Protect personal data
Any personal data processed through an API must be protected, and their processing must be documented in the same way as in other information systems.
When designing an API, you must draw up a privacy statement to be published together with the API. Personal data, including e-mail and IP addresses, are often collected when using APIs, as a result of which a personal data file builds up. Personal data may need to be collected for such purposes as tracking API key use.