GDPR glossary of key privacy terms
Understand the essential terminology behind GDPR compliance, data protection, and privacy governance.
Introduction
The General Data Protection Regulation (GDPR) defines a structured framework of legal and operational concepts that govern how personal data must be handled.
This glossary provides clear and practical definitions of key GDPR terms to support compliance, governance, and privacy understanding across organizations.
GDPR key terms
Personal data
Any information relating to an identified or identifiable natural person, such as name, email, IP address, or location data.
Data subject
The individual whose personal data is being processed.
Data controller
The entity that determines the purposes and means of processing personal data.
Data processor
A third party that processes personal data on behalf of the controller.
Processing
Any operation performed on personal data, including collection, storage, use, sharing, or deletion.
Consent
A freely given, specific, informed, and unambiguous indication of agreement to personal data processing
Special categories of data
Sensitive data such as health, biometric, political opinions, religious beliefs, or ethnic origin.
Data breach
A security incident leading to unauthorized access, loss, or disclosure of personal data.
DPIA
A process to assess risks of high-risk data processing activities.
Right of access
The right of individuals to access their personal data and obtain informations about its processing.
Right to erasure
Also known as “right to be forgotten”, allowing individuals to request deletion of their data.
Data minimization
The principle that only necessary personal data should be collected and processed.
Purpose limitation
Data must be collected for specific, explicit, and legitimate purposes only.
Storage limitation
Personal data should not be kept longer than necessary.
Accuracy
Personal data must be kept accurate up to date.
Integrity and confidentiality
Personal data must be processed securely to prevent unauthorized access or loss.
Accountability
Organizations must demonstrate compliance with GDPR principles.
Lawful basis
A valid legal reason for processing personal data (e.g., consent, contract, legal obbligation).
Data protection officer
A designated individual responsible for overseeing GDPR compliance.
Supervisory authority
A public authority responsible for monitoring GDPR enforcement (e.g., data protection authority).
Data transfer
Movement of personal data outside its original jurisdiction.
Third-party processor
External organizations processing data on behalf of a controller.
Profiling
Automated processing used to evaluate or predict personal aspects of individuals.
Automated decision-making
Decisions made solely by automated systems without human intervention.
Pseudonymisation
Processing data so it can no longer be attributed to a person without additional information.
Anonymisation
Irriversible process of removing personal identifiers from data.
Data retention policy
Rules defining how long personal data is stored.
Data subject rights
A set of rights granted to individuals under GDPR (access, correction, deletion, etc…).
Privacy by design
Integrating data protection principles into systems and processes from the start.
Privacy by default
Systems should automatically apply the highest level of privacy settings.