OWASP / www-project-ai-security-and-privacy-guide

OWASP Foundation Web Respository
199 stars 53 forks source link

Remove reference to GDPR, refer to FIPPs instead #2

Closed engin-bozdag closed 1 year ago

engin-bozdag commented 1 year ago

The GDPR section is incomplete and contains some errors. Further, GDPR is only one of the privacy legislations available. There are other legislations that have more strict rules than the GDPR. Adding examples of issues:

engin-bozdag commented 1 year ago

Two options: 1) you revise GDPR section to ensure it aligns with GDPR. I am also happy to take a stab here if you want me to send a pull request with edits 2) Remove GDPR reference and stick to FIPP's (access, correct, minimization, accuracy, consent, purpose specification and use limitation, security, transparency).

robvanderveer commented 1 year ago

Thanks very much, Engin. I knew I could count on you. Wow, covering algorithm privacy is a slippery slope for sure. I just processed your most urgent comments and will pick the rest up later. I didn't cover article 25 because the guide is not meant to discuss engineering for privacy in general. It already states that, but I should make that more precise and refer to some external guidance on this (e.g. article 25).

robvanderveer commented 1 year ago

Engin has delivered on these issues