Certificate Problem Report for a TLS- or S/MIME certificate
Privacy policy in the event of security incidents
Why do we collect data within the scope of this process?
As the certificate issuer, D-Trust GmbH must provide a way to report suspected certificate misuse. The following data will be collected in connection:
- first and family name, e-mail (mandatory) and telephone number (optional).
D-Trust GmbH is obliged to contact both, the person reporting the security incident and the subscriber. Please refer to the Baseline Requirements of the CA/B Forum https://cabforum.org/baseline-requirements-documents/ for more information. The legitimate interest of D-Trust GmbH is to protect our products and the general public from insecure online communication (using TLS-secured connections).
How do we process the data and how long is the data stored?
In the Support area of D-Trust's website you can report a security problem with TLS or S/MIME certificates. Also for CA certificates issued according to the specifications of the CA/Browser Forum. Simply complete the form provided and send it to the e-mail address shown there. The report will then be handled according to a defined process in the IT systems of Bundesdruckerei GmbH and D-Trust GmbH. Any personal data from the report will be kept in the IT systems of Bundesdruckerei GmbH and D-Trust GmbH until the entire incident was clarified. If neither the reporter nor the subscriber provides further feedback within a period of 12 weeks, the data will be deleted at the end of the following year.
Who will be informed about the incident?
In order to process the case or connected to audits, both Bundesdruckerei GmbH and D-Trust GmbH and, if applicable, the respective conformity assessment body will receive the contents of the report including the personal data of the reporter.
Who is responsible according to the General Data Protection Regulation?
The responsible representative for data processing and the rights of the persons concerned and the right of appeal to a supervisory authority for data protection can be found in the following data protection information: https://www.d-trust.net/en/privacy-statement