- Personal Data
- Any information that relates to an identified or identifiable living individual, including names, email addresses, IP addresses, and cookie identifiers.
- Data Controller
- The organisation or individual that determines the purposes and means of processing personal data β the party legally responsible for GDPR compliance.
- Data Processor
- A third party that processes personal data on behalf of the controller β such as a cloud hosting provider or email marketing platform.
- Lawful Basis
- One of six legal grounds under GDPR Article 6 that must exist before processing personal data β consent, contract, legal obligation, vital interests, public task, or legitimate interests.
- Data Subject
- The living individual whose personal data is being collected or processed β typically a customer, user, employee, or website visitor.
- Data Subject Rights
- GDPR-guaranteed entitlements including the right to access, rectify, erase, restrict, port, and object to the processing of one's personal data.
- Legitimate Interests
- A lawful basis permitting processing when the controller's interest is balanced against and does not override the data subject's rights β requires a documented legitimate interests assessment.
- Data Retention Period
- The defined length of time personal data is kept before it is securely deleted or anonymised, which must be disclosed in the privacy notice.
- Data Protection Officer (DPO)
- A designated individual responsible for overseeing GDPR compliance β mandatory for public authorities, organisations processing data at large scale, or those processing special categories of data.
- Special Category Data
- Sensitive personal data requiring enhanced protection under GDPR Article 9, including health information, racial or ethnic origin, biometric data, and political opinions.
- International Transfer
- The movement of personal data to a country outside the European Economic Area, which requires an adequacy decision, standard contractual clauses, or another approved safeguard.
- Privacy by Design
- A GDPR principle requiring data protection to be built into systems and processes from the outset rather than added as an afterthought.