OWASP Top 10 for LLM Applications 2025
Sensitive Information and Privacy

OWASP Top 10 for LLM Applications 2025 OWASPLLM-3: Sensitive Information Disclosure and Privacy (LLM02)

Address OWASP LLM02:2025 Sensitive Information Disclosure + Privacy and Lawful Basis for LLM Processing. Sensitive Information Disclosure occurs when LLM systems disclose training data + user data + system data including PII + credentials + intellectual property + trade secrets to unauthorised parties via memorisation + leakage + inference + side-channel attacks. Mitigations include (a) classify data flowing into + through LLM systems + apply appropriate protection per classification + (b) implement data minimisation in training + fine-tuning + retrieval + (c) implement differential privacy + sanitisation + redaction for training data + (d) implement access controls + output filtering against unauthorised disclosure + (e) implement appropriate legal basis + consent + DPIAs for personal data processing per applicable regulation (GDPR + CCPA + APPI + similar) + (f) maintain data subject rights handling including erasure consideration for trained models.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.