Privacy

Legal Disclaimer This document has been prepared by the developer of Citadel solely for informational purposes in order to facilitate the Organisation’s deployment of Citadel. It is provided as a general template and technical reference only. It does not constitute legal advice, regulatory advice, or a legal assessment of the Organisation’s specific processing activities. It does not replace the Organisation’s obligation to assess the lawfulness of its processing operations, determine whether a Data Protection Impact Assessment (DPIA) is required under Article 35 GDPR or any applicable data protection legislation, or ensure compliance with applicable employment, cybersecurity, and data protection laws.

Ensure that, amongst others, the following points have been covered during your deployment.

  Action
The data processing acitvity has been added to the Record Of Processing Activities (ROPA)
Access rights and retention policy has been defined regarding the generated security events
End-users have been notified of the use of Citadel (and this is documented)
End-users have been informed of the data processing operations taking place following the implementation of Citadel and are informed of their data subjects rights including right of access, right to data rectification and right to data deletion (and this is documented)
Deviations from the default Citadel configuration and best practices have been documented

You can use the Privacy Notice built into Citadel, as part of your obligations to inform your users. See the manual for more information.

Legal Disclaimer This installation guide does not replace the controller’s obligation to conduct and document its own assessment based on the specific characteristics of its deployment.