Anonymization
Removing identifiable information from data to make it impossible to trace back to an individual (Recital 26).
Cookies & Online Tracking
Small files or scripts placed on a visitor’s device to remember activity or preferences; where they involve personal data, GDPR consent rules apply alongside the ePrivacy Directive (Articles 4(11), 7).
Data Breach
A security incident leading to unauthorized access, alteration, or loss (disclosure, or destruction) of personal data (Article 4(12)).
Encryption
Converting data into a secure format to prevent unauthorized access during transmission or storage (Recital 83).
Incident Response Plan
A structured approach for managing and mitigating the impact of data breaches (not explicitly defined in GDPR but essential for compliance under Articles 33–34).
Integrity and Confidentiality
The principle requiring personal data to be processed securely and protected against unauthorised access, loss, or damage using appropriate technical and organisational measures (Articles 5(1)(f), 32).
Pseudonymization
Replacing identifiers with pseudonyms to protect personal data and reduce privacy risks (Article 4(5)).