- Personal Data
- Any information relating to an identified or identifiable natural person β including names, email addresses, IP addresses, and device identifiers.
- Data Controller
- The organization that determines the purposes and means of processing personal data and bears primary GDPR accountability.
- Data Processor
- A third party that processes personal data on behalf of the controller β such as a cloud provider or payroll service.
- Article 32
- The GDPR provision requiring controllers and processors to implement appropriate technical and organizational security measures proportionate to the risk of processing.
- Technical and Organizational Measures (TOMs)
- The combination of technical controls (encryption, access logs) and procedural controls (training, policies) used to protect personal data.
- Data Breach
- A security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
- Pseudonymization
- Processing personal data in a way that it can no longer be attributed to a specific individual without additional information kept separately and securely.
- Data Minimization
- The GDPR principle requiring organizations to collect and process only the minimum personal data necessary for a specific, stated purpose.
- Accountability Principle
- The GDPR requirement that controllers not only comply with the regulation but actively demonstrate compliance through documented policies and records.
- Supervisory Authority
- The national data protection regulator in each EU member state β such as the ICO in the UK or the CNIL in France β responsible for enforcing GDPR.
- Lawful Basis
- One of six legal grounds under GDPR (consent, contract, legal obligation, vital interests, public task, or legitimate interests) that must underpin every processing activity.
- Data Subject
- The identified or identifiable natural person whose personal data is being processed β a customer, employee, website visitor, or supplier contact.