Research guide
Privacy and legal terms glossary
Short, source-based definitions of the terms that appear in privacy policies, data processing agreements, and Terms of Service. Each entry links to a guide or generator where the concept matters in practice. Definitions summarize the legal concepts and do not replace the text of the law.
Definitions
- Personal data (personal information)
Any information relating to an identified or identifiable natural person, directly or indirectly, such as a name, email address, online identifier, IP address, device identifier, or location data. The GDPR calls it personal data; California law and many other laws call it personal information and define it broadly to include information that is reasonably capable of being associated with a consumer or household.
Related: What a privacy policy should include
- Data subject
The identified or identifiable person that personal data relates to. California law uses the term consumer for a California resident, and other laws use individual or titular.
Related: GDPR privacy policy guide
- Controller
The person or organization that, alone or jointly with others, determines the purposes and means of processing personal data. The controller is responsible for the privacy notice, the legal basis, and responding to rights requests. The operator of a website or app is usually the controller of its users' data.
Related: GDPR privacy policy guide
- Processor
A person or organization that processes personal data on behalf of a controller and under its instructions, such as a hosting, email delivery, or support-desk provider. Under the GDPR the relationship must be governed by a contract with specific terms.
Related: GDPR privacy policy guide
- Sub-processor
A processor engaged by another processor to carry out part of the processing for a controller, for example a cloud platform used by an email service. Processors generally need the controller's authorization to use sub-processors and must pass on equivalent data protection obligations.
Related: SaaS Privacy Policy generator
- Service provider and contractor
California terms for recipients that process personal information on a business's behalf under a written contract that restricts their use of it. Disclosures to qualifying service providers and contractors are generally not sales or sharing.
Related: CCPA and CPRA privacy policy guide
- Special category data
GDPR categories that receive extra protection: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health data, and data concerning sex life or sexual orientation. Processing needs both a legal basis and an additional condition under Article 9.
Related: GDPR privacy policy guide
- Sensitive personal information
A California category that includes government identifiers, account log-in credentials, financial account details with access codes, precise geolocation, racial or ethnic origin, religious beliefs, union membership, the contents of certain communications, genetic data, biometric data used for identification, and health, sex life, or sexual orientation information. Consumers can limit certain uses of it.
Related: CCPA and CPRA privacy policy guide
- Lawful basis (legal basis)
The justification under GDPR Article 6 for processing personal data: consent, performance of a contract, legal obligation, vital interests, public task, or legitimate interests. A privacy notice must state the basis for each purpose.
Related: GDPR privacy policy guide
- Consent
Under the GDPR, a freely given, specific, informed, and unambiguous indication of the person's wishes by a statement or clear affirmative action. Pre-ticked boxes and silence do not count, and consent must be as easy to withdraw as to give.
Related: Analytics privacy disclosures
- Legitimate interests
A GDPR legal basis that allows processing necessary for the legitimate interests of the controller or a third party, unless those interests are overridden by the person's rights and interests. The notice must say which interests are relied on, such as security or fraud prevention.
Related: GDPR privacy policy guide
- Recognised legitimate interests
A UK lawful basis introduced by the Data (Use and Access) Act 2025 for listed purposes, such as certain security, crime prevention, and safeguarding activities, where the balancing test used for ordinary legitimate interests is not required.
Related: GDPR and UK GDPR policy generator
- Privacy policy (privacy notice)
A public statement explaining how an organization collects, uses, shares, retains, and protects personal information, and how people can exercise their rights. Laws such as the GDPR, CalOPPA, PIPEDA, and the Australian Privacy Act, and platforms such as Google Play and the Apple App Store, set requirements for its contents.
Related: Privacy Policy generator
- Data subject request (privacy rights request)
A request from a person to exercise a privacy right, such as access, correction, deletion, portability, objection, or opting out of sale or sharing. Laws set response deadlines and verification rules, so the request methods in a policy need to work in practice.
Related: What a privacy policy should include
- Data processing agreement (DPA)
A contract between a controller and a processor that sets out the subject matter, duration, nature, and purpose of processing, and the processor's obligations on instructions, confidentiality, security, sub-processors, assistance, deletion, and audits, as required by GDPR Article 28.
Related: SaaS Privacy Policy generator
- Data protection officer (DPO)
A person designated under the GDPR to advise on and monitor data protection compliance. Appointment is mandatory for public authorities and for organizations whose core activities involve large-scale systematic monitoring or large-scale processing of special category data. If appointed, the DPO's contact details belong in the privacy notice.
Related: GDPR privacy policy guide
- EU or UK representative
A person or company established in the EU or UK that a controller or processor based outside it may need to appoint when the GDPR or UK GDPR applies because it offers goods or services to, or monitors, people there. The representative's identity and contact details belong in the notice.
Related: GDPR and UK GDPR policy generator
- International data transfer
Making personal data available to a recipient in another country, including by storing it with a provider there or allowing remote access. The GDPR and UK GDPR restrict transfers to countries without equivalent protection unless a safeguard applies, and several other laws require transfers to be disclosed.
Related: GDPR privacy policy guide
- Adequacy decision
A decision by the European Commission, or by the UK government for UK transfers, that a country or framework provides an essentially equivalent level of data protection, allowing transfers there without additional safeguards.
Related: GDPR privacy policy guide
- Standard contractual clauses (SCCs)
Model data protection clauses adopted by the European Commission that exporters and importers sign to safeguard transfers of personal data outside the EEA. The UK uses its own addendum and agreement for UK transfers. A notice should say which safeguard is used and how to obtain a copy.
Related: GDPR privacy policy guide
- Sale of personal information
Under California law, selling, renting, releasing, disclosing, or otherwise making personal information available to a third party for monetary or other valuable consideration. A business that sells must disclose it and offer an opt-out.
Related: CCPA and CPRA privacy policy guide
- Cross-context behavioral advertising
Targeting advertising to a consumer based on personal information obtained from the consumer's activity across businesses, websites, apps, or services other than the one the consumer is intentionally interacting with. Retargeting pixels commonly fall within this California definition.
Related: Advertising privacy disclosures
- Targeted advertising
The term most US state privacy laws other than California's use for displaying ads selected from personal data obtained from a consumer's activities over time across unaffiliated websites or applications. Consumers generally have a right to opt out of it.
Related: Advertising privacy disclosures
- Profiling
Automated processing of personal data to evaluate personal aspects of a person, such as preferences, interests, behavior, location, reliability, or economic situation. Profiling that supports significant decisions carries additional rights under the GDPR and several US state laws.
Related: AI product privacy disclosures
- Automated decision-making
Decisions made by technological means without meaningful human involvement. GDPR Article 22 gives people rights relating to solely automated decisions with legal or similarly significant effects, and privacy notices must describe such decisions and the logic involved.
Related: AI product privacy disclosures
- Pseudonymisation
Processing personal data so that it can no longer be attributed to a specific person without additional information that is kept separately and protected. Pseudonymised data is still personal data under the GDPR.
Related: Analytics privacy disclosures
- Anonymisation
Irreversibly transforming data so that no person can be identified by any means reasonably likely to be used. Truly anonymous data falls outside the GDPR, but the threshold is high and hashed or tokenized identifiers usually do not meet it.
Related: Analytics privacy disclosures
- De-identified information
A US term for information that cannot reasonably be linked to a particular person, where the business takes reasonable measures to prevent re-identification, publicly commits not to re-identify it, and contractually requires recipients to do the same.
Related: CCPA and CPRA privacy policy guide
- Data minimisation
The principle that personal data should be adequate, relevant, and limited to what is necessary for the purposes for which it is processed. Collecting fields you do not use creates disclosure and security obligations without benefit.
Related: Do I need a privacy policy?
- Retention period
How long personal data is kept before deletion or anonymisation. The GDPR requires the notice to give the period or the criteria used to determine it, and California requires retention information for each category.
Related: What a privacy policy should include
- Personal data breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Many laws require notification of regulators and affected people within set deadlines when the risk threshold is met.
Related: What a privacy policy should include
- Tracking technology
Any technique that stores or reads information on a device or follows activity, including cookies, local storage, pixels, tags, SDKs, device fingerprinting, and advertising identifiers. Consent and disclosure rules apply to the technique's effect, not only to cookies.
Related: Advertising privacy disclosures
- Opt-out preference signal (Global Privacy Control)
A browser or device setting, such as Global Privacy Control, that communicates a consumer's choice to opt out of sale, sharing, or targeted advertising. California and several other states require covered businesses to treat qualifying signals as valid opt-out requests.
Related: CCPA and CPRA privacy policy guide
- Do Not Track
A browser signal indicating a preference not to be tracked. There is no general legal duty to honor it, but CalOPPA requires a privacy policy to disclose how the operator responds to it.
Related: CalOPPA privacy policy generator
- Verifiable parental consent (COPPA)
Consent obtained from a parent, through a method reasonably designed to confirm the person is the parent, before an operator of a child-directed service, or one with actual knowledge, collects personal information from a child under 13 in the United States. The amended COPPA Rule requires separate consent before disclosing children's information to third parties, subject to limited exceptions.
Related: Advertising privacy disclosures
- Terms of Service (Terms of Use, Terms and Conditions)
The contract that sets the rules for using a website, app, or service: eligibility, accounts, acceptable use, payments, intellectual property, disclaimers, liability, termination, and disputes. The names are used interchangeably.
Related: Terms of Service generator
- Clickwrap agreement
An agreement accepted by an affirmative action such as ticking a box or clicking an I agree button next to a link to the terms. Clickwrap acceptance is generally easier to prove than browsewrap, where terms are only linked in a footer.
Related: Terms of Service generator
- Acceptable use policy
Rules describing prohibited conduct on a service, such as illegal activity, security abuse, infringement, spam, harassment, and unauthorized scraping. It may be a section of the Terms or a separate document incorporated into them.
Related: Terms of Service generator
- End-user license agreement (EULA)
A license that grants a user the right to install or use software under stated restrictions, while ownership stays with the licensor. Apps and downloadable software often use a EULA in addition to, or instead of, Terms of Service.
Related: App Terms of Service generator
- Limitation of liability
A clause that excludes certain types of loss and caps the amount one party can recover from the other. Mandatory consumer protections and liability for matters such as fraud or death and personal injury caused by negligence generally cannot be excluded.
Related: SaaS Terms of Service generator
- Indemnity
A promise by one party to cover the other's losses from specified claims, for example third-party claims caused by a business customer's content. Indemnities are usually limited to business users because consumer law restricts them.
Related: SaaS Terms of Service generator
- Governing law and venue
Clauses choosing which jurisdiction's law applies to the contract and where disputes are heard. Consumers in many countries keep the protection of their home law and courts regardless of the clause.
Related: Terms of Service generator
- Arbitration clause
A clause requiring disputes to be resolved by a private arbitrator instead of a court, typically naming the provider, rules, location, and fee allocation, sometimes with an opt-out window. Enforceability against consumers varies widely by country.
Related: Terms of Service generator
- Class action waiver
A clause in which users agree to bring claims only individually rather than as part of a class or collective action. It is usually paired with arbitration and is restricted or unenforceable in many jurisdictions.
Related: Terms of Service generator
- DMCA notice
A copyright takedown notice under the US Digital Millennium Copyright Act. Services hosting user content can qualify for the section 512 safe harbor by designating an agent with the US Copyright Office, publishing the agent's contact details, and responding to valid notices and counter-notices.
Related: Terms of Service generator
- Digital Services Act (DSA)
EU Regulation 2022/2065, which sets obligations for intermediary services, including hosting services and online platforms, such as a single point of contact, clear terms on content restrictions, notice-and-action mechanisms, and statements of reasons for moderation decisions.
Related: Terms of Service generator
- Force majeure
A clause excusing a party from liability for delays or failures caused by events beyond its reasonable control, such as natural disasters, network outages at third parties, or government action.
Related: Terms of Service generator
Official sources checked for this guide
Platform rules and legislation can change. Verify the current text before publishing or making a high-risk decision.