GDPR Basics (Essential Terms)

Confused about GDPR jargon? No problem! Our glossary breaks down all the key terms and definitions you need to understand the language of data privacy and compliance. This glossary will grow as we continue to add new terms and explanations, making it an essential reference for everyone.

Data Protection Officer (DPO)

A professional appointed to oversee GDPR compliance and advise organizations on data protection (Articles 37–39).

Data Subject

An individual whose personal data is processed. GDPR grants data subjects specific rights, such as the right to access, rectify, and erase their data (Articles 12–23).

Explicit Consent

A stricter form of consent — a clear, unambiguous statement rather than just an action — required before an organisation can process special category data (Article 9(2)(a)).

Lawful Basis for Processing

One of six legal grounds — such as consent or legitimate interest — that a company must have before it can lawfully process personal data (Article 6).

Legal Obligation

A lawful basis allowing personal data to be processed when it is necessary to comply with a legal duty the organisation is subject to, such as tax or employment law (Article 6(1)(c)).

Legitimate Interest

A lawful basis for processing data where it is necessary and does not override individual rights (Article 6(1)(f)).

Personal Data

Any information relating to an identified or identifiable individual, such as names, email addresses, or IP addresses (Article 4(1)).

Privacy by Default

Ensuring privacy settings are configured to the highest level by default (Article 25).

Privacy by Design

Integrating data protection principles into the development of systems and processes from the beginning (Article 25).

Privacy Notice (Transparency Notice)

The document or webpage that tells individuals, in plain language, how their personal data is collected, used, and protected (Articles 12–14).