- Data Controller
- The entity that determines the purposes and means of processing personal data — typically the organization that originally collected it.
- Data Processor
- An entity that processes personal data on behalf of a data controller, acting only on documented instructions.
- Personal Data
- Any information that identifies or could identify a living individual — including names, email addresses, IP addresses, and device identifiers.
- Permitted Purpose
- The specific, documented use cases for which the recipient is authorized to use the shared data, as enumerated in the agreement.
- Onward Transfer
- The act of a data recipient sharing received data with a further third party — typically restricted or prohibited without prior written consent.
- Data Breach
- Any unauthorized access, disclosure, alteration, loss, or destruction of shared data, whether accidental or deliberate.
- Data Minimization
- The principle that only the minimum data necessary to achieve the permitted purpose should be shared, stored, and processed.
- Sub-processor
- A third party engaged by the data processor to carry out specific processing activities on behalf of the data controller.
- Data Subject
- The living individual to whom personal data relates — the person whose rights are protected under applicable privacy law.
- Retention Period
- The maximum duration for which the recipient is permitted to hold the shared data before it must be deleted or returned.
- Adequacy Decision
- A formal determination by the European Commission that a non-EU country provides an equivalent level of data protection to the GDPR standard.
- Technical and Organizational Measures (TOMs)
- The security controls — encryption, access controls, audit logs, staff training — that a party implements to protect shared data.