GDPR Explained
The GDPR glossary.
The GDPR is full of jargon. Here are the key terms in plain English — each defined, connected to the articles it comes from, and cross-linked to related concepts.
A
AccountabilityThe principle that you must not only comply with the GDPR but be able to demonstrate it with records and policies.Adequacy decisionA European Commission decision that a non-EU country offers adequate data protection, allowing free transfers there.AnonymisationIrreversibly stripping data of anything that could identify a person — after which the GDPR no longer applies.Automated decision-makingDecisions made solely by automated means — with special safeguards where they have legal or similarly significant effects.
B
Binding Corporate RulesApproved internal rules that let a multinational group transfer personal data across borders within the group.Biometric dataData from physical or behavioural traits — like fingerprints or facial geometry — used to uniquely identify a person.Breach notificationThe duty to report a risky personal data breach to the regulator within 72 hours, and to affected people without undue delay.
C
D
Data controllerThe organisation or person that decides why and how personal data is processed — and carries primary responsibility under the GDPR.Data minimisationCollect only the personal data you actually need for your purpose — no more.Data Processing AgreementThe mandatory written contract that must be in place between a controller and a processor.Data processorA third party that processes personal data on behalf of, and under the instructions of, a data controller.Data protection by design and by defaultBuilding data protection into systems from the outset, and defaulting to the most privacy-friendly settings.Data Protection Impact AssessmentA structured risk assessment you must run before high-risk processing, to identify and reduce privacy risks.Data Protection OfficerAn independent expert who advises on and monitors GDPR compliance — mandatory for some organisations.Data subjectThe living individual whom the personal data is about — the person the GDPR is designed to protect.
E
EU representativeA person or firm in the EU that non-EU organisations must appoint to act as their local GDPR contact.EU–US Data Privacy FrameworkThe 2023 adequacy framework allowing transfers to certified US organisations.European Data Protection BoardThe EU body of national regulators that ensures the GDPR is applied consistently and issues guidance.Explicit consentA higher standard of consent — an express statement — required to process special-category data or for certain transfers.
G
I
J
L
Lawful basisOne of the six legal grounds in Article 6 that every act of processing must rely on.Legitimate interestA flexible lawful basis for processing that is necessary for a genuine interest, balanced against the individual's rights.Legitimate interest assessmentThe documented three-part test (purpose, necessity, balancing) you run before relying on legitimate interests.
M
O
P
Personal dataAny information relating to an identified or identifiable living person, from a name or email to an IP address or location data.Personal data breachA security incident that leads to loss, unauthorised access to, or disclosure of personal data.Privacy noticeThe transparency document telling people how and why you process their personal data.ProcessingAlmost anything you do with personal data — collecting, storing, using, sharing, or even deleting it.ProfilingAutomated processing that evaluates personal aspects of someone — like performance, interests, behaviour or location.PseudonymisationReplacing identifying fields with a pseudonym so data can't be attributed to a person without separately-kept extra information.Purpose limitationCollect data for specified, explicit purposes and don't reuse it in incompatible ways.
R
Records of Processing ActivitiesThe internal inventory of your processing activities that most organisations must maintain under Article 30.Right to data portabilityThe right to receive your data in a structured, machine-readable format and reuse it — or have it sent to another provider.Right to erasureThe data subject's right to have their personal data deleted in certain circumstances.Right to objectThe right to object to processing based on legitimate interests or public task — and an absolute right to stop direct marketing.Right to rectificationThe right to have inaccurate personal data corrected and incomplete data completed.Right to restriction of processingThe right to have processing paused — data stored but not otherwise used — in certain situations.
S
Special category dataSensitive data — health, race, religion, sexual orientation, biometrics and more — that gets extra protection under Article 9.Standard Contractual ClausesPre-approved contract terms that provide a safeguard for transferring personal data outside the EEA.Storage limitationKeep personal data in identifiable form only as long as you need it — then delete or anonymise.Subject access requestA request from an individual to see the personal data an organisation holds about them — usually answered within one month.Supervisory authorityThe independent national regulator that enforces the GDPR and handles complaints.
T
Still not sure how it applies?
Definitions get you started — our team helps you apply them to your data, contracts and risk.