risk
Excessive collection, purpose creep and secondary use
Collecting more personal data than necessary (data-minimization failure) and using it for purposes materially different from those disclosed without fresh notice/consent, expanding attack surface and violating purpose-limitation.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- privacy
- domain
- Data Protection & Privacy
- taxonomy
- nist-privacy-risk
- inherent_rating
- high
Details
- risk_id
- data-excessive-collection-purpose-creep
- category
- privacy
- likelihood
- high
- impact
- medium
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- nist-privacy-risk
Source
No record-specific source URL is provided.
Connections
- UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary mitigates Excessive collection, purpose creep and secondary use
- strength
- primary
- rationale
- Purpose limitation plus the minimum-necessary standard directly restricts over-use/over-disclosure and blocks secondary use without new authority.
- UC-DATA-01 — Process personal data only under a documented lawful basis mitigates Excessive collection, purpose creep and secondary use
- strength
- related
- rationale
- Collecting personal data only for the documented purposes constrains over-collection and purpose creep at the point of collection.
- UC-DATA-13 — Safeguard personal information with reasonable security mitigates Excessive collection, purpose creep and secondary use
- strength
- primary
- rationale
- PII-protection requirements include data-minimization and purpose-limitation, directly addressing over-collection and purpose creep.