Data Protection Officer (DPO)
A professional appointed to oversee GDPR compliance and advise organizations on data protection (Articles 37–39).
Data Subject
An individual whose personal data is processed. GDPR grants data subjects specific rights, such as the right to access, rectify, and erase their data (Articles 12–23).
Explicit Consent
A stricter form of consent — a clear, unambiguous statement rather than just an action — required before an organisation can process special category data (Article 9(2)(a)).
Lawful Basis for Processing
One of six legal grounds — such as consent or legitimate interest — that a company must have before it can lawfully process personal data (Article 6).
Legal Obligation
A lawful basis allowing personal data to be processed when it is necessary to comply with a legal duty the organisation is subject to, such as tax or employment law (Article 6(1)(c)).
Legitimate Interest
A lawful basis for processing data where it is necessary and does not override individual rights (Article 6(1)(f)).
Personal Data
Any information relating to an identified or identifiable individual, such as names, email addresses, or IP addresses (Article 4(1)).
Privacy by Default
Ensuring privacy settings are configured to the highest level by default (Article 25).
Privacy by Design
Integrating data protection principles into the development of systems and processes from the beginning (Article 25).
Privacy Notice (Transparency Notice)
The document or webpage that tells individuals, in plain language, how their personal data is collected, used, and protected (Articles 12–14).