GDPR glossary of key privacy terms

Understand the essential terminology behind GDPR compliance, data protection, and privacy governance.

Introduction

The General Data Protection Regulation (GDPR) defines a structured framework of legal and operational concepts that govern how personal data must be handled.

This glossary provides clear and practical definitions of key GDPR terms to support compliance, governance, and privacy understanding across organizations.

GDPR key terms

Personal data

Any information relating to an identified or identifiable natural person, such as name, email, IP address, or location data.

Data subject

The individual whose personal data is being processed.

Data controller

The entity that determines the purposes and means of processing personal data.

Data processor

A third party that processes personal data on behalf of the controller.

Processing

Any operation performed on personal data, including collection, storage, use, sharing, or deletion.

Consent

A freely given, specific, informed, and unambiguous indication of agreement to personal data processing

Special categories of data

Sensitive data such as health, biometric, political opinions, religious beliefs, or ethnic origin.

Data breach

A security incident leading to unauthorized access, loss, or disclosure of personal data.

DPIA

A process to assess risks of high-risk data processing activities.

Right of access

The right of individuals to access their personal data and obtain informations about its processing.

Right to erasure

Also known as “right to be forgotten”, allowing individuals to request deletion of their data.

Data minimization

The principle that only necessary personal data should be collected and processed.

Purpose limitation

Data must be collected for specific, explicit, and legitimate purposes only.

Storage limitation

Personal data should not be kept longer than necessary.

Accuracy

Personal data must be kept accurate up to date.

Integrity and confidentiality

Personal data must be processed securely to prevent unauthorized access or loss.

Accountability

Organizations must demonstrate compliance with GDPR principles.

Lawful basis

A valid legal reason for processing personal data (e.g., consent, contract, legal obbligation).

Data protection officer

A designated individual responsible for overseeing GDPR compliance.

Supervisory authority

A public authority responsible for monitoring GDPR enforcement (e.g., data protection authority).

Data transfer

Movement of personal data outside its original jurisdiction.

Third-party processor

External organizations processing data on behalf of a controller.

Profiling

Automated processing used to evaluate or predict personal aspects of individuals.

Automated decision-making

Decisions made solely by automated systems without human intervention.

Pseudonymisation

Processing data so it can no longer be attributed to a person without additional information.

Anonymisation

Irriversible process of removing personal identifiers from data.

Data retention policy

Rules defining how long personal data is stored.

Data subject rights

A set of rights granted to individuals under GDPR (access, correction, deletion, etc…).

Privacy by design

Integrating data protection principles into systems and processes from the start.

Privacy by default

Systems should automatically apply the highest level of privacy settings.

Scroll to Top