GLOSSARY
Definitions for 30+ privacy and data protection terms you need to know.
California's landmark privacy law giving consumers rights over their personal information, including the right to know, delete, and opt-out of data sales.
A lawful basis for processing personal data where the individual has given clear, informed, affirmative agreement.
The requirement to obtain user permission before setting non-essential cookies on their device.
The transfer of personal data from one country or jurisdiction to another.
A security incident that leads to unauthorized access, disclosure, alteration, or destruction of personal data.
The entity that determines the purposes and means of processing personal data.
The process of identifying and documenting what personal data an organization collects, where it is stored, and how it flows.
The right to receive personal data in a structured, machine-readable format and transfer it to another service.
An entity that processes personal data on behalf of the data controller.
Policies governing how long personal data is stored before being deleted or anonymized.
A legally binding contract between a data controller and data processor that governs how personal data is processed.
A systematic process to evaluate and minimize data protection risks of a project or processing activity.
A designated individual responsible for overseeing data protection strategy and compliance within an organization.
A formal request from an individual exercising their privacy rights, such as access, deletion, or correction of personal data.
Individually identifiable health information that is protected under HIPAA.
Any information that can be used to identify a specific individual, such as name, email, SSN, or IP address.
An approach where privacy considerations are embedded into systems and processes from the design phase.
A systematic assessment of a project to identify and reduce privacy risks.
A now-invalidated framework for EU-US data transfers, replaced by the EU-US Data Privacy Framework.
Documentation required by GDPR of all personal data processing activities within an organization.
An individual's right to obtain a copy of their personal data and information about how it is processed.
An individual's right under GDPR to request deletion of their personal data.
Sensitive personal data under GDPR that receives additional protection, including health, biometric, racial, and religious data.
Pre-approved contractual terms for transferring personal data to countries outside the EEA.
An independent public authority responsible for monitoring and enforcing data protection laws.
PrivaBase automates compliance across 135+ frameworks. Start free.
Start Free