← All findings
f-014 — GDPR / KVKK over-disclosure — customer records via /customer-lookup
high · support-portal · status open · first seen 2026-04-23
Framework mapping
| Framework | Controls / requirements |
|---|---|
| GDPR (EU 2016/679) Privacy |
Art.5(1)(c) Art.32 |
| KVKK (Türkiye 6698) Privacy |
Md.4 Md.12 |
| SOC 2 Type II Trust services |
CC6.7 |