Reference
Privacy and AI governance glossary
The vocabulary of global privacy work, defined in the way practitioners actually use it. Every term links to a shareable anchor so you can point colleagues at a definition.
Showing 59 of 59 terms.
A
- Access control(Least privilege)Data security
- Granting each account only the access necessary for its role, and reviewing that access periodically. Over-permissioned collaboration platforms are the most common source of accidental internal exposure.
- AccountabilityPrivacy law
- The obligation not only to comply but to be able to demonstrate compliance through documentation, assessments, contracts, training records and evidence that controls operate.
- Adequacy decisionPrivacy law
- A determination by a competent authority that another jurisdiction provides an essentially equivalent level of data protection, allowing transfers to proceed without additional safeguards.
- AI governanceAI governance
- The set of policies, roles, assessments and controls that determine how AI systems are selected, built, deployed, monitored and retired, and who is accountable for their outcomes.AI privacy and data readiness
- AI impact assessmentAI governance
- A structured assessment of an AI use case covering purpose, data, affected individuals, accuracy, bias, transparency, oversight, security and fallback, carried out before deployment.
- AI tool register(AI inventory)AI governance
- A maintained list of AI systems in use, with owner, purpose, data categories, vendor, risk rating and review date. It is the AI equivalent of a processing record and the first thing an auditor asks for.
- Algorithmic biasAI governance
- Systematic disparity in AI outputs across groups, arising from training data, labelling, feature selection, deployment context or feedback loops. Relevant to both discrimination law and fairness under privacy law.
B
C
D
- Dark patternPrivacy operations
- Interface design that nudges people toward choices against their interests, such as unequal accept and reject options in a consent banner. Regulators increasingly treat these as invalidating consent.
- Data classificationData security
- Assigning sensitivity levels to information so that handling, sharing and retention controls can be applied consistently and automatically.
- Data inventory(Data map)Privacy operations
- A view of what personal data exists, where it is stored, which systems process it and who owns it. A RoPA describes activities; an inventory describes locations and assets.
- Data loss prevention(DLP)Data security
- Controls that detect and prevent sensitive data leaving approved locations or channels, based on content inspection, classification labels or context.
- Data minimisationPrivacy law
- The requirement that personal data be adequate, relevant and limited to what is necessary for the purpose. In practice it is a design constraint on forms, logs, telemetry and data warehouses.
- Data portabilityPrivacy law
- The right to receive personal data provided by the individual in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another organisation.
- Data protection impact assessment(DPIA / PIA)Privacy operations
- A structured assessment of a processing activity's risks to individuals and the measures that reduce them, carried out before high-risk processing begins.DPIA triage tool
- Data protection officer(DPO)Privacy operations
- A designated individual responsible for advising on, and monitoring, compliance with data protection law. Several regimes mandate appointment based on sector, scale or risk, and require independence and reporting to senior management.
- Data retention schedulePrivacy operations
- A documented set of retention periods by record type, with the legal or business justification and the technical enforcement point where deletion occurs.
- Data sharing agreementPrivacy operations
- An agreement between controllers setting out the purposes, scope, security and responsibilities for personal data shared between them, including how rights requests and incidents are handled.
- Data subject(Data Principal / Consumer)Privacy law
- The individual to whom personal data relates and who holds the rights granted by the applicable law.
E
H
L
M
N
O
P
- Personal data(Personal information)Privacy law
- Any information relating to an identified or identifiable individual. Identifiability includes indirect routes: an account number, device identifier or combination of attributes can be personal data even when no name is present.
- Personal data breachPrivacy operations
- A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Availability incidents count, not just disclosures.
- Privacy by designPrivacy operations
- Building privacy safeguards into systems, processes and default settings from the outset rather than retrofitting them after a design is fixed.
- Privacy maturity modelPrivacy operations
- A scale describing how developed a privacy programme is, typically from ad hoc to optimised, used to set realistic improvement targets rather than pass or fail judgements.Privacy readiness assessment
- Privacy notice(Privacy policy)Privacy operations
- The external-facing explanation of how an organisation processes personal data. It must reflect real practice; a notice describing processing that does not happen is itself a transparency failure.
- Processor(Data intermediary / Service provider)Privacy law
- An organisation that processes personal data on behalf of, and under the documented instructions of, a controller. Processors owe direct duties on security, sub-processing and assistance under most modern regimes.
- ProfilingPrivacy law
- Automated processing of personal data to evaluate personal aspects of an individual, such as performance, economic situation, health, preferences, reliability, behaviour, location or movements.
- Prompt injectionAI governance
- An attack where instructions embedded in content processed by a model cause it to ignore its intended constraints, potentially disclosing data it can access or taking unintended actions.
- PseudonymisationData security
- Processing personal data so it can no longer be attributed to an individual without additional information kept separately and protected. Pseudonymised data remains personal data.
R
- Records of processing activities(RoPA)Privacy operations
- A structured register of processing activities recording purposes, categories of data and individuals, recipients, transfers, retention and security measures. It is the backbone artefact most other privacy work depends on.RoPA starter kit
S
- Security incident responseData security
- The documented process for detecting, triaging, containing, eradicating and recovering from an incident, including the decision points that trigger privacy breach assessment.
- Sensitive data discoveryData security
- Scanning structured and unstructured repositories to locate sensitive data types. Value depends on detection tuning and a remediation decision model, not on scan volume.
- Shadow ITData security
- Technology used by teams without organisational review or approval. It matters for privacy because unreviewed tools receive personal data outside inventories, contracts and retention controls.
- Special category data(Sensitive personal data)Privacy law
- Categories of personal data that attract additional conditions before processing, typically including health, biometric and genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership and data about sex life or sexual orientation.
- Standard Contractual Clauses(SCCs)Privacy law
- Pre-approved contractual terms adopted by a regulator or authority that provide a safeguard for personal data transferred to a country without an adequacy decision.
T
V
- Vendor risk assessment(Third-party due diligence)Privacy operations
- A structured review of a supplier's data handling, security posture, sub-processing, location and contractual commitments before and during engagement.Vendor privacy quick check