Skip to content

GDPR

GDPR — EU Regulation 2016/679. Run with --compliance=Gdpr to keep only the findings mapped to it, with their control ids in a ControlId column.

Controls covered: Art. 5(1)(f), Art. 32(1)(a/b/c/d) — technical security of processing only

Official text: Regulation (EU) 2016/679.

In the tables below, Where it appears names the checks that carry the control. (declared) marks a control of the standard that is relevant to a virtualisation cluster but that no check can verify from the Proxmox VE API — typically a process, a plan or a test. It is listed so the coverage is explicit: evidence for it has to come from outside cv4pve-diag.

Only technical articles relevant to a virtualisation cluster. Procedural / organisational requirements (DPIA, breach notification, data subject rights, …) are out of scope.

Article Title Where it appears
Art. 5(1)(f) Integrity and confidentiality (security principle) TFA, access privilege, certificates, firewall, account lifecycle, duplicate MAC
Art. 32(1)(a) Pseudonymisation and encryption of personal data Certificates
Art. 32(1)(b) Confidentiality, integrity, availability and resilience of processing systems HA, replication, single-node, storage/node availability, patch, CVE, disk cache integrity, TFA
Art. 32(1)(c) Timely restoration of availability after an incident Backup (all areas), backup storage availability
Art. 32(1)(d) Regular testing of the effectiveness of security measures Cluster log, task failures, NTP, services, metric server, user notification, firewall audit logging

How the mapping works, and its limits: Compliance overview.