- Data Controller
- The organization that determines the purpose and means of processing personal data — typically the business that owns the customer or employee relationship.
- Data Processor
- A third party that processes personal data solely on the instructions of the data controller, such as a cloud provider, payroll platform, or marketing tool.
- Personal Data
- Any information that identifies or can identify a living individual — including names, email addresses, IP addresses, device identifiers, and behavioral data.
- Processing
- Any operation performed on personal data — collection, storage, use, disclosure, transfer, alteration, or deletion.
- Sub-processor
- A third party engaged by the processor to carry out specific processing activities on behalf of the controller, such as a cloud hosting provider used by a SaaS vendor.
- Data Subject
- The living individual whose personal data is being processed — a customer, employee, website visitor, or any other identifiable person.
- Lawful Basis
- The legal justification for processing personal data under applicable law — in GDPR, one of six grounds including consent, contract, legal obligation, vital interests, public task, or legitimate interests.
- Standard Contractual Clauses (SCCs)
- Pre-approved contractual provisions issued by the European Commission that provide a legal mechanism for transferring personal data from the EU to countries without an adequacy decision.
- Data Breach
- A security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
- Data Subject Rights
- Legal entitlements of individuals under privacy laws — including the right to access, correct, delete, restrict, port, or object to processing of their personal data.
- Adequacy Decision
- A formal finding by the European Commission that a non-EU country provides a level of data protection essentially equivalent to the EU, permitting free data transfer without additional safeguards.
- DPIA (Data Protection Impact Assessment)
- A structured risk assessment required under GDPR for processing activities likely to result in high risk to individuals, conducted before the processing begins.