Glossary
A plain-English privacy glossary
From CCPA to processor agreements, every term defined in 60 words or fewer.
01 / GDPR
European Union law that governs how personal data of EU residents is collected, processed, and stored.
02 / CCPA / CPRA
California consumer privacy law granting residents access, deletion, and opt-out rights for their personal information.
03 / Consent
A clear, specific, freely given indication by a user that they agree to a defined data processing activity.
04 / Processor
A vendor that handles personal data only on documented instructions from a controller, such as an analytics provider.
05 / Controller
The entity that decides why and how personal data is processed. Usually the business that runs the website or app.
06 / Data Processing Agreement
Data Processing Agreement. A contract between controller and processor that defines responsibilities and safeguards.
07 / Data Protection Officer
Data Protection Officer. A staff or contracted role that oversees privacy compliance and acts as a regulator contact.
09 / Personal Information
Personal Information (CCPA) or Personally Identifiable Information. Any information that identifies, relates to, or could be linked to a person.
10 / Data subject rights
Rights given to individuals over their personal data, such as access, deletion, rectification, and portability.