Accountability
The principle that an organisation is not only responsible for complying with GDPR but must also be able to demonstrate that compliance with records and evidence (Article 5(2)).
Accuracy
The principle that personal data must be kept accurate and up to date, with reasonable steps taken to correct or erase inaccurate data without delay (Article 5(1)(d)).
Children’s Consent (Age of Digital Consent)
Special GDPR rules for online services aimed at children, requiring parental authorisation below a set age — 16 by default, which member states may lower (Cyprus sets it at 14) (Article 8).
Consent
A freely given, specific, informed, and unambiguous indication of agreement to data processing through a clear affirmative action (Articles 4(11) and 7).
Contractual Necessity
A lawful basis allowing personal data to be processed when it is necessary to enter into or carry out a contract with the individual (Article 6(1)(b)).
Data Breach
A security incident leading to unauthorized access, alteration, or loss (disclosure, or destruction) of personal data (Article 4(12)).
Data Controller
The entity that determines the purposes and means of processing personal data (Article 4(7)).
Data Minimization
Ensuring only the data necessary for a specific purpose is collected and processed (Article 5(1)(c)).
Data Processor
An entity that processes personal data on behalf of the data controller (Article 4(8)).
Data Protection Impact Assessment (DPIA)
A process to identify and minimize risks to personal data in high-risk processing activities, such as profiling (Article 35).