Update csp.md expanded note on links to external resources
per issue 216
diff --git a/content/pages/csp.md b/content/pages/csp.md
index a503bc2..200de8f 100644
--- a/content/pages/csp.md
+++ b/content/pages/csp.md
@@ -7,7 +7,7 @@
- External trackers from 3rd party providers are **not allowed**. The ASF offers <a href="https://matomo.org/" target="_blank">Matomo</a> analytics for all project websites through <a href="https://analytics.apache.org" target="_blank">analytics.apache.org</a>.
- External resources, such as videos or PDFs, from providers with which we do not have a Data Processing Agreement (DPA) are **not allowed** to be embedded in the project's website. If you have a DPA request or inquiry, contact `privacy@apache.org`. They can also tell you if a provider whose content you want to embed in your website has already signed a DPA.
- - Links to external resources **are allowed** if the site visitor must give explicit consent in order to see or use the content. This consent cannot be opt-out, and there must be a clear way for the visitor to retract consent at a later time.
+ - Links that lead to downloadable external resources **are allowed** if the site visitor must give explicit consent in order to see or use the content (such as by clicking a button or a link). This consent cannot be opt-out, and there must be a clear way for the visitor to retract consent at a later time.
This policy brings project websites into alignment with the security and privacy parameters defined by the VP, Data Privacy and as requested by The ASF Security Committee. We ask that projects do not circumvent them without express permission from our VP, Data Privacy.