{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["nist-privacy-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-privacy-program-noncompliance","description":"Failure to honour data-subject rights (access, deletion, portability, restriction) on time, missing lawful-basis/consent documentation, defective consent mechanisms, invalid cross-border transfer mechanisms, or inadequate notices — driving fines and private rights of action.","details":{"category":"privacy","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"data-privacy-program-noncompliance","taxonomies":["nist-privacy-risk","enterprise-risk"],"treatment":"mitigate"},"id":"risk:data-privacy-program-noncompliance","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-privacy-program-noncompliance","sourceIds":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","soc2"],"sourceUrl":null,"title":"Privacy-program non-compliance (GDPR, CCPA, state laws)","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2ce39baacf4e08681a6e141f99447226f227084a6d955c5b9f97cc90a6558291","properties":{"rationale":"Maintaining legally-required notices and registrations addresses the inadequate-notice driver of regulatory non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:42fc495ceafeb9fe0981d70396cc5adef709d767e5063e137704d2b82e254f00","properties":{"rationale":"Customer-facing input and output data policies (training use, retention, ownership, opt-out, deletion) are the notice-and-consent backbone of a privacy program for AI services.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-17-420198e3.json","sourceId":"uc:UC-AI-17","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4f8d93673fa9f3293d2ecdc19e71b8646b700f06b36ecb14ab10189217fb8cff","properties":{"rationale":"Correcting identified deficiencies and monitoring complaint trends catches and remediates compliance gaps.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-17-e1b78e4e.json","sourceId":"uc:UC-DATA-17","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5522ed4a796ef520de6c41be5b2f846782fa1694b789f63a2f7d8da09f23d2cf","properties":{"rationale":"Valid, documented transfer mechanisms remove the invalid-cross-border-transfer driver of non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:74b60b0522af619e0dfe45df700b919f5d141c72346f71ae5c412129875a17bb","properties":{"rationale":"Providing accountings on verified request fulfills a data-subject right, supporting compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-14-2c0be84c.json","sourceId":"uc:UC-DATA-14","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:88ce1cc28f79db491c622197df631497ee89a669b669c4d16605501f16ebc046","properties":{"rationale":"Recording the lawful basis in a register removes the 'missing lawful-basis documentation' driver of regulatory fines and private actions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-01-9fcf72e8.json","sourceId":"uc:UC-DATA-01","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8ee06b48f8255c98016fe00d9a68a99481f46dc60bb8934f6c8725f29fd01a01","properties":{"rationale":"Written processor commitments and their enforcement support the organization's data-protection compliance obligations.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-16-57ae2c9a.json","sourceId":"uc:UC-DATA-16","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:91009775ad3f068d3dc9c55e3e41cb9b4a1800e0aff8127b232b2f778cb7108b","properties":{"rationale":"Valid consent capture, records, and honored withdrawals/opt-outs remove the defective-consent-mechanism driver of fines and private actions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b2a214b13d62b4e14783c3eae4ada122863c80907dd25fab0198d7be368231ee","properties":{"rationale":"Fulfilling access requests within statutory deadlines addresses the failure-to-honor-DSR driver of non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","sourceId":"uc:UC-DATA-06","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:babc2f679c479b5e1c64ef64adffeec5727c9bab34ed9fee8461e2e6be6d107d","properties":{"rationale":"Executing/denying correction requests within statutory deadlines addresses the DSR-timeliness driver of non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f904d64067d0121654ee8d018acdf44e96484364813f8f3778bfcbc227893874","properties":{"rationale":"A verified process executing erasure/portability/restriction/objection within statutory clocks is the core defense against failing to honor DSRs on time.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ff37d12965458a338a9f729a715c02966dfd4deec003c4428b559f0b677d3cae","properties":{"rationale":"The pre-operation authorization decision forces privacy requirements to be assessed before a system or internal connection is used.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-26-3a91d068.json","sourceId":"uc:UC-AUDIT-26","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"}],"schemaVersion":1}
