Skip to content

Reference

Privacy and AI governance glossary

The vocabulary of global privacy work, defined in the way practitioners actually use it. Every term links to a shareable anchor so you can point colleagues at a definition.

Showing 59 of 59 terms.

A

Access control(Least privilege)Data security
Granting each account only the access necessary for its role, and reviewing that access periodically. Over-permissioned collaboration platforms are the most common source of accidental internal exposure.
AccountabilityPrivacy law
The obligation not only to comply but to be able to demonstrate compliance through documentation, assessments, contracts, training records and evidence that controls operate.
Adequacy decisionPrivacy law
A determination by a competent authority that another jurisdiction provides an essentially equivalent level of data protection, allowing transfers to proceed without additional safeguards.
AI governanceAI governance
The set of policies, roles, assessments and controls that determine how AI systems are selected, built, deployed, monitored and retired, and who is accountable for their outcomes.AI privacy and data readiness
AI impact assessmentAI governance
A structured assessment of an AI use case covering purpose, data, affected individuals, accuracy, bias, transparency, oversight, security and fallback, carried out before deployment.
AI tool register(AI inventory)AI governance
A maintained list of AI systems in use, with owner, purpose, data categories, vendor, risk rating and review date. It is the AI equivalent of a processing record and the first thing an auditor asks for.
Algorithmic biasAI governance
Systematic disparity in AI outputs across groups, arising from training data, labelling, feature selection, deployment context or feedback loops. Relevant to both discrimination law and fairness under privacy law.
AnonymisationData security
Irreversibly altering data so an individual is no longer identifiable by any reasonably likely means. Genuinely anonymised data falls outside data protection law, which is why the threshold is high.
Automated decision-makingPrivacy law
A decision taken about an individual by automated means without meaningful human involvement. Where it produces legal or similarly significant effects, most regimes require safeguards, transparency and often a route to human review.

B

Binding Corporate Rules(BCRs)Privacy law
Internal data protection rules adopted by a corporate group and approved by a supervisory authority, allowing intra-group international transfers without separate contracts.

C

Controller(Data Fiduciary / Business)Privacy law
The organisation that determines the purposes and means of processing personal data. The controller owes the primary duties to individuals and regulators, even where a supplier performs the processing.
Cross-context behavioural advertisingPrivacy law
Targeting advertising to an individual based on their activity across distinct sites, applications or services that are not owned by the business with which they intentionally interact.

D

Dark patternPrivacy operations
Interface design that nudges people toward choices against their interests, such as unequal accept and reject options in a consent banner. Regulators increasingly treat these as invalidating consent.
Data classificationData security
Assigning sensitivity levels to information so that handling, sharing and retention controls can be applied consistently and automatically.
Data inventory(Data map)Privacy operations
A view of what personal data exists, where it is stored, which systems process it and who owns it. A RoPA describes activities; an inventory describes locations and assets.
Data loss prevention(DLP)Data security
Controls that detect and prevent sensitive data leaving approved locations or channels, based on content inspection, classification labels or context.
Data minimisationPrivacy law
The requirement that personal data be adequate, relevant and limited to what is necessary for the purpose. In practice it is a design constraint on forms, logs, telemetry and data warehouses.
Data portabilityPrivacy law
The right to receive personal data provided by the individual in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another organisation.
Data protection impact assessment(DPIA / PIA)Privacy operations
A structured assessment of a processing activity's risks to individuals and the measures that reduce them, carried out before high-risk processing begins.DPIA triage tool
Data protection officer(DPO)Privacy operations
A designated individual responsible for advising on, and monitoring, compliance with data protection law. Several regimes mandate appointment based on sector, scale or risk, and require independence and reporting to senior management.
Data retention schedulePrivacy operations
A documented set of retention periods by record type, with the legal or business justification and the technical enforcement point where deletion occurs.
Data sharing agreementPrivacy operations
An agreement between controllers setting out the purposes, scope, security and responsibilities for personal data shared between them, including how rights requests and incidents are handled.
Data subject(Data Principal / Consumer)Privacy law
The individual to whom personal data relates and who holds the rights granted by the applicable law.
Data subject access request(DSAR / SAR)Privacy operations
A request from an individual for a copy of their personal data and information about how it is processed. Handling it well depends on identity verification, search scope, redaction and a defensible response clock.
De-identificationData security
Removing or obscuring direct identifiers. It sits between pseudonymisation and anonymisation in strength and is defined differently across regimes, so the label alone does not determine legal treatment.

E

Encryption at rest and in transitData security
Protecting stored data and network traffic using cryptography. It reduces breach impact and, in several regimes, affects whether individuals must be notified after an incident.
ExplainabilityAI governance
The ability to describe, in terms a person affected can understand, the logic and main factors behind an automated decision or recommendation.

H

Human oversight(Human in the loop)AI governance
Meaningful review by a person with authority and information to change an AI-informed outcome. Rubber-stamping does not meet the standard where a regime requires human involvement.

L

Lawful basisPrivacy law
The legal ground relied on for a processing activity. Under the GDPR the six bases are consent, contract, legal obligation, vital interests, public task and legitimate interests; other regimes use narrower or differently framed lists.
Legitimate interests assessment(LIA)Privacy operations
A documented three-part test — purpose, necessity and balancing — used to justify processing under the legitimate interests basis and to evidence that individual rights and expectations were considered.

M

Model output disclosureAI governance
The risk that an AI system reveals personal or confidential information in a response, whether from retrieved context, memory, training data or an over-broad system prompt.
Model training dataAI governance
The data used to train or fine-tune a model. Privacy questions include lawful basis, minimisation, retention, whether personal data can be extracted from the model, and whether deletion requests can be honoured.

N

Notifiable breachPrivacy operations
A personal data breach meeting the applicable threshold for reporting to a regulator or to affected individuals. Thresholds and clocks vary by jurisdiction, so a single global rule rarely works.

O

Opt-out preference signal(Global Privacy Control)Privacy law
A browser or device signal communicating an individual's choice to opt out of sale or sharing of personal information. Several US state laws require covered businesses to honour it.

P

Personal data(Personal information)Privacy law
Any information relating to an identified or identifiable individual. Identifiability includes indirect routes: an account number, device identifier or combination of attributes can be personal data even when no name is present.
Personal data breachPrivacy operations
A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Availability incidents count, not just disclosures.
Privacy by designPrivacy operations
Building privacy safeguards into systems, processes and default settings from the outset rather than retrofitting them after a design is fixed.
Privacy maturity modelPrivacy operations
A scale describing how developed a privacy programme is, typically from ad hoc to optimised, used to set realistic improvement targets rather than pass or fail judgements.Privacy readiness assessment
Privacy notice(Privacy policy)Privacy operations
The external-facing explanation of how an organisation processes personal data. It must reflect real practice; a notice describing processing that does not happen is itself a transparency failure.
Processor(Data intermediary / Service provider)Privacy law
An organisation that processes personal data on behalf of, and under the documented instructions of, a controller. Processors owe direct duties on security, sub-processing and assistance under most modern regimes.
ProfilingPrivacy law
Automated processing of personal data to evaluate personal aspects of an individual, such as performance, economic situation, health, preferences, reliability, behaviour, location or movements.
Prompt injectionAI governance
An attack where instructions embedded in content processed by a model cause it to ignore its intended constraints, potentially disclosing data it can access or taking unintended actions.
PseudonymisationData security
Processing personal data so it can no longer be attributed to an individual without additional information kept separately and protected. Pseudonymised data remains personal data.
Purpose creepPrivacy operations
The gradual expansion of processing beyond the purposes originally communicated, usually through incremental internal reuse of an existing dataset.
Purpose limitationPrivacy law
The requirement to collect personal data for specified, explicit and legitimate purposes and not to process it further in a manner incompatible with those purposes.

R

Records of processing activities(RoPA)Privacy operations
A structured register of processing activities recording purposes, categories of data and individuals, recipients, transfers, retention and security measures. It is the backbone artefact most other privacy work depends on.RoPA starter kit
Retrieval-augmented generation(RAG)AI governance
An architecture in which a model retrieves content from a document store at query time. Privacy risk comes from the permissions on that store: retrieval inherits whatever over-sharing already exists.
Right to erasure(Right to be forgotten)Privacy law
The right to have personal data deleted where a specified ground applies, subject to exemptions such as legal obligations, defence of legal claims and freedom of expression.

S

Security incident responseData security
The documented process for detecting, triaging, containing, eradicating and recovering from an incident, including the decision points that trigger privacy breach assessment.
Sensitive data discoveryData security
Scanning structured and unstructured repositories to locate sensitive data types. Value depends on detection tuning and a remediation decision model, not on scan volume.
Shadow ITData security
Technology used by teams without organisational review or approval. It matters for privacy because unreviewed tools receive personal data outside inventories, contracts and retention controls.
Special category data(Sensitive personal data)Privacy law
Categories of personal data that attract additional conditions before processing, typically including health, biometric and genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership and data about sex life or sexual orientation.
Standard Contractual Clauses(SCCs)Privacy law
Pre-approved contractual terms adopted by a regulator or authority that provide a safeguard for personal data transferred to a country without an adequacy decision.
Storage limitation(Retention limitation)Privacy law
The requirement to keep personal data in identifiable form no longer than necessary. A retention schedule only satisfies it when deletion actually happens at a technical enforcement point.
Sub-processorPrivacy operations
A third party engaged by a processor to carry out part of the processing. Most regimes require authorisation, flow-down of terms and notice of changes.

T

Transfer impact assessment(TIA / TRA)Privacy operations
An assessment of whether a transfer mechanism such as Standard Contractual Clauses delivers protection that is essentially equivalent in the destination country, considering local law, practice and supplementary measures.

V

Vendor risk assessment(Third-party due diligence)Privacy operations
A structured review of a supplier's data handling, security posture, sub-processing, location and contractual commitments before and during engagement.Vendor privacy quick check

Z

Zero trustData security
A security model that assumes no implicit trust based on network location and continuously verifies identity, device posture and authorisation for each access request.