Glossary

Confused about GDPR jargon? No problem! Our glossary breaks down all the key terms and definitions you need to understand the language of data privacy and compliance. This glossary will grow as we continue to add new terms and explanations, making it an essential reference for everyone.

Adequacy Decision

EU Commission decision confirming that a non-EU country ensures adequate data protection, allowing data transfers without additional safeguards (Article 45).

Anonymization

Removing identifiable information from data to make it impossible to trace back to an individual (Recital 26).

Automated Decision-Making & Profiling

Decisions made about a person using only automated systems (like AI or algorithms), without meaningful human involvement (Article 22).

Biometric Data

Personal data from physical or biological characteristics — fingerprints, facial images, iris scans — used to uniquely identify a person. A special category of sensitive data (Article 4(14); Article 9).

Consent

A freely given, specific, informed, and unambiguous indication of agreement to data processing through a clear affirmative action (Articles 4(11) and 7).

Controller-Processor Agreement

A legally required contract outlining responsibilities between a data controller and processor (Article 28(3)).

Cross-Border Processing

Processing that affects individuals in multiple EU countries or involves data transferred across borders (Article 4(23)).

Data Breach

A security incident leading to unauthorized access, alteration, or loss (disclosure, or destruction) of personal data (Article 4(12)).

Data Controller

The entity that determines the purposes and means of processing personal data (Article 4(7)).

Data Minimization

Ensuring only the data necessary for a specific purpose is collected and processed (Article 5(1)(c)).