Biometric Data
Personal data from physical or biological characteristics — fingerprints, facial images, iris scans — used to uniquely identify a person. A special category of sensitive data (Article 4(14); Article 9).
Children’s Consent (Age of Digital Consent)
Special GDPR rules for online services aimed at children, requiring parental authorisation below a set age — 16 by default, which member states may lower (Cyprus sets it at 14) (Article 8).
Consent
A freely given, specific, informed, and unambiguous indication of agreement to data processing through a clear affirmative action (Articles 4(11) and 7).
Contractual Necessity
A lawful basis allowing personal data to be processed when it is necessary to enter into or carry out a contract with the individual (Article 6(1)(b)).
Controller-Processor Agreement
A legally required contract outlining responsibilities between a data controller and processor (Article 28(3)).
Cookies & Online Tracking
Small files or scripts placed on a visitor’s device to remember activity or preferences; where they involve personal data, GDPR consent rules apply alongside the ePrivacy Directive (Articles 4(11), 7).
Cross-Border Processing
Processing that affects individuals in multiple EU countries or involves data transferred across borders (Article 4(23)).
Data Breach
A security incident leading to unauthorized access, alteration, or loss (disclosure, or destruction) of personal data (Article 4(12)).
Data Breach Notification (72-Hour Rule)
The requirement to report certain personal data breaches to the supervisory authority within 72 hours of becoming aware of them (Articles 33–34).
Data Controller
The entity that determines the purposes and means of processing personal data (Article 4(7)).