CIPP/E glossary
Review the recurring terms in this CIPP/E guide. Use each definition as a prompt, then explain the term without looking.
This glossary supports recall. The linked lessons provide the legal context, exceptions and scenarios that a short definition cannot hold.
- 1995 Data Protection Directive
- The Directive (95/46/EC) that first established the core concepts of personal data, controller and processor, since carried into the GDPR.
- 2008 Framework Decision
- Council Framework Decision 2008/977/JHA on data in police and judicial cooperation, replaced by the LED.
- 72-hour rule
- The outer limit for notifying the regulator: without undue delay and, where feasible, within 72 hours of the controller becoming aware of the breach.
- Acceptable use policy (AUP)
- A policy setting expected standards for using employer communications equipment and stating that use may be monitored.
- Accountability
- The Article 24 duty to ensure and be able to demonstrate compliance with the GDPR, with measures reviewed and updated over time.
- Accountability principle
- The duty of controllers to demonstrate (and prove) their compliance with the other principles. Added expressly by the GDPR.
- Accuracy
- Take reasonable measures to ensure personal data is accurate and, where necessary, kept up to date.
- Accuracy principle
- Article 5(1)(d): personal data must be accurate and kept up to date - the principle that underpins the right to rectification.
- Active recall
- Trying to produce the answer from memory before checking - the single highest-leverage study technique.
- Activity reports
- Article 59 - DPAs must publish regular (annual) public reports on their activities, promoting transparency in the regulatory system.
- Ad hoc contractual clauses
- Tailored contract clauses that require supervisory authority authorisation.
- Additional Protocol
- 2001 protocol to Convention 108 on supervisory authorities and transborder flows; imported the 'adequate' level of protection concept from the 1995 Directive.
- Adequacy
- Standard requiring a non-EEA destination to offer an adequate level of protection before transfers are allowed.
- Adequacy decision
- A European Commission determination that a third country's protection is essentially equivalent to the EU's, removing the need for extra transfer safeguards.
- Adequacy finding
- A Commission decision that a non-EU country provides an adequate level of data protection by EU standards, easing data transfers.
- Adequate level of protection
- Protection essentially equivalent to the EU framework, assessed against the rule of law and enforceable rights, independent supervision, and international commitments.
- Administrative fine
- A monetary penalty an SA may impose for GDPR infringement; must be effective, proportionate and dissuasive.
- Adtech
- The ecosystem of advertising-technology companies (ad networks, exchanges, DSPs/SSPs, data brokers) that profile and target individuals.
- Advocate general
- An ECJ officer who gives a reasoned, non-binding opinion on how the case should be decided.
- AI
- Software using techniques (e.g. machine learning) that, for human-defined objectives, generate content, predictions, recommendations or decisions.
- AI Act
- Regulation (EU) 2024/1689, a risk-based framework for AI systems that entered into force on 1 August 2024.
- AI Regulation
- Regulation (EU) 2024/1689, the EU's risk-based legal framework for artificial intelligence.
- ANAB
- ANSI National Accreditation Board - accredits the IAPP's CIPP/E (and CIPM, CIPP/US, CIPT) under ISO/IEC 17024:2012.
- Anonymised data
- Data stripped of all unique identifiers; not personal data. Pseudonymous data is NOT anonymous.
- anonymous data
- Data not related to an identified or identifiable person, rendered unidentifiable; not protected by the GDPR.
- Anonymous reporting
- Reporting without identifying the reporter; discouraged because the accused has no right of reply and reports may be malicious.
- Antović and Mirković v Montenegro
- ECtHR case; CCTV in university lecture theatres infringed lecturers' right to private life (a 4:3 decision).
- App
- A mobile application; can collect data via device sensors and access stored data, often linkable to the device owner.
- Appropriate safeguards
- Mechanisms (e.g. SCCs, BCRs) that contractually or otherwise bind the recipient to protect data to an EU standard when there is no adequacy decision.
- Appropriate technical and organisational measures
- The controls (technical and organisational) the GDPR requires controllers and processors to put in place; 'appropriate' means proportionate to risk, not absolute.
- Approved codes of conduct and certification
- EDPB-reviewed mechanisms that must be binding and enforceable with accredited monitoring; certifications valid up to 3 years (renewable).
- Article 10
- Governs data on criminal convictions and offences - processed only under official authority or as authorised by law with safeguards.
- Article 11
- Where identification is not required, the controller need not maintain extra data solely to comply with the GDPR.
- Article 13
- Information to provide when personal data is collected directly from the data subject, given at the time of collection.
- Article 14
- Information to provide when personal data is obtained indirectly (from another source); includes all Article 13 info plus the categories and source of the data.
- Article 14(5)(b)
- Exception allowing info to be made 'publicly available' where direct notice is impossible or a disproportionate effort (e.g. indirectly collected data).
- Article 15(2)
- ePrivacy provision requiring member states to apply the GDPR's judicial remedies, liabilities and sanctions to infringements of the ePrivacy Directive.
- Article 16(1) TFEU
- Provides that everyone has the right to the protection of personal data concerning them.
- Article 17
- The right to erasure / right to be forgotten - deletion of personal data on specified grounds, subject to exemptions.
- Article 2
- The provision defining the GDPR's material scope and its exclusions.
- Article 2(2)(a)
- Excludes processing 'in the course of an activity which falls outside the scope of Union law' - public security, defence, national security.
- Article 2(2)(b)
- Excludes member state processing under Chapter 2 of Title V TEU - the EU's common foreign and security policy.
- Article 2(2)(c)
- The Article number of the household exemption.
- Article 2(2)(d)
- Exempts processing by competent authorities for prevention, investigation, detection or prosecution of criminal offences, or execution of criminal penalties, including safeguarding against threats to public security.
- Article 21
- GDPR right to object. Art 21(2) gives an absolute right to object to direct marketing 'at any time'; once exercised, the data may no longer be processed for marketing.
- Article 22
- The right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects.
- Article 23
- GDPR provision allowing EU/Member State law to restrict data-subject rights, subject to respecting the essence of fundamental rights and being necessary and proportionate.
- Article 23 GDPR
- 'Restrictions' - permits EU or member state law to restrict data subject rights and certain principles, subject to necessity, proportionality and respect for the essence of rights.
- Article 24
- Codifies the accountability obligation: implement appropriate technical and organisational measures, review/update them, and scale them to the risk.
- Article 25
- GDPR article requiring data protection by design and by default; directed at controllers.
- Article 26
- Requires joint controllers to determine, by arrangement, their respective compliance responsibilities and make the essence available to data subjects.
- Article 27 representative
- An EU-based representative that a non-EU controller/processor caught by Article 3(2) must appoint as a contact point for supervisory authorities and data subjects.
- Article 28
- Requires a written controller-processor contract with mandatory content and governs sub-processing.
- Article 28 contract
- The mandatory data processing agreement a controller must put in place with its processor, listing prescribed terms.
- Article 28(10)
- GDPR provision under which a processor that determines the purposes or essential means of processing is treated as a controller for that processing.
- Article 28(3)
- GDPR provision listing the mandatory clauses a processor contract must contain.
- Article 29
- Requires anyone acting under the controller's (or processor's) authority to process personal data only on the controller's instructions.
- Article 29 Working Party
- Predecessor advisory body to the EDPB; its guidance remains relevant where it aligns with the GDPR.
- Article 29 Working Party (WP29)
- The EDPB's predecessor advisory body; its opinions remain valid where they align with the GDPR.
- Article 3(1)
- Applies the GDPR to processing in the context of the activities of an EU establishment of a controller or processor, whether or not the processing happens in the EU.
- Article 3(2)
- Extends the GDPR to non-EU controllers/processors that offer goods/services to, or monitor, people in the EU.
- Article 3(3)
- Applies the GDPR where a non-EU-established controller processes in a place where member state law applies by virtue of public international law (e.g. embassies, member-state-registered ships).
- Article 30
- Records of processing activities: the records controllers and processors must keep (written/electronic) and make available to the DPA on request.
- Article 30(2)
- Requires a processor to keep a written record of processing activities carried out on behalf of controllers, available to the DPA on request.
- Article 30(5)
- The records-of-processing exemption for organisations with fewer than 250 employees, subject to three risk-based carve-outs.
- Article 31
- General duty for controllers and processors (and representatives) to cooperate with the DPA, on request, in performing its tasks.
- Article 32
- The GDPR article requiring controllers and processors to implement appropriate technical and organisational measures to ensure security appropriate to the risk.
- Article 32(4)
- Provision concerning employees and other workers acting under the controller's/processor's authority; they must act within their instructions.
- Article 33
- Requires controllers to notify the supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware, unless it is unlikely to risk rights and freedoms.
- Article 33(5) register
- The controller's internal record of every personal data breach (including those it decides not to notify), held to allow retrospective regulator review.
- Article 34
- Requires controllers to communicate a personal data breach to affected data subjects without undue delay where it is likely to result in a high risk to their rights and freedoms.
- Article 35
- Requires a DPIA where processing is likely to result in a high risk to rights and freedoms; lists example high-risk activities and required DPIA contents.
- Article 36
- Prior consultation: where a DPIA shows residual high risk with no sufficient mitigation, the controller must consult the DPA before processing.
- Article 37
- Sets out when a DPO must be designated (public authority; core activities = large-scale regular/systematic monitoring; or large-scale special-category processing).
- Article 4(1) GDPR
- The GDPR's definition of personal data.
- Article 44
- GDPR provision restricting transfers of personal data outside the EEA unless the third country ensures an adequate level of protection.
- Article 45(1)
- The GDPR provision allowing transfers to a third country, territory, sector or international organisation that the Commission has decided ensures an adequate level of protection.
- Article 48
- A restriction: a third-country court or authority order for data is only recognised via an international agreement (e.g. a mutual legal assistance treaty) or EU/Member State law.
- Article 49
- The GDPR article listing derogations - narrow, last-resort grounds for a transfer when no adequacy decision or appropriate safeguard is available.
- Article 49 derogation
- Exceptions allowing transfers without standard safeguards (e.g. explicit consent); interpreted restrictively by the EDPB.
- Article 49(5)
- Allows Member States to limit transfers of specific categories of data for important public-interest reasons.
- Article 5
- The GDPR provision setting out the seven data processing principles plus accountability.
- Article 5(2)
- The accountability sub-provision: the controller must be able to demonstrate its compliance with the six principles - new to the GDPR.
- Article 5(3)
- ePrivacy provision requiring consent (with prior clear information) to store or access information on a user's device - the 'cookie consent' rule.
- Article 5(3) (ePrivacy)
- ePrivacy rule requiring prior informed consent to store or access information on terminal equipment (e.g. cookies), regardless of whether the data is personal; strictly-necessary cookies are exempt.
- Article 5(3) ePrivacy
- Permits storing/accessing information on a user's terminal equipment only with the user's consent given after clear and comprehensive information.
- Article 57 tasks
- The long list of DPA duties: monitor and enforce, raise awareness, handle complaints, investigate, advise parliaments, support consistency and the EDPB, approve codes/certifications/transfers, keep records.
- Article 6
- The article listing the six lawful bases for processing ordinary personal data.
- Article 6 legal basis
- A lawful ground to process the data in the first place (e.g. consent, contract, legitimate interests). Needed before any transfer mechanism is even considered.
- Article 7
- Sets out the conditions that must be demonstrated when a controller relies on consent.
- Article 8
- GDPR provision requiring parental consent for children's consent-based processing under 16 (states may lower to 13).
- Article 8 (Charter)
- Charter article guaranteeing everyone the right to the protection of personal data concerning them, with control by an independent authority.
- Article 8 (children)
- Sets a default consent age of 16 for information society services, which member states may lower to no less than 13.
- Article 8 (ECHR)
- Protects the right to respect for private and family life; the basis for the ECtHR's data protection case law, though it does not specifically mention data protection.
- Article 8 ECHR
- Protects the right to respect for private and family life, home and correspondence; a qualified, not absolute, right.
- Article 83(4)
- The lower fining tier: up to €10 million, or 2% of total worldwide annual turnover for undertakings, whichever is higher.
- Article 83(5)
- The higher fining tier: up to €20 million, or 4% of total worldwide annual turnover for undertakings, whichever is higher.
- Article 88
- GDPR provision letting Member States lay down more specific rules (including by collective agreement) for processing employees' data in the employment context.
- Article 88 GDPR
- GDPR provision allowing member states to set more specific national rules for processing employees' personal data, with safeguards for dignity and fundamental rights.
- Article 89(1)
- Requires safeguards (e.g. data minimisation, possibly pseudonymisation) for archiving/research/statistical processing.
- Article 9
- GDPR article on special categories of data, which are prohibited unless a specific condition (e.g. employment/social-security law, vital interests, legal claims) applies.
- Article 9(1)
- Prohibits processing of special categories of personal data unless an exception applies.
- Article 9(2)(b)
- Exception allowing sensitive-data processing necessary for employment, social security and social protection obligations/rights, where authorised by EU/member state law or a collective agreement.
- Articles 28(2) and (4)
- GDPR provisions regulating when and how a processor may engage a sub-processor and the liability that follows.
- Articles 32 to 36
- Cover data security, breach notification, data protection impact assessments and prior consultation with DPAs; the processor must assist the controller with these.
- Authentication
- Using biometrics to answer 'are you who you claim to be?' - e.g. a fingerprint to unlock a device.
- Automated calling system
- A system that places marketing calls without a live person; it always requires consent under ePrivacy.
- Automated decision-making
- A decision based solely on automated processing; access disclosures must reveal its existence, logic, significance and envisaged consequences.
- Automated processing
- Processing without human intervention; a DPIA trigger where it underpins decisions with legal or similarly significant effects.
- Availability
- Data is accessible when it is needed.
- Availability loss
- A temporary inability to access data (e.g., a power outage) - can itself amount to a personal data breach.
- Awareness
- A controller is 'aware' (WP29) when it has a reasonable degree of certainty that a security incident has occurred leading to personal data being compromised.
- B2B cloud services
- Cloud services for business customers - the only scope of the EU Cloud Code (not consumer/B2C services).
- Background checks
- Pre/ongoing employment checks (social media, education, criminal record); must not create illegal blacklists.
- Balancing exercise
- Weighing the controller's legitimate interests against the individual's rights and freedoms, to decide whether legitimate interests can support postal marketing.
- Balancing test
- Weighing the controller's/third party's legitimate interest against the data subject's interests, rights and freedoms, including their reasonable expectations.
- BCR
- Abbreviation for binding corporate rules; articulated in Article 47 of the GDPR; the 'gold standard' of global data protection.
- BCRs
- Approved internal group rulebook legitimising intra-group transfers.
- Behavioural data
- Data about how a person acts, generated by their use of technology and devices, which companies can capture and analyse.
- Best-answer question
- A scenario item where several options are defensible but one is the most correct - typical of Apply/Analyze questions.
- Big Brother Watch v UK
- 2021 ECtHR Grand Chamber case on bulk interception; found a violation of ECHR Article 8 but required 'end-to-end safeguards'.
- Binding Corporate Rules
- BCRs - internal, legally binding rules for intra-group transfers in multinationals, approved by a competent supervisory authority; minimum requirements in Article 47.
- biometric data
- Special-category data only when processed for the purpose of uniquely identifying a natural person.
- Biometric data (Article 4(14))
- Data from specific technical processing of physical, physiological or behavioural traits that allows or confirms unique identification; special-category only when used to uniquely identify.
- Biometric template
- A digital representation of the distinct characteristics extracted from raw biometric data (e.g. minutiae location and direction for a fingerprint).
- Blacklists
- Lists identifying individuals the employer will not employ; a significant privacy intrusion and generally illegal.
- Blocking
- The Directive-era right (Art 12(b)–(c)) to have a controller keep but refrain from using data for a period.
- Bloom's taxonomy
- A ladder of cognitive levels: Remember, Understand, Apply, Analyze, Evaluate, Create. Exam verbs map to these levels.
- Body of Knowledge
- BoK - the documented competencies and performance indicators assessed on the exam, with the Exam Blueprint min/max question counts.
- Breyer
- CJEU decision holding an IP address can be personal data where the ISP could link it to a person.
- Breyer v Germany
- CJEU case holding dynamic IP addresses can be personal data in the hands of a party (e.g. the state) able to lawfully obtain identifying data from an ISP.
- Burden of proof
- Under the GDPR it lies with the controller (not the data subject, as under the Directive) to show compelling grounds override the subject's rights.
- BYOD
- Bring Your Own Device - employees use personal devices for work; the employer is controller of work-related personal data on the device, not of the employee's own personal data.
- BYOD policy
- A policy explaining how employees may use BYOD, their responsibilities, storage, security and data removal.
- Case C-184/20
- CJEU decision: data liable indirectly to reveal sensitive information falls under the Article 9(1) prohibition (special category by inference).
- CCTV
- Closed-circuit television / video surveillance; captures personal data and potentially biometric data of those filmed.
- Certification
- Data protection seals and marks (Arts 42–43) issued by accredited certification bodies to demonstrate compliance.
- Certification mechanisms
- Approved certifications (Article 42) usable as a transfer mechanism with binding, enforceable commitments by the importer.
- Chapter 5 of the GDPR
- The chapter governing transfers of personal data to third countries and international organisations.
- Chapter V
- The GDPR chapter (Articles 44–49) governing transfers of personal data to third countries and international organisations.
- Charter
- The Charter of Fundamental Rights of the EU; Article 7 (private and family life) and Article 8 (protection of personal data) are key to surveillance.
- Charter of Fundamental Rights
- EU text consolidating the civil, political, economic and social rights of EU citizens and residents; made legally binding by Lisbon.
- Charter of Fundamental Rights of the EU (CFREU)
- EU instrument, made binding by the Treaty of Lisbon, in light of which EU data protection law is interpreted.
- Children's Code
- The UK Age Appropriate Design Code (in force Sept 2021) setting standards to design data protection into services likely to be used by children.
- CIA triad
- Confidentiality, integrity and availability - cornerstones of information security; Article 32(1)(b) adds resilience.
- CIPP/E
- Certified Information Privacy Professional/Europe - the IAPP's European data protection certification.
- CJEU
- Court of Justice of the European Union (Luxembourg) - interprets EU law, including the GDPR; an EU institution.
- Classification scheme
- A taxonomy so everyone knows the sensitivity and personal nature of data compromised, helping decide treatment and breach disclosure.
- Clear affirmative action
- An active, unambiguous indication of agreement required for valid consent (no pre-ticked boxes / no silence).
- Clear and plain language
- The Article 12(1) standard: concise, transparent, intelligible and easily accessible communication.
- Cloud computing
- IT services delivered over the internet; the provider is usually a processor under Article 28, but can become a controller in some circumstances.
- CNIL
- France's data protection authority (Commission nationale de l'informatique et des libertés).
- CNIL Guide for Processors
- France's DPA guide (2017) emphasising that processors must assist controllers and ensure sub-processors give the same guarantees.
- Codes of conduct
- Self-regulatory rules drawn up by representative bodies (Art 40) for compliance, with a monitoring body (Art 41) checking adherence.
- Collective agreement
- An agreement that, if it acknowledges certain monitoring, suggests the proportionality balance has been struck.
- Compatibility test
- Recital 50 factors used to decide whether a secondary purpose is compatible: link, context/expectations, nature of data, consequences, safeguards.
- Compatible further processing
- Secondary use that is consistent with the original purpose - no new legal basis needed.
- Compelling legitimate grounds
- Grounds the controller must demonstrate to continue legitimate-interest/public-interest processing despite an objection - they must override the data subject's interests.
- Compelling legitimate interests
- A narrow derogation for transfers that are non-repetitive and concern only a limited number of data subjects.
- Compensation
- An individual's right to claim damages for material or non-material harm from a GDPR infringement (rare in practice).
- Competency
- A cluster of connected tasks/abilities forming a broad knowledge domain in the BoK.
- Compromise testing
- Using advanced forensics to discover whether an organisation is already compromised, since attackers can lie unnoticed on a network for years.
- Confidentiality
- Access to data is granted on a need-to-know basis.
- Confidentiality versus anonymity
- Keeping the whistleblower's identity confidential (preferred) rather than encouraging fully anonymous reports.
- Conflict of interest
- The DPO may hold other roles only if they do not conflict with the DPO function.
- Consent
- Freely given, specific, informed, unambiguous agreement to processing for a specific purpose; must be as easy to withdraw as to give.
- Consent (employment)
- Often invalid for employees because the power imbalance means it is rarely freely given; processing can be unlawful even where consent was obtained.
- Consent age
- Age for valid children's consent online - GDPR default 16, but states may lower it to no less than 13.
- Consent procedure
- For particularly important decisions (e.g. EU enlargement), Parliament's consent is required.
- Consistency mechanism
- Chapter VII process where the Commission, EDPB and SAs adopt measures to ensure the GDPR is applied consistently across the EU.
- Consultation procedure
- The Council must consult Parliament but is not bound by its opinion; the Council alone holds legislative power.
- Contact tracing
- Identifying who a person has been in contact with; during COVID-19, apps notified users of close proximity to a confirmed carrier.
- content element
- Present when information is about an individual in the ordinary sense of the word (e.g. a test result clearly relates to the student).
- Contract
- Processing necessary to perform a contract with the data subject, or to take pre-contractual steps at their request.
- Contract basis (6(1)(b))
- Processing necessary to perform a contract with the data subject, or to take pre-contractual steps at their request.
- Contractual necessity
- Art 6(1)(b) - basis for processing necessary to perform a contract; the EDPB does not believe it supports targeted online advertising.
- Controller
- The natural or legal person, public authority, agency or other body that, alone or jointly, determines the purposes and means of processing (Article 4(7)).
- Convention 108
- 1981 Council of Europe treaty - the first legally binding data protection instrument; limited to automatic processing.
- Convention 108+
- Modernised (Oct 2018) version of Convention 108 aligned with the GDPR; a route for non-EU countries to adopt GDPR basics.
- Convergence
- The merging of telecoms, internet and media technologies that prompted widening telecoms law to all electronic communications.
- converging decisions
- Separate decisions by different entities that complement each other and are necessary for processing, with a tangible impact on its purposes and means.
- Cooperation procedure
- Article 60 - the lead authority shares a draft decision with concerned DPAs, who may agree or raise a reasoned objection; unresolved objections escalate to the EDPB.
- Core activities
- The primary operations of the organisation (not ancillary support functions), used to decide whether a DPO is mandatory.
- Corporate Telephone Preference Service
- UK central opt-out register for corporate subscribers; marketers must cleanse against it before B2B marketing calls.
- Corrective powers
- Article 58(2) powers including warnings, reprimands, orders, processing bans and administrative fines.
- Costeja judgment
- CJEU ruling of 13 May 2014 (C-131/12) that a data subject may ask a search engine to delist links to pages appearing under a search of their name.
- Costs of implementation
- Not necessarily the most expensive option - demonstrably good, proportionate management decisions about spend.
- Council configurations
- The ten subject-specific formats (e.g. Justice and Home Affairs) the Council meets in; powers stay the same as it is a unitary institution.
- Council of Europe
- International organisation (not the EU) that drew up the ECHR; based the ECHR on the UDHR.
- Council of Europe (CoE)
- International organisation of 46 Member States that promotes democracy, human rights and the rule of law; not an EU body and has no legislative power of its own.
- Council of Ministers
- The Council of the EU, where member states meet to review and agree legislation.
- Council of the EU
- Body of Member State representatives whose membership changes with the topic; reviewed the GDPR via its DAPIX Committee.
- Council of the European Union
- The 'Council of Ministers' - the EU's main decision-making body and co-legislator with the Parliament; one minister per state attends.
- Court of Justice (ECJ)
- The higher part of the CJEU; 27 judges and eight advocates general; hears preliminary rulings and major actions.
- Court of Justice of the European Union
- The EU's judicial body in Luxembourg; rules on EU law. Comprises the Court of Justice (ECJ) and the General Court.
- Covert monitoring
- Undisclosed surveillance; permitted only in narrow circumstances, often where specific criminal activity is suspected.
- Cross-border processing
- Article 4(23): processing in the context of establishments in more than one Member State, or by a single EU establishment that substantially affects data subjects in more than one Member State.
- CSIRT
- Computer Security Incident Response Team - national teams established under the NIS Directive to handle cyber incidents.
- CSO
- Civil society organisation - a not-for-profit ('privacy advocate' or 'pressure group') that can represent individuals under Article 80.
- Cybersecurity
- The protection of network and information systems from attack; closely related to, but not always identical with, personal data security.
- Dark patterns
- Deceptive interface designs that manipulate users about their personal data; EDPB Guidelines 03/2022 list six categories.
- Data bank
- An extensive store of personal information set up by public administrations and large enterprises to collect, process and share data.
- data concerning health
- Data on a person's physical or mental health, including care provision, revealing their past, current or future health status.
- Data loss prevention (DLP)
- Tools that protect IT infrastructure and confidential data; processing employee data and counting as a form of monitoring.
- Data minimisation
- Only data that is relevant and necessary for the purpose may be processed.
- Data portability
- Article 20: the right to receive personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Data processing agreement (DPA)
- The written Article 28 contract between controller and processor setting out subject matter, duration, nature, purpose, data types, data-subject categories and the parties' obligations.
- Data Protection Act 2018
- UK statute (DPA) that supplemented the GDPR and, post-Brexit, sits alongside the UK GDPR (as amended).
- Data protection by default
- Ensuring that, by default, only personal data necessary for each specific purpose is collected, processed, stored and made accessible.
- Data protection by design
- Building data protection into the planning and design phase, before processing begins.
- Data protection by design and by default
- Building data protection into systems and defaulting to the most protective settings.
- Data Protection Directive
- 1995 EU directive, precursor to the GDPR, that Member States had to transpose into local law.
- Data protection officer
- A compliance-focused role, mandated for the first time by the GDPR (Arts 37–39), immune from dismissal and acting as a quasi-regulator within the organisation.
- Data protection officer (DPO)
- Where one is appointed, the controller must give the DPO's contact details to the data subject.
- Data protection policy
- An internal Article 24(2) document that trains staff and sets the rules and consequences for handling personal data; required where proportionate.
- Data Protection Review Court
- Part of the DPF's two-tier redress system, giving EU individuals a path to challenge US intelligence access to their data.
- Data Retention Directive
- 2006 directive requiring ISPs/telcos to retain communications metadata; struck down by the CJEU in Digital Rights Ireland (2014).
- Data retention policy
- A documented framework setting how long each category of data is kept and when it is deleted.
- Data subject
- The identified or identifiable individual whose data is affected; the recipient of an Article 34 communication.
- Data subject request (DSR)
- A request by a data subject - here, to rectify incomplete or incorrect records.
- Data subject rights
- The set of enforceable rights individuals hold over their personal data, set out in GDPR Articles 12–23.
- Data subjects who are in the Union
- The trigger group for Article 3(2). Interpretation is unsettled; EU residency should not be assumed to be a prerequisite.
- decisive influence
- The factual test for 'determines' - who actually decides whether and how processing takes place.
- Derogation
- A narrow, last-resort exemption under Article 49 allowing a transfer in a specific situation when neither adequacy nor safeguards are available.
- Derogations
- Last-resort exemptions, narrowly interpreted, permitting a transfer in specific situations (consent, contract, public interest, legal claims, vital interests, public register, compelling legitimate interests).
- Device fingerprinting
- Collecting many technical data points (screen resolution, browser settings, OS) to uniquely identify a device without a cookie.
- Digital Rights Ireland
- 2014 CJEU judgment that struck down the Data Retention Directive for disproportionately infringing Charter privacy rights.
- Digital service providers
- Online marketplaces, online search engines and cloud computing services (Annex III) - e.g. eBay, Google, Amazon.
- Direct effect
- The ability of an EU instrument to be relied on directly. The GDPR (a Regulation) has direct effect; the ePrivacy Directive does NOT - it had to be implemented into national law.
- Direct marketing
- A communication by any advertising/marketing means directed towards specific individuals; pure service messages or those not processing personal data are not direct marketing.
- Directive
- EU law that obliges Member States to implement it via national legislation; the Data Protection Directive had 34 articles, implemented differently in each state.
- Directive 95/46
- The 1995 Data Protection Directive; the EU's main data protection law until the GDPR replaced it.
- Directly applicable
- Applies in all member states automatically without national implementing legislation.
- Disproportionate effort
- An Article 34 exception allowing a public communication instead of individual notice to data subjects.
- Distractor
- A deliberately plausible wrong option, usually drawn from a common misconception or an adjacent concept.
- Documented instructions
- Written instructions from the controller; the processor may process only on these (including for international transfers) unless required otherwise by EU/member state law.
- DPA
- Data protection authority - the member-state regulator (e.g. France's CNIL, the UK's ICO, Spain's AEPD).
- DPIA
- Data protection impact assessment - a legal requirement in high-risk cases, with specified contents, used to plan in protection and demonstrate compliance.
- DPO
- Data protection officer - a staff member or contractor, expert in data protection law and practices, who advises on and monitors compliance.
- Dynamic IP address
- A device receives a different IP address on each startup - making it harder to link separate browsing sessions.
- Easily accessible
- Information that is apparent to the data subject without their having to seek it out.
- ECHR
- European Convention on Human Rights - a Council of Europe treaty signed in Rome 1950, in force 1953; binds member states only.
- ECtHR
- European Court of Human Rights (Strasbourg) - enforces the ECHR; NOT an EU institution.
- Edge computing
- Processing personal data on the user's device rather than a central server - complicating the controller analysis.
- EDPB
- European Data Protection Board - replaced the Article 29 Working Party on 25 May 2018; issues guidelines, recommendations and binding decisions.
- EDPB Guidelines 03/2022
- EDPB guidance on dark patterns in social-media interfaces and how to recognise and avoid them.
- EDPB Guidelines 07/2020
- EDPB guidance on the concepts of controller and processor, setting the two conditions to qualify as a processor.
- EDPB Guidelines 1/2024
- EDPB guidelines on processing based on legitimate interests under Article 6(1)(f), setting three cumulative conditions.
- EDPB Guidelines 3/2019
- EDPB guidance on processing personal data through video devices.
- EDPB Guidelines 8/2020
- EDPB guidance on targeting social-media users, distinguishing provided, observed and inferred data.
- EDPB Opinion 22/2024
- EDPB opinion clarifying controllers' obligations regarding the use of processors and sub-processors.
- EDPB Opinion 5/2019
- Opinion explaining the interplay between the GDPR and the ePrivacy Directive (complement, parallel, lex specialis, lex generalis).
- EDPS
- European Data Protection Supervisor - supervises the EU institutions' own compliance; sits on the EDPB with limited voting rights.
- EEA
- European Economic Area - the EU plus Iceland, Liechtenstein and Norway. GDPR transfer rules apply to data leaving this zone.
- EEC
- European Economic Community - the trade bloc whose cross-border trade encouraged a rise in information sharing.
- Effective judicial remedy
- An individual's right to take a controller, processor or SA to court over a GDPR infringement.
- Effective, proportionate and dissuasive
- The mandatory character of all administrative fines under Article 83(1).
- Electronic mail
- ePrivacy Art 2(h): any text, voice, sound or image message over a public network stored until collected - technology-neutral, so it covers email, SMS and MMS.
- Employee handbook
- A common vehicle for delivering the privacy notice to staff, alongside or instead of a standalone notification.
- Employee monitoring
- Observation of workers' activity (email, internet, calls, location); lawful only if necessary, lawfully based, proportionate and transparent.
- Employment contract
- Lawful basis under Article 6(1)(b) where processing is necessary to perform the contract (e.g. paying salary).
- Encryption
- Rendering data unintelligible to anyone without the key; named in Article 32(1)(a) as a control to be considered.
- Encryption safe harbor
- Article 34(3)(a) exception: communication is not required if the data was rendered unintelligible (e.g. by encryption) to unauthorised persons.
- ENISA
- The EU Agency for Cybersecurity, which maintains the European Vulnerability Database (EUVD).
- ePrivacy Directive
- Directive 2002/58 governing communications over public electronic networks; main basis is consent, applies to public (not private) networks, and is lex specialis to the GDPR.
- ePrivacy Regulation
- A 2017 proposal to replace the ePrivacy Directive. The Commission withdrew it on 6 October 2025.
- Essential entities
- NIS2 category covering energy, banking, health and drinking water.
- Essential equivalence
- The standard a third-country framework must meet - protection essentially equivalent to, not identical with, the EU regime.
- Essential means
- Core decisions about how processing happens; deciding these (not just technical means) tips a processor into being a controller.
- Establishment
- A presence in a member state with stable arrangements and effective exercise of activities; even minimal activities can suffice (Weltimmo).
- Establishment criterion
- Article 3(1): the GDPR applies to processing by an EU-established controller/processor, regardless of where processing occurs.
- EU AI Act
- The world's first comprehensive AI regulation, passed by the European Parliament on 13 March 2024; risk-based, with four tiers, and extraterritorial.
- EU Charter
- Charter of Fundamental Rights of the EU, including rights to privacy and data protection.
- EU Cloud Code
- The EU Data Protection Code of Conduct for Cloud Service Providers, approved May 2021, for B2B cloud processors.
- EU representative
- An Article 27 contact point in the EU for organisations caught by Article 3(2) but not established in the EU; addressable by supervisory authorities and data subjects.
- EU-US Data Privacy Framework
- The framework covered by Commission Implementing Decision (EU) 2023/1795 for transfers to participating US organisations.
- European Commission
- EU institution with one commissioner per Member State that proposes legislation.
- European Convention on Human Rights
- The ECHR - the human rights treaty the ECtHR enforces, protecting fundamental rights of people in contracting states.
- European Convention on Human Rights (ECHR)
- Binding international treaty drawn up by the Council of Europe, in force 1953, protecting private life (Art. 8) and free expression (Art. 10).
- European Council
- Heads of state or government; sets political direction but is NOT a legislature.
- European Court of Human Rights
- Strasbourg court of the Council of Europe (not the EU) that applies the ECHR; founded 1959.
- European Court of Human Rights (ECtHR)
- Strasbourg court that enforces the ECHR; it is NOT an EU body.
- European Data Protection Board (EDPB)
- EU body of national SA representatives that ensures consistent application of the GDPR; replaced the Article 29 Working Party.
- European Data Protection Supervisor
- The authority that regulates data protection compliance within the EU's own institutions.
- European Data Protection Supervisor (EDPS)
- Independent authority overseeing the EU institutions' (Commission, Parliament) compliance with data protection rules; ambassadorial role and issues opinions.
- European Essential Guarantees
- EDPB Recommendations 02/2020 distilling four requirements that surveillance laws must meet to match the Charter's level of protection.
- European Parliament
- Directly elected EU body (MEPs); reviewed the GDPR via its LIBE Committee.
- European Union (EU)
- Economic and political union of 27 Member States; its privacy instruments include the CFREU, TFEU, GDPR and ePrivacy Directive.
- European Vulnerability Database (EUVD)
- A vulnerability database provided under NIS2 and maintained by ENISA.
- EU–US Data Privacy Framework
- The DPF - the current US adequacy arrangement, adequacy decision adopted 10 July 2023, with a two-tier redress system.
- Exam Blueprint
- The minimum and maximum number of questions drawn from each domain on the exam.
- Exit Regulations
- The Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019, which adapted the GDPR and DPA for Brexit.
- Expectation of privacy
- If not told of monitoring, employees have a greater expectation of privacy; notice reduces but never eliminates it.
- Explicit consent
- Heightened form of consent needed for sensitive data; for employees it is a last resort because of the power imbalance.
- Fair processing information
- The set of information a controller must give data subjects about how their personal data are processed, required mainly by Articles 13 and 14.
- Fair processing notice
- A privacy notice; the convenient written/electronic method by which a controller communicates the information required by Articles 13/14.
- Fairness
- A GDPR principle expressly linked to transparency; failing to give required information, or not processing in line with the information given, is likely to make processing unfair.
- Filing system
- A structured set of personal data accessible according to specific criteria; brings non-automated processing within material scope.
- First communication
- If data obtained from another source are used to communicate with the subject, information is due at the latest at that first communication.
- Five-step calculation
- The EDPB's method: identify processing operations; set a starting point (nature/seriousness + turnover); weigh aggravating/mitigating features; establish the maximum; ensure the fine is effective, proportionate and dissuasive.
- Free flow of personal data
- Principle that data should move freely for commerce and public functions, balanced against privacy.
- Freely given
- The data subject can genuinely choose and withdraw at any time, as easily as giving; avoid where there is a clear imbalance of power.
- FTC
- U.S. Federal Trade Commission - the regulator responsible for enforcing Safe Harbor commitments against participating firms.
- Function creep
- The gradual drift of data use beyond the originally stated purpose; purpose specification guards against it.
- Galileo
- The EU's Global Satellite Navigation System, the European equivalent of the American GPS.
- GDPR
- The General Data Protection Regulation, which added direct legal obligations for processors and emphasised the customer-supplier contract.
- General Court
- The renamed Court of First Instance (CFI); the lower part of the CJEU, with appeals on points of law going to the ECJ.
- genetic data
- A special category under Article 9 relating to inherited or acquired genetic characteristics.
- Google Spain
- CJEU ruling (2014, Google Spain / Google v AEPD) establishing the right to be forgotten and treating search engines as controllers of personal data appearing in third-party pages.
- Granular consent
- Offering separate consents for specific types of processing rather than one bundled consent for everything in a policy.
- Granularity
- Providing a separate consent mechanism for each distinct processing purpose.
- Guardian of the treaties
- The Commission's role of monitoring compliance by institutions, member states and natural/legal persons, with power to act against breaches.
- Guidelines 3/2018
- EDPB guidelines on the territorial scope of the GDPR (Article 3).
- Guidelines 3/2019
- EDPB Guidelines on processing of personal data through video devices (CCTV) - covers purpose, signage, retention and design.
- Hesse
- German state that introduced the first regional data protection law in 1970.
- High risk
- The Article 34 threshold at which data subjects must be informed of a breach.
- High-risk AI system
- AI permitted but subject to strict requirements (data quality, documentation, human oversight, conformity assessment, CE marking, registration).
- High-risk AI systems
- AI systems subject to the AI Act's detailed risk-management, documentation and oversight duties.
- Hindrance / technical feasibility
- Limits on portability - transfer must be without hindrance, and direct controller-to-controller transfer only where technically feasible.
- Household exemption
- Exemption where an individual processes personal data purely for personal or household reasons; disapplied in business or over-broad sharing.
- IaaS
- Infrastructure as a Service - supplier provides remote computing resources; the user maintains the operating platform and applications.
- ICO
- Information Commissioner's Office - the UK's data protection supervisory authority.
- identifiable
- A person who has not been identified yet but who it is possible to identify, directly or indirectly.
- Identification
- Using biometrics to answer 'who are you?' - e.g. facial recognition on social-media photos.
- Identity verification
- The controller's duty to use all reasonable efforts to confirm who is making a request, requesting only what is necessary and proportionate.
- Illusion of competence
- The false sense of mastery created by fluent re-reading and highlighting; recognising material is not the same as recalling it.
- Imbalance of power
- The unequal relationship between employer and employee that usually prevents consent from being freely given.
- Implementing act
- The legal instrument by which the Commission formally adopts an adequacy decision.
- Implied consent
- Treating continued browsing as agreement; no longer acceptable post-GDPR - consent must be a specific, informed, unambiguous, affirmative act.
- Important entities
- NIS2 category covering waste management, food, medical devices and electronics.
- Impossibility
- An Article 14(5)(b) exemption the WP29 treats as absolute - something is either impossible or it is not; there are no degrees of impossibility.
- In the context of the activities
- The second Article 3(1) limb: there must be an inextricable link between the EU establishment's activities and the processing, even where the processing is done by a non-EU controller.
- In the context of the sale
- The condition that the contact details were obtained around a sale. Some states read it literally (a completed sale); others (NL, UK) read it broadly (pre-sales, account registration, competition entry).
- Incident response plan
- A pre-agreed plan covering detection through immediate response into the long term, with roles, governance, decision principles and rehearsal.
- Independence
- Articles 51–52 - DPAs must act with complete independence, with sufficient skills and resources (Art 52(4)) and not be subject to State scrutiny.
- Information society service
- A service normally provided for remuneration, at a distance, by electronic means, at the individual request of a recipient.
- Insider threat
- The security risk posed by an organisation's own employees and workers, managed through policy, training and monitoring.
- Institutional status
- Formal status that lets a body make binding decisions rather than play a purely advisory role.
- Integrity
- Data is kept accurate and complete.
- Integrity and confidentiality
- Article 5(1)(f) security principle: ensure appropriate security against unauthorised/unlawful processing and accidental loss, destruction or damage.
- Internal market
- The EU single market requiring free movement of goods, persons, services and capital - and thus of personal data.
- International agreements
- Cross-border arrangements relied on for transfers, e.g. the EU–US passenger name records (PNR) agreement.
- International organisation
- An organisation and its subordinate bodies governed by public international law, or any body set up by or on the basis of an agreement between two or more countries.
- Internet of Things (IoT)
- The networked interconnection of everyday objects, which generates further data about individuals.
- Interoperability
- The goal of portability: enabling data to move usefully between services and controllers.
- Investigative powers
- Article 58(1) powers to obtain information, carry out audits and access premises and data to investigate compliance.
- Investigatory powers
- Article 58(1) - access to evidence, documents, premises and equipment, plus the power to audit, inspect and notify alleged infringements.
- IoT
- Internet of Things - physical objects with technology to connect to a network and transmit information, often via sensors.
- IP address
- A numerical label assigned to internet-connected devices; may reveal the ISP and the device's physical location.
- ISMS
- Information Security Management System - the policy framework that organises an organisation's security controls.
- jigsaw identification
- Identifying a person by combining separate pieces of information that individually do not identify them.
- Joint controllers
- Two or more controllers that jointly determine the purposes and means of processing (Article 26).
- joint controllership
- Where two or more entities jointly determine the purposes and means of the same processing, sharing controller responsibilities.
- Just-in-time notice
- Information provided at the specific point of data collection, when it is most relevant to the data subject (e.g. beside a form field).
- Just-in-time notices
- Notices delivered at the precise point of data collection or use.
- Large scale
- Assessed by reference to number of data subjects (not company size), volume/range of data, duration/permanence, and geographical extent (WP29).
- Law Enforcement Directive
- EU directive governing processing by competent authorities for law-enforcement purposes - lawful, fair, necessary and proportionate.
- Lawful basis
- One of the six legal grounds in Article 6 (consent, contract, legal obligation, vital interests, public interest, legitimate interests). Processing needs at least one.
- Layered approach
- Structuring security paperwork in three layers: high-level policy statements, then controls, then detailed operating procedures.
- Layered notice
- A notice presenting the most important information in a short first layer, with fuller detail accessible behind links or another channel.
- Layered notices
- A format that presents key elements up front with links to fuller detail; WP29 endorses up to three layers.
- LED
- Law Enforcement Directive (EU) 2016/680, governing processing by competent authorities for criminal-justice purposes.
- Legal hold
- A suspension of normal use where data is stored but not otherwise processed.
- Legal obligation
- Processing necessary to comply with an EU or Member State legal obligation; interpreted narrowly.
- Legal obligation (6(1)(c))
- Processing necessary to comply with a legal obligation in EU or member-state law - not a contract, not third-country law.
- Legitimacy
- There must be a lawful basis (often the legitimate-interests balancing test) and the processing must be fair.
- Legitimate interest
- Art 6(1)(f) lawful basis - a balancing test weighing the controller's/third party's interest against the data subject's interests and rights.
- Legitimate Interest Assessment (LIA)
- The documented balancing test weighing the controller's interest against the data subject's interests, rights and freedoms.
- Legitimate interests
- Lawful basis under Article 6(1)(f); cannot be relied on by public authorities for their tasks, cannot be adverse to employees' rights, and cannot ground special-category processing.
- Legitimate-interests balancing test
- Weighing the employer's legitimate interest (e.g. protecting against threats) against employees' rights; the usual basis for monitoring.
- lex specialis
- A more specific law that prevails over a general one; the ePrivacy Directive is lex specialis over the GDPR for electronic communications.
- LIA
- Legitimate interest assessment - the documented record of the three-part test the ICO expects controllers to keep.
- Lindqvist
- ECJ case C-101/01 (2003): loading personal data onto a website hosted in a member state, accessible to anyone online, is not itself a transfer to a third country.
- Litigation posture
- The stance, reflected in the incident response plan, on roles of internal/external lawyers and legal professional privilege when a breach may lead to enforcement or litigation.
- Lloyd v Google
- UK class-action that reached the UK Supreme Court, which rejected the representative action - an example of private enforcement around tracking/cookies.
- Location data
- Data such as latitude/longitude; an identifier under the GDPR, and under ePrivacy usually requires opt-in consent given its intrusiveness.
- Location-based services (LBS)
- Services that use a device's location to deliver applications such as navigation, advertising, gaming, payments and emergency response.
- López Ribalda v Spain
- ECtHR Grand Chamber case; covert workplace cameras to investigate theft did not violate Article 8 on the facts.
- Main establishment
- Article 4(16) - for controllers, where decisions on purposes and means of processing are taken (usually central administration); for processors, the main processing activities.
- Mainframe computers
- Large early computers whose rise in the public and private sectors drove the perceived threat to privacy.
- Manifestly made public
- An Article 9 condition where the data subject has clearly made special category data public - a high threshold.
- Manifestly unfounded or excessive
- The very high threshold that lets a controller charge a reasonable fee or refuse; it must be justified and documented.
- Manual data
- Personal data held in a structured filing system by non-automatic means; the Directive subjected it to the same rules as automated data.
- Margin of manoeuvre
- Flexibility member states had to transpose Directive principles into national law, causing divergence.
- masking
- Data obfuscation that manipulates real data to reduce risk while preserving desired properties.
- Material scope
- The Article 2 rules deciding which kinds of processing the GDPR governs, and which are excluded.
- Member state employment law
- National labour/employment rules that vary widely across the EU and must be considered alongside the GDPR.
- MEP
- Member of the European Parliament, directly elected every five years.
- Metadata
- Data about data - e.g. traffic data (calling numbers), location data and subscriber data - as opposed to the content of a communication.
- Mobile device management (MDM)
- Software that can locate devices and remove data on demand, e.g. when an employee leaves or a device is lost/stolen.
- Monitoring behaviour
- Tracking individuals in the EU (e.g. profiling online) - a trigger for GDPR's extraterritorial scope.
- Monitoring body
- An independent body that verifies a cloud provider's compliance with the EU Cloud Code.
- Monitoring of behaviour
- Article 3(2)(b): catches non-EU organisations monitoring (profiling) the behaviour of people in the EU, as far as that behaviour takes place in the Union; no intention required.
- Mutual assistance
- Cooperation mechanism for the provision of relevant information between supervisory authorities.
- Mutual recognition
- The streamlined process, incorporated into the GDPR, by which DPAs recognise each other's review in approving BCRs.
- National security / defence / public security
- Example grounds on which member states may legislate to restrict data subject rights.
- natural person
- A living individual (birth to death), including sole traders, employees, partners and directors - as distinct from a corporation.
- Necessity
- The employer must show the monitoring is really necessary and consider less-intrusive options first.
- Necessity, proportionality and legality
- Core principles all EU law enforcement processing must meet, with safeguards for individuals.
- New purpose (further processing)
- Where a controller intends to use data for a purpose other than originally collected; it must inform the subject of the new purpose plus relevant further information before that processing starts.
- NIS 2
- Directive (EU) 2022/2555, which replaced the original NIS Directive and strengthened EU cybersecurity duties.
- NIS 2 Directive
- Directive (EU) 2022/2555, the adopted successor that widens scope and strengthens cybersecurity duties.
- NIS Directive
- The first EU-wide cybersecurity law, in force May 2018; aligns with and bolsters GDPR security but is not specifically about personal data.
- NIS2 Directive
- Directive (EU) 2022/2555, in force from 16 January 2023 with a 17 October 2024 transposition deadline.
- non-essential means
- Practical implementation choices (e.g. which software, which staff) that a controller may delegate to a processor.
- Notice
- Transparency information telling employees what data is used, for what purposes, who to contact, and what their rights are.
- NOYB
- Max Schrems' NGO ('none of your business') that filed 422 formal GDPR complaints with ten DPAs over cookie banners.
- OBA
- Online behavioural advertising - website ads targeted on a user's behaviour observed over time, often via third-party ad-network cookies with unique identifiers.
- OECD
- Organisation for Economic Co-operation and Development; promotes economic growth and has members beyond Europe, giving its 1980 Guidelines wide reach.
- OECD Guidelines
- 1980 guidelines that introduced harmonised data-collection principles underpinning later European and global self-regulatory regimes.
- OECD principles
- Eight foundational data principles: collection limitation, data quality, purpose specification, use limitation, openness, individual participation, accountability, security safeguards.
- Offering of goods or services
- Article 3(2)(a): catches non-EU organisations that offer goods/services to people in the EU, irrespective of whether payment is required; targeting must be intentional, not inadvertent.
- Official Journal
- The publication in which EU legislation is published to become law.
- One-month outer limit
- Under Article 14(3), the longest time a controller may wait to give fair processing information when data are obtained from another source.
- One-month time limit
- The default deadline (from receipt) to respond to a data subject request under Article 12(3).
- One-stop shop
- The principle that for cross-border processing a single lead supervisory authority is the controller/processor's 'sole interlocutor' (Art 56(6)).
- One-stop-shop
- Procedure where the LSA investigates, drafts a decision and coordinates with concerned SAs so organisations deal with one main authority.
- Online identifier
- An identifier (e.g. cookie ID, IP address) by reference to which a person 'can' be identified - making related data personal data.
- Onward transfer
- A further transfer of the data by the original recipient to yet another country or party. It must also be protected to an adequate standard.
- Opening clauses
- Over 50 GDPR provisions allowing member states to make supplementary national law.
- Operators of essential services
- Entities (Annex II) in energy, water, transport, health, banking and digital infrastructure whose disruption would significantly affect critical activities.
- Opinion 04/2024
- EDPB opinion on the concept of main establishment under Article 4(16)(a) and the one-stop-shop.
- Opt-out
- A model where inaction is treated as agreement - the opposite of consent, which needs an active indication.
- Opt-out address
- A valid address suited to the medium for opt-out requests (e.g. a reply email/link, or 'Text STOP to 12345' for SMS) - required by Art 13(4).
- Opt-out register
- A list (e.g. a do-not-call register) that marketers must screen against before making live calls in jurisdictions that use them.
- Ordinary procedure
- Co-decision procedure where both Parliament and Council must assent; legislation fails if either opposes it. Used for data protection.
- OTT services
- Over-the-top services such as messaging, email and voice apps, brought into scope alongside traditional telecoms.
- Outsourcing
- Arrangement where an organisation hires an external supplier to carry out data processing on its behalf.
- PaaS
- Platform as a Service - supplier provides the operating platform and hardware; the user maintains the applications.
- Penetration testing
- Authorised simulated attacks by 'ethical hackers' to test a technology stack; the ICO has cited lack of pen-testing in enforcement.
- Performance indicator
- The discrete tasks/abilities within a competency that exam questions actually assess.
- personal data
- Article 4(1) GDPR: any information relating to an identified or identifiable natural person.
- Personal data breach
- Article 4(12): a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
- Phased notification
- Providing breach information to the regulator in stages where the full picture is not yet clear, rather than delaying notification.
- PIA
- Privacy impact assessment - a broader, lighter assessment that can be run on any process; not the GDPR's legal requirement.
- PII
- Personally identifiable information - a U.S.-style term not defined in the GDPR; it cannot be assumed to mean the same as 'personal data'.
- Planet 49
- ECJ decision (C-673/17) ruling that pre-ticked checkboxes do not constitute valid consent; the user must act.
- Planet49
- CJEU ruling (October 2019) confirming cookie consent must be active behaviour, applies even to non-personal data, and must inform users about cookie duration and third-party access.
- Policy-based regulation
- Regulators assessing compliance by examining an organisation's paperwork - cheaper, quicker and more certain than operations-based regulation.
- Pre-contractual due diligence
- The controller's duty to vet a prospective processor (policies, security, certifications, maturity) before engaging it.
- Preference service
- A national opt-out register (e.g. UK Mail Preference Service / Telephone Preference Service) for a given channel.
- Preliminary ruling
- A ruling the ECJ gives when a national court refers a question on the interpretation or validity of EU law.
- Prior checking
- Requirement in some countries (e.g. France) to notify or obtain authorisation from the regulator before deploying surveillance.
- Prior consultation
- Article 36 duty to consult the supervisory authority when a high risk remains after mitigation; the SA may advise or block the processing.
- Prior opt-in consent
- Consent obtained before the message is sent / cookie is set. The default ePrivacy rule for most digital channels.
- Privacy by Design (PbD)
- The concept developed by Ann Cavoukian (former Ontario Commissioner), built on seven foundational principles of embedding privacy into design.
- Privacy dashboard
- A tool linked to a notice that lets data subjects view and control how their personal data are processed; useful across multiple devices.
- Privacy notice
- A statement describing how an organisation collects, uses, retains and discloses personal data; also called a privacy statement, fair processing statement or privacy policy.
- Privacy Sandbox
- Google's Chrome initiative (announced 2019) to replace third-party-cookie cross-site tracking with more privacy-friendly tools.
- Privacy Shield
- Safe Harbor's replacement, invalidated by Schrems II in 2020 for the same surveillance-redress reasons.
- Processing
- Any operation or set of operations performed on personal data, whether or not by automated means (Article 4(2)).
- Processor
- A separate entity that processes personal data on the instructions of, and on behalf of, the controller (Article 4(8)).
- Processor BCRs
- BCRs adapted to the processor's role; let a provider's overseas entities qualify as 'safe processors' so customers can transfer data to them.
- Professional secrecy
- Article 54(2) - DPAs and their staff are bound by professional secrecy regarding confidential information they access.
- Profiling
- Automated processing to evaluate, analyse or predict personal aspects of a person - e.g. via cookies, web beacons or digital fingerprinting.
- Proportionality
- Monitoring must be proportionate to the issue, a reasoned and realistic response to a real threat.
- Provided by the data subject
- Data the person actively gave or that was observed from their activity - not data the controller derived or inferred.
- Provider / deployer
- Under the AI Act, providers develop or sell AI systems; deployers use them. Both can fall within scope, including operators outside the EU whose output is used in the EU.
- Proxy request
- A subject access request made via a third party (attorney, accountant, etc.) acting on the data subject's behalf, requiring proof of entitlement.
- Pseudonymisation
- Processing personal data so it can no longer be attributed to a specific person without separately held additional information.
- pseudonymised data
- Personal data processed so it can no longer be attributed to a data subject without separately-kept additional information; still personal data and WITHIN the GDPR.
- pseudonymous data
- Data with identifying aspects detached but re-identifiable using separately kept information; still personal data under the GDPR.
- Public international law
- The body of law (treaties etc.) under which a member state's law can apply in places like embassies, consulates, ships and aircraft.
- Public task (6(1)(e))
- Processing necessary for a task in the public interest or the exercise of official authority vested in the controller.
- purpose element
- Present when information is processed to evaluate, consider or analyse an individual in a certain way.
- Purpose limitation
- Data collected for a specified purpose may not be further processed in an incompatible way; a compatibility test governs further use.
- Purposes and means
- The "why" (purposes) and the "how" (means) of processing. Determining the essential means is reserved to the controller.
- Qualified majority
- A weighted voting threshold assessed by number of member states and the share of EU population they represent.
- Qualified majority voting
- Voting assessed both by number of member states and by the share of EU population represented (always 65% of population).
- Rapporteur
- An MEP appointed to prepare a report on a proposed legislative text within a committee.
- Reasonable measures
- Processes to prevent inaccuracy at collection and during processing, judged against data type and purpose.
- Reasoned objection
- A concerned DPA's objection to a draft decision (e.g. on the finding or the size of a fine) under Article 60(4).
- Recalibration of responsibilities
- The GDPR's shift that keeps controllers primarily accountable while raising processors to a much higher level of direct responsibility.
- Recital 105 GDPR
- Requires the Commission to take particular account of a third country's accession to Convention 108 when assessing adequacy.
- Recital 26
- Identifiability is judged by 'all the means reasonably likely to be used' to identify a person.
- Recital 27
- States the GDPR does not apply to the personal data of deceased persons, though member states may provide rules for it.
- Recital 43
- GDPR recital stating consent is not a valid ground where there is a clear imbalance between data subject and controller.
- Recital 45
- Requires the legal-obligation and public-task bases to rest on EU or member-state law, and rules out reliance on non-EU law.
- Records of processing
- Article 30 written inventory of processing activities, kept by controllers and processors subject to thresholds.
- Rectification
- Correcting inaccurate personal data and completing incomplete data, under Article 16.
- Regular and systematic monitoring
- Ongoing, methodical tracking of data subjects; per WP29, all internet tracking/profiling qualifies.
- Regulation
- EU law that is directly applicable and enforceable in every Member State with no need for local implementation; the GDPR is a Regulation.
- Regulation 2018/1725
- The separate EU regulation that applies to processing of personal data by EU institutions, bodies, offices and agencies, which the GDPR itself does not cover.
- Remote wipe / MDM
- Mobile-device-management capability to wipe a lost, stolen or leaver's device; employers must be transparent that personal content may also be wiped.
- Representative action
- Article 80 - group/class litigation where a not-for-profit body (CSO) represents individuals, spreading cost and risk.
- Reprimand
- A corrective measure short of a fine, appropriate where an infringement poses no significant risk or a fine would disproportionately burden a natural person.
- Resilience
- Data and systems can withstand and recover from errors or threats; new to EU data-protection law via the GDPR.
- Restriction of processing
- Article 18: marking stored personal data so it is kept but its future processing is limited - like a legal hold.
- Restrictions (Article 23)
- National or Union law may limit the scope of rights in Articles 12–22 (and corresponding Article 5 principles) for specified, necessary purposes.
- result element
- Present when the processing of information has an impact on the individual's rights and interests.
- Right of access
- Article 15: on request, a data subject gets confirmation of processing, a copy of their data, and prescribed details about how it is processed.
- Right of co-determination
- A works council's right to approve or reject certain employer decisions; rejection may force the employer to go to court.
- Right of legislative initiative
- The power to propose legislation - held by the Commission; Union legislative acts may generally only be adopted on a Commission proposal.
- Right to be forgotten
- The right (from Google Spain, later Article 17) to have certain personal data delisted/erased, balanced against public-interest factors.
- Right to erasure
- Article 17, the 'right to be forgotten': the right to have personal data deleted in defined circumstances.
- Right to lodge a complaint
- Article 77 - the right to complain to a DPA, exercisable at the individual's residence, place of work, or place of the infringement.
- Right to object
- Article 21: the right to object to certain processing; absolute for direct marketing, conditional for public-interest/legitimate-interest and research processing.
- Right to object (marketing)
- Under the GDPR, an absolute right to object to direct marketing at any time; the controller must stop and suppress the contact details.
- Right to rectification
- Article 16: the right to have inaccurate personal data corrected and incomplete data completed, without undue delay.
- Right to request delisting
- The search-engine application of the right to be forgotten; it combines the right to erasure and the right to object (Article 21).
- Rights and freedoms
- The interests of individuals (e.g. against identity theft, distress, financial loss) whose risk level triggers Article 33/34 obligations.
- Risk reporting
- The idea that breach notification/communication is a transparency mechanism applying only where a breach involves risks to individuals' rights and freedoms.
- Risk-based approach
- Calibrating accountability measures to the nature, scope, context, purposes and risks of the processing.
- Robinson List
- A national opt-out register / preference service letting individuals globally opt out of one channel of marketing regardless of who is sending it.
- Ryneš
- CJEU case (C-212/13): a home security camera filming a public footpath was NOT a purely personal/household activity; the household exemption is narrowly construed.
- SaaS
- Software as a Service - supplier provides infrastructure, platform AND application.
- Safe Harbor
- The original US–EU self-certification framework, struck down by the CJEU in Schrems I (2015).
- Safe processor
- A service provider whose processing meets BCR adequacy standards, allowing customers to overcome the global transfer restriction regardless of the provider's location.
- Sarbanes-Oxley Act (2002)
- US law that drove adoption of anonymous reporting systems for fraud and financial misstatement.
- SCCs
- Standard Contractual Clauses - Commission-approved model contract clauses (2021 version) for transfers to third countries; cloud usually needs module two.
- Schrems I
- 2015 CJEU ruling invalidating Safe Harbor because it did not limit US government access for national security.
- Schrems II
- 16 July 2020 CJEU ruling invalidating Privacy Shield; held SCCs valid but requiring a case-by-case assessment of the destination.
- Secure archiving
- Restricting access to a former employee's records and storing them securely once daily HR access is no longer needed.
- Security of processing
- The obligation under Article 32 to protect personal data with measures appropriate to the risk; covers prevention, detection/response and remedial security.
- Security paperwork
- The repository of an organisation's security rules - policies, controls and processes - and the natural reference point in investigations and litigation.
- Security principle
- The GDPR requirement (Article 5(1)(f)) to process personal data securely, protecting it against unauthorised/unlawful processing and accidental loss, destruction or damage.
- Self-regulation
- Mechanisms where the regulated entity supervises and enforces its own compliance, e.g. accountability, DPOs, codes of conduct and certification.
- Service bureaux
- Early service providers (also called computer bureaux) that catered to the computing needs of organisations without their own data processing capacity.
- Single out
- To distinguish one user from others (e.g. by an online identifier) even without knowing their real name - enough to make data 'personal data'.
- Single set of rules
- One harmonised EU framework replacing divergent national transpositions of the Directive.
- Soft opt-in
- ePrivacy exemption letting a controller email/SMS its own similar products/services to a person whose details it obtained during a sale, if the person could opt out at collection and in every subsequent message.
- Solely automated
- A decision with no meaningful human intervention; a token or rubber-stamp human review does not make it non-solely-automated.
- SOX
- US Sarbanes-Oxley Act 2002; requires confidential complaint mechanisms and reaches EU subsidiaries of US companies, conflicting with EU data protection law.
- Spaced retrieval
- Distributing recall practice over days rather than cramming, so each item is revisited just as you are about to forget it.
- Special categories
- Sensitive data such as biometric, genetic, health, sex life or sexual orientation data; processing it defeats the under-250 exemption.
- Special categories of data
- Under Convention 108, data revealing racial origin, political opinions, religious or other beliefs, health, sexual life or criminal convictions; not processed automatically unless domestic law gives appropriate safeguards.
- Special-category data
- Article 9 data revealing racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic or biometric data, health, or sex life/orientation; processing is prohibited unless an exception applies.
- Standard Contractual Clauses
- SCCs / model clauses - Commission-approved, non-negotiable standard contract terms binding the importer to EU-level protection. The most commonly used safeguard.
- Standardised icons
- Machine-readable visual symbols the GDPR permits to give an easily visible, understandable overview of processing; the Commission may adopt delegated acts on them.
- State of the art
- Not necessarily the most advanced technology - the consensus of security professionals about what is currently reasonable.
- State-of-the-art test
- The requirement to consider the consensus of professional security opinion and industry best practice (not merely industry average) when choosing controls.
- Static IP address
- A device always uses the same IP address - allowing different sessions from the same device to be linked.
- Statutory retention period
- A legally required minimum keeping period (e.g. tax, health and safety, employment) - keeping data to meet it is not 'too long'.
- Stem
- The question text before the answer options; scenario stems hide the key fact that decides the answer.
- Storage limitation
- Personal data is retained only as long as necessary for the original purpose.
- Strictly necessary exemption
- ePrivacy exemption covering storage/access necessary to provide a service the user explicitly requested (e.g. executing a voice command).
- Strictly-necessary exemption
- Cookies needed solely to transmit a communication, or strictly necessary for a service the user explicitly requested (e.g. a shopping basket), are exempt - but this very rarely covers OBA cookies.
- Structured, commonly used, machine-readable
- The required format for ported data; 'commonly used' is taken to exclude proprietary formats.
- Sub-processor
- An entity engaged by a processor to carry out specific processing activities on behalf of the controller (e.g. "Recruitment USA Inc." engaged by the agency).
- Subject access request (DSAR)
- A request under Article 15 for confirmation of processing, access to the personal data, and prescribed accompanying information.
- Subscriber data
- Generally the name, contact details and payment information of the user.
- Substitute notice
- A broad public announcement (e.g. press release or website statement) used where individual communication would involve disproportionate effort.
- Successive relearning
- Repeatedly retrieving the same material across spaced sessions until it is reliably recalled - the strongest predictor of exam performance.
- Sufficient guarantees
- The standard a processor must meet under Article 28 - proof, via assurance mechanisms, of competence to implement appropriate technical and organisational measures.
- Suitable safeguards
- Recital 71 protections: information, the right to human intervention, to express a view, to get an explanation, and to challenge the decision.
- Sunset clause
- A clause unique to the UK adequacy decisions making them automatically expire after four years, requiring review.
- Supplementary measures
- Extra technical or contractual protections (e.g. encryption) added to a safeguard when the destination's law is not essentially equivalent. Not themselves a transfer mechanism.
- Supplementary statement
- An additional statement the data subject may add to complete incomplete data under the right to rectification.
- Suppression
- Keeping a record of opted-out contact details (rather than deleting them) so the person is not re-marketed to.
- Suppression list
- A retained record that an individual must not be marketed to (e.g. in marketing-automation software), used instead of deletion so they are not re-acquired and re-marketed.
- Surveillance
- Observation of individuals - covert or overt, real-time or stored from records.
- Surveillance capitalism
- The idea of companies profiting from the use of behavioural data about individuals.
- SWIFT
- Case study where a self-styled processor transferred data to US authorities itself, moving outside the scope of a processor.
- Targeted online advertising
- Building profiles of individuals and routing ads to those meeting set criteria, usually via cookies or similar tech.
- Targeter
- An advertiser or entity that uses an SMP to target its users; often a joint controller with the SMP per EDPB guidance.
- Targeting/monitoring criterion
- Article 3(2): the GDPR reaches non-EU controllers/processors that offer goods or services to, or monitor the behaviour of, data subjects in the EU.
- Technical and organisational measures
- The mix of technology, processes and governance steps used to ensure and evidence compliant processing.
- Telephone Preference Service
- A national opt-out register for telephone marketing; in opt-out states marketers must cleanse call lists against it before calling.
- Terminal equipment
- Devices (including connected objects) at the user's end; storing/accessing info on them engages the ePrivacy Directive.
- Territorial scope
- The Article 3 rules deciding which organisations are bound by the GDPR, based on EU establishment or on targeting/monitoring people in the EU.
- TFEU
- Treaty on the Functioning of the European Union - the renamed Treaty Establishing the European Community.
- Third country
- Any country outside the European Economic Area (EEA).
- Trade and Cooperation Agreement
- The EU–UK agreement (24 Dec 2020) that bridged transfers after Brexit until the UK adequacy decision was adopted.
- Trade union membership
- A category of special (sensitive) personal data under Article 9.
- Traffic data
- Metadata about type, format, time, duration, origin/destination, routing and networks of a communication (e.g. calling/called numbers).
- Trans-Atlantic Data Privacy Framework
- The successor framework announced March 2022 by the Biden administration and the Commission to address Schrems II shortcomings.
- Transborder data flows
- Movement of personal data across national borders; Convention 108 bars blocking these solely to protect privacy between parties.
- Transfer
- Not defined in the GDPR; understood as a substantive processing operation on personal data in a third country, completing the export.
- Transfer Impact Assessment
- TIA - an industry term (not EDPB/Commission terminology) for the case-by-case assessment of whether the destination's law is essentially equivalent.
- Transit
- Mere routing of data through a third country with no substantive processing there - not a regulated transfer.
- Transparency
- Article 12: the principle that information and communications to data subjects be concise, intelligible, easily accessible and in clear plain language.
- Treaty of Lisbon
- 2007 treaty that amended the EU Treaty and renamed the EC Treaty as the TFEU, reforming the EU's institutions and decision-making.
- trialogue
- Procedure, presided over by the Commission, that reconciles the Parliament's and Council's texts into a compromise.
- Trilogue
- Negotiation between the EU Council, Parliament and Commission - the procedure also used to enact the GDPR.
- Two-month extension
- An additional period the controller may take for especially complex or numerous requests, having informed the data subject.
- UK GDPR
- The GDPR as incorporated into UK domestic law by the European Union (Withdrawal) Act 2018 after Brexit.
- Unambiguous
- Consent shown by a clear affirmative, opt-in action; silence, pre-ticked boxes and inactivity do not count.
- Undertaking
- An economic unit engaged in commercial activity (companies). Recital 150 ties it to TFEU Arts 101–102 competition law, so a group acting as one unit may be treated as a single undertaking.
- Universal Declaration of Human Rights
- UDHR - adopted by the UN General Assembly on 10 December 1948; basis for later European data protection standards.
- Universal Declaration of Human Rights (UDHR)
- Nonbinding declaration adopted by the UN General Assembly on 10 December 1948 that set milestone privacy and free-expression standards.
- Urgency procedure
- Article 66 - in exceptional cases a DPA may adopt provisional measures (max three months) bypassing the cooperation/consistency procedures.
- User log files
- Logs of user actions (queries, content served, navigation) built from cookies and IP addresses; constitute monitoring under Art 3(2)(b).
- Value-added service
- A service requiring location data beyond what's needed to transmit/bill a communication; defined widely enough to include location-based marketing, so opt-in consent is required (Art 9).
- Vendor due diligence
- Checking and auditing a processor before and during engagement to confirm it provides sufficient guarantees (Article 28).
- Verifiable parental consent
- Consent of a parent/guardian, capable of being verified, required when an ISS relies on consent and is offered to a child below the applicable age.
- Vital interests
- Processing necessary to protect the life of the data subject or another natural person.
- Vital interests (6(1)(d))
- Processing necessary to protect someone's life - confined to rare emergencies.
- VVA
- Virtual voice assistant - technology paired with connected objects to understand and execute voice commands.
- Weltimmo
- CJEU case (C-230/14): a Slovak-incorporated company targeting Hungary via a Hungarian-language property site was 'established' in Hungary; even a single representative and minimal activity can suffice.
- Whistle-blowing Directive
- EU directive requiring businesses and government bodies to establish internal whistleblowing systems; implementation due by 17 December 2021.
- Whistleblower Directive (2019)
- EU directive requiring Member States to give public- and private-sector whistleblowers effective reporting channels and protection against retaliation.
- Wirtschaftsakademie
- CJEU 'Facebook Fan Page' case (C-210/16): a fan-page administrator was a joint controller with the SMP, despite not processing the data itself.
- Withdrawal of consent
- The subject's right to revoke consent at any time, after which the controller must stop the consent-based processing.
- Works Constitution Act 1972
- German law giving works councils co-determination rights, including the ability to object to employee monitoring devices.
- Works council
- A body representing employees, formed once a workforce threshold is met; in some countries it must be notified, consulted or asked to approve employee-data processing.
- WP29
- Article 29 Working Party - the EDPB's predecessor; its guidance is still relevant where consistent with the GDPR.
- WP29 Adequacy Referential
- Article 29 Working Party guidance (6 February 2018) setting the core data protection principles needed for essential equivalence with the EU framework.
Sources
Sources and study method
This independent study material uses the current published CIPP/E outline, active recall, spaced retrieval and scenario practice. Read the full method. Current sources. Current CIPP/E certification page, IAPP certification FAQs.