Emerging Technologies & GDPR

Confused about GDPR jargon? No problem! Our glossary breaks down all the key terms and definitions you need to understand the language of data privacy and compliance. This glossary will grow as we continue to add new terms and explanations, making it an essential reference for everyone.

AI Literacy

The skills, knowledge and understanding that allow staff to use AI systems informedly and to recognise their risks. Providers and deployers must take measures to support its development (Article 4, EU AI Act).

AI System

A machine-based system that operates with some autonomy and infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions (Article 3(1), EU AI Act).

AI Transparency Obligations

The duty to disclose certain uses of AI: telling people when they are interacting with a machine, marking synthetic content in a machine-readable format, and labelling deepfakes and AI-generated text published to inform the public on matters of public interest (Article 50, EU AI Act).

Automated Decision-Making & Profiling

Decisions made about a person using only automated systems (like AI or algorithms), without meaningful human involvement (Article 22).

Biometric Data

Personal data from physical or biological characteristics — fingerprints, facial images, iris scans — used to uniquely identify a person. A special category of sensitive data (Article 4(14); Article 9).

Deployer

Any organisation using an AI system under its own authority in the course of its activities. Most businesses using off-the-shelf AI tools are deployers rather than providers (Article 3(4), EU AI Act).

Facial Recognition Technology

Technology that identifies or verifies a person from their facial features — treated as biometric, special category data processing under GDPR when used to uniquely identify someone (Article 9).

General-Purpose AI Model (GPAI)

An AI model trained on large amounts of data that displays significant generality and can competently perform a wide range of distinct tasks — the kind of model behind general-purpose chat assistants (Article 3(63), EU AI Act).

High-Risk AI System

An AI system whose use poses a significant risk to health, safety or fundamental rights — including systems used in recruitment, credit scoring, education and access to essential services (Article 6 and Annexes I and III, EU AI Act).

Prohibited AI Practices

Uses of AI banned outright in the EU, including social scoring, inferring emotions in the workplace or in education, biometric categorisation to infer protected characteristics, and untargeted scraping of facial images (Article 5, EU AI Act).