Glossary

Confused about GDPR jargon? No problem! Our glossary breaks down all the key terms and definitions you need to understand the language of data privacy and compliance. This glossary will grow as we continue to add new terms and explanations, making it an essential reference for everyone.

Necessity and Proportionality

A core legal test requiring that data processing goes no further than what is genuinely needed to achieve its purpose (Articles 5–6).

One-Stop-Shop Mechanism

A GDPR system letting an organisation operating in several EU countries deal with a single lead supervisory authority instead of one per country (Article 56).

Personal Data

Any information relating to an identified or identifiable individual, such as names, email addresses, or IP addresses (Article 4(1)).

Privacy by Default

Ensuring privacy settings are configured to the highest level by default (Article 25).

Privacy by Design

Integrating data protection principles into the development of systems and processes from the beginning (Article 25).

Privacy Notice (Transparency Notice)

The document or webpage that tells individuals, in plain language, how their personal data is collected, used, and protected (Articles 12–14).

Processing

Any operation performed on personal data, including collection, storage, alteration, and deletion (Article 4(2)).

Prohibited AI Practices

Uses of AI banned outright in the EU, including social scoring, inferring emotions in the workplace or in education, biometric categorisation to infer protected characteristics, and untargeted scraping of facial images (Article 5, EU AI Act).

Provider (AI Act)

The organisation that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark (Article 3(3), EU AI Act).

Pseudonymization

Replacing identifiers with pseudonyms to protect personal data and reduce privacy risks (Article 4(5)).