- Personal Data
- Any information that identifies or could identify a living individual β including names, email addresses, IP addresses, and device identifiers.
- Data Controller
- The organization or person that determines the purposes and means of processing personal data β typically the website or app operator.
- Data Processor
- A third party that processes personal data on behalf of the data controller, such as an email marketing platform or cloud hosting provider.
- Lawful Basis for Processing
- Under GDPR, one of six legal justifications that must exist before processing personal data β including consent, contract performance, and legitimate interests.
- Cookie
- A small text file placed on a user's device by a website to remember preferences, track sessions, or support analytics and advertising.
- GDPR
- The General Data Protection Regulation β EU law effective May 2018 that sets strict standards for collecting, processing, and storing personal data of EU residents.
- CCPA
- The California Consumer Privacy Act β US state law giving California residents the right to know what personal data is collected, to delete it, and to opt out of its sale.
- Data Retention Period
- The defined length of time an organization keeps personal data before securely deleting or anonymizing it.
- Opt-Out Mechanism
- A clear method β typically a link, toggle, or email address β by which a user can withdraw consent or request that their data not be sold or shared.
- Data Breach
- An unauthorized access, disclosure, or loss of personal data that may trigger notification obligations to regulators and affected individuals.
- Legitimate Interests
- A GDPR lawful basis allowing processing when the controller's business interests are not overridden by the individual's privacy rights β requires a documented balancing test.