GDPR Basics (Essential Terms)

Confused about GDPR jargon? No problem! Our glossary breaks down all the key terms and definitions you need to understand the language of data privacy and compliance. This glossary will grow as we continue to add new terms and explanations, making it an essential reference for everyone.

Processing

Any operation performed on personal data, including collection, storage, alteration, and deletion (Article 4(2)).

Purpose Limitation

The principle that personal data collected for one stated purpose cannot later be reused for a different, incompatible purpose without a fresh legal basis (Article 5(1)(b)).

Right to Access

The right of individuals to obtain confirmation of whether their personal data is being processed, access their data, and receive related information (Article 15).

Right to Erasure (Right to Be Forgotten)

The right to request the deletion of personal data under specific conditions (Article 17).

Right to Object

The right to object to the processing of personal data, especially for direct marketing purposes (Article 21).

Right to Rectification

The right to have inaccurate personal data corrected or incomplete data completed (Article 16).

Right to Restrict Processing

The right to limit the processing of personal data under specific circumstances, such as disputes over data accuracy (Article 18).

Special Category Data

Sensitive personal data — such as health, religion, ethnicity, or sexual orientation — that requires extra protection and a stricter legal basis to process (Article 9).

Storage Limitation

The principle that personal data should be kept in a form that identifies people only for as long as necessary for its purpose, then deleted or anonymised (Article 5(1)(e)).

Vital Interests

A lawful basis allowing personal data to be processed when it is necessary to protect someone’s life or physical safety, used mainly in emergencies (Article 6(1)(d)).