Glossary

Confused about GDPR jargon? No problem! Our glossary breaks down all the key terms and definitions you need to understand the language of data privacy and compliance. This glossary will grow as we continue to add new terms and explanations, making it an essential reference for everyone.

Accountability

The principle that an organisation is not only responsible for complying with GDPR but must also be able to demonstrate that compliance with records and evidence (Article 5(2)).

Accuracy

The principle that personal data must be kept accurate and up to date, with reasonable steps taken to correct or erase inaccurate data without delay (Article 5(1)(d)).

Adequacy Decision

EU Commission decision confirming that a non-EU country ensures adequate data protection, allowing data transfers without additional safeguards (Article 45).

Administrative Fines

Financial penalties regulators can issue for GDPR violations, up to 20 million euro or 4% of global annual turnover, whichever is higher (Article 83).

AI Literacy

The skills, knowledge and understanding that allow staff to use AI systems informedly and to recognise their risks. Providers and deployers must take measures to support its development (Article 4, EU AI Act).

AI System

A machine-based system that operates with some autonomy and infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions (Article 3(1), EU AI Act).

AI Transparency Obligations

The duty to disclose certain uses of AI: telling people when they are interacting with a machine, marking synthetic content in a machine-readable format, and labelling deepfakes and AI-generated text published to inform the public on matters of public interest (Article 50, EU AI Act).

Anonymization

Removing identifiable information from data to make it impossible to trace back to an individual (Recital 26).

Automated Decision-Making & Profiling

Decisions made about a person using only automated systems (like AI or algorithms), without meaningful human involvement (Article 22).

Binding Corporate Rules (BCRs)

Internal, regulator-approved rules that let a multinational group transfer personal data between its own entities across borders (Article 47).