Accountability
The principle that an organisation is not only responsible for complying with GDPR but must also be able to demonstrate that compliance with records and evidence (Article 5(2)).
Accuracy
The principle that personal data must be kept accurate and up to date, with reasonable steps taken to correct or erase inaccurate data without delay (Article 5(1)(d)).
Adequacy Decision
EU Commission decision confirming that a non-EU country ensures adequate data protection, allowing data transfers without additional safeguards (Article 45).
Administrative Fines
Financial penalties regulators can issue for GDPR violations, up to 20 million euro or 4% of global annual turnover, whichever is higher (Article 83).
Anonymization
Removing identifiable information from data to make it impossible to trace back to an individual (Recital 26).
Automated Decision-Making & Profiling
Decisions made about a person using only automated systems (like AI or algorithms), without meaningful human involvement (Article 22).
Binding Corporate Rules (BCRs)
Internal, regulator-approved rules that let a multinational group transfer personal data between its own entities across borders (Article 47).
Biometric Data
Personal data from physical or biological characteristics — fingerprints, facial images, iris scans — used to uniquely identify a person. A special category of sensitive data (Article 4(14); Article 9).
Children’s Consent (Age of Digital Consent)
Special GDPR rules for online services aimed at children, requiring parental authorisation below a set age — 16 by default, which member states may lower (Cyprus sets it at 14) (Article 8).
Consent
A freely given, specific, informed, and unambiguous indication of agreement to data processing through a clear affirmative action (Articles 4(11) and 7).