- Data Subject
- An identified or identifiable natural person whose personal data is recorded and processed β in this context, the client whose contact information is stored.
- Data Controller
- The business or individual that determines the purposes and means of processing personal data, and bears primary compliance responsibility under privacy law.
- Lawful Basis for Processing
- The legal justification under data protection law β such as consent, contract performance, or legitimate interest β that permits a business to collect and store personal data.
- Consent
- A freely given, specific, informed, and unambiguous indication by the data subject that they agree to their personal data being processed for a stated purpose.
- Data Retention Policy
- A documented rule specifying how long personal data is kept and the process for securely deleting or anonymizing it once that period expires.
- Personal Identifiable Information (PII)
- Any information that can be used alone or in combination with other data to identify a specific individual, such as name, email address, phone number, or physical address.
- Primary Contact
- The individual at a client organization who is the designated first point of contact for day-to-day communication with the service provider.
- Relationship Owner
- The internal employee or account manager responsible for managing the client relationship and keeping the contact record current.
- Opt-Out
- A mechanism allowing the data subject to withdraw consent for specific types of communication or data processing at any time without penalty.
- Data Breach Notification
- The legal obligation to inform affected individuals and, in many jurisdictions, the relevant supervisory authority within a defined timeframe when personal data is compromised.
- Right to Erasure
- A data subject's right β codified in GDPR and similar laws β to request that their personal information be permanently deleted from a business's records.