Difference between revisions of "OWASP Top 10 Privacy Risks Project"

Jump to: navigation, search
Line 108: Line 108:
* Florian Stahl
* Florian Stahl
* Stefan Burgmair
* Stefan Burgmair
* Vinoth Sivasubramanian

Revision as of 04:33, 25 February 2014


OWASP Project Header.jpg

OWASP Top 10 Privacy Risks Project

OWASP Top 10 Privacy Risks Project aims to develop a top 10 list for privacy risks in web applications because currently there is no such catalog available. The list will cover technological and organizational aspects like missing data encryption or the lack of transparency.


Discussions about how to protect privacy and personal data are ongoing and mostly pushed by lawyers and legal experts. But there is no specific description of privacy risks for web applications that companies can apply during development and for users to check whether their privacy is protected well. There are helpful concepts like Privacy by Design, but no detailed description of real life risks causing incidents and privacy breaches in practice. This project will mitigate this gap and create a Top 10 list with technical and organizational privacy risks in web applications and possible counter-measures. Beyond that, we want to raise the awareness of the management and people who are involved in creating and operating web applications for privacy risks during the SDLC and the usage of the data, bring visibility to the right issues and create a community of people that gives practical input for further developement of this project.


A detailed description will be provided shortly.


OWASP Top 10 Privacy Risks Project is free to use. It is licensed under the GNU GPL v3 License.

What is the Top 10 Privacy Risks Project?

Description in a nutshell

Contact us

Project Leader

Florian Stahl

Related Projects

Quick Download

  • Link to page/download

News and Events

  • [20 Feb 2014] Project Start

External Links

OECD Privacy Guidelines


Owasp-incubator-trans-85.png Owasp-builders-small.png
Project Type Files DOC.jpg

Why is this project only about web applications and not about any kind of software?
Web applications can easily collect data from users without their permission or informing them about the usage of their data. Trackers and cookies deliberately enable the monitoring of the users behaviour, often for selling those data. That is the reason why this subject is so important, especialy for web applications.
What is the difference between this project and the OWASP top 10?
There are two main differences. First, the OWASP top 10 describes technical risks, that are not primarily affecting privacy. Second, the OWASP top 10 does neither regard intended parts of the software like cookies or trackers nor organisational issues like privacy agreements or profiling.
Why should companys and other organisations be concerned about privacy risks?
Privacy risks may have serious consequences for an organisation, such as:
  • perceived harm to privacy;
  • a failure to meet public expectations on the protection of personal information;
  • retrospective imposition of regulatory conditions;
  • low adoption rates or poor participation in the scheme from both the public and partner organisations;
  • the costs of redesigning the system or retro-fitting solutions;
  • collapse of a project or completed system;
  • withdrawal of support from key supporting organisations due to perceived privacy harms; and/ or
  • failure to comply with the law, leading to enforcement action from the regulator or compensation claims from individuals.

(Source: http://ico.org.uk/pia_handbook_html_v2/html/1-Chap2-2.html)


The Top 10 Privacy Risk list is developed by a team of volunteers. The primary contributors to date have been:

  • Florian Stahl
  • Stefan Burgmair
  • Vinoth Sivasubramanian


As of February 2014, the proceeding is:

  • Collection of interested participants and supporters (building a team) – till march 14
  • Developing a method for identifying the risks – till mid-march 2014
  • Creating a draft list of risks - till first week of april 2014
  • Discussing the draft list - till end of april 2014
  • Developing a rating method - from now on, till end of april 2014
  • Rating the risks, creating the list of Top 10 Privacy Risks (Version 1.0) and discus the results - till end of may 2014
  • Creating papers, best practices, etc. - Q3/2014
  • Ongoing improvement, rerating etc. - Q3/2014

Involvement in the development and promotion of the project is actively encouraged! You do not have to be a security or privacy expert in order to contribute. Some of the ways you can help:

  • Discuss with us at the Forum for Discussions and Progress
  • Answer the questionnaire for identifying and rating the Top 10 privacy list (will be provided soon)
  • Tell your colleagues and friends about the project
  • Provide feedback and input (feel free to contact us)

To avoid overwriting issues we will use google docs for our discussions.


What does this OWASP project offer you?
What releases are available for this project?
what is this project?
Name: OWASP Top 10 Privacy Risks Project (home page)
Purpose: "The deliverable of the project will be a PDF document or web site with a list of the top 10 privacy risks in web applications and possible counter-measures. The goal is to develop a top 10 list for privacy risks in web applications to raise the awareness for this issue and enable the responsible persons to handle personal data in a more responsible way.

The list will cover technological and organizational aspects like missing data encryption or the lack of transparency."

License: GNU GPL v3 License
who is working on this project?
Project Leader(s):
  • Florian Stahl @
  • Stefan Burgmair @
how can you learn more?
Project Pamphlet: Not Yet Created
Project Presentation:
Mailing list: Mailing List Archives
Project Roadmap: View
Key Contacts
  • Contact Florian Stahl @ to contribute to this project
  • Contact Florian Stahl @ to review or sponsor this project
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
Not Yet Published
last reviewed release
Not Yet Reviewed

other releases