Data Localization
A legal or policy requirement that certain personal data be stored and processed within a specific country or region, rather than transferred abroad (Articles 44–49).
Data Minimization
Ensuring only the data necessary for a specific purpose is collected and processed (Article 5(1)(c)).
Data Processor
An entity that processes personal data on behalf of the data controller (Article 4(8)).
Data Protection Impact Assessment (DPIA)
A process to identify and minimize risks to personal data in high-risk processing activities, such as profiling (Article 35).
Data Protection Officer (DPO)
A professional appointed to oversee GDPR compliance and advise organizations on data protection (Articles 37–39).
Data Subject
An individual whose personal data is processed. GDPR grants data subjects specific rights, such as the right to access, rectify, and erase their data (Articles 12–23).
Deployer
Any organisation using an AI system under its own authority in the course of its activities. Most businesses using off-the-shelf AI tools are deployers rather than providers (Article 3(4), EU AI Act).
Encryption
Converting data into a secure format to prevent unauthorized access during transmission or storage (Recital 83).
Explicit Consent
A stricter form of consent — a clear, unambiguous statement rather than just an action — required before an organisation can process special category data (Article 9(2)(a)).
Facial Recognition Technology
Technology that identifies or verifies a person from their facial features — treated as biometric, special category data processing under GDPR when used to uniquely identify someone (Article 9).