Necessity and Proportionality
A core legal test requiring that data processing goes no further than what is genuinely needed to achieve its purpose (Articles 5–6).
One-Stop-Shop Mechanism
A GDPR system letting an organisation operating in several EU countries deal with a single lead supervisory authority instead of one per country (Article 56).
Personal Data
Any information relating to an identified or identifiable individual, such as names, email addresses, or IP addresses (Article 4(1)).
Privacy by Default
Ensuring privacy settings are configured to the highest level by default (Article 25).
Privacy by Design
Integrating data protection principles into the development of systems and processes from the beginning (Article 25).
Privacy Notice (Transparency Notice)
The document or webpage that tells individuals, in plain language, how their personal data is collected, used, and protected (Articles 12–14).
Processing
Any operation performed on personal data, including collection, storage, alteration, and deletion (Article 4(2)).
Prohibited AI Practices
Uses of AI banned outright in the EU, including social scoring, inferring emotions in the workplace or in education, biometric categorisation to infer protected characteristics, and untargeted scraping of facial images (Article 5, EU AI Act).
Provider (AI Act)
The organisation that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark (Article 3(3), EU AI Act).
Pseudonymization
Replacing identifiers with pseudonyms to protect personal data and reduce privacy risks (Article 4(5)).