AGIDAT – Datenschutz | Informationssicherheit

GDPR Glossary

Plain-English definitions of key data protection terms and abbreviations.

Data protection is full of abbreviations and legal terms. This glossary explains the most important ones in plain English — no legal background required.

Art. 6 GDPR
Lawful bases of processing. Every processing of personal data requires one of six bases: consent, performance of a contract, legal obligation, vital interests, public interest, or legitimate interest.
Art. 9 GDPR
Special categories of personal data subject to enhanced protection: health data, genetic data, biometric data, ethnic origin, political opinions, religious beliefs, trade union membership, sex life.
Consent
Freely given, informed, unambiguous agreement to data processing (Art. 7 GDPR). Must be given through an active action (no pre-ticked boxes), must be revocable at any time, and must be obtained before processing begins.
Controller
The natural or legal person who determines the purposes and means of processing personal data (Art. 4(7) GDPR). In a company, this is the management. Bears the legal responsibility.
Data Breach
A personal data breach under Art. 4(12) GDPR: the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. Notification obligation: 72 hours to the supervisory authority.
Data Minimization
The principle of data minimization (Art. 5(1)(c) GDPR): only process as much data as is necessary for the specific purpose. "As little as possible, as much as necessary."
Data Processing Agreement (DPA)
A contract required under Art. 28 GDPR between a controller and a processor. Governs what data may be processed and how, security measures, deletion obligations, and audit rights.
Data Protection Impact Assessment (DPIA)
A risk analysis required under Art. 35 GDPR for processing that poses a high risk to individuals. Mandatory for, e.g., large-scale profiling, large-scale processing of special category data, or systematic monitoring of public areas.
Data Protection Officer (DPO)
A natural or legal person who monitors compliance with data protection law and provides advice. Can be appointed internally or externally. Must have expert knowledge and be independent of instructions.
Data Subject
The natural person whose personal data is being processed. Has rights under Art. 15–22 GDPR: access, rectification, erasure, restriction, data portability, objection.
Deletion/Retention Concept
Documentation of when which data must be deleted. Takes into account statutory retention periods (German tax law: 10 years) and the data protection principle of storage limitation.
GDPR
General Data Protection Regulation (Regulation (EU) 2016/679). Directly applicable in all EU member states since 25 May 2018. Governs the processing of personal data by companies and public authorities.
ISMS
Information Security Management System. A systematic approach to managing information security within an organization. The basis for ISO 27001 certification.
Personal Data
Any information relating to an identified or identifiable person. Examples: name, email address, IP address, customer number, vehicle registration number, biometric characteristics.
Processor
A service provider who processes personal data on behalf of the controller. Examples: cloud providers, email services, payroll providers. Requires a written Data Processing Agreement (DPA).
Pseudonymization
Processing personal data so that it can no longer be attributed to a specific person without additional information. Reduces risk but is not full protection (unlike anonymization).
Purpose Limitation
Principle (Art. 5(1)(b) GDPR): data may only be used for the purpose for which it was originally collected. New purposes require a new legal basis or must be compatible with the original purpose.
Records of Processing Activities (RoPA)
Mandatory documentation (Art. 30 GDPR) recording all relevant processing activities: purpose, legal basis, data subjects, categories, recipients, deletion periods, TOMs.
Technical and Organizational Measures (TOMs)
Measures under Art. 32 GDPR to protect personal data: encryption, access controls, backups, pseudonymization, physical access controls, staff training.