[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9z04wK1iIef_3EuevjWNk3V7z9o2v6FwJeQ9h9INkr0":3,"$fDuOfbrGklFg9DNstLQj01v77JKgm8YTNP3W1V3nd5U4":72,"faq-section-":226,"white_papers":227},{"tableOfContents":4,"markDownContent":5,"htmlContent":6,"metaTitle":7,"metaDescription":7,"wordCount":8,"readTime":9,"title":10,"nbDownloads":11,"excerpt":12,"lang":13,"url":14,"intro":15,"featured":4,"state":16,"author":17,"authorId":18,"datePublication":22,"dateCreation":23,"dateUpdate":24,"mainCategory":25,"categories":41,"metaDatas":69,"imageUrl":7,"imageThumbUrls":70,"id":71},false,"## 🚀 New features\n\n### Integrations: Microsoft Teams connector\n\n![](https://static.dastra.eu/richtext/83c361b2-2467-467a-b3af-6c10c002d87b/pasted-image-0-original.png)\n\nWorkflow rules carry most of your reminders: a review that is coming due, an access request that changes stage, a task that remains unassigned. Until now, these reminders had only two destinations: the Dastra notification center or email notifications. For some users in your organization, however, the reminder gets lost in an inbox, or they do not think to open the notification center to check whether anything has happened.\n\nThe **Microsoft Teams connector** opens up a third destination, where your team is already communicating. You link a Teams channel to your workspace, and your workflow rules then gain a new action: post a notification in that channel.\n\nThe rule author writes the title and message themselves, inserts data from the triggering object, and chooses whether or not to include a direct link to that object in Dastra. The connection can be tested from the configuration screen, and the connector can be paused or uninstalled at any time.\n\n![](https://static.dastra.eu/richtext/f221c0a4-ca4f-40c1-9879-582a3633fdab/pasted-image-2-original.png)\n\n### Integrations: Jira connector\n\n![](https://static.dastra.eu/richtext/4d3d29b8-a4c9-4228-b6fc-9a356d16469f/pasted-image-3-original.png)\n\nTeams that handle data subject rights requests often work in Jira, where each request takes the form of a ticket. Without automatic linking, the same request has to be re-entered in Dastra and its progress tracked twice, risking divergence between the two tools. The **Jira connector** now brings the solution into Dastra.\n\nThe **Jira connector** links a Jira project to the data subject rights register. A ticket created in Jira automatically creates a request in Dastra, with the requester’s information and the subject of the request. The status then stays aligned **both ways**: the Jira ticket status advances the request stage in Dastra, and a stage change in Dastra updates the Jira ticket.\n\nConfiguration is fully self-service from the workspace settings:\n\n- Authenticate Dastra with Jira, then choose the relevant project and issue type.\n- Describe how ticket fields feed the request.\n- Map each Jira status to a Dastra workflow stage.\n- Define the default organisational unit for newly created requests.\n- Set up the incoming notification from Jira, protected by a secret generated by Dastra.\n\n![](https://static.dastra.eu/richtext/2966ff58-1219-4985-9d62-690174bd1acd/pasted-image-4-original.png)\n\nYou manage your requests from your team’s tool while keeping the register, history, and automations required by your compliance needs in Dastra.\n\n**What is Jira?**\n\nJira is Atlassian’s project and issue tracking platform, widely used by teams to track tasks, bugs, and workflows.\n\n### Integrations: SAP LeanIX connector\n\n![](https://static.dastra.eu/richtext/012136a4-596c-46e2-9a82-bd2f0638f056/pasted-image-5-original.png)\n\nFor some organisations or work teams, the application map lives in SAP LeanIX: each application has its own record there, with its common name, description, lifecycle stage, owners, and the number under which the company identifies it. Dastra’s asset repository, for its part, holds data mapping and compliance information: linked processing activities, security measures, vendor, reviews. Without a link between the two, the mapping has to be re-entered application by application, and the two inventories diverge as soon as the first deployment goes live.\n\nThe **SAP LeanIX connector** links a LeanIX instance to the asset repository. Automatically import your Application fact sheets from SAP LeanIX into Dastra as assets (daily sync, upsert). Since the LeanIX data model is unique to each instance, no fixed mapping would work: you choose, from among the fields actually declared in your model, those that populate each asset field, including the internal number to the asset reference and the owner’s address to a custom field.\n\n![](https://static.dastra.eu/richtext/5bbb6387-2334-4189-9ff5-3fac18ab2bf3/pasted-image-6-original.png)\n\nYou also decide whether missing assets should be created and how to match a LeanIX record with an asset already present in Dastra. Each imported asset keeps track of the fact sheet it comes from, and the daily refresh never overwrites anything entered in Dastra.\n\nWhat is SAP LeanIX?\n\nSAP LeanIX is a SaaS enterprise architecture management platform. It maintains an inventory of applications, IT components, and their lifecycle in order to govern and rationalise the information system.\n\n### Integrations: ServiceNow connector\n\n![](https://static.dastra.eu/richtext/4d1b5ae0-8e66-4571-b7b1-0f808e1113fb/pasted-image-7-original.png)\n\nYour applications are inventoried in ServiceNow, while compliance is documented in Dastra? Without a link between the two tools, every new application must be entered twice, and the gap between the technical inventory and the compliance repository grows without anyone knowing which one is authoritative.\n\nMatching is all the more difficult because the two tools do not speak the same language: the same concept (an application’s status, type, or criticality) does not have the same name or the same values on each side, and each ServiceNow instance is configured differently.\n\n![](https://static.dastra.eu/richtext/c4e27bf1-d550-4acf-a736-68c8a4151799/pasted-image-8-original.png)\n\nThe **ServiceNow connector** links a ServiceNow instance to the asset repository. You define the mapping between the columns of the business application table and Dastra asset fields, **including value translation from one list to another**, and you choose whether missing assets should be created and how an incoming record should be matched to an existing asset. The sync then runs daily, without ever deleting the work of your compliance teams.\n\nWhat is ServiceNow?\n\nServiceNow is a SaaS digital workflow platform (ITSM, ITOM, ITAM, HR, SecOps, etc.) that centralises and automates IT and business processes within an organisation. It is widely used for incident management, requests, assets, and enterprise-scale data.\n\n---\n\n### Compliance: framework version management\n\n![](https://static.dastra.eu/richtext/4941417a-59da-4255-8f0d-ecd1765d20a0/pasted-image-9-original.png)\n\nYou can now be **notified when a newer version of the source framework is available**, preview changes to controls, tests, risk scenarios, and threats, and then create an up-to-date new version by confirming.\n\n**Framework versioning** follows the same principle already proven in the Questionnaires module. If your organisation can manage custom frameworks, you can now create a new version from an existing one, work on it as a draft, publish it, and retain the history.\n\nYou can therefore:\n\n- **Create a new version** of a framework, custom or imported, carrying over its chapters, requirements, and linked controls, with a change note and an automatically assigned number.\n- **Publish or unpublish** a version, **delete** an abandoned draft, and let multiple published versions of the same framework **coexist**.\n- Designate the **main version**, which will be suggested and installed by default when a framework is added to a project from the library.\n- View the **full version history** (number, change note, status, date, and author) and open a previous version in read-only mode.\n\nThe main benefit is the **independence of your compliance projects**. A project is tied to a specific version: a project built on version 1 of a framework is not affected by the framework evolving to version 2, and both versions can be used at the same time on two different projects. Migrating a project to another version remains a manual, explicit action, blocked while an audit is in progress so as not to distort ongoing work.\n\n![](https://static.dastra.eu/richtext/1e772972-bc97-486a-9d39-649bbfcc8ec4/pasted-image-10-original.png)\n\nThe requirements of a published version are locked, metadata (label, logo, description) remains editable, and creating a version does not consume any additional quota. Your existing frameworks automatically become version 1, with their current status preserved and your projects attached to this version 1: no action is required from you.\n\nIn a control record, the linked requirements panel displays the **source framework version number**: two identical requirements coming from two different versions are no longer seen as duplicates.\n\n---\n\n### Cookies: management of uncategorised cookies\n\nThe cookie scan compares each detected cookie against Dastra’s service repository. When no match is found, the cookie remains orphaned. Yet your consent banner addresses visitors **by service** only: a cookie not linked to any service is never shown to the visitor, and the consent collected does not cover it. Since the repository cannot know every proprietary or implementation-specific cookie, this happens on most scanned websites.\n\nWith the uncategorised cookie management tool, a “Uncategorised cookies” tab now appears both in the scan results screen and in the banner editor, preceded by a warning badge showing the count.\n\n![](https://static.dastra.eu/richtext/4fe49ea1-44e5-4394-ad9e-89ba9bc28752/pasted-image-11-original.png)\n\nFrom this list, you can:\n\n- **Link several cookies to an existing service** in a single action, without creating a duplicate if the cookie is already declared there.\n- **Create a new service from a selection**, with the form prefilled from the most frequent domain among the selected cookies.\n- **Delete** cookies you do not wish to declare, after confirmation.\n- **Remove a cookie from a service** to send it back to the uncategorised cookies list.\n\nCounters, the warning badge, and the distribution chart update immediately after each action, without rerunning the scan. Most importantly, **nothing is lost**: anything not handled when the banner is created remains attached to it and can be addressed later from the editor. Rerunning a scan on an existing banner compares detected cookies against the repository and then against your current configuration, and marks services already present with a green check.\n\nUncategorised cookies are never shown in the public banner: your visitors continue to see only services grouped by purpose.\n\n---\n\n### Security: passkey sign-in\n\n![](https://static.dastra.eu/richtext/459b88e0-da5a-4d5f-9aaa-8d43b5722a77/pasted-image-12-original.png)\n\nDastra now offers the ability to sign in using a **passkey**, with no password or verification code to enter.\n\nA **passkey** replaces the password and six-digit code with a simple check on your device: a fingerprint, face scan, or PIN. You no longer have anything to remember or copy, and sign-in takes only a few seconds.\n\nAbove all, it provides **protection** against phishing that passwords cannot offer. A password and a verification code can be entered on any page imitating Dastra, then immediately replayed elsewhere. A passkey, by contrast, works only on the real Dastra site: it stays on your device, never circulates, and therefore cannot be copied, intercepted, or reused.\n\nIn practical terms:\n\n- You create a passkey from the dedicated section of the **Account Security** page, or directly after signing in when Dastra offers it.\n- You then sign in **without entering a password or code**.\n- You can **name** your passkeys to distinguish them from one device to another, and delete them at any time.\n- The interaction with the existing **two-factor authentication** remains consistent: the passkey counts as strong proof and does not add a superfluous step.\n\nBrowsers that do not support passkeys continue to offer the usual sign-in flow. Organisations that have deployed single sign-on already have their own solution and are not concerned by this mechanism.\n\nRead the [passkey documentation](https://doc.dastra.eu/security/passkey)\n\n### Advanced configuration: send your security logs to your SIEM\n\n![](https://static.dastra.eu/richtext/5ba20b5c-887f-4075-98ea-797e0b6caa7a/pasted-image-13-original.png)\n\nDastra logs activity in your account: sign-ins, permission changes, API keys, SSO configurations, user or workspace deletions. Previously, these traces stayed in Dastra, whereas an organisation’s security monitoring is carried out in its SIEM, where logs from all applications are centralised. Correlating a permission change in Dastra with an incident detected elsewhere was therefore not possible.\n\nThe **SIEM integration** opens up two complementary routes.\n\nThe **real-time forwarding**, configured once for the whole account and reserved to its owner, sends each logged event to your collector address. Four formats are supported to cover the main tools on the market: **Splunk HEC (JSON)**, **CEF (Common Event Format)**, **Syslog (RFC 5424)**, and **Dynatrace (Log Monitoring v2)**. Authentication adapts to your collector (Bearer token, API key, custom authorisation scheme, custom header, or none), custom headers can be added, and a severity filter lets you forward only what matters. The connection is tested before saving, and no configuration is stored without a valid connection.\n\nThe **manual export** completes the setup: from the “Security logs” page, an “Export (SIEM)” menu produces a file in CEF, Syslog RFC 5424, or Splunk HEC format, applying the selected period and event types shown on screen. Useful for one-off backfills or for handing traces to an auditor. Spreadsheet export remains available alongside it, unchanged.\n\nThe authentication token is never shown again after saving, and empty information is omitted from the message rather than sent blank.\n\nWhat is a SIEM?\n\nA SIEM (Security Information and Event Management, for example Splunk, Microsoft Sentinel, QRadar) centralises your organisation’s security event logs for detection, investigation, and compliance.\n\n## ✨ Improvements\n\n### Processing register: AI assessment of the 9 DPIA criteria\n\nYou can now **ask the AI assistant** to **fill in the 9 assessment criteria from the EDPB list** based on the information already entered. You immediately know whether a DPIA is required, while retaining control over each proposed answer.\n\n![](https://static.dastra.eu/richtext/0b0a5540-40bf-410c-a73e-f30030d2e69f/pasted-image-14-original.png)\n\n### Filter on multiple custom fields:\n\nMany of you requested it: it is now possible to create filters on list-type custom fields (checkboxes or multi-select fields).\n\n### \\[Important change\\] Mandatory approval by questionnaire owners:\n\nThe audit questionnaire validation process has been redesigned to **separate individual approval from final publication**. Each validator (required or optional) can now approve the questionnaire independently via a dedicated button, with the option to leave a review comment and revoke their approval. Final publication (validation) is allowed only when **all** required validators have approved. Visual tracking of approval progress is displayed in the validation view, summary, response list, and validator manager. Pending owners are notified by email for each new approval.\n\nTo learn more, read [the questionnaire validation documentation](https://doc.dastra.eu/features/audit/questionnaire-validation)\n\n![](https://static.dastra.eu/richtext/d60ac7d8-9b8a-4f25-b46d-45fe33542dc6/pasted-image-15-original.png)\n\n### \\[Important change\\] Separation of write permission from create permission\n\nFrom now on, the permission to create new items (manually, with AI, or otherwise) has been fully separated from write permission across several modules. Rest assured, this will have no impact on your current role setup, which will automatically include write permission. The purpose of this feature is to allow a combination of the right to edit one’s own items and the right to create.","\u003Ch2 id=\"new-features\">🚀 New features\u003C/h2>\n\u003Ch3 id=\"integrations-microsoft-teams-connector\">Integrations: Microsoft Teams connector\u003C/h3>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/83c361b2-2467-467a-b3af-6c10c002d87b/pasted-image-0-original.png\" alt=\"\" />\u003C/p>\n\u003Cp>Workflow rules carry most of your reminders: a review that is coming due, an access request that changes stage, a task that remains unassigned. Until now, these reminders had only two destinations: the Dastra notification center or email notifications. For some users in your organization, however, the reminder gets lost in an inbox, or they do not think to open the notification center to check whether anything has happened.\u003C/p>\n\u003Cp>The \u003Cstrong>Microsoft Teams connector\u003C/strong> opens up a third destination, where your team is already communicating. You link a Teams channel to your workspace, and your workflow rules then gain a new action: post a notification in that channel.\u003C/p>\n\u003Cp>The rule author writes the title and message themselves, inserts data from the triggering object, and chooses whether or not to include a direct link to that object in Dastra. The connection can be tested from the configuration screen, and the connector can be paused or uninstalled at any time.\u003C/p>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/f221c0a4-ca4f-40c1-9879-582a3633fdab/pasted-image-2-original.png\" alt=\"\" />\u003C/p>\n\u003Ch3 id=\"integrations-jira-connector\">Integrations: Jira connector\u003C/h3>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/4d3d29b8-a4c9-4228-b6fc-9a356d16469f/pasted-image-3-original.png\" alt=\"\" />\u003C/p>\n\u003Cp>Teams that handle data subject rights requests often work in Jira, where each request takes the form of a ticket. Without automatic linking, the same request has to be re-entered in Dastra and its progress tracked twice, risking divergence between the two tools. The \u003Cstrong>Jira connector\u003C/strong> now brings the solution into Dastra.\u003C/p>\n\u003Cp>The \u003Cstrong>Jira connector\u003C/strong> links a Jira project to the data subject rights register. A ticket created in Jira automatically creates a request in Dastra, with the requester’s information and the subject of the request. The status then stays aligned \u003Cstrong>both ways\u003C/strong>: the Jira ticket status advances the request stage in Dastra, and a stage change in Dastra updates the Jira ticket.\u003C/p>\n\u003Cp>Configuration is fully self-service from the workspace settings:\u003C/p>\n\u003Cul>\n\u003Cli>Authenticate Dastra with Jira, then choose the relevant project and issue type.\u003C/li>\n\u003Cli>Describe how ticket fields feed the request.\u003C/li>\n\u003Cli>Map each Jira status to a Dastra workflow stage.\u003C/li>\n\u003Cli>Define the default organisational unit for newly created requests.\u003C/li>\n\u003Cli>Set up the incoming notification from Jira, protected by a secret generated by Dastra.\u003C/li>\n\u003C/ul>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/2966ff58-1219-4985-9d62-690174bd1acd/pasted-image-4-original.png\" alt=\"\" />\u003C/p>\n\u003Cp>You manage your requests from your team’s tool while keeping the register, history, and automations required by your compliance needs in Dastra.\u003C/p>\n\u003Cp>\u003Cstrong>What is Jira?\u003C/strong>\u003C/p>\n\u003Cp>Jira is Atlassian’s project and issue tracking platform, widely used by teams to track tasks, bugs, and workflows.\u003C/p>\n\u003Ch3 id=\"integrations-sap-leanix-connector\">Integrations: SAP LeanIX connector\u003C/h3>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/012136a4-596c-46e2-9a82-bd2f0638f056/pasted-image-5-original.png\" alt=\"\" />\u003C/p>\n\u003Cp>For some organisations or work teams, the application map lives in SAP LeanIX: each application has its own record there, with its common name, description, lifecycle stage, owners, and the number under which the company identifies it. Dastra’s asset repository, for its part, holds data mapping and compliance information: linked processing activities, security measures, vendor, reviews. Without a link between the two, the mapping has to be re-entered application by application, and the two inventories diverge as soon as the first deployment goes live.\u003C/p>\n\u003Cp>The \u003Cstrong>SAP LeanIX connector\u003C/strong> links a LeanIX instance to the asset repository. Automatically import your Application fact sheets from SAP LeanIX into Dastra as assets (daily sync, upsert). Since the LeanIX data model is unique to each instance, no fixed mapping would work: you choose, from among the fields actually declared in your model, those that populate each asset field, including the internal number to the asset reference and the owner’s address to a custom field.\u003C/p>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/5bbb6387-2334-4189-9ff5-3fac18ab2bf3/pasted-image-6-original.png\" alt=\"\" />\u003C/p>\n\u003Cp>You also decide whether missing assets should be created and how to match a LeanIX record with an asset already present in Dastra. Each imported asset keeps track of the fact sheet it comes from, and the daily refresh never overwrites anything entered in Dastra.\u003C/p>\n\u003Cp>What is SAP LeanIX?\u003C/p>\n\u003Cp>SAP LeanIX is a SaaS enterprise architecture management platform. It maintains an inventory of applications, IT components, and their lifecycle in order to govern and rationalise the information system.\u003C/p>\n\u003Ch3 id=\"integrations-servicenow-connector\">Integrations: ServiceNow connector\u003C/h3>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/4d1b5ae0-8e66-4571-b7b1-0f808e1113fb/pasted-image-7-original.png\" alt=\"\" />\u003C/p>\n\u003Cp>Your applications are inventoried in ServiceNow, while compliance is documented in Dastra? Without a link between the two tools, every new application must be entered twice, and the gap between the technical inventory and the compliance repository grows without anyone knowing which one is authoritative.\u003C/p>\n\u003Cp>Matching is all the more difficult because the two tools do not speak the same language: the same concept (an application’s status, type, or criticality) does not have the same name or the same values on each side, and each ServiceNow instance is configured differently.\u003C/p>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/c4e27bf1-d550-4acf-a736-68c8a4151799/pasted-image-8-original.png\" alt=\"\" />\u003C/p>\n\u003Cp>The \u003Cstrong>ServiceNow connector\u003C/strong> links a ServiceNow instance to the asset repository. You define the mapping between the columns of the business application table and Dastra asset fields, \u003Cstrong>including value translation from one list to another\u003C/strong>, and you choose whether missing assets should be created and how an incoming record should be matched to an existing asset. The sync then runs daily, without ever deleting the work of your compliance teams.\u003C/p>\n\u003Cp>What is ServiceNow?\u003C/p>\n\u003Cp>ServiceNow is a SaaS digital workflow platform (ITSM, ITOM, ITAM, HR, SecOps, etc.) that centralises and automates IT and business processes within an organisation. It is widely used for incident management, requests, assets, and enterprise-scale data.\u003C/p>\n\u003Chr />\n\u003Ch3 id=\"compliance-framework-version-management\">Compliance: framework version management\u003C/h3>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/4941417a-59da-4255-8f0d-ecd1765d20a0/pasted-image-9-original.png\" alt=\"\" />\u003C/p>\n\u003Cp>You can now be \u003Cstrong>notified when a newer version of the source framework is available\u003C/strong>, preview changes to controls, tests, risk scenarios, and threats, and then create an up-to-date new version by confirming.\u003C/p>\n\u003Cp>\u003Cstrong>Framework versioning\u003C/strong> follows the same principle already proven in the Questionnaires module. If your organisation can manage custom frameworks, you can now create a new version from an existing one, work on it as a draft, publish it, and retain the history.\u003C/p>\n\u003Cp>You can therefore:\u003C/p>\n\u003Cul>\n\u003Cli>\u003Cstrong>Create a new version\u003C/strong> of a framework, custom or imported, carrying over its chapters, requirements, and linked controls, with a change note and an automatically assigned number.\u003C/li>\n\u003Cli>\u003Cstrong>Publish or unpublish\u003C/strong> a version, \u003Cstrong>delete\u003C/strong> an abandoned draft, and let multiple published versions of the same framework \u003Cstrong>coexist\u003C/strong>.\u003C/li>\n\u003Cli>Designate the \u003Cstrong>main version\u003C/strong>, which will be suggested and installed by default when a framework is added to a project from the library.\u003C/li>\n\u003Cli>View the \u003Cstrong>full version history\u003C/strong> (number, change note, status, date, and author) and open a previous version in read-only mode.\u003C/li>\n\u003C/ul>\n\u003Cp>The main benefit is the \u003Cstrong>independence of your compliance projects\u003C/strong>. A project is tied to a specific version: a project built on version 1 of a framework is not affected by the framework evolving to version 2, and both versions can be used at the same time on two different projects. Migrating a project to another version remains a manual, explicit action, blocked while an audit is in progress so as not to distort ongoing work.\u003C/p>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/1e772972-bc97-486a-9d39-649bbfcc8ec4/pasted-image-10-original.png\" alt=\"\" />\u003C/p>\n\u003Cp>The requirements of a published version are locked, metadata (label, logo, description) remains editable, and creating a version does not consume any additional quota. Your existing frameworks automatically become version 1, with their current status preserved and your projects attached to this version 1: no action is required from you.\u003C/p>\n\u003Cp>In a control record, the linked requirements panel displays the \u003Cstrong>source framework version number\u003C/strong>: two identical requirements coming from two different versions are no longer seen as duplicates.\u003C/p>\n\u003Chr />\n\u003Ch3 id=\"cookies-management-of-uncategorised-cookies\">Cookies: management of uncategorised cookies\u003C/h3>\n\u003Cp>The cookie scan compares each detected cookie against Dastra’s service repository. When no match is found, the cookie remains orphaned. Yet your consent banner addresses visitors \u003Cstrong>by service\u003C/strong> only: a cookie not linked to any service is never shown to the visitor, and the consent collected does not cover it. Since the repository cannot know every proprietary or implementation-specific cookie, this happens on most scanned websites.\u003C/p>\n\u003Cp>With the uncategorised cookie management tool, a “Uncategorised cookies” tab now appears both in the scan results screen and in the banner editor, preceded by a warning badge showing the count.\u003C/p>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/4fe49ea1-44e5-4394-ad9e-89ba9bc28752/pasted-image-11-original.png\" alt=\"\" />\u003C/p>\n\u003Cp>From this list, you can:\u003C/p>\n\u003Cul>\n\u003Cli>\u003Cstrong>Link several cookies to an existing service\u003C/strong> in a single action, without creating a duplicate if the cookie is already declared there.\u003C/li>\n\u003Cli>\u003Cstrong>Create a new service from a selection\u003C/strong>, with the form prefilled from the most frequent domain among the selected cookies.\u003C/li>\n\u003Cli>\u003Cstrong>Delete\u003C/strong> cookies you do not wish to declare, after confirmation.\u003C/li>\n\u003Cli>\u003Cstrong>Remove a cookie from a service\u003C/strong> to send it back to the uncategorised cookies list.\u003C/li>\n\u003C/ul>\n\u003Cp>Counters, the warning badge, and the distribution chart update immediately after each action, without rerunning the scan. Most importantly, \u003Cstrong>nothing is lost\u003C/strong>: anything not handled when the banner is created remains attached to it and can be addressed later from the editor. Rerunning a scan on an existing banner compares detected cookies against the repository and then against your current configuration, and marks services already present with a green check.\u003C/p>\n\u003Cp>Uncategorised cookies are never shown in the public banner: your visitors continue to see only services grouped by purpose.\u003C/p>\n\u003Chr />\n\u003Ch3 id=\"security-passkey-sign-in\">Security: passkey sign-in\u003C/h3>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/459b88e0-da5a-4d5f-9aaa-8d43b5722a77/pasted-image-12-original.png\" alt=\"\" />\u003C/p>\n\u003Cp>Dastra now offers the ability to sign in using a \u003Cstrong>passkey\u003C/strong>, with no password or verification code to enter.\u003C/p>\n\u003Cp>A \u003Cstrong>passkey\u003C/strong> replaces the password and six-digit code with a simple check on your device: a fingerprint, face scan, or PIN. You no longer have anything to remember or copy, and sign-in takes only a few seconds.\u003C/p>\n\u003Cp>Above all, it provides \u003Cstrong>protection\u003C/strong> against phishing that passwords cannot offer. A password and a verification code can be entered on any page imitating Dastra, then immediately replayed elsewhere. A passkey, by contrast, works only on the real Dastra site: it stays on your device, never circulates, and therefore cannot be copied, intercepted, or reused.\u003C/p>\n\u003Cp>In practical terms:\u003C/p>\n\u003Cul>\n\u003Cli>You create a passkey from the dedicated section of the \u003Cstrong>Account Security\u003C/strong> page, or directly after signing in when Dastra offers it.\u003C/li>\n\u003Cli>You then sign in \u003Cstrong>without entering a password or code\u003C/strong>.\u003C/li>\n\u003Cli>You can \u003Cstrong>name\u003C/strong> your passkeys to distinguish them from one device to another, and delete them at any time.\u003C/li>\n\u003Cli>The interaction with the existing \u003Cstrong>two-factor authentication\u003C/strong> remains consistent: the passkey counts as strong proof and does not add a superfluous step.\u003C/li>\n\u003C/ul>\n\u003Cp>Browsers that do not support passkeys continue to offer the usual sign-in flow. Organisations that have deployed single sign-on already have their own solution and are not concerned by this mechanism.\u003C/p>\n\u003Cp>Read the \u003Ca href=\"https://doc.dastra.eu/security/passkey\">passkey documentation\u003C/a>\u003C/p>\n\u003Ch3 id=\"advanced-configuration-send-your-security-logs-to-your-siem\">Advanced configuration: send your security logs to your SIEM\u003C/h3>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/5ba20b5c-887f-4075-98ea-797e0b6caa7a/pasted-image-13-original.png\" alt=\"\" />\u003C/p>\n\u003Cp>Dastra logs activity in your account: sign-ins, permission changes, API keys, SSO configurations, user or workspace deletions. Previously, these traces stayed in Dastra, whereas an organisation’s security monitoring is carried out in its SIEM, where logs from all applications are centralised. Correlating a permission change in Dastra with an incident detected elsewhere was therefore not possible.\u003C/p>\n\u003Cp>The \u003Cstrong>SIEM integration\u003C/strong> opens up two complementary routes.\u003C/p>\n\u003Cp>The \u003Cstrong>real-time forwarding\u003C/strong>, configured once for the whole account and reserved to its owner, sends each logged event to your collector address. Four formats are supported to cover the main tools on the market: \u003Cstrong>Splunk HEC (JSON)\u003C/strong>, \u003Cstrong>CEF (Common Event Format)\u003C/strong>, \u003Cstrong>Syslog (RFC 5424)\u003C/strong>, and \u003Cstrong>Dynatrace (Log Monitoring v2)\u003C/strong>. Authentication adapts to your collector (Bearer token, API key, custom authorisation scheme, custom header, or none), custom headers can be added, and a severity filter lets you forward only what matters. The connection is tested before saving, and no configuration is stored without a valid connection.\u003C/p>\n\u003Cp>The \u003Cstrong>manual export\u003C/strong> completes the setup: from the “Security logs” page, an “Export (SIEM)” menu produces a file in CEF, Syslog RFC 5424, or Splunk HEC format, applying the selected period and event types shown on screen. Useful for one-off backfills or for handing traces to an auditor. Spreadsheet export remains available alongside it, unchanged.\u003C/p>\n\u003Cp>The authentication token is never shown again after saving, and empty information is omitted from the message rather than sent blank.\u003C/p>\n\u003Cp>What is a SIEM?\u003C/p>\n\u003Cp>A SIEM (Security Information and Event Management, for example Splunk, Microsoft Sentinel, QRadar) centralises your organisation’s security event logs for detection, investigation, and compliance.\u003C/p>\n\u003Ch2 id=\"improvements\">✨ Improvements\u003C/h2>\n\u003Ch3 id=\"processing-register-ai-assessment-of-the-9-dpia-criteria\">Processing register: AI assessment of the 9 DPIA criteria\u003C/h3>\n\u003Cp>You can now \u003Cstrong>ask the AI assistant\u003C/strong> to \u003Cstrong>fill in the 9 assessment criteria from the EDPB list\u003C/strong> based on the information already entered. You immediately know whether a DPIA is required, while retaining control over each proposed answer.\u003C/p>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/0b0a5540-40bf-410c-a73e-f30030d2e69f/pasted-image-14-original.png\" alt=\"\" />\u003C/p>\n\u003Ch3 id=\"filter-on-multiple-custom-fields\">Filter on multiple custom fields:\u003C/h3>\n\u003Cp>Many of you requested it: it is now possible to create filters on list-type custom fields (checkboxes or multi-select fields).\u003C/p>\n\u003Ch3 id=\"important-change-mandatory-approval-by-questionnaire-owners\">[Important change] Mandatory approval by questionnaire owners:\u003C/h3>\n\u003Cp>The audit questionnaire validation process has been redesigned to \u003Cstrong>separate individual approval from final publication\u003C/strong>. Each validator (required or optional) can now approve the questionnaire independently via a dedicated button, with the option to leave a review comment and revoke their approval. Final publication (validation) is allowed only when \u003Cstrong>all\u003C/strong> required validators have approved. Visual tracking of approval progress is displayed in the validation view, summary, response list, and validator manager. Pending owners are notified by email for each new approval.\u003C/p>\n\u003Cp>To learn more, read \u003Ca href=\"https://doc.dastra.eu/features/audit/questionnaire-validation\">the questionnaire validation documentation\u003C/a>\u003C/p>\n\u003Cp>\u003Cimg loading=\"lazy\"  src=\"https://static.dastra.eu/richtext/d60ac7d8-9b8a-4f25-b46d-45fe33542dc6/pasted-image-15-original.png\" alt=\"\" />\u003C/p>\n\u003Ch3 id=\"important-change-separation-of-write-permission-from-create-permission\">[Important change] Separation of write permission from create permission\u003C/h3>\n\u003Cp>From now on, the permission to create new items (manually, with AI, or otherwise) has been fully separated from write permission across several modules. Rest assured, this will have no impact on your current role setup, which will automatically include write permission. The purpose of this feature is to allow a combination of the right to edit one’s own items and the right to create.\u003C/p>\n",null,2317,13,"Version 2.0.6: Integrations (LeanIX, Teams, SIEM), passkeys, framework versioning",0,"New version","en","version-206-integrations-leanix-teams-siem-passkeys-framework-versioning","This release opens Dastra up to your information system with an enhanced native integrations platform and four new connectors (Microsoft Teams, Jira, SAP LeanIX, and ServiceNow). It also introduces versioning for compliance frameworks, passkey login, forwarding security logs to your SIEM, as well as a series of functional improvements to your registers and lists.","Published",{"id":18,"displayName":19,"avatarUrl":7,"bio":7,"blogUrl":7,"color":7,"userId":20,"creationDate":21},25695,"Benoît Cadieux",22098,"2026-01-26T13:29:24","2026-09-03T19:39:00","2026-09-03T18:39:08.9318102","2026-09-03T18:57:05.1125997",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":31},2,"Blog","A list of curated articles provided by the community","blog","#28449a",[32,35,38],{"lang":33,"name":27,"description":34},"fr","Une liste d'articles rédigés par la communauté",{"lang":36,"name":27,"description":37},"es","Una lista de artículos escritos por la comunidad",{"lang":39,"name":27,"description":40},"de","Eine Liste von Artikeln, die von der Community verfasst wurden",[42,47],{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":43},[44,45,46],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},{"id":48,"name":49,"description":50,"url":51,"color":52,"parentId":26,"count":7,"imageUrl":7,"parent":53,"order":58,"translations":59},10,"Release notes","Keep up with the latest features of Dastra: product updates, new functionalities, and improvements to our GDPR compliance and data management platform.","release","#8c316a",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":54},[55,56,57],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},5,[60,63,66],{"lang":33,"name":61,"description":62},"Notes de version","Restez informé(e) des dernières fonctionnalités de Dastra : mises à jour, évolutions produit et améliorations de notre solution de conformité RGPD et de gestion des données personnelles.",{"lang":39,"name":64,"description":65},"Veröffentlichungen","Alle Versionshinweise und Funktionen von Dastra",{"lang":36,"name":67,"description":68},"Lanzamientos","Todas las notas de la versión e información sobre las funciones de Dastra",[],[],60552,{"total":73,"items":74,"parent":221},8,[75,96,117,139,149,170,188,204],{"id":76,"name":77,"description":78,"url":79,"color":80,"parentId":26,"count":7,"imageUrl":7,"parent":81,"order":73,"translations":86},20,"Inside Dastra","Go behind the scenes at Dastra: company news, culture, events, team highlights, and the people driving our GDPR solution.","dastra-life","#e3cf68",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":82},[83,84,85],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},[87,90,93],{"lang":33,"name":88,"description":89},"Vie de Dastra","Plongez dans les coulisses de Dastra : actualités internes, culture d’entreprise, événements, équipes et engagements. Découvrez qui se cache derrière notre solution RGPD.",{"lang":39,"name":91,"description":92},"Innerhalb von Dastra","Eintauchen in das Unternehmen",{"lang":36,"name":94,"description":95},"Dentro de Dastra","Sumérjase en la empresa",{"id":97,"name":98,"description":99,"url":100,"color":101,"parentId":26,"count":7,"imageUrl":7,"parent":102,"order":107,"translations":108},69,"Expertise","Gain insights from our experts on GDPR compliance, data protection, and privacy challenges. In-depth articles, professional analysis, and real-world best practices.","indepth","#000000",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":103},[104,105,106],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},7,[109,111,114],{"lang":33,"name":98,"description":110},"Bénéficiez des conseils de nos experts sur la conformité RGPD, la protection des données et les enjeux privacy. Articles de fond, analyses et retours d’expérience métier.",{"lang":39,"name":112,"description":113},"Fachwissen","Entdecken Sie die Artikel unserer DSGVO-Experten",{"lang":36,"name":115,"description":116},"Experiencia","Descubre los artículos de nuestros expertos en Privacy",{"id":118,"name":119,"description":120,"url":121,"color":122,"parentId":26,"count":7,"imageUrl":7,"parent":123,"order":128,"translations":129},4,"Use cases","Discover how companies use Dastra to manage their GDPR compliance. Testimonials, use cases, and real-world integrations of our privacy management solution.","case-studies","#b61b9c",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":124},[125,126,127],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},6,[130,133,136],{"lang":33,"name":131,"description":132},"Retours d'expérience","Découvrez comment les entreprises utilisent Dastra pour piloter leur conformité RGPD. Témoignages, cas d’usage et intégrations concrètes de notre solution de privacy management.",{"lang":39,"name":134,"description":135},"Case Studies","Entdecken Sie die Erfahrungsberichte unserer Kunden",{"lang":36,"name":137,"description":138},"Casos prácticos","Descubra los testimonios de nuestros clientes",{"id":48,"name":49,"description":50,"url":51,"color":52,"parentId":26,"count":7,"imageUrl":7,"parent":140,"order":58,"translations":145},{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":141},[142,143,144],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},[146,147,148],{"lang":33,"name":61,"description":62},{"lang":39,"name":64,"description":65},{"lang":36,"name":67,"description":68},{"id":150,"name":151,"description":152,"url":153,"color":154,"parentId":26,"count":7,"imageUrl":7,"parent":155,"order":118,"translations":160},9,"News","Stay up to date with the latest news from data protection authorities: decisions, fines, guidelines, and regulatory trends in GDPR and privacy.","news","#1676ca",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":156},[157,158,159],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},[161,164,167],{"lang":33,"name":162,"description":163},"Actualités","Suivez les dernières actualités des autorités de protection des données (CNIL, EDPS, etc.) : décisions, sanctions, lignes directrices et tendances réglementaires en matière de RGPD et de privacy.",{"lang":36,"name":165,"description":166},"Actualidad","Todos los artículos relativos a las autoridades de protección de datos",{"lang":39,"name":168,"description":169},"Nachrichten","Alle Artikel mit Bezug zu Datenschutzbehörden",{"id":171,"name":172,"description":173,"url":174,"color":101,"parentId":26,"count":7,"imageUrl":7,"parent":175,"order":180,"translations":181},221,"AI Governance","Best practices, regulatory frameworks and real-world insights to manage AI responsibly and in compliance with the AI Act.","ai-governance",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":176},[177,178,179],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},3,[182,185],{"lang":33,"name":183,"description":184},"Gouvernance de l'IA","Bonnes pratiques, cadres réglementaires et retours d'expérience pour piloter l'IA de façon responsable et conforme à l'AI Act.",{"lang":39,"name":186,"description":187},"KI-Governance","Best Practices, regulatorische Rahmenbedingungen und Praxiserfahrungen für einen verantwortungsvollen KI-Einsatz im Einklang mit dem AI Act.",{"id":189,"name":190,"description":191,"url":192,"color":101,"parentId":26,"count":7,"imageUrl":7,"parent":193,"order":26,"translations":198},220,"Compliance","Regulatory news, practical guides and analysis to keep your organization compliant with the GDPR and beyond.","compliance",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":194},[195,196,197],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},[199,202],{"lang":33,"name":200,"description":201},"Conformité","Actualités réglementaires, guides pratiques et analyses pour maintenir votre organisation en conformité RGPD et au-delà.",{"lang":39,"name":190,"description":203},"Regulatorische Neuigkeiten, Praxisleitfäden und Analysen, um Ihre Organisation DSGVO-konform und darüber hinaus aufzustellen.",{"id":205,"name":206,"description":207,"url":208,"color":101,"parentId":26,"count":7,"imageUrl":7,"parent":209,"order":214,"translations":215},219,"Privacy","Principles, techniques and trends in personal data protection — from privacy by design to data subject rights.","privacy",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":210},[211,212,213],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},1,[216,218],{"lang":33,"name":206,"description":217},"Principes, techniques et tendances autour de la protection des données personnelles — de la privacy by design aux droits des personnes.",{"lang":39,"name":219,"description":220},"Datenschutz","Grundsätze, Methoden und Trends zum Schutz personenbezogener Daten — von Privacy by Design bis zu Betroffenenrechten.",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":222},[223,224,225],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},[],{"items":228,"total":295,"size":214,"page":214},[229],{"title":230,"nbDownloads":180,"excerpt":231,"lang":13,"url":232,"intro":233,"featured":4,"state":16,"author":234,"authorId":235,"datePublication":239,"dateCreation":240,"dateUpdate":241,"mainCategory":242,"categories":248,"metaDatas":281,"imageUrl":285,"imageThumbUrls":286,"id":294},"AI Act Transparency Notice Template (Word Format) Compliant with Article 50","Download a Microsoft Word template for AI transparency notices compliant with Article 50 of the EU AI Act, including four ready-to-use notice variants for AI providers and deployers.","ai-act-transparency-notice-template-word-format-compliant-with-article-50","Since 2 August 2026, Article 50 of the European Artificial Intelligence Act (AI Act) has introduced transparency obligations for several categories of AI systems. AI providers and deployers must inform individuals when they interact with AI, are exposed to AI-generated content, are subject to emotion recognition or biometric categorisation, or encounter AI-generated deepfakes. To help organisations comply with these requirements, Dastra provides a free Microsoft Word template that can be adapted and integrated into your documentation, websites and user interfaces.",{"id":235,"displayName":236,"avatarUrl":237,"bio":7,"blogUrl":7,"color":7,"userId":235,"creationDate":238},38,"Paul-Emmanuel Bidault","https://static.dastra.eu/tenant-27/avatar/38/paul-emmanuel-bidault-150.jpg","2019-12-03T19:09:28","2026-08-06T12:40:00","2026-08-06T12:40:04.9054724","2026-08-06T12:59:59.293083",{"id":243,"name":244,"description":7,"url":245,"color":246,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":180,"translations":247},70,"Livre blanc","white-papers","#1795d3",[],[249,254,259,261,269,277],{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":11,"translations":250},[251,252,253],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},{"id":255,"name":256,"description":7,"url":257,"color":101,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":128,"translations":258},48,"Ressources","resources",[],{"id":243,"name":244,"description":7,"url":245,"color":246,"parentId":7,"count":7,"imageUrl":7,"parent":7,"order":180,"translations":260},[],{"id":262,"name":263,"description":264,"url":265,"color":266,"parentId":255,"count":7,"imageUrl":267,"parent":7,"order":11,"translations":268},83,"IA","Toutes les ressources sur l'IA","intelligence-artificielle","#342d9f","https://static.dastra.eu/tag/9bce43f2-c750-4e6c-9b31-18ea1409a5ba/dalle-2024-11-25-225448-a-modern-and-sleek-square-logo-for-artificial-intellige-original.webp",[],{"id":270,"name":271,"description":272,"url":273,"color":274,"parentId":255,"count":7,"imageUrl":275,"parent":7,"order":11,"translations":276},92,"Artificial intelligence","Key ressources for AI","ai-ressources","#0f1cd7","https://static.dastra.eu/tag/3cf3f039-04ed-4b3a-b386-a99b43cb4e64/ai-act-bis-original.png",[],{"id":171,"name":172,"description":173,"url":174,"color":101,"parentId":26,"count":7,"imageUrl":7,"parent":7,"order":180,"translations":278},[279,280],{"lang":33,"name":183,"description":184},{"lang":39,"name":186,"description":187},[282],{"typeMetaDataId":118,"value":283,"id":284},"https://static.dastra.eu/backofficefilescontainer/875e1e54-f479-43ff-9572-c4add516b85c/Dastra-AI-transparency-notice-template-art50-EN.docx",117744,"https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-original.png",[287,288,289,290,291,292,293],"https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-1000.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-1500.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-800.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-600.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-300.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-100.webp",60275,14]