Note

  • The information on this page is presented as-is, and does not constitute legal advice.

Privacy

Ensure that the following points have been covered during your deployment.

  Action
“Security policy verifications & web security event logging” has been added to the Record Of Processing Activities (ROPA)
An authorisation and retention policy has been defined regarding the generated security events
End-users have been notified of the use of Citadel (and this is documented)
End-users have been informed of their right to be informed, to access, to rectify, and to erase the data that concerns them (and this is documented)
Deviations from the default Citadel configuration and best practices have been documented

If you configure the Privacy Notice (see manual) then this will most likely cover the notification of Citadel and the privacy rights.