- Data Controller
- The party that determines the purposes and means of processing personal data — typically the business engaging the service provider.
- Data Processor
- The party that processes personal data on behalf of the data controller, following the controller's documented instructions.
- Confidential Information
- Any non-public data, records, or materials disclosed by one party to the other in connection with the processing services, as defined in the agreement.
- Permitted Purpose
- The specific, limited reason for which the processor is authorized to access or use the confidential data — anything outside this scope is prohibited.
- Subprocessor
- A third party engaged by the processor to perform part of the data processing on the processor's behalf, subject to the same confidentiality obligations.
- Personal Data
- Any information relating to an identified or identifiable natural person — including names, email addresses, financial records, and health data.
- Security Incident
- Any unauthorized access, use, disclosure, alteration, or destruction of confidential data — whether accidental or intentional.
- Breach Notification
- The contractual and, in many jurisdictions, legal obligation to inform the data controller and relevant authorities of a security incident within a defined timeframe.
- Data Minimization
- The principle that a processor should access and retain only the minimum amount of data necessary to perform the contracted services.
- Return or Destruction Obligation
- The requirement that the processor return all confidential data to the controller or certifiably destroy it upon termination of the agreement.
- Technical and Organizational Measures (TOMs)
- Specific security controls — encryption, access restrictions, audit logging — that the processor commits to maintaining to protect the data.