risk
Absence of privacy-by-design and default
Because systems and products are built without embedding privacy controls at the architecture level, privacy protections are bolted on after launch rather than applied by default, so personal data is over-collected and exposed and costly manual remediation is required.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- privacy
- domain
- Data Protection & Privacy
- Secure Development (SDLC) & Application Security
- taxonomy
- nist-privacy-risk
- inherent_rating
- medium
Details
- risk_id
- privacy-no-privacy-by-design
- category
- privacy
- likelihood
- medium
- impact
- medium
- inherent_rating
- medium
- treatment
- mitigate
- taxonomies
- nist-privacy-risk
Source
No record-specific source URL is provided.
Connections
- UC-SDLC-03 — Define and approve security requirements for applications mitigates Absence of privacy-by-design and default
- strength
- primary
- rationale
- Eliciting and approving data-protection requirements before design embeds privacy at the requirements stage rather than bolting it on post-launch.
- UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary mitigates Absence of privacy-by-design and default
- strength
- related
- rationale
- The minimum-necessary/data-minimization requirement is a core privacy-by-default principle reducing over-collection and exposure.
- UC-SDLC-04 — Engineer systems with secure architecture and design mitigates Absence of privacy-by-design and default
- strength
- primary
- rationale
- Applying data-protection and least-privilege principles at the architecture stage embeds privacy/security by design and default.
- UC-DATA-12 — De-identify, mask, or pseudonymize personal data mitigates Absence of privacy-by-design and default
- strength
- related
- rationale
- Applying pseudonymization when full identifiers aren't required is a core privacy-by-design/default technique.
- UC-SDLC-02 — Plan and resource development programs and projects mitigates Absence of privacy-by-design and default
- strength
- related
- rationale
- Identifying and resourcing privacy/security requirements at planning enables privacy engineering rather than post-launch remediation.