- Data Controller
- The natural or legal person that determines the purposes and means of processing personal data — typically the business engaging a vendor.
- Data Processor
- A third party that processes personal data exclusively on behalf of and under the documented instructions of the data controller.
- Personal Data
- Any information relating to an identified or identifiable natural person — including names, email addresses, IP addresses, and device identifiers.
- Processing
- Any operation performed on personal data, including collection, storage, use, transfer, alteration, and deletion.
- Sub-Processor
- A third party engaged by the data processor to carry out specific processing activities on the controller's personal data.
- Technical and Organizational Measures (TOMs)
- The specific security controls — encryption, access controls, pseudonymization, backup procedures — that the processor implements to protect personal data.
- Data Subject
- The living individual whose personal data is being processed — a customer, employee, website visitor, or other natural person.
- Data Breach
- A security incident that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
- Standard Contractual Clauses (SCCs)
- Pre-approved contractual terms issued by the European Commission that enable lawful transfer of personal data from the EU to third countries.
- GDPR Article 28
- The GDPR provision that mandates a binding written contract between every controller and processor, specifying the processor's obligations and the controller's rights.
- Data Protection Impact Assessment (DPIA)
- A structured analysis required before high-risk processing activities that evaluates privacy risks and the measures taken to mitigate them.
- Pseudonymization
- Processing personal data in a way that it can no longer be attributed to a specific individual without additional information held separately and securely.