GDPR Glossary
Plain-English definitions of key data protection terms and abbreviations.
Data protection is full of abbreviations and legal terms. This glossary explains the most important ones in plain English — no legal background required.
- Art. 6 GDPR
- Lawful bases of processing. Every processing of personal data requires one of six bases: consent, performance of a contract, legal obligation, vital interests, public interest, or legitimate interest.
- Art. 9 GDPR
- Special categories of personal data subject to enhanced protection: health data, genetic data, biometric data, ethnic origin, political opinions, religious beliefs, trade union membership, sex life.
- Consent
- Freely given, informed, unambiguous agreement to data processing (Art. 7 GDPR). Must be given through an active action (no pre-ticked boxes), must be revocable at any time, and must be obtained before processing begins.
- Controller
- The natural or legal person who determines the purposes and means of processing personal data (Art. 4(7) GDPR). In a company, this is the management. Bears the legal responsibility.
- Data Breach
- A personal data breach under Art. 4(12) GDPR: the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. Notification obligation: 72 hours to the supervisory authority.
- Data Minimization
- The principle of data minimization (Art. 5(1)(c) GDPR): only process as much data as is necessary for the specific purpose. "As little as possible, as much as necessary."
- Data Processing Agreement (DPA)
- A contract required under Art. 28 GDPR between a controller and a processor. Governs what data may be processed and how, security measures, deletion obligations, and audit rights.
- Data Protection Impact Assessment (DPIA)
- A risk analysis required under Art. 35 GDPR for processing that poses a high risk to individuals. Mandatory for, e.g., large-scale profiling, large-scale processing of special category data, or systematic monitoring of public areas.
- Data Protection Officer (DPO)
- A natural or legal person who monitors compliance with data protection law and provides advice. Can be appointed internally or externally. Must have expert knowledge and be independent of instructions.
- Data Subject
- The natural person whose personal data is being processed. Has rights under Art. 15–22 GDPR: access, rectification, erasure, restriction, data portability, objection.
- Deletion/Retention Concept
- Documentation of when which data must be deleted. Takes into account statutory retention periods (German tax law: 10 years) and the data protection principle of storage limitation.
- GDPR
- General Data Protection Regulation (Regulation (EU) 2016/679). Directly applicable in all EU member states since 25 May 2018. Governs the processing of personal data by companies and public authorities.
- ISMS
- Information Security Management System. A systematic approach to managing information security within an organization. The basis for ISO 27001 certification.
- Personal Data
- Any information relating to an identified or identifiable person. Examples: name, email address, IP address, customer number, vehicle registration number, biometric characteristics.
- Processor
- A service provider who processes personal data on behalf of the controller. Examples: cloud providers, email services, payroll providers. Requires a written Data Processing Agreement (DPA).
- Pseudonymization
- Processing personal data so that it can no longer be attributed to a specific person without additional information. Reduces risk but is not full protection (unlike anonymization).
- Purpose Limitation
- Principle (Art. 5(1)(b) GDPR): data may only be used for the purpose for which it was originally collected. New purposes require a new legal basis or must be compatible with the original purpose.
- Records of Processing Activities (RoPA)
- Mandatory documentation (Art. 30 GDPR) recording all relevant processing activities: purpose, legal basis, data subjects, categories, recipients, deletion periods, TOMs.
- Technical and Organizational Measures (TOMs)
- Measures under Art. 32 GDPR to protect personal data: encryption, access controls, backups, pseudonymization, physical access controls, staff training.