under Andorra Law

819ADPD-004

Non-Compliant Cross-Border Transfers from Andorra

820ADPD-005

Inadequate Channels to Honor Erasure Rights in Andorra

821SRBPD-001

Lack of Explicit Consent for Sensitive Data in Serbia

822SRBPD-002

Missing Representative contacts in Serbia for Foreign Controllers

823SRBPD-003

Inadequate Disclosures in Privacy Notice under Serbian Law

824SRBPD-004

Non-Compliant 72-Hour Breach Reporting in Serbia

825SRBPD-005

Inadequate Subject Access Rights Response Methods in Serbia

826ALBPD-001

Processing Personal Data without Notification in Albania

827ALBPD-002

Unauthorized Cross-Border Transfer of Albanian Personal Data

828ALBPD-003

Non-Compliant Direct Marketing Communications in Albania

829ALBPD-004

Inadequate Database Safeguards under Albanian Law

830ALBPD-005

Inadequate Subject Access Rights Response Methods in Albania

831TUNPD-001

Processing Personal Data without INPDP Declaration in Tunisia

832TUNPD-002

Lack of Written Consent for Sensitive Data in Tunisia

833TUNPD-003

Inadequate Deletion and Correction Channels under Tunisian Law

834TUNPD-004

Non-Compliant Direct Marketing Communications in Tunisia

835TUNPD-005

Non-Compliant Cross-Border Data Transfer from Tunisia

836SENPD-001

Processing Personal Data without CDP Notification in Senegal

837SENPD-002

Inadequate Technical Database Safeguards in Senegal

838SENPD-003

Missing Third-Party Recipient Disclosures in Senegal Notice

839SENPD-004

Non-Compliant Direct Marketing Communications in Senegal

840SENPD-005

Inadequate Rectification and Deletion Rights in Senegal

841CIVPD-001

Failure to Register Database Processing with ARTCI in Ivory Coast

842CIVPD-002

Lack of Explicit Consent for Sensitive Data in Ivory Coast

843CIVPD-003

Inadequate Erasure and Rectification Channels in Ivory Coast

844CIVPD-004

Non-Compliant Cross-Border Transfers from Ivory Coast

845CIVPD-005

Non-Compliant Direct Marketing Communications in Ivory Coast

846MNGPD-001

Processing Personal Data without Legal Basis in Mongolia

847MNGPD-002

Missing Security Incident Notification Channels under Mongolian Law

848MNGPD-003

Lack of Data Subject Rectification and Erasure Rights in Mongolia

849MNGPD-004

Processing Biometric Data without Written Consent in Mongolia

850MNGPD-005

Non-Compliant Direct Marketing Communications in Mongolia

851NORPD-001

Processing Sensitive Personal Data without Explicit Consent in Norway

852NORPD-002

Incomplete Age Verification for Children’s Services in Norway

853NORPD-003

Inadequate Privacy notice Disclosures under Norwegian Regulations

854NORPD-004

Lack of 72-Hour Security Incident Notification Protocols in Norway

855NORPD-005

Inadequate Access and Erasure Response Pathways in Norway

856ISLPD-001

Processing Sensitive Data without Written Consent in Iceland

857ISLPD-002

Missing Age Verification for Children’s Consent in Iceland

858ISLPD-003

Incomplete Disclosures in Icelandic Privacy Notice

859ISLPD-004

Lack of Security incident Notification Protocols in Iceland

860ISLPD-005

Inadequate Subject Rights Response Methods in Iceland

861LIEPD-001

Processing Sensitive Personal Data without Explicit Consent in Liechtenstein

862LIEPD-002

Incomplete Age Verification for Children’s Consent in Liechtenstein

863LIEPD-003

Inadequate Privacy Notice Disclosures under Liechtenstein Law

864LIEPD-004

Lack of 72-Hour Security incident Notification Protocols in Liechtenstein

865LIEPD-005

Inadequate Subject Rights Access Channels in Liechtenstein

866MKDPD-001

Processing Sensitive Data without Written Consent in North Macedonia

867MKDPD-002

Missing DPO Designation or Registration in North Macedonia

868MKDPD-003

Inadequate Privacy Notice Disclosures under Macedonian Regulations

869MKDPD-004

Lack of 72-Hour Security incident Notification Protocols in North Macedonia

870MKDPD-005

Inadequate Subject Rights Access Channels in North Macedonia

871MNEPD-001

Lack of Consent for Sensitive Data Processing in Montenegro

872MNEPD-002

Inadequate Database Safeguards under Montenegrin Law

873MNEPD-003

Inadequate Privacy Notice Disclosures under Montenegrin Law

874MNEPD-004

Unauthorized Cross-Border Transfer of Montenegrin Data

875MNEPD-005

Inadequate Subject Rights Access Channels in Montenegro

876BIHPD-001

Lack of Explicit Consent for Sensitive Data in Bosnia & Herzegovina

877BIHPD-002

Inadequate Security Safeguards for Bosnian Database Files

878BIHPD-003

Inadequate Privacy notice Disclosures under Bosnian Regulations

879BIHPD-004

Unauthorized Cross-Border Transfer of Bosnian Personal Data

880BIHPD-005

Lack of Deletion and Rectification Rights Response Channels in Bosnia

881MDAPD-001

Failure to Register Processing Registry with CNPDCP in Moldova

882MDAPD-002

Lack of Explicit Consent for Sensitive Data in Moldova

883MDAPD-003

Inadequate Disclosures in Privacy notice under Moldovan Law

884MDAPD-004

Non-Compliant Cross-Border Transfers from Moldova

885MDAPD-005

Inadequate Subject Rights Access Channels in Moldova

886KGZPD-001

Processing Personal Data without Legal Basis in Kyrgyzstan

887KGZPD-002

Lack of Explicit Consent for Sensitive Data in Kyrgyzstan

888KGZPD-003

Inadequate Disclosures in Privacy Notice under Kyrgyz Law

889KGZPD-004

Non-Compliant Cross-Border Transfers from Kyrgyzstan

890KGZPD-005

Inadequate Subject Rights Response Methods in Kyrgyzstan

891TJKPD-001

Processing Personal Data without Legal Basis in Tajikistan

892TJKPD-002

Lack of Explicit Consent for Sensitive Data in Tajikistan

893TJKPD-003

Inadequate Disclosures in Privacy Notice under Tajik Law

894TJKPD-004

Non-Compliant Cross-Border Transfers from Tajikistan

895TJKPD-005

Inadequate Subject Rights Response Methods in Tajikistan

896TGOPD-001

Processing Personal Data without IPDCP Notification in Togo

897TGOPD-002

Lack of Explicit Consent for Sensitive Data in Togo

898TGOPD-003

Inadequate Deletion and Correction Channels under Togolese Law

899TGOPD-004

Non-Compliant Cross-Border Transfers from Togo

900TGOPD-005

Non-Compliant Direct Marketing Communications in Togo

901BENPD-001

Processing Personal Data without APDP Declaration in Benin

902BENPD-002

Lack of Explicit Consent for Sensitive Data in Benin

903BENPD-003

Inadequate Erasure and Rectification Channels in Benin

904BENPD-004

Non-Compliant Cross-Border Transfers from Benin

905BENPD-005

Non-Compliant Direct Marketing Communications in Benin

906MLIPD-001

Processing Personal Data without APDP Notification in Mali

907MLIPD-002

Lack of Explicit Consent for Sensitive Data in Mali

908MLIPD-003

Inadequate Deletion and Correction Channels under Malian Law

909MLIPD-004

Non-Compliant Cross-Border Transfers from Mali

910MLIPD-005

Non-Compliant Direct Marketing Communications in Mali

911NERPD-001

Processing Personal Data without HAPDP Notification in Niger

912NERPD-002

Lack of Explicit Consent for Sensitive Data in Niger

913NERPD-003

Inadequate Deletion and Correction Channels under Nigerien Law

914NERPD-004

Non-Compliant Cross-Border Transfers from Niger

915NERPD-005

Non-Compliant Direct Marketing Communications in Niger

916GABPD-001

Processing Personal Data without CNPDCP Notification in Gabon

917GABPD-002

Lack of Explicit Consent for Sensitive Data in Gabon

918GABPD-003

Inadequate Deletion and Correction Channels under Gabonese Law

919GABPD-004

Non-Compliant Cross-Border Transfers from Gabon

920GABPD-005

Non-Compliant Direct Marketing Communications in Gabon

921MDGPD-001

Processing Personal Data without CMIL Notification in Madagascar

922MDGPD-002

Lack of Explicit Consent for Sensitive Data in Madagascar

923MDGPD-003

Inadequate Deletion and Correction Channels under Malagasy Law

924MDGPD-004

Non-Compliant Cross-Border Transfers from Madagascar

925MDGPD-005

Non-Compliant Direct Marketing Communications in Madagascar

926CPVPD-001

Processing Personal Data without CNPD Notification in Cabo Verde

927CPVPD-002

Lack of Explicit Consent for Sensitive Data in Cabo Verde

928CPVPD-003

Inadequate Deletion and Correction Channels under Cape Verdean Law

929CPVPD-004

Non-Compliant Cross-Border Transfers from Cabo Verde

930CPVPD-005

Non-Compliant Direct Marketing Communications in Cabo Verde

931LSTPD-001

Processing Sensitive Personal Data without Consent in Lesotho

932LSTPD-002

Inadequate Technical Database Safeguards in Lesotho

933LSTPD-003

Missing Third-Party Recipient Disclosures in Lesotho Notice

934LSTPD-004

Non-Compliant Direct Marketing Communications in Lesotho

935LSTPD-005

Inadequate Rectification and Deletion Rights in Lesotho

936COGPD-001

Processing Personal Data without CNIL Notification in Congo

937COGPD-002

Lack of Explicit Consent for Sensitive Data in Congo

938COGPD-003

Inadequate Deletion and Correction Channels under Congolese Law

939COGPD-004

Non-Compliant Cross-Border Transfers from Congo

940COGPD-005

Non-Compliant Direct Marketing Communications in Congo

941FIPD-001

Processing Personal Data without Legal Basis in Fiji

942FIPD-002

Lack of Explicit Consent for Sensitive Data in Fiji

943FIPD-003

Inadequate Disclosures in Privacy Notice under Fiji Law

944FIPD-004

Non-Compliant Cross-Border Transfers from Fiji

945FIPD-005

Inadequate Subject Rights Response Methods in Fiji

946PNGPD-001

Processing Personal Data without Legal Basis in Papua New Guinea

947PNGPD-002

Lack of Explicit Consent for Sensitive Data in Papua New Guinea

948PNGPD-003

Inadequate Disclosures in Privacy Notice under PNG Law

949PNGPD-004

Non-Compliant Cross-Border Transfers from Papua New Guinea

950PNGPD-005

Inadequate Subject Rights Response Methods in Papua New Guinea

951SMRPD-001

Lack of Explicit Consent for Sensitive Data Processing in San Marino

952SMRPD-002

Missing DPO Designation or Registration in San Marino

953SMRPD-003

Inadequate Disclosures in Sammarinese Privacy Notice

954SMRPD-004

Non-Compliant Cross-Border Transfers from San Marino

955SMRPD-005

Inadequate Subject Rights Access Channels in San Marino

956GIBPD-001

Processing Sensitive Personal Data without Explicit Consent in Gibraltar

957GIBPD-002

Missing Age Verification for Children’s Consent in Gibraltar

958GIBPD-003

Incomplete Disclosures in Gibraltar Privacy Notice

959GIBPD-004

Lack of 72-Hour Security incident Notification Protocols in Gibraltar

960GIBPD-005

Inadequate Subject Rights Access Channels in Gibraltar

961JSYPD-001

Processing Sensitive Personal Data without Explicit Consent in Jersey

962JSYPD-002

Incomplete Age Verification for Children’s Consent in Jersey

963JSYPD-003

Inadequate Privacy Notice Disclosures under Jersey Law

964JSYPD-004

Lack of 72-Hour Security incident Notification Protocols in Jersey

965JSYPD-005

Inadequate Subject Rights Access Channels in Jersey

966GGYPD-001

Processing Sensitive Personal Data without Explicit Consent in Guernsey

967GGYPD-002

Incomplete Age Verification for Children’s Consent in Guernsey

968GGYPD-003

Inadequate Privacy Notice Disclosures under Guernsey Law

969GGYPD-004

Lack of 72-Hour Security incident Notification Protocols in Guernsey

970GGYPD-005

Inadequate Subject Rights Access Channels in Guernsey

971IOMPD-001

Lack of Explicit Consent for Sensitive Data Processing in Isle of Man

972IOMPD-002

Incomplete Age Verification for Children’s Consent in Isle of Man

973IOMPD-003

Inadequate Privacy Notice Disclosures under Manx Law

974IOMPD-004

Lack of 72-Hour Security incident Notification Protocols in Isle of Man

975IOMPD-005

Inadequate Subject Rights Access Channels in Isle of Man

976FROPD-001

Lack of Explicit Consent for Sensitive Data Processing in Faroe Islands

977FROPD-002

Inadequate Database Security Safeguards in Faroe Islands

978FROPD-003

Inadequate Privacy Notice Disclosures under Faroese Law

979FROPD-004

Unauthorized Cross-Border Transfer of Faroese Data

980FROPD-005

Inadequate Subject Rights Access Channels in Faroe Islands

981BMUPD-001

Lack of Explicit Consent for Sensitive Data under Bermuda PIPA

982BMUPD-002

Missing Privacy Officer Contact Info under Bermuda PIPA

983BMUPD-003

Lack of Subject Profiling Opt-Out under Bermuda PIPA

984BMUPD-004

Lack of Formal Data Processor Agreements under Bermuda Law

985BMUPD-005

Non-Compliant Cross-Border Transfers from Bermuda

986CYMPD-001

Lack of Explicit Consent for Sensitive Data under Cayman DPA

987CYMPD-002

Inadequate Data Security Safeguards in Cayman Islands

988CYMPD-003

Non-Compliant 30-Day Access Request Timelines in Cayman Islands

989CYMPD-004

Non-Adequate Cross-Border Transfer from Cayman Islands

990CYMPD-005

Excessive Data Retention Limits under Cayman Law

991LCAPD-001

Processing Sensitive Personal Data without Written Consent in Saint Lucia

992LCAPD-002

Processing Personal Data without Controller Registration in Saint Lucia

993LCAPD-003

Inadequate Technical Database Safeguards in Saint Lucia

994LCAPD-004

Non-Compliant Data Retention Cycles in Saint Lucia

995LCAPD-005

Non-Compliant Cross-Border Transfer of Saint Lucian Data

996KNAPD-001

Processing Sensitive Personal Data without Consent in St. Kitts & Nevis

997KNAPD-002

Processing Personal Data without Controller Registration in St. Kitts & Nevis

998KNAPD-003

Inadequate Technical Database Safeguards in St. Kitts & Nevis

999KNAPD-004

Non-Compliant Data Retention Cycles in St. Kitts & Nevis

1000KNAPD-005

Non-Compliant Cross-Border Transfer of St. Kitts & Nevis Data

1001ATGPD-001

Processing Sensitive Personal Data without Consent in Antigua & Barbuda

1002ATGPD-002

Processing Personal Data without Controller Registration in Antigua & Barbuda

1003ATGPD-003

Inadequate Technical Database Safeguards in Antigua & Barbuda

1004ATGPD-004

Non-Compliant Data Retention Cycles in Antigua & Barbuda

1005ATGPD-005

Non-Compliant Cross-Border Transfer of Antigua & Barbuda Data

1006SYCPD-001

Processing Sensitive Data without Written Consent in Seychelles

1007SYCPD-002

Inadequate Database Security Safeguards in Seychelles

1008SYCPD-003

Inadequate Privacy Notice Disclosures under Seychelles Law

1009SYCPD-004

Unauthorized Cross-Border Transfer of Seychelles Data

1010SYCPD-005

Inadequate Subject Rights Access Channels in Seychelles

1011SWZPD-001

Processing Sensitive Personal Data without Consent in Eswatini

1012SWZPD-002

Inadequate Technical Database Safeguards in Eswatini

1013SWZPD-003

Missing Third-Party Recipient Disclosures in Eswatini Notice

1014SWZPD-004

Non-Compliant Direct Marketing Communications in Eswatini

1015SWZPD-005

Inadequate Rectification and Deletion Rights in Eswatini

1016GINPD-001

Processing Personal Data without APDP Notification in Guinea

1017GINPD-002

Lack of Explicit Consent for Sensitive Data in Guinea

1018GINPD-003

Inadequate Deletion and Correction Channels under Guinean Law

1019GINPD-004

Non-Compliant Cross-Border Transfers from Guinea

1020GINPD-005

Non-Compliant Direct Marketing Communications in Guinea

1021BFAPD-001

Processing Personal Data without CIL Notification in Burkina Faso

1022BFAPD-002

Lack of Explicit Consent for Sensitive Data in Burkina Faso

1023BFAPD-003

Inadequate Deletion and Correction Channels under Burkinabe Law

1024BFAPD-004

Non-Compliant Cross-Border Transfers from Burkina Faso

1025BFAPD-005

Non-Compliant Direct Marketing Communications in Burkina Faso

1026MRTPD-001

Processing Personal Data without APDP Notification in Mauritania

1027MRTPD-002

Lack of Explicit Consent for Sensitive Data in Mauritania

1028MRTPD-003

Inadequate Deletion and Correction Channels under Mauritanian Law

1029MRTPD-004

Non-Compliant Cross-Border Transfers from Mauritania

1030MRTPD-005

Non-Compliant Direct Marketing Communications in Mauritania

1031TCDPD-001

Processing Personal Data without ANAD Notification in Chad

1032TCDPD-002

Lack of Explicit Consent for Sensitive Data in Chad

1033TCDPD-003

Inadequate Deletion and Correction Channels under Chadian Law

1034TCDPD-004

Non-Compliant Cross-Border Transfers from Chad

1035TCDPD-005

Non-Compliant Direct Marketing Communications in Chad

1036MACPD-001

Lack of Explicit Consent for Sensitive Data under Macau Law

1037MACPD-002

Failure to Register Database Processing with GPDP in Macau

1038MACPD-003

Inadequate Deletion and Correction Channels under Macau Law

1039MACPD-004

Non-Compliant Cross-Border Transfers from Macau

1040MACPD-005

Non-Compliant Direct Marketing Communications in Macau

1041NPLPD-001

Processing Personal Data without Legal Basis in Nepal

1042NPLPD-002

Lack of Explicit Consent for Sensitive Data in Nepal

1043NPLPD-003

Inadequate Disclosures in Privacy Notice under Nepal Law

1044NPLPD-004

Non-Compliant Cross-Border Transfers from Nepal

1045NPLPD-005

Inadequate Subject Rights Response Methods in Nepal

1046PAKPD-001

Processing Personal Data without Legal Basis in Pakistan

1047PAKPD-002

Lack of Explicit Consent for Sensitive Data in Pakistan

1048PAKPD-003

Inadequate Disclosures in Privacy Notice under Pakistan Law

1049PAKPD-004

Non-Compliant Cross-Border Transfers from Pakistan

1050PAKPD-005

Inadequate Subject Rights Response Methods in Pakistan

1051DJIPD-001

Processing Personal Data without CNDP Notification in Djibouti

1052DJIPD-002

Lack of Explicit Consent for Sensitive Data in Djibouti

1053DJIPD-003

Inadequate Deletion and Correction Channels under Djiboutian Law

1054DJIPD-004

Non-Compliant Cross-Border Transfers from Djibouti

1055DJIPD-005

Non-Compliant Direct Marketing Communications in Djibouti

1056LAOPD-001

Processing Personal Data without Legal Basis in Laos

1057LAOPD-002

Lack of Explicit Consent for Sensitive Data in Laos

1058LAOPD-003

Inadequate Disclosures in Privacy Notice under Laos Law

1059LAOPD-004

Non-Compliant Cross-Border Transfers from Laos

1060LAOPD-005

Inadequate Subject Rights Response Methods in Laos

1061BTNDP-001

Processing Personal Data without Legal Basis in Bhutan

1062BTNDP-002

Lack of Explicit Consent for Sensitive Data in Bhutan

1063BTNDP-003

Inadequate Disclosures in Privacy Notice under Bhutan Law

1064BTNDP-004

Non-Compliant Cross-Border Transfers from Bhutan

1065BTNDP-005

Inadequate Subject Rights Response Methods in Bhutan

1066MMRPD-001

Processing Personal Data without Legal Basis in Myanmar

1067MMRPD-002

Lack of Explicit Consent for Sensitive Data in Myanmar

1068MMRPD-003

Inadequate Disclosures in Privacy Notice under Myanmar Law

1069MMRPD-004

Non-Compliant Cross-Border Transfers from Myanmar

1070MMRPD-005

Inadequate Subject Rights Response Methods in Myanmar

1071KHMPD-001

Processing Personal Data without Legal Basis in Cambodia

1072KHMPD-002

Lack of Explicit Consent for Sensitive Data in Cambodia

1073KHMPD-003

Inadequate Disclosures in Privacy Notice under Cambodia Law

1074KHMPD-004

Non-Compliant Cross-Border Transfers from Cambodia

1075KHMPD-005

Inadequate Subject Rights Response Methods in Cambodia

1076LBNPD-001

Processing Personal Data without Notification in Lebanon

1077LBNPD-002

Lack of Explicit Consent for Sensitive Data in Lebanon

1078LBNPD-003

Inadequate Deletion and Correction Channels under Lebanese Law

1079LBNPD-004

Non-Compliant Cross-Border Transfers from Lebanon

1080LBNPD-005

Non-Compliant Direct Marketing Communications in Lebanon

1081YEMPD-001

Processing Personal Data without Legal Basis in Yemen

1082YEMPD-002

Lack of Explicit Consent for Sensitive Data in Yemen

1083YEMPD-003

Inadequate Disclosures in Privacy Notice under Yemen Law

1084YEMPD-004

Non-Compliant Cross-Border Transfers from Yemen

1085YEMPD-005

Inadequate Subject Rights Response Methods in Yemen

1086SYRPD-001

Processing Personal Data without Legal Basis in Syria

1087SYRPD-002

Lack of Explicit Consent for Sensitive Data in Syria

1088SYRPD-003

Inadequate Disclosures in Privacy Notice under Syrian Law

1089SYRPD-004

Non-Compliant Cross-Border Transfers from Syria

1090SYRPD-005

Inadequate Subject Rights Response Methods in Syria

1091IRQPD-001

Processing Personal Data without Legal Basis in Iraq

1092IRQPD-002

Lack of Explicit Consent for Sensitive Data in Iraq

1093IRQPD-003

Inadequate Disclosures in Privacy Notice under Iraq Law

1094IRQPD-004

Non-Compliant Cross-Border Transfers from Iraq

1095IRQPD-005

Inadequate Subject Rights Response Methods in Iraq

1096MWIPD-001

Processing Personal Data without Legal Basis in Malawi

1097MWIPD-002

Lack of Explicit Consent for Sensitive Data in Malawi

1098MWIPD-003

Inadequate Disclosures in Privacy Notice under Malawi Law

1099MWIPD-004

Non-Compliant Cross-Border Transfers from Malawi

1100MWIPD-005

Inadequate Subject Rights Response Methods in Malawi

1101MOZPD-001

Processing Personal Data without Legal Basis in Mozambique

1102MOZPD-002

Lack of Explicit Consent for Sensitive Data in Mozambique

1103MOZPD-003

Inadequate Disclosures in Privacy Notice under Mozambique Law

1104MOZPD-004

Non-Compliant Cross-Border Transfers from Mozambique

1105MOZPD-005

Inadequate Subject Rights Response Methods in Mozambique

1106NAMPD-001

Processing Personal Data without Legal Basis in Namibia

1107NAMPD-002

Lack of Explicit Consent for Sensitive Data in Namibia

1108NAMPD-003

Inadequate Disclosures in Privacy Notice under Namibia Law

1109NAMPD-004

Non-Compliant Cross-Border Transfers from Namibia

1110NAMPD-005

Inadequate Subject Rights Response Methods in Namibia

1111GRNPD-001

Processing Sensitive Personal Data without Written Consent in Grenada

1112GRNPD-002

Processing Personal Data without Controller Registration in Grenada

1113GRNPD-003

Inadequate Technical Database Safeguards in Grenada

1114GRNPD-004

Non-Compliant Data Retention Cycles in Grenada

1115GRNPD-005

Non-Compliant Cross-Border Transfer of Grenadian Data

1116VCTPD-001

Processing Sensitive Data without Consent in St. Vincent & Grenadines

1117VCTPD-002

Processing Personal Data without Controller Registration in St. Vincent & Grenadines

1118VCTPD-003

Inadequate Technical Database Safeguards in St. Vincent & Grenadines

1119VCTPD-004

Non-Compliant Data Retention Cycles in St. Vincent & Grenadines

1120VCTPD-005

Non-Compliant Cross-Border Transfer of St. Vincent & Grenadines Data

1121SAMPD-001

Processing Personal Data without Legal Basis in Samoa

1122SAMPD-002

Lack of Explicit Consent for Sensitive Data in Samoa

1123SAMPD-003

Inadequate Disclosures in Privacy Notice under Samoan Law

1124SAMPD-004

Non-Compliant Cross-Border Transfers from Samoa

1125SAMPD-005

Inadequate Subject Rights Response Methods in Samoa

1126TONPD-001

Processing Personal Data without Legal Basis in Tonga

1127TONPD-002

Lack of Explicit Consent for Sensitive Data in Tonga

1128TONPD-003

Inadequate Disclosures in Privacy Notice under Tonga Law

1129TONPD-004

Non-Compliant Cross-Border Transfers from Tonga

1130TONPD-005

Inadequate Subject Rights Response Methods in Tonga

1131VUTPD-001

Processing Personal Data without Legal Basis in Vanuatu

1132VUTPD-002

Lack of Explicit Consent for Sensitive Data in Vanuatu

1133VUTPD-003

Inadequate Disclosures in Privacy Notice under Vanuatu Law

1134VUTPD-004

Non-Compliant Cross-Border Transfers from Vanuatu

1135VUTPD-005

Inadequate Subject Rights Response Methods in Vanuatu

1136GUYPD-001

Processing Sensitive Personal Data without Consent in Guyana

1137GUYPD-002

Processing Personal Data without Controller Registration in Guyana

1138GUYPD-003

Inadequate Technical Database Safeguards in Guyana

1139GUYPD-004

Non-Compliant Data Retention Cycles in Guyana

1140GUYPD-005

Non-Compliant Cross-Border Transfer of Guyanese Data

1141BLZPD-001

Processing Sensitive Data without Written Consent in Belize

1142BLZPD-002

Processing Personal Data without Controller Registration in Belize

1143BLZPD-003

Inadequate Technical Database Safeguards in Belize

1144BLZPD-004

Non-Compliant Data Retention Cycles in Belize

1145BLZPD-005

Non-Compliant Cross-Border Transfer of Belizean Data

1146SURPD-001

Processing Sensitive Data without Written Consent in Suriname

1147SURPD-002

Processing Personal Data without Controller Registration in Suriname

1148SURPD-003

Inadequate Technical Database Safeguards in Suriname

1149SURPD-004

Non-Compliant Data Retention Cycles in Suriname

1150SURPD-005

Non-Compliant Cross-Border Transfer of Surinamese Data

1151BDIPD-001

Processing Personal Data without Authority Notification in Burundi

1152BDIPD-002

Lack of Explicit Consent for Sensitive Data in Burundi

1153BDIPD-003

Inadequate Deletion and Correction Channels under Burundian Law

1154BDIPD-004

Non-Compliant Cross-Border Transfers from Burundi

1155BDIPD-005

Non-Compliant Direct Marketing Communications in Burundi

1156ERIPD-001

Processing Personal Data without Legal Basis in Eritrea

1157ERIPD-002

Lack of Explicit Consent for Sensitive Data in Eritrea

1158ERIPD-003

Inadequate Disclosures in Privacy Notice under Eritrean Law

1159ERIPD-004

Non-Compliant Cross-Border Transfers from Eritrea

1160ERIPD-005

Inadequate Subject Rights Response Methods in Eritrea

1161SOMPD-001

Processing Personal Data without Legal Basis in Somalia

1162SOMPD-002

Lack of Explicit Consent for Sensitive Data in Somalia

1163SOMPD-003

Inadequate Disclosures in Privacy Notice under Somali Law

1164SOMPD-004

Non-Compliant Cross-Border Transfers from Somalia

1165SOMPD-005

Inadequate Subject Rights Response Methods in Somalia

1166SDNPD-001

Processing Personal Data without Legal Basis in Sudan

1167SDNPD-002

Lack of Explicit Consent for Sensitive Data in Sudan

1168SDNPD-003

Inadequate Disclosures in Privacy Notice under Sudan Law

1169SDNPD-004

Non-Compliant Cross-Border Transfers from Sudan

1170SDNPD-005

Inadequate Subject Rights Response Methods in Sudan

1171SSDPD-001

Processing Personal Data without Legal Basis in South Sudan

1172SSDPD-002

Lack of Explicit Consent for Sensitive Data in South Sudan

1173SSDPD-003

Inadequate Disclosures in Privacy Notice under South Sudan Law

1174SSDPD-004

Non-Compliant Cross-Border Transfers from South Sudan

1175SSDPD-005

Inadequate Subject Rights Response Methods in South Sudan

1176GNQPD-001

Processing Personal Data without Authority Notification in Equatorial Guinea

1177GNQPD-002

Lack of Explicit Consent for Sensitive Data in Equatorial Guinea

1178GNQPD-003

Inadequate Disclosures in Privacy Notice under Equatorial Guinean Law

1179GNQPD-004

Non-Compliant Cross-Border Transfers from Equatorial Guinea

1180GNQPD-005

Inadequate Rights Response Channels for Equatorial Guinean Subjects

1181CAFPD-001

Processing Personal Data without Legal Basis in CAR

1182CAFPD-002

Lack of Explicit Consent for Sensitive Data in CAR

1183CAFPD-003

Inadequate Disclosures in Privacy Notice under CAR Law

1184CAFPD-004

Non-Compliant Cross-Border Transfers from CAR

1185CAFPD-005

Lack of Rectification and Erasure Channels in CAR

1186SLEPD-001

Processing Personal Data without Legal Basis in Sierra Leone

1187SLEPD-002

Lack of Explicit Consent for Sensitive Data in Sierra Leone

1188SLEPD-003

Inadequate Disclosures in Privacy Notice under Sierra Leone Law

1189SLEPD-004

Non-Compliant Cross-Border Transfers from Sierra Leone

1190SLEPD-005

Lack of Subject Rights Response Methods in Sierra Leone

1191LBRPD-001

Processing Personal Data without Legal Basis in Liberia

1192LBRPD-002

Lack of Explicit Consent for Sensitive Data in Liberia

1193LBRPD-003

Inadequate Disclosures in Privacy Notice under Liberian Law

1194LBRPD-004

Non-Compliant Cross-Border Transfers from Liberia

1195LBRPD-005

Inadequate Subject Rights Response Methods in Liberia

1196GMBPD-001

Processing Personal Data without Legal Basis in Gambia

1197GMBPD-002

Lack of Explicit Consent for Sensitive Data in Gambia

1198GMBPD-003

Inadequate Disclosures in Privacy Notice under Gambian Law

1199GMBPD-004

Non-Compliant Cross-Border Transfers from Gambia

1200GMBPD-005

Inadequate Subject Rights Response Methods in Gambia

1201GWIPD-001

Processing Personal Data without Legal Basis in Guinea-Bissau

1202GWIPD-002

Lack of Explicit Consent for Sensitive Data in Guinea-Bissau

1203GWIPD-003

Inadequate Disclosures in Privacy Notice under Guinea-Bissau Law

1204GWIPD-004

Non-Compliant Cross-Border Transfers from Guinea-Bissau

1205GWIPD-005

Inadequate Subject Rights Response Methods in Guinea-Bissau

1206LSOPD-001

Processing Personal Data without Legal Basis in Lesotho

1207LSOPD-002

Lack of Explicit Consent for Sensitive Data in Lesotho

1208LSOPD-003

Inadequate Disclosures in Privacy Notice under Lesotho Law

1209LSOPD-004

Non-Compliant Cross-Border Transfers from Lesotho

1210LSOPD-005

Inadequate Subject Rights Response Methods in Lesotho

1211TLSPD-001

Processing Personal Data without Legal Basis in Timor-Leste

1212TLSPD-002

Lack of Explicit Consent for Sensitive Data in Timor-Leste

1213TLSPD-003

Inadequate Disclosures in Privacy Notice under Timor-Leste Law

1214TLSPD-004

Non-Compliant Cross-Border Transfers from Timor-Leste

1215TLSPD-005

Inadequate Subject Rights Response Methods in Timor-Leste

1216MDVPD-001

Processing Personal Data without Legal Basis in Maldives

1217MDVPD-002

Lack of Explicit Consent for Sensitive Data in Maldives

1218MDVPD-003

Inadequate Disclosures in Privacy Notice under Maldivian Law

1219MDVPD-004

Non-Compliant Cross-Border Transfers from Maldives

1220MDVPD-005

Inadequate Subject Rights Response Methods in Maldives

1221BRNPD-001

Processing Personal Data without Legal Basis in Brunei

1222BRNPD-002

Lack of Explicit Consent for Sensitive Data in Brunei

1223BRNPD-003

Inadequate Disclosures in Privacy Notice under Brunei Law

1224BRNPD-004

Non-Compliant Cross-Border Transfers from Brunei

1225BRNPD-005

Inadequate Subject Rights Response Methods in Brunei

1226SLBPD-001

Processing Personal Data without Legal Basis in Solomon Islands

1227SLBPD-002

Lack of Explicit Consent for Sensitive Data in Solomon Islands

1228SLBPD-003

Inadequate Disclosures in Privacy Notice under Solomon Islands Law

1229SLBPD-004

Non-Compliant Cross-Border Transfers from Solomon Islands

1230SLBPD-005

Inadequate Subject Rights Response Methods in Solomon Islands

1231FSMPD-001

Processing Personal Data without Legal Basis in Micronesia

1232FSMPD-002

Lack of Explicit Consent for Sensitive Data in Micronesia

1233FSMPD-003

Inadequate Disclosures in Privacy Notice under Micronesia Law

1234FSMPD-004

Non-Compliant Cross-Border Transfers from Micronesia

1235FSMPD-005

Inadequate Subject Rights Response Methods in Micronesia

1236MHLPD-001

Processing Personal Data without Legal Basis in Marshall Islands

1237MHLPD-002

Lack of Explicit Consent for Sensitive Data in Marshall Islands

1238MHLPD-003

Inadequate Disclosures in Privacy Notice under Marshall Islands Law

1239MHLPD-004

Non-Compliant Cross-Border Transfers from Marshall Islands

1240MHLPD-005

Inadequate Subject Rights Response Methods in Marshall Islands

1241PLWPD-001

Processing Personal Data without Legal Basis in Palau

1242PLWPD-002

Lack of Explicit Consent for Sensitive Data in Palau

1243PLWPD-003

Inadequate Disclosures in Privacy Notice under Palau Law

1244PLWPD-004

Non-Compliant Cross-Border Transfers from Palau

1245PLWPD-005

Inadequate Subject Rights Response Methods in Palau

1246KIRPD-001

Processing Personal Data without Legal Basis in Kiribati

1247KIRPD-002

Lack of Explicit Consent for Sensitive Data in Kiribati

1248KIRPD-003

Inadequate Disclosures in Privacy Notice under Kiribati Law

1249KIRPD-004

Non-Compliant Cross-Border Transfers from Kiribati

1250KIRPD-005

Inadequate Subject Rights Response Methods in Kiribati

1251CHNPD-001

Processing Sensitive Data without Written Consent in China

1252CHNPD-002

Processing Personal Data without Authority Notification in China

1253CHNPD-003

Inadequate Technical Database Safeguards in China

1254CHNPD-004

Non-Compliant Data Retention Cycles in China

1255CHNPD-005

Non-Compliant Cross-Border Transfer of Chinese Data

1256RUSPD-001

Processing Sensitive Data without Written Consent in Russia

1257RUSPD-002

Processing Personal Data without Authority Notification in Russia

1258RUSPD-003

Inadequate Technical Database Safeguards in Russia

1259RUSPD-004

Non-Compliant Data Retention Cycles in Russia

1260RUSPD-005

Non-Compliant Cross-Border Transfer of Russian Data

1261TURPD-001

Processing Sensitive Data without Written Consent in Turkey

1262TURPD-002

Processing Personal Data without Authority Notification in Turkey

1263TURPD-003

Inadequate Technical Database Safeguards in Turkey

1264TURPD-004

Non-Compliant Data Retention Cycles in Turkey

1265TURPD-005

Non-Compliant Cross-Border Transfer of Turkish Data

1266NGAPD-001

Processing Sensitive Data without Written Consent in Nigeria

1267NGAPD-002

Processing Personal Data without Authority Notification in Nigeria

1268NGAPD-003

Inadequate Technical Database Safeguards in Nigeria

1269NGAPD-004

Non-Compliant Data Retention Cycles in Nigeria

1270NGAPD-005

Non-Compliant Cross-Border Transfer of Nigerian Data

1271AFGPD-001

Processing Sensitive Data without Written Consent in Afghanistan

1272AFGPD-002

Processing Personal Data without Authority Notification in Afghanistan

1273AFGPD-003

Inadequate Technical Database Safeguards in Afghanistan

1274AFGPD-004

Non-Compliant Data Retention Cycles in Afghanistan

1275AFGPD-005

Non-Compliant Cross-Border Transfer of Afghan Data

1276AZEPD-001

Processing Sensitive Data without Written Consent in Azerbaijan

1277AZEPD-002

Processing Personal Data without Authority Notification in Azerbaijan

1278AZEPD-003

Inadequate Technical Database Safeguards in Azerbaijan

1279AZEPD-004

Non-Compliant Data Retention Cycles in Azerbaijan

1280AZEPD-005

Non-Compliant Cross-Border Transfer of Azerbaijani Data

1281BGDPD-001

Processing Sensitive Data without Written Consent in Bangladesh

1282BGDPD-002

Processing Personal Data without Authority Notification in Bangladesh

1283BGDPD-003

Inadequate Technical Database Safeguards in Bangladesh

1284BGDPD-004

Non-Compliant Data Retention Cycles in Bangladesh

1285BGDPD-005

Non-Compliant Cross-Border Transfer of Bangladeshi Data

1286BLRPD-001

Processing Sensitive Data without Written Consent in Belarus

1287BLRPD-002

Processing Personal Data without Authority Notification in Belarus

1288BLRPD-003

Inadequate Technical Database Safeguards in Belarus

1289BLRPD-004

Non-Compliant Data Retention Cycles in Belarus

1290BLRPD-005

Non-Compliant Cross-Border Transfer of Belarusian Data

1291CMRPD-001

Processing Sensitive Data without Written Consent in Cameroon

1292CMRPD-002

Processing Personal Data without Authority Notification in Cameroon

1293CMRPD-003

Inadequate Technical Database Safeguards in Cameroon

1294CMRPD-004

Non-Compliant Data Retention Cycles in Cameroon

1295CMRPD-005

Non-Compliant Cross-Border Transfer of Cameroonian Data

1296COMPD-001

Processing Sensitive Data without Written Consent in Comoros

1297COMPD-002

Processing Personal Data without Authority Notification in Comoros

1298COMPD-003

Inadequate Technical Database Safeguards in Comoros

1299COMPD-004

Non-Compliant Data Retention Cycles in Comoros

1300COMPD-005

Non-Compliant Cross-Border Transfer of Comorian Data

1301CUBPD-001

Processing Sensitive Data without Written Consent in Cuba

1302CUBPD-002

Processing Personal Data without Authority Notification in Cuba

1303CUBPD-003

Inadequate Technical Database Safeguards in Cuba

1304CUBPD-004

Non-Compliant Data Retention Cycles in Cuba

1305CUBPD-005

Non-Compliant Cross-Border Transfer of Cuban Data

1306CODPD-001

Processing Sensitive Data without Written Consent in DR Congo

1307CODPD-002

Processing Personal Data without Authority Notification in DR Congo

1308CODPD-003

Inadequate Technical Database Safeguards in DR Congo

1309CODPD-004

Non-Compliant Data Retention Cycles in DR Congo

1310CODPD-005

Non-Compliant Cross-Border Transfer of Congolese Data

1311ETHPD-001

Processing Sensitive Data without Written Consent in Ethiopia

1312ETHPD-002

Processing Personal Data without Authority Notification in Ethiopia

1313ETHPD-003

Inadequate Technical Database Safeguards in Ethiopia

1314ETHPD-004

Non-Compliant Data Retention Cycles in Ethiopia

1315ETHPD-005

Non-Compliant Cross-Border Transfer of Ethiopian Data

1316HTIPD-001

Processing Sensitive Data without Written Consent in Haiti

1317HTIPD-002

Processing Personal Data without Authority Notification in Haiti

1318HTIPD-003

Inadequate Technical Database Safeguards in Haiti

1319HTIPD-004

Non-Compliant Data Retention Cycles in Haiti

1320HTIPD-005

Non-Compliant Cross-Border Transfer of Haitian Data

1321IRNPD-001

Processing Sensitive Data without Written Consent in Iran

1322IRNPD-002

Processing Personal Data without Authority Notification in Iran

1323IRNPD-003

Inadequate Technical Database Safeguards in Iran

1324IRNPD-004

Non-Compliant Data Retention Cycles in Iran

1325IRNPD-005

Non-Compliant Cross-Border Transfer of Iranian Data

1326LBYPD-001

Processing Sensitive Data without Written Consent in Libya

1327LBYPD-002

Processing Personal Data without Authority Notification in Libya

1328LBYPD-003

Inadequate Technical Database Safeguards in Libya

1329LBYPD-004

Non-Compliant Data Retention Cycles in Libya

1330LBYPD-005

Non-Compliant Cross-Border Transfer of Libyan Data

1331NRUPD-001

Processing Sensitive Data without Written Consent in Nauru

1332NRUPD-002

Processing Personal Data without Authority Notification in Nauru

1333NRUPD-003

Inadequate Technical Database Safeguards in Nauru

1334NRUPD-004

Non-Compliant Data Retention Cycles in Nauru

1335NRUPD-005

Non-Compliant Cross-Border Transfer of Nauruan Data

1336PRKPD-001

Processing Sensitive Data without Written Consent in North Korea

1337PRKPD-002

Processing Personal Data without Authority Notification in North Korea

1338PRKPD-003

Inadequate Technical Database Safeguards in North Korea

1339PRKPD-004

Non-Compliant Data Retention Cycles in North Korea

1340PRKPD-005

Non-Compliant Cross-Border Transfer of North Korean Data

1341TKMPD-001

Processing Sensitive Data without Written Consent in Turkmenistan

1342TKMPD-002

Processing Personal Data without Authority Notification in Turkmenistan

1343TKMPD-003

Inadequate Technical Database Safeguards in Turkmenistan

1344TKMPD-004

Non-Compliant Data Retention Cycles in Turkmenistan

1345TKMPD-005

Non-Compliant Cross-Border Transfer of Turkmen Data

1346TUVPD-001

Processing Sensitive Data without Written Consent in Tuvalu

1347TUVPD-002

Processing Personal Data without Authority Notification in Tuvalu

1348TUVPD-003

Inadequate Technical Database Safeguards in Tuvalu

1349TUVPD-004

Non-Compliant Data Retention Cycles in Tuvalu

1350TUVPD-005

Non-Compliant Cross-Border Transfer of Tuvaluan Data

1351VATPD-001

Processing Sensitive Data without Written Consent in Vatican City

1352VATPD-002

Processing Personal Data without Authority Notification in Vatican City

1353VATPD-003

Inadequate Technical Database Safeguards in Vatican City

1354VATPD-004

Non-Compliant Data Retention Cycles in Vatican City

1355VATPD-005

Non-Compliant Cross-Border Transfer of Vatican Data

1356ESHPD-001

Processing Sensitive Data without Written Consent in Western Sahara

1357ESHPD-002

Processing Personal Data without Authority Notification in Western Sahara

1358ESHPD-003

Inadequate Technical Database Safeguards in Western Sahara

1359ESHPD-004

Non-Compliant Data Retention Cycles in Western Sahara

1360ESHPD-005

Non-Compliant Cross-Border Transfer of Sahrawi Data

1361BGRPD-001

Processing Sensitive Data without Written Consent in Bulgaria

1362BGRPD-002

Processing Personal Data without Authority Notification in Bulgaria

1363BGRPD-003

Inadequate Technical Database Safeguards in Bulgaria

1364BGRPD-004

Non-Compliant Data Retention Cycles in Bulgaria

1365BGRPD-005

Non-Compliant Cross-Border Transfer of Bulgarian Data

1366HRVPD-001

Processing Sensitive Data without Written Consent in Croatia

1367HRVPD-002

Processing Personal Data without Authority Notification in Croatia

1368HRVPD-003

Inadequate Technical Database Safeguards in Croatia

1369HRVPD-004

Non-Compliant Data Retention Cycles in Croatia

1370HRVPD-005

Non-Compliant Cross-Border Transfer of Croatian Data

1371ESTPD-001

Processing Sensitive Data without Written Consent in Estonia

1372ESTPD-002

Processing Personal Data without Authority Notification in Estonia

1373ESTPD-003

Inadequate Technical Database Safeguards in Estonia

1374ESTPD-004

Non-Compliant Data Retention Cycles in Estonia

1375ESTPD-005

Non-Compliant Cross-Border Transfer of Estonian Data

1376LVAPD-001

Processing Sensitive Data without Written Consent in Latvia

1377LVAPD-002

Processing Personal Data without Authority Notification in Latvia

1378LVAPD-003

Inadequate Technical Database Safeguards in Latvia

1379LVAPD-004

Non-Compliant Data Retention Cycles in Latvia

1380LVAPD-005

Non-Compliant Cross-Border Transfer of Latvian Data

1381LTUPD-001

Processing Sensitive Data without Written Consent in Lithuania

1382LTUPD-002

Processing Personal Data without Authority Notification in Lithuania

1383LTUPD-003

Inadequate Technical Database Safeguards in Lithuania

1384LTUPD-004

Non-Compliant Data Retention Cycles in Lithuania

1385LTUPD-005

Non-Compliant Cross-Border Transfer of Lithuanian Data

1386CYPPD-001

Processing Sensitive Data without Written Consent in Cyprus

1387CYPPD-002

Processing Personal Data without Authority Notification in Cyprus

1388CYPPD-003

Inadequate Technical Database Safeguards in Cyprus

1389CYPPD-004

Non-Compliant Data Retention Cycles in Cyprus

1390CYPPD-005

Non-Compliant Cross-Border Transfer of Cypriot Data

1391MLTPD-001

Processing Sensitive Data without Written Consent in Malta

1392MLTPD-002

Processing Personal Data without Authority Notification in Malta

1393MLTPD-003

Inadequate Technical Database Safeguards in Malta

1394MLTPD-004

Non-Compliant Data Retention Cycles in Malta

1395MLTPD-005

Non-Compliant Cross-Border Transfer of Maltese Data

1396SVKPD-001

Processing Sensitive Data without Written Consent in Slovakia

1397SVKPD-002

Processing Personal Data without Authority Notification in Slovakia

1398SVKPD-003

Inadequate Technical Database Safeguards in Slovakia

1399SVKPD-004

Non-Compliant Data Retention Cycles in Slovakia

1400SVKPD-005

Non-Compliant Cross-Border Transfer of Slovak Data

1401SVNPD-001

Processing Sensitive Data without Written Consent in Slovenia

1402SVNPD-002

Processing Personal Data without Authority Notification in Slovenia

1403SVNPD-003

Inadequate Technical Database Safeguards in Slovenia

1404SVNPD-004

Non-Compliant Data Retention Cycles in Slovenia

1405SVNPD-005

Non-Compliant Cross-Border Transfer of Slovenian Data

1406LUXPD-001

Processing Sensitive Data without Written Consent in Luxembourg

1407LUXPD-002

Processing Personal Data without Authority Notification in Luxembourg

1408LUXPD-003

Inadequate Technical Database Safeguards in Luxembourg

1409LUXPD-004

Non-Compliant Data Retention Cycles in Luxembourg

1410LUXPD-005

Non-Compliant Cross-Border Transfer of Luxembourgish Data

1411CZEPD-001

Processing Sensitive Data without Written Consent in Czech Republic

1412CZEPD-002

Processing Personal Data without Authority Notification in Czech Republic

1413CZEPD-003

Inadequate Technical Database Safeguards in Czech Republic

1414CZEPD-004

Non-Compliant Data Retention Cycles in Czech Republic

1415CZEPD-005

Non-Compliant Cross-Border Transfer of Czech Data

1416HUNPD-001

Processing Sensitive Data without Written Consent in Hungary

1417HUNPD-002

Processing Personal Data without Authority Notification in Hungary

1418HUNPD-003

Inadequate Technical Database Safeguards in Hungary

1419HUNPD-004

Non-Compliant Data Retention Cycles in Hungary

1420HUNPD-005

Non-Compliant Cross-Border Transfer of Hungarian Data

1421ROUPD-001

Processing Sensitive Data without Written Consent in Romania

1422ROUPD-002

Processing Personal Data without Authority Notification in Romania

1423ROUPD-003

Inadequate Technical Database Safeguards in Romania

1424ROUPD-004

Non-Compliant Data Retention Cycles in Romania

1425ROUPD-005

Non-Compliant Cross-Border Transfer of Romanian Data

1426POLPD-001

Processing Sensitive Data without Written Consent in Poland

1427POLPD-002

Processing Personal Data without Authority Notification in Poland

1428POLPD-003

Inadequate Technical Database Safeguards in Poland

1429POLPD-004

Non-Compliant Data Retention Cycles in Poland

1430POLPD-005

Non-Compliant Cross-Border Transfer of Polish Data

1431IRLPD-001

Processing Sensitive Data without Written Consent in Ireland

1432IRLPD-002

Processing Personal Data without Authority Notification in Ireland

1433IRLPD-003

Inadequate Technical Database Safeguards in Ireland

1434IRLPD-004

Non-Compliant Data Retention Cycles in Ireland

1435IRLPD-005

Non-Compliant Cross-Border Transfer of Irish Data

1436AUTPD-001

Processing Sensitive Data without Written Consent in Austria

1437AUTPD-002

Processing Personal Data without Authority Notification in Austria

1438AUTPD-003

Inadequate Technical Database Safeguards in Austria

1439AUTPD-004

Non-Compliant Data Retention Cycles in Austria

1440AUTPD-005

Non-Compliant Cross-Border Transfer of Austrian Data

1441SWEPD-001

Processing Sensitive Data without Written Consent in Sweden

1442SWEPD-002

Processing Personal Data without Authority Notification in Sweden

1443SWEPD-003

Inadequate Technical Database Safeguards in Sweden

1444SWEPD-004

Non-Compliant Data Retention Cycles in Sweden

1445SWEPD-005

Non-Compliant Cross-Border Transfer of Swedish Data

1446FLNPD-001

Processing Sensitive Data without Written Consent in Finland

1447FLNPD-002

Processing Personal Data without Authority Notification in Finland

1448FLNPD-003

Inadequate Technical Database Safeguards in Finland

1449FLNPD-004

Non-Compliant Data Retention Cycles in Finland

1450FLNPD-005

Non-Compliant Cross-Border Transfer of Finnish Data

1451DNKPD-001

Processing Sensitive Data without Written Consent in Denmark

1452DNKPD-002

Processing Personal Data without Authority Notification in Denmark

1453DNKPD-003

Inadequate Technical Database Safeguards in Denmark

1454DNKPD-004

Non-Compliant Data Retention Cycles in Denmark

1455DNKPD-005

Non-Compliant Cross-Border Transfer of Danish Data

1456BELPD-001

Processing Sensitive Data without Written Consent in Belgium

1457BELPD-002

Processing Personal Data without Authority Notification in Belgium

1458BELPD-003

Inadequate Technical Database Safeguards in Belgium

1459BELPD-004

Non-Compliant Data Retention Cycles in Belgium

1460BELPD-005

Non-Compliant Cross-Border Transfer of Belgian Data

1461GRCPD-001

Processing Sensitive Data without Written Consent in Greece

1462GRCPD-002

Processing Personal Data without Authority Notification in Greece

1463GRCPD-003

Inadequate Technical Database Safeguards in Greece

1464GRCPD-004

Non-Compliant Data Retention Cycles in Greece

1465GRCPD-005

Non-Compliant Cross-Border Transfer of Greek Data

1466PRTPD-001

Processing Sensitive Data without Written Consent in Portugal

1467PRTPD-002

Processing Personal Data without Authority Notification in Portugal

1468PRTPD-003

Inadequate Technical Database Safeguards in Portugal

1469PRTPD-004

Non-Compliant Data Retention Cycles in Portugal

1470PRTPD-005

Non-Compliant Cross-Border Transfer of Portuguese Data

1471GRLPD-001

Processing Sensitive Data without Written Consent in Greenland

1472GRLPD-002

Processing Personal Data without Authority Notification in Greenland

1473GRLPD-003

Inadequate Technical Database Safeguards in Greenland

1474GRLPD-004

Non-Compliant Data Retention Cycles in Greenland

1475GRLPD-005

Non-Compliant Cross-Border Transfer of Greenlandic Data

1476FLKPD-001

Processing Sensitive Data without Written Consent in Falkland Islands

1477FLKPD-002

Processing Personal Data without Authority Notification in Falkland Islands

1478FLKPD-003

Inadequate Technical Database Safeguards in Falkland Islands

1479FLKPD-004

Non-Compliant Data Retention Cycles in Falkland Islands

1480FLKPD-005

Non-Compliant Cross-Border Transfer of Falkland Islands Data

1481PYFPD-001

Processing Sensitive Data without Written Consent in French Polynesia

1482PYFPD-002

Processing Personal Data without Authority Notification in French Polynesia

1483PYFPD-003

Inadequate Technical Database Safeguards in French Polynesia

1484PYFPD-004

Non-Compliant Data Retention Cycles in French Polynesia

1485PYFPD-005

Non-Compliant Cross-Border Transfer of French Polynesian Data

1486NCLPD-001

Processing Sensitive Data without Written Consent in New Caledonia

1487NCLPD-002

Processing Personal Data without Authority Notification in New Caledonia

1488NCLPD-003

Inadequate Technical Database Safeguards in New Caledonia

1489NCLPD-004

Non-Compliant Data Retention Cycles in New Caledonia

1490NCLPD-005

Non-Compliant Cross-Border Transfer of New Caledonian Data

1491MSRPD-001

Processing Sensitive Data without Written Consent in Montserrat

1492MSRPD-002

Processing Personal Data without Authority Notification in Montserrat

1493MSRPD-003

Inadequate Technical Database Safeguards in Montserrat

1494MSRPD-004

Non-Compliant Data Retention Cycles in Montserrat

1495MSRPD-005

Non-Compliant Cross-Border Transfer of Montserratian Data

1496SHNPD-001

Processing Sensitive Data without Written Consent in Saint Helena

1497SHNPD-002

Processing Personal Data without Authority Notification in Saint Helena

1498SHNPD-003

Inadequate Technical Database Safeguards in Saint Helena

1499SHNPD-004

Non-Compliant Data Retention Cycles in Saint Helena

1500SHNPD-005

Non-Compliant Cross-Border Transfer of Saint Helenian Data

1501OWASP-001

SQL Injection Vulnerability in User Input

1502OWASP-002

Cross-Site Scripting (XSS) Vulnerability

1503OWASP-003

Broken Authentication and Session Leakage

1504OWASP-004

Unencrypted Transmission of Sensitive Data

1505OWASP-005

Broken Object-Level Access Control

1506OWASP-006

Debug Mode Active in Production Environment

1507OWASP-007

XML External Entity (XXE) Injection Vulnerability

1508OWASP-008

Insecure Deserialization of Untrusted Input

1509OWASP-009

Outdated Libraries with Known Vulnerabilities

1510OWASP-010

Insufficient Security Logging and Auditing

1511NISTP-001

Inadequate Access Control Policies

1512NISTP-002

Missing Audit Record Generation

1513NISTP-003

Ineffective Configuration Management

1514NISTP-004

Missing Multi-Factor Authentication for Admins

1515NISTP-005

Inadequate Incident Response Plan Integration

1516NISTP-006

Inadequate System Maintenance Tracking

1517NISTP-007

Lack of Media Protection and Backup Encryption

1518NISTP-008

Missing Server Room Access Logs (Hosted Servers)

1519NISTP-009

Inadequate Security Training Records

1520NISTP-010

Missing Network Boundaries and DNSSEC Controls

1521ISO27-001

Inadequate Information Security Policies

1522ISO27-002

Lack of Defined Security Roles and Authorities

1523ISO27-003

Inadequate Asset Inventory for Customer Data

1524ISO27-004

Weak Use of Cryptography for User Passwords

1525ISO27-005

Inadequate Physical Security for Web Servers

1526ISO27-006

Poor Operations Security and Unverified Backups

1527ISO27-007

Insecure Network Architecture and Weak Routing Controls

1528ISO27-008

Lack of Secure Coding Standards in Software Development

1529ISO27-009

Lack of Security Requirements in Supplier Agreements

1530ISO27-010

Lack of Incident Management and Escalation Paths

1531SOC2P-001

Inadequate System Monitoring for Security Anomalies

1532SOC2P-002

Weak Access Credentials and Missing Multi-Factor Auth

1533SOC2P-003

Insufficient Data Transmission Protections

1534SOC2P-004

Weak Data Classification Policies

1535SOC2P-005

Lack of Vulnerability Management Infrastructure

1536SOC2P-006

Lack of System Availability and Failover Testing

1537SOC2P-007

Weak Processing Integrity for Transactions

1538SOC2P-008

Inadequate Confidentiality Protections for Data Storage

1539SOC2P-009

Weak Data Lifecycle Management

1540SOC2P-010

Missing Change Control and Peer Review Controls

1541CISA-001

Default Administrative Passwords Enabled

1542CISA-002

Missing Multi-Factor Authentication for Admin Consoles

1543CISA-003

Known Exploited Vulnerabilities in Web Software

1544CISA-004

Ineffective Internet-Facing Asset Inventory

1545CISA-005

Missing DNS Integrity Protection Controls

1546CISA-006

Insecure Email Authentication Standards (No DMARC)

1547CISA-007

Lack of Security Incident Exercises

1548CISA-008

Insecure Remote Access Protocols Enabled

1549CISA-009

Inadequate Data Backup Isolation

1550CISA-010

Ineffective Internal Vulnerability Scanning

1551EUDSA-001

Missing Direct Point of Contact for Authorities

1552EUDSA-002

Missing Terms for Content Moderation Rules

1553EUDSA-003

Lack of Recommender System Parameter Transparency

1554EUDSA-004

Non-Compliant Interface Manipulation (Dark Patterns)

1555EUDSA-005

Unlabeled Online Advertisements and Sponsors

1556EUDSA-006

Missing Notice-and-Action Mechanism for Users

1557EUDSA-007

Non-Compliant User Suspension Rules

1558EUDSA-008

Missing Statements of Reasons in Public Directory

1559EUDSA-009

Inadequate Complaint Handling System

1560EUDSA-010

Deceptive Advertising Targeting Policies

1561EUDMA-001

Unfair Self-Preferencing in Product Listings

1562EUDMA-002

Unlawful Multi-Source Data Combination

1563EUDMA-003

Restricting Third-Party Software Side-Loading

1564EUDMA-004

Restricting Business User Data Portability

1565EUDMA-005

Unfair Advertising Performance Reporting

1566EUDMA-006

Restricting Cross-Platform Price Parity (Anti-Steering)

1567EUDMA-007

Deceptive Choice Screen Implementation

1568EUDMA-008

Restricting Platform Services Interoperability

1569EUDMA-009

Deceptive and Complex Unsubscribe Flows

1570EUDMA-010

Unlawful Exploitation of Business User Sales Data

1571UKAAC-001

Inadequate Age Verification for Sensitive Content

1572UKAAC-002

High-Risk Tracking Active by Default for Minors

1573UKAAC-003

Complex Privacy Disclosures for Young Audiences

1574UKAAC-004

Deceptive Nudge UI Techniques Target Minors

1575UKAAC-005

Unlawful Automated Minor Profiling

1576UKAAC-006

Missing Parental Tracking Notifications

1577UKAAC-007

Unlawful Children's Data Sharing with Advertisers

1578UKAAC-008

Inadequate Data Minimization for Under-18s

1579UKAAC-009

Harmful Marketing Target Practices for Children

1580UKAAC-010

Insecure Default Minor Profile Settings

1581CAAAC-001

Missing DPIA for Services Accessed by Minors

1582CAAAC-002

Deceptive Age Assurance Implementation

1583CAAAC-003

Disabled Default High Privacy Settings

1584CAAAC-004

Unlawful Automated Minor Behavioral Profiling

1585CAAAC-005

Unlawful Sale of Verified Minors' Data

1586CAAAC-006

Missing Active Tracking Indicators for Minors

1587CAAAC-007

Deceptive Nudge Patterns Bypass Privacy Settings

1588CAAAC-008

Complex Terms of Service Explanations

1589CAAAC-009

Unlawful Collection of Minor Geolocation History

1590CAAAC-010

Missing Deletion and Profile Eraser Controls

1591EUAIA-001

Missing AI Interaction Disclosures for Users

1592EUAIA-002

Missing Generative AI Content Disclosures

1593EUAIA-003

Prohibited Deployments of Emotion Recognition Systems

1594EUAIA-004

Unlawful Biometric Classification Implementations

1595EUAIA-005

Deceptive Deepfake Image and Video Disclosures

1596EUAIA-006

Inadequate High-Risk AI System Risk Management

1597EUAIA-007

Missing Logging Capabilities for High-Risk AI Systems

1598EUAIA-008

Lack of Human Oversight in Automated Recruitment

1599EUAIA-009

Unlawful Web Data Scraping for AI Training

1600EUAIA-010

Insecure High-Risk AI Database Integration

1601TXDPS-001

Inaccessible Data Access Channel under Texas Data Privacy and Security Act (TDPSA)

1602TXDPS-002

Missing Data Rectification Form under Texas Data Privacy and Security Act (TDPSA)

1603TXDPS-003

Inaccessible Data Deletion Portal under Texas Data Privacy and Security Act (TDPSA)

1604TXDPS-004

Lack of Data Portability Export under Texas Data Privacy and Security Act (TDPSA)

1605TXDPS-005

Missing Opt-Out of Targeted Advertising under Texas Data Privacy and Security Act (TDPSA)

1606TXDPS-006

Missing Opt-Out of Personal Data Sales under Texas Data Privacy and Security Act (TDPSA)

1607TXDPS-007

Missing Opt-Out of Automated Profiling under Texas Data Privacy and Security Act (TDPSA)

1608TXDPS-008

Processing Sensitive Data without Consent under Texas Data Privacy and Security Act (TDPSA)

1609TXDPS-009

Missing Data Protection Impact Assessment under Texas Data Privacy and Security Act (TDPSA)

1610TXDPS-010

Non-Compliant Notice at Collection under Texas Data Privacy and Security Act (TDPSA)

1611VCDPA-001

Inaccessible Data Access Channel under Virginia Consumer Data Protection Act (VCDPA)

1612VCDPA-002

Missing Data Rectification Form under Virginia Consumer Data Protection Act (VCDPA)

1613VCDPA-003

Inaccessible Data Deletion Portal under Virginia Consumer Data Protection Act (VCDPA)

1614VCDPA-004

Lack of Data Portability Export under Virginia Consumer Data Protection Act (VCDPA)

1615VCDPA-005

Missing Opt-Out of Targeted Advertising under Virginia Consumer Data Protection Act (VCDPA)

1616VCDPA-006

Missing Opt-Out of Personal Data Sales under Virginia Consumer Data Protection Act (VCDPA)

1617VCDPA-007

Missing Opt-Out of Automated Profiling under Virginia Consumer Data Protection Act (VCDPA)

1618VCDPA-008

Processing Sensitive Data without Consent under Virginia Consumer Data Protection Act (VCDPA)

1619VCDPA-009

Missing Data Protection Impact Assessment under Virginia Consumer Data Protection Act (VCDPA)

1620VCDPA-010

Non-Compliant Notice at Collection under Virginia Consumer Data Protection Act (VCDPA)

1621COPR-001

Inaccessible Data Access Channel under Colorado Privacy Act (CPA)

1622COPR-002

Missing Data Rectification Form under Colorado Privacy Act (CPA)

1623COPR-003

Inaccessible Data Deletion Portal under Colorado Privacy Act (CPA)

1624COPR-004

Lack of Data Portability Export under Colorado Privacy Act (CPA)

1625COPR-005

Missing Opt-Out of Targeted Advertising under Colorado Privacy Act (CPA)

1626COPR-006

Missing Opt-Out of Personal Data Sales under Colorado Privacy Act (CPA)

1627COPR-007

Missing Opt-Out of Automated Profiling under Colorado Privacy Act (CPA)

1628COPR-008

Processing Sensitive Data without Consent under Colorado Privacy Act (CPA)

1629COPR-009

Missing Data Protection Impact Assessment under Colorado Privacy Act (CPA)

1630COPR-010

Non-Compliant Notice at Collection under Colorado Privacy Act (CPA)

1631CTDPA-001

Inaccessible Data Access Channel under Connecticut Data Privacy Act (CTDPA)

1632CTDPA-002

Missing Data Rectification Form under Connecticut Data Privacy Act (CTDPA)

1633CTDPA-003

Inaccessible Data Deletion Portal under Connecticut Data Privacy Act (CTDPA)

1634CTDPA-004

Lack of Data Portability Export under Connecticut Data Privacy Act (CTDPA)

1635CTDPA-005

Missing Opt-Out of Targeted Advertising under Connecticut Data Privacy Act (CTDPA)

1636CTDPA-006

Missing Opt-Out of Personal Data Sales under Connecticut Data Privacy Act (CTDPA)

1637CTDPA-007

Missing Opt-Out of Automated Profiling under Connecticut Data Privacy Act (CTDPA)

1638CTDPA-008

Processing Sensitive Data without Consent under Connecticut Data Privacy Act (CTDPA)

1639CTDPA-009

Missing Data Protection Impact Assessment under Connecticut Data Privacy Act (CTDPA)

1640CTDPA-010

Non-Compliant Notice at Collection under Connecticut Data Privacy Act (CTDPA)

1641UCPA-001

Inaccessible Data Access Channel under Utah Consumer Privacy Act (UCPA)

1642UCPA-002

Missing Data Rectification Form under Utah Consumer Privacy Act (UCPA)

1643UCPA-003

Inaccessible Data Deletion Portal under Utah Consumer Privacy Act (UCPA)

1644UCPA-004

Lack of Data Portability Export under Utah Consumer Privacy Act (UCPA)

1645UCPA-005

Missing Opt-Out of Targeted Advertising under Utah Consumer Privacy Act (UCPA)

1646UCPA-006

Missing Opt-Out of Personal Data Sales under Utah Consumer Privacy Act (UCPA)

1647UCPA-007

Missing Opt-Out of Automated Profiling under Utah Consumer Privacy Act (UCPA)

1648UCPA-008

Processing Sensitive Data without Consent under Utah Consumer Privacy Act (UCPA)

1649UCPA-009

Missing Data Protection Impact Assessment under Utah Consumer Privacy Act (UCPA)

1650UCPA-010

Non-Compliant Notice at Collection under Utah Consumer Privacy Act (UCPA)

1651ORCPA-001

Inaccessible Data Access Channel under Oregon Consumer Privacy Act (OCPA)

1652ORCPA-002

Missing Data Rectification Form under Oregon Consumer Privacy Act (OCPA)

1653ORCPA-003

Inaccessible Data Deletion Portal under Oregon Consumer Privacy Act (OCPA)

1654ORCPA-004

Lack of Data Portability Export under Oregon Consumer Privacy Act (OCPA)

1655ORCPA-005

Missing Opt-Out of Targeted Advertising under Oregon Consumer Privacy Act (OCPA)

1656ORCPA-006

Missing Opt-Out of Personal Data Sales under Oregon Consumer Privacy Act (OCPA)

1657ORCPA-007

Missing Opt-Out of Automated Profiling under Oregon Consumer Privacy Act (OCPA)

1658ORCPA-008

Processing Sensitive Data without Consent under Oregon Consumer Privacy Act (OCPA)

1659ORCPA-009

Missing Data Protection Impact Assessment under Oregon Consumer Privacy Act (OCPA)

1660ORCPA-010

Non-Compliant Notice at Collection under Oregon Consumer Privacy Act (OCPA)

1661FLORDB-001

Inaccessible Data Access Channel under Florida Digital Bill of Rights (FDBR)

1662FLORDB-002

Missing Data Rectification Form under Florida Digital Bill of Rights (FDBR)

1663FLORDB-003

Inaccessible Data Deletion Portal under Florida Digital Bill of Rights (FDBR)

1664FLORDB-004

Lack of Data Portability Export under Florida Digital Bill of Rights (FDBR)

1665FLORDB-005

Missing Opt-Out of Targeted Advertising under Florida Digital Bill of Rights (FDBR)

1666FLORDB-006

Missing Opt-Out of Personal Data Sales under Florida Digital Bill of Rights (FDBR)

1667FLORDB-007

Missing Opt-Out of Automated Profiling under Florida Digital Bill of Rights (FDBR)

1668FLORDB-008

Processing Sensitive Data without Consent under Florida Digital Bill of Rights (FDBR)

1669FLORDB-009

Missing Data Protection Impact Assessment under Florida Digital Bill of Rights (FDBR)

1670FLORDB-010

Non-Compliant Notice at Collection under Florida Digital Bill of Rights (FDBR)

1671PIPEDA-001

Inaccessible Data Access Channel under Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

1672PIPEDA-002

Missing Data Rectification Form under Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

1673PIPEDA-003

Inaccessible Data Deletion Portal under Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

1674PIPEDA-004

Lack of Data Portability Export under Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

1675PIPEDA-005

Missing Opt-Out of Targeted Advertising under Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

1676PIPEDA-006

Missing Opt-Out of Personal Data Sales under Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

1677PIPEDA-007

Missing Opt-Out of Automated Profiling under Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

1678PIPEDA-008

Processing Sensitive Data without Consent under Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

1679PIPEDA-009

Missing Data Protection Impact Assessment under Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

1680PIPEDA-010

Non-Compliant Notice at Collection under Canada Personal Information Protection and Electronic Documents Act (PIPEDA)

1681LAW25-001

Inaccessible Data Access Channel under Quebec Law 25

1682LAW25-002

Missing Data Rectification Form under Quebec Law 25

1683LAW25-003

Inaccessible Data Deletion Portal under Quebec Law 25

1684LAW25-004

Lack of Data Portability Export under Quebec Law 25

1685LAW25-005

Missing Opt-Out of Targeted Advertising under Quebec Law 25

1686LAW25-006

Missing Opt-Out of Personal Data Sales under Quebec Law 25

1687LAW25-007

Missing Opt-Out of Automated Profiling under Quebec Law 25

1688LAW25-008

Processing Sensitive Data without Consent under Quebec Law 25

1689LAW25-009

Missing Data Protection Impact Assessment under Quebec Law 25

1690LAW25-010

Non-Compliant Notice at Collection under Quebec Law 25

1691TDDDG-001

Inaccessible Data Access Channel under German Telecommunications-Telemedia Data Protection Act (TDDDG)

1692TDDDG-002

Missing Data Rectification Form under German Telecommunications-Telemedia Data Protection Act (TDDDG)

1693TDDDG-003

Inaccessible Data Deletion Portal under German Telecommunications-Telemedia Data Protection Act (TDDDG)

1694TDDDG-004

Lack of Data Portability Export under German Telecommunications-Telemedia Data Protection Act (TDDDG)

1695TDDDG-005

Missing Opt-Out of Targeted Advertising under German Telecommunications-Telemedia Data Protection Act (TDDDG)

1696TDDDG-006

Missing Opt-Out of Personal Data Sales under German Telecommunications-Telemedia Data Protection Act (TDDDG)

1697TDDDG-007

Missing Opt-Out of Automated Profiling under German Telecommunications-Telemedia Data Protection Act (TDDDG)

1698TDDDG-008

Processing Sensitive Data without Consent under German Telecommunications-Telemedia Data Protection Act (TDDDG)

1699TDDDG-009

Missing Data Protection Impact Assessment under German Telecommunications-Telemedia Data Protection Act (TDDDG)

1700TDDDG-010

Non-Compliant Notice at Collection under German Telecommunications-Telemedia Data Protection Act (TDDDG)

1701SGPDPA-001

Inaccessible Data Access Channel under Singapore Personal Data Protection Act (PDPA)

1702SGPDPA-002

Missing Data Rectification Form under Singapore Personal Data Protection Act (PDPA)

1703SGPDPA-003

Inaccessible Data Deletion Portal under Singapore Personal Data Protection Act (PDPA)

1704SGPDPA-004

Lack of Data Portability Export under Singapore Personal Data Protection Act (PDPA)

1705SGPDPA-005

Missing Opt-Out of Targeted Advertising under Singapore Personal Data Protection Act (PDPA)

1706SGPDPA-006

Missing Opt-Out of Personal Data Sales under Singapore Personal Data Protection Act (PDPA)

1707SGPDPA-007

Missing Opt-Out of Automated Profiling under Singapore Personal Data Protection Act (PDPA)

1708SGPDPA-008

Processing Sensitive Data without Consent under Singapore Personal Data Protection Act (PDPA)

1709SGPDPA-009

Missing Data Protection Impact Assessment under Singapore Personal Data Protection Act (PDPA)

1710SGPDPA-010

Non-Compliant Notice at Collection under Singapore Personal Data Protection Act (PDPA)

1711AUSAPP-001

Inaccessible Data Access Channel under Australian Privacy Principles (APPs)

1712AUSAPP-002

Missing Data Rectification Form under Australian Privacy Principles (APPs)

1713AUSAPP-003

Inaccessible Data Deletion Portal under Australian Privacy Principles (APPs)

1714AUSAPP-004

Lack of Data Portability Export under Australian Privacy Principles (APPs)

1715AUSAPP-005

Missing Opt-Out of Targeted Advertising under Australian Privacy Principles (APPs)

1716AUSAPP-006

Missing Opt-Out of Personal Data Sales under Australian Privacy Principles (APPs)

1717AUSAPP-007

Missing Opt-Out of Automated Profiling under Australian Privacy Principles (APPs)

1718AUSAPP-008

Processing Sensitive Data without Consent under Australian Privacy Principles (APPs)

1719AUSAPP-009

Missing Data Protection Impact Assessment under Australian Privacy Principles (APPs)

1720AUSAPP-010

Non-Compliant Notice at Collection under Australian Privacy Principles (APPs)

1721NZPRIV-001

Inaccessible Data Access Channel under New Zealand Privacy Act 2020

1722NZPRIV-002

Missing Data Rectification Form under New Zealand Privacy Act 2020

1723NZPRIV-003

Inaccessible Data Deletion Portal under New Zealand Privacy Act 2020

1724NZPRIV-004

Lack of Data Portability Export under New Zealand Privacy Act 2020

1725NZPRIV-005

Missing Opt-Out of Targeted Advertising under New Zealand Privacy Act 2020

1726NZPRIV-006

Missing Opt-Out of Personal Data Sales under New Zealand Privacy Act 2020

1727NZPRIV-007

Missing Opt-Out of Automated Profiling under New Zealand Privacy Act 2020

1728NZPRIV-008

Processing Sensitive Data without Consent under New Zealand Privacy Act 2020

1729NZPRIV-009

Missing Data Protection Impact Assessment under New Zealand Privacy Act 2020

1730NZPRIV-010

Non-Compliant Notice at Collection under New Zealand Privacy Act 2020

1731JPAPPI-001

Inaccessible Data Access Channel under Japan Act on the Protection of Personal Information (APPI)

1732JPAPPI-002

Missing Data Rectification Form under Japan Act on the Protection of Personal Information (APPI)

1733JPAPPI-003

Inaccessible Data Deletion Portal under Japan Act on the Protection of Personal Information (APPI)

1734JPAPPI-004

Lack of Data Portability Export under Japan Act on the Protection of Personal Information (APPI)

1735JPAPPI-005

Missing Opt-Out of Targeted Advertising under Japan Act on the Protection of Personal Information (APPI)

1736JPAPPI-006

Missing Opt-Out of Personal Data Sales under Japan Act on the Protection of Personal Information (APPI)

1737JPAPPI-007

Missing Opt-Out of Automated Profiling under Japan Act on the Protection of Personal Information (APPI)

1738JPAPPI-008

Processing Sensitive Data without Consent under Japan Act on the Protection of Personal Information (APPI)

1739JPAPPI-009

Missing Data Protection Impact Assessment under Japan Act on the Protection of Personal Information (APPI)

1740JPAPPI-010

Non-Compliant Notice at Collection under Japan Act on the Protection of Personal Information (APPI)

1741KRPIPA-001

Inaccessible Data Access Channel under South Korea Personal Information Protection Act (PIPA)

1742KRPIPA-002

Missing Data Rectification Form under South Korea Personal Information Protection Act (PIPA)

1743KRPIPA-003

Inaccessible Data Deletion Portal under South Korea Personal Information Protection Act (PIPA)

1744KRPIPA-004

Lack of Data Portability Export under South Korea Personal Information Protection Act (PIPA)

1745KRPIPA-005

Missing Opt-Out of Targeted Advertising under South Korea Personal Information Protection Act (PIPA)

1746KRPIPA-006

Missing Opt-Out of Personal Data Sales under South Korea Personal Information Protection Act (PIPA)

1747KRPIPA-007

Missing Opt-Out of Automated Profiling under South Korea Personal Information Protection Act (PIPA)

1748KRPIPA-008

Processing Sensitive Data without Consent under South Korea Personal Information Protection Act (PIPA)

1749KRPIPA-009

Missing Data Protection Impact Assessment under South Korea Personal Information Protection Act (PIPA)

1750KRPIPA-010

Non-Compliant Notice at Collection under South Korea Personal Information Protection Act (PIPA)

1751VNDPD-001

Inaccessible Data Access Channel under Vietnam Personal Data Protection Decree 13/2023/ND-CP

1752VNDPD-002

Missing Data Rectification Form under Vietnam Personal Data Protection Decree 13/2023/ND-CP

1753VNDPD-003

Inaccessible Data Deletion Portal under Vietnam Personal Data Protection Decree 13/2023/ND-CP

1754VNDPD-004

Lack of Data Portability Export under Vietnam Personal Data Protection Decree 13/2023/ND-CP

1755VNDPD-005

Missing Opt-Out of Targeted Advertising under Vietnam Personal Data Protection Decree 13/2023/ND-CP

1756VNDPD-006

Missing Opt-Out of Personal Data Sales under Vietnam Personal Data Protection Decree 13/2023/ND-CP

1757VNDPD-007

Missing Opt-Out of Automated Profiling under Vietnam Personal Data Protection Decree 13/2023/ND-CP

1758VNDPD-008

Processing Sensitive Data without Consent under Vietnam Personal Data Protection Decree 13/2023/ND-CP

1759VNDPD-009

Missing Data Protection Impact Assessment under Vietnam Personal Data Protection Decree 13/2023/ND-CP

1760VNDPD-010

Non-Compliant Notice at Collection under Vietnam Personal Data Protection Decree 13/2023/ND-CP

1761THPDPA-001

Inaccessible Data Access Channel under Thailand Personal Data Protection Act (PDPA)

1762THPDPA-002

Missing Data Rectification Form under Thailand Personal Data Protection Act (PDPA)

1763THPDPA-003

Inaccessible Data Deletion Portal under Thailand Personal Data Protection Act (PDPA)

1764THPDPA-004

Lack of Data Portability Export under Thailand Personal Data Protection Act (PDPA)

1765THPDPA-005

Missing Opt-Out of Targeted Advertising under Thailand Personal Data Protection Act (PDPA)

1766THPDPA-006

Missing Opt-Out of Personal Data Sales under Thailand Personal Data Protection Act (PDPA)

1767THPDPA-007

Missing Opt-Out of Automated Profiling under Thailand Personal Data Protection Act (PDPA)

1768THPDPA-008

Processing Sensitive Data without Consent under Thailand Personal Data Protection Act (PDPA)

1769THPDPA-009

Missing Data Protection Impact Assessment under Thailand Personal Data Protection Act (PDPA)

1770THPDPA-010

Non-Compliant Notice at Collection under Thailand Personal Data Protection Act (PDPA)

1771INDPDP-001

Inaccessible Data Access Channel under India Digital Personal Data Protection Act 2023 (DPDP)

1772INDPDP-002

Missing Data Rectification Form under India Digital Personal Data Protection Act 2023 (DPDP)

1773INDPDP-003

Inaccessible Data Deletion Portal under India Digital Personal Data Protection Act 2023 (DPDP)

1774INDPDP-004

Lack of Data Portability Export under India Digital Personal Data Protection Act 2023 (DPDP)

1775INDPDP-005

Missing Opt-Out of Targeted Advertising under India Digital Personal Data Protection Act 2023 (DPDP)

1776INDPDP-006

Missing Opt-Out of Personal Data Sales under India Digital Personal Data Protection Act 2023 (DPDP)

1777INDPDP-007

Missing Opt-Out of Automated Profiling under India Digital Personal Data Protection Act 2023 (DPDP)

1778INDPDP-008

Processing Sensitive Data without Consent under India Digital Personal Data Protection Act 2023 (DPDP)

1779INDPDP-009

Missing Data Protection Impact Assessment under India Digital Personal Data Protection Act 2023 (DPDP)

1780INDPDP-010

Non-Compliant Notice at Collection under India Digital Personal Data Protection Act 2023 (DPDP)

1781BRLGPD-001

Inaccessible Data Access Channel under Brazil General Data Protection Law (LGPD)

1782BRLGPD-002

Missing Data Rectification Form under Brazil General Data Protection Law (LGPD)

1783BRLGPD-003

Inaccessible Data Deletion Portal under Brazil General Data Protection Law (LGPD)

1784BRLGPD-004

Lack of Data Portability Export under Brazil General Data Protection Law (LGPD)

1785BRLGPD-005

Missing Opt-Out of Targeted Advertising under Brazil General Data Protection Law (LGPD)

1786BRLGPD-006

Missing Opt-Out of Personal Data Sales under Brazil General Data Protection Law (LGPD)

1787BRLGPD-007

Missing Opt-Out of Automated Profiling under Brazil General Data Protection Law (LGPD)

1788BRLGPD-008

Processing Sensitive Data without Consent under Brazil General Data Protection Law (LGPD)

1789BRLGPD-009

Missing Data Protection Impact Assessment under Brazil General Data Protection Law (LGPD)

1790BRLGPD-010

Non-Compliant Notice at Collection under Brazil General Data Protection Law (LGPD)

1791ZAPOPI-001

Inaccessible Data Access Channel under South Africa Protection of Personal Information Act (POPIA)

1792ZAPOPI-002

Missing Data Rectification Form under South Africa Protection of Personal Information Act (POPIA)

1793ZAPOPI-003

Inaccessible Data Deletion Portal under South Africa Protection of Personal Information Act (POPIA)

1794ZAPOPI-004

Lack of Data Portability Export under South Africa Protection of Personal Information Act (POPIA)

1795ZAPOPI-005

Missing Opt-Out of Targeted Advertising under South Africa Protection of Personal Information Act (POPIA)

1796ZAPOPI-006

Missing Opt-Out of Personal Data Sales under South Africa Protection of Personal Information Act (POPIA)

1797ZAPOPI-007

Missing Opt-Out of Automated Profiling under South Africa Protection of Personal Information Act (POPIA)

1798ZAPOPI-008

Processing Sensitive Data without Consent under South Africa Protection of Personal Information Act (POPIA)

1799ZAPOPI-009

Missing Data Protection Impact Assessment under South Africa Protection of Personal Information Act (POPIA)

1800ZAPOPI-010

Non-Compliant Notice at Collection under South Africa Protection of Personal Information Act (POPIA)

1801TXSBB-001

Unregistered Data Broker Operations

1802TXSBB-002

Unregistered Data Broker Operations Audit and Record Failures

1803TXSBB-003

Unregistered Data Broker Operations Interface Design Flaws

1804TXSBB-004

Unregistered Data Broker Operations Cryptographic Strengths

1805TXSBB-005

Unregistered Data Broker Operations Vulnerability Scanning Failures

1806TXSBB-006

Unregistered Data Broker Operations Consent Logging Integrity

1807TXSBB-007

Unregistered Data Broker Operations Opt-Out Links Visibility

1808TXSBB-008

Unregistered Data Broker Operations Privacy Notice Disclosures

1809TXSBB-009

Unregistered Data Broker Operations Audit Control Verification

1810TXSBB-010

Unregistered Data Broker Operations Administrative Key Credentials

1811WAHMHD-001

Unlawful Geofencing Around Health Facilities

1812WAHMHD-002

Unlawful Geofencing Around Health Facilities Audit and Record Failures

1813WAHMHD-003

Unlawful Geofencing Around Health Facilities Interface Design Flaws

1814WAHMHD-004

Unlawful Geofencing Around Health Facilities Cryptographic Strengths

1815WAHMHD-005

Unlawful Geofencing Around Health Facilities Vulnerability Scanning Failures

1816WAHMHD-006

Unlawful Geofencing Around Health Facilities Consent Logging Integrity

1817WAHMHD-007

Unlawful Geofencing Around Health Facilities Opt-Out Links Visibility

1818WAHMHD-008

Unlawful Geofencing Around Health Facilities Privacy Notice Disclosures

1819WAHMHD-009

Unlawful Geofencing Around Health Facilities Audit Control Verification

1820WAHMHD-010

Unlawful Geofencing Around Health Facilities Administrative Key Credentials

1821NYDFS-001

Missing Financial Cybersecurity Certification

1822NYDFS-002

Missing Financial Cybersecurity Certification Audit and Record Failures

1823NYDFS-003

Missing Financial Cybersecurity Certification Interface Design Flaws

1824NYDFS-004

Missing Financial Cybersecurity Certification Cryptographic Strengths

1825NYDFS-005

Missing Financial Cybersecurity Certification Vulnerability Scanning Failures

1826NYDFS-006

Missing Financial Cybersecurity Certification Consent Logging Integrity

1827NYDFS-007

Missing Financial Cybersecurity Certification Opt-Out Links Visibility

1828NYDFS-008

Missing Financial Cybersecurity Certification Privacy Notice Disclosures

1829NYDFS-009

Missing Financial Cybersecurity Certification Audit Control Verification

1830NYDFS-010

Missing Financial Cybersecurity Certification Administrative Key Credentials

1831PSD2-001

Non-Compliant Strong Customer Authentication (SCA)

1832PSD2-002

Non-Compliant Strong Customer Authentication (SCA) Audit and Record Failures

1833PSD2-003

Non-Compliant Strong Customer Authentication (SCA) Interface Design Flaws

1834PSD2-004

Non-Compliant Strong Customer Authentication (SCA) Cryptographic Strengths

1835PSD2-005

Non-Compliant Strong Customer Authentication (SCA) Vulnerability Scanning Failures

1836PSD2-006

Non-Compliant Strong Customer Authentication (SCA) Consent Logging Integrity

1837PSD2-007

Non-Compliant Strong Customer Authentication (SCA) Opt-Out Links Visibility

1838PSD2-008

Non-Compliant Strong Customer Authentication (SCA) Privacy Notice Disclosures

1839PSD2-009

Non-Compliant Strong Customer Authentication (SCA) Audit Control Verification

1840PSD2-010

Non-Compliant Strong Customer Authentication (SCA) Administrative Key Credentials

1841PCISC-001

Inadequate Client-Side Script Integrity Controls

1842PCISC-002

Inadequate Client-Side Script Integrity Controls Audit and Record Failures

1843PCISC-003

Inadequate Client-Side Script Integrity Controls Interface Design Flaws

1844PCISC-004

Inadequate Client-Side Script Integrity Controls Cryptographic Strengths

1845PCISC-005

Inadequate Client-Side Script Integrity Controls Vulnerability Scanning Failures

1846PCISC-006

Inadequate Client-Side Script Integrity Controls Consent Logging Integrity

1847PCISC-007

Inadequate Client-Side Script Integrity Controls Opt-Out Links Visibility

1848PCISC-008

Inadequate Client-Side Script Integrity Controls Privacy Notice Disclosures

1849PCISC-009

Inadequate Client-Side Script Integrity Controls Audit Control Verification

1850PCISC-010

Inadequate Client-Side Script Integrity Controls Administrative Key Credentials

1851GLBAS-001

Missing Secure Transmission Controls for Financial Data

1852GLBAS-002

Missing Secure Transmission Controls for Financial Data Audit and Record Failures

1853GLBAS-003

Missing Secure Transmission Controls for Financial Data Interface Design Flaws

1854GLBAS-004

Missing Secure Transmission Controls for Financial Data Cryptographic Strengths

1855GLBAS-005

Missing Secure Transmission Controls for Financial Data Vulnerability Scanning Failures

1856GLBAS-006

Missing Secure Transmission Controls for Financial Data Consent Logging Integrity

1857GLBAS-007

Missing Secure Transmission Controls for Financial Data Opt-Out Links Visibility

1858GLBAS-008

Missing Secure Transmission Controls for Financial Data Privacy Notice Disclosures

1859GLBAS-009

Missing Secure Transmission Controls for Financial Data Audit Control Verification

1860GLBAS-010

Missing Secure Transmission Controls for Financial Data Administrative Key Credentials

1861FTCDP-001

Fictitious Original Pricing Discounts

1862FTCDP-002

Fictitious Original Pricing Discounts Audit and Record Failures

1863FTCDP-003

Fictitious Original Pricing Discounts Interface Design Flaws

1864FTCDP-004

Fictitious Original Pricing Discounts Cryptographic Strengths

1865FTCDP-005

Fictitious Original Pricing Discounts Vulnerability Scanning Failures

1866FTCDP-006

Fictitious Original Pricing Discounts Consent Logging Integrity

1867FTCDP-007

Fictitious Original Pricing Discounts Opt-Out Links Visibility

1868FTCDP-008

Fictitious Original Pricing Discounts Privacy Notice Disclosures

1869FTCDP-009

Fictitious Original Pricing Discounts Audit Control Verification

1870FTCDP-010

Fictitious Original Pricing Discounts Administrative Key Credentials

1871FTCCC-001

Asymmetric Subscription Cancellation Flow

1872FTCCC-002

Asymmetric Subscription Cancellation Flow Audit and Record Failures

1873FTCCC-003

Asymmetric Subscription Cancellation Flow Interface Design Flaws

1874FTCCC-004

Asymmetric Subscription Cancellation Flow Cryptographic Strengths

1875FTCCC-005

Asymmetric Subscription Cancellation Flow Vulnerability Scanning Failures

1876FTCCC-006

Asymmetric Subscription Cancellation Flow Consent Logging Integrity

1877FTCCC-007

Asymmetric Subscription Cancellation Flow Opt-Out Links Visibility

1878FTCCC-008

Asymmetric Subscription Cancellation Flow Privacy Notice Disclosures

1879FTCCC-009

Asymmetric Subscription Cancellation Flow Audit Control Verification

1880FTCCC-010

Asymmetric Subscription Cancellation Flow Administrative Key Credentials

1881FTCFR-001

Undisclosed Compensated Review Incentives

1882FTCFR-002

Undisclosed Compensated Review Incentives Audit and Record Failures

1883FTCFR-003

Undisclosed Compensated Review Incentives Interface Design Flaws

1884FTCFR-004

Undisclosed Compensated Review Incentives Cryptographic Strengths

1885FTCFR-005

Undisclosed Compensated Review Incentives Vulnerability Scanning Failures

1886FTCFR-006

Undisclosed Compensated Review Incentives Consent Logging Integrity

1887FTCFR-007

Undisclosed Compensated Review Incentives Opt-Out Links Visibility

1888FTCFR-008

Undisclosed Compensated Review Incentives Privacy Notice Disclosures

1889FTCFR-009

Undisclosed Compensated Review Incentives Audit Control Verification

1890FTCFR-010

Undisclosed Compensated Review Incentives Administrative Key Credentials

1891EUDOR-001

Missing IT Vulnerability Audit Records

1892EUDOR-002

Missing IT Vulnerability Audit Records Audit and Record Failures

1893EUDOR-003

Missing IT Vulnerability Audit Records Interface Design Flaws

1894EUDOR-004

Missing IT Vulnerability Audit Records Cryptographic Strengths

1895EUDOR-005

Missing IT Vulnerability Audit Records Vulnerability Scanning Failures

1896EUDOR-006

Missing IT Vulnerability Audit Records Consent Logging Integrity

1897EUDOR-007

Missing IT Vulnerability Audit Records Opt-Out Links Visibility

1898EUDOR-008

Missing IT Vulnerability Audit Records Privacy Notice Disclosures

1899EUDOR-009

Missing IT Vulnerability Audit Records Audit Control Verification

1900EUDOR-010

Missing IT Vulnerability Audit Records Administrative Key Credentials

1901EUCTA-001

Missing Beneficial Ownership Details in Portal Footer

1902EUCTA-002

Missing Beneficial Ownership Details in Portal Footer Audit and Record Failures

1903EUCTA-003

Missing Beneficial Ownership Details in Portal Footer Interface Design Flaws

1904EUCTA-004

Missing Beneficial Ownership Details in Portal Footer Cryptographic Strengths

1905EUCTA-005

Missing Beneficial Ownership Details in Portal Footer Vulnerability Scanning Failures

1906EUCTA-006

Missing Beneficial Ownership Details in Portal Footer Consent Logging Integrity

1907EUCTA-007

Missing Beneficial Ownership Details in Portal Footer Opt-Out Links Visibility

1908EUCTA-008

Missing Beneficial Ownership Details in Portal Footer Privacy Notice Disclosures

1909EUCTA-009

Missing Beneficial Ownership Details in Portal Footer Audit Control Verification

1910EUCTA-010

Missing Beneficial Ownership Details in Portal Footer Administrative Key Credentials

1911WCAG2-001

Inadequate Button Target Size

1912WCAG2-002

Inadequate Button Target Size Audit and Record Failures

1913WCAG2-003

Inadequate Button Target Size Interface Design Flaws

1914WCAG2-004

Inadequate Button Target Size Cryptographic Strengths

1915WCAG2-005

Inadequate Button Target Size Vulnerability Scanning Failures

1916WCAG2-006

Inadequate Button Target Size Consent Logging Integrity

1917WCAG2-007

Inadequate Button Target Size Opt-Out Links Visibility

1918WCAG2-008

Inadequate Button Target Size Privacy Notice Disclosures

1919WCAG2-009

Inadequate Button Target Size Audit Control Verification

1920WCAG2-010

Inadequate Button Target Size Administrative Key Credentials

1921EAAAX-001

Inaccessible E-Commerce Checkout Controls

1922EAAAX-002

Inaccessible E-Commerce Checkout Controls Audit and Record Failures

1923EAAAX-003

Inaccessible E-Commerce Checkout Controls Interface Design Flaws

1924EAAAX-004

Inaccessible E-Commerce Checkout Controls Cryptographic Strengths

1925EAAAX-005

Inaccessible E-Commerce Checkout Controls Vulnerability Scanning Failures

1926EAAAX-006

Inaccessible E-Commerce Checkout Controls Consent Logging Integrity

1927EAAAX-007

Inaccessible E-Commerce Checkout Controls Opt-Out Links Visibility

1928EAAAX-008

Inaccessible E-Commerce Checkout Controls Privacy Notice Disclosures

1929EAAAX-009

Inaccessible E-Commerce Checkout Controls Audit Control Verification

1930EAAAX-010

Inaccessible E-Commerce Checkout Controls Administrative Key Credentials

1931ONADA-001

Missing Accessibility Feedback Channel

1932ONADA-002

Missing Accessibility Feedback Channel Audit and Record Failures

1933ONADA-003

Missing Accessibility Feedback Channel Interface Design Flaws

1934ONADA-004

Missing Accessibility Feedback Channel Cryptographic Strengths

1935ONADA-005

Missing Accessibility Feedback Channel Vulnerability Scanning Failures

1936ONADA-006

Missing Accessibility Feedback Channel Consent Logging Integrity

1937ONADA-007

Missing Accessibility Feedback Channel Opt-Out Links Visibility

1938ONADA-008

Missing Accessibility Feedback Channel Privacy Notice Disclosures

1939ONADA-009

Missing Accessibility Feedback Channel Audit Control Verification

1940ONADA-010

Missing Accessibility Feedback Channel Administrative Key Credentials

1941SEC50-001

Missing Closed Captions on Training Videos

1942SEC50-002

Missing Closed Captions on Training Videos Audit and Record Failures

1943SEC50-003

Missing Closed Captions on Training Videos Interface Design Flaws

1944SEC50-004

Missing Closed Captions on Training Videos Cryptographic Strengths

1945SEC50-005

Missing Closed Captions on Training Videos Vulnerability Scanning Failures

1946SEC50-006

Missing Closed Captions on Training Videos Consent Logging Integrity

1947SEC50-007

Missing Closed Captions on Training Videos Opt-Out Links Visibility

1948SEC50-008

Missing Closed Captions on Training Videos Privacy Notice Disclosures

1949SEC50-009

Missing Closed Captions on Training Videos Audit Control Verification

1950SEC50-010

Missing Closed Captions on Training Videos Administrative Key Credentials

1951EEOC-001

Missing Automated Hiring Algorithmic Bias Audit

1952EEOC-002

Missing Automated Hiring Algorithmic Bias Audit Audit and Record Failures

1953EEOC-003

Missing Automated Hiring Algorithmic Bias Audit Interface Design Flaws

1954EEOC-004

Missing Automated Hiring Algorithmic Bias Audit Cryptographic Strengths

1955EEOC-005

Missing Automated Hiring Algorithmic Bias Audit Vulnerability Scanning Failures

1956EEOC-006

Missing Automated Hiring Algorithmic Bias Audit Consent Logging Integrity

1957EEOC-007

Missing Automated Hiring Algorithmic Bias Audit Opt-Out Links Visibility

1958EEOC-008

Missing Automated Hiring Algorithmic Bias Audit Privacy Notice Disclosures

1959EEOC-009

Missing Automated Hiring Algorithmic Bias Audit Audit Control Verification

1960EEOC-010

Missing Automated Hiring Algorithmic Bias Audit Administrative Key Credentials

1961BIPAX-001

Missing Biometric Scanner Consent in Virtual Try-On

1962BIPAX-002

Missing Biometric Scanner Consent in Virtual Try-On Audit and Record Failures

1963BIPAX-003

Missing Biometric Scanner Consent in Virtual Try-On Interface Design Flaws

1964BIPAX-004

Missing Biometric Scanner Consent in Virtual Try-On Cryptographic Strengths

1965BIPAX-005

Missing Biometric Scanner Consent in Virtual Try-On Vulnerability Scanning Failures

1966BIPAX-006

Missing Biometric Scanner Consent in Virtual Try-On Consent Logging Integrity

1967BIPAX-007

Missing Biometric Scanner Consent in Virtual Try-On Opt-Out Links Visibility

1968BIPAX-008

Missing Biometric Scanner Consent in Virtual Try-On Privacy Notice Disclosures

1969BIPAX-009

Missing Biometric Scanner Consent in Virtual Try-On Audit Control Verification

1970BIPAX-010

Missing Biometric Scanner Consent in Virtual Try-On Administrative Key Credentials

1971CIPAX-001

Chatbot Live Transcription Without CIPA Warning

1972CIPAX-002

Chatbot Live Transcription Without CIPA Warning Audit and Record Failures

1973CIPAX-003

Chatbot Live Transcription Without CIPA Warning Interface Design Flaws

1974CIPAX-004

Chatbot Live Transcription Without CIPA Warning Cryptographic Strengths

1975CIPAX-005

Chatbot Live Transcription Without CIPA Warning Vulnerability Scanning Failures

1976CIPAX-006

Chatbot Live Transcription Without CIPA Warning Consent Logging Integrity

1977CIPAX-007

Chatbot Live Transcription Without CIPA Warning Opt-Out Links Visibility

1978CIPAX-008

Chatbot Live Transcription Without CIPA Warning Privacy Notice Disclosures

1979CIPAX-009

Chatbot Live Transcription Without CIPA Warning Audit Control Verification

1980CIPAX-010

Chatbot Live Transcription Without CIPA Warning Administrative Key Credentials

1981LKSG-001

Missing Supply Chain Grievance Channel

1982LKSG-002

Missing Supply Chain Grievance Channel Audit and Record Failures

1983LKSG-003

Missing Supply Chain Grievance Channel Interface Design Flaws

1984LKSG-004

Missing Supply Chain Grievance Channel Cryptographic Strengths

1985LKSG-005

Missing Supply Chain Grievance Channel Vulnerability Scanning Failures

1986LKSG-006

Missing Supply Chain Grievance Channel Consent Logging Integrity

1987LKSG-007

Missing Supply Chain Grievance Channel Opt-Out Links Visibility

1988LKSG-008

Missing Supply Chain Grievance Channel Privacy Notice Disclosures

1989LKSG-009

Missing Supply Chain Grievance Channel Audit Control Verification

1990LKSG-010

Missing Supply Chain Grievance Channel Administrative Key Credentials

1991CSRD-001

Missing Digital Sustainability Disclosures

1992CSRD-002

Missing Digital Sustainability Disclosures Audit and Record Failures

1993CSRD-003

Missing Digital Sustainability Disclosures Interface Design Flaws

1994CSRD-004

Missing Digital Sustainability Disclosures Cryptographic Strengths

1995CSRD-005

Missing Digital Sustainability Disclosures Vulnerability Scanning Failures

1996CSRD-006

Missing Digital Sustainability Disclosures Consent Logging Integrity

1997CSRD-007

Missing Digital Sustainability Disclosures Opt-Out Links Visibility

1998CSRD-008

Missing Digital Sustainability Disclosures Privacy Notice Disclosures

1999CSRD-009

Missing Digital Sustainability Disclosures Audit Control Verification

2000CSRD-010

Missing Digital Sustainability Disclosures Administrative Key Credentials

Oracle v2.1 · Live

Terminal Threat Scanner

Drop in any domain. Oracle probes WCAG, ADA, GDPR, CCPA, PCI-DSS, SOC 2, and ISO 27001 in seconds and returns a live compliance score.

oracle-threat-scanner — bash
$

Enter a domain above and click Initiate Scan to run the Oracle compliance audit.

Disclaimer: The results of this automated scan are for informational and educational purposes only and do not constitute official legal advice. The specified fine amounts reflect the maximum possible legislative sanctions for the respective types of violations.

Don't wait for the fine.

Scan your domain now — free, instant, no signup.

Run Free Enterprise Audit