Reference

Privacy Glossary

Plain-language explanations of privacy terms and concepts.

52 terms found

A

ADMT (Automated Decision-Making Technology)

Regulations

Technology that makes decisions or assists in making decisions about individuals without direct human involvement. Under CCPA, businesses must provide notice and opt-out rights for certain ADMT uses.

Related:

AI (Artificial Intelligence)

Concepts

Systems that simulate human intelligence to perform tasks like decision-making, pattern recognition, and predictions. In privacy, AI raises concerns about bias, transparency, and automated decision-making.

Related:

Algorithm

B

A set of rules or instructions that a computer follows to solve a problem or perform a task. Algorithms are the foundation of AI systems and can introduce bias if not properly designed and tested.

Related:

B

B2B (Business-to-Business)

Concepts

Transactions and relationships between businesses rather than between a business and consumers. B2B privacy considerations often differ from B2C, with different legal obligations and expectations.

Related:

B2C (Business-to-Consumer)

C

Transactions and relationships between a business and individual consumers. B2C privacy is heavily regulated under laws like CCPA and GDPR.

Related:

Bias (Algorithmic)

Concepts

Systematic and unfair discrimination in the outputs of AI systems, often resulting from biased training data or flawed algorithm design.

Related:

Biometric Data

Concepts

Physical or behavioral characteristics that can be used to identify an individual, including fingerprints, facial recognition, voiceprints, and iris scans. Under CCPA, biometric data is considered sensitive personal information.

Related:

C

CalOPPA (California Online Privacy Protection Act)

Regulations

A California law requiring commercial websites and online services that collect personally identifiable information from California residents to conspicuously post a privacy policy. Effective 2004.

Related:

CCPA (California Consumer Privacy Act)

Regulations

A California law that gives consumers rights over their personal information, including the right to know what data is collected, to delete it, and to opt out of its sale. Effective January 1, 2020.

Related:

CI (Contextual Integrity)

Frameworks

A privacy framework developed by Helen Nissenbaum that evaluates whether an information flow is appropriate based on the context of the situation — not just whether the information is "personal" or "anonymous."

Related:

Contextual Integrity

Frameworks

A privacy framework developed by Helen Nissenbaum that evaluates information flows based on the norms of the context in which they occur. Privacy is not about keeping information secret — it's about ensuring information flows appropriately according to contextual norms.

Related:

CPPA (California Privacy Protection Agency)

D

The agency responsible for enforcing the CCPA and CPRA in California. It has authority to investigate violations and impose fines.

Related:

CPRA (California Privacy Rights Act)

Regulations

An amendment to the CCPA passed in 2020 that expanded consumer rights and established the California Privacy Protection Agency (CPPA). Effective January 1, 2023.

Related:

D

Data Minimization

Concepts

The principle that organizations should collect only the personal information they actually need for a specific purpose, and retain it only as long as necessary.

Related:

Data Subject

E

The individual to whom personal information relates. In privacy law, data subjects have rights over their personal information.

Related:

DNT (Do Not Track)

Concepts

A browser setting that signals to websites that you do not want to be tracked across different websites or online services. CalOPPA requires websites to disclose how they respond to DNT signals.

Related:

E

EDPB (European Data Protection Board)

Regulations

The EU body responsible for ensuring consistent application of the GDPR across member states. It issues guidelines and binding decisions on data protection matters.

Related:

Enforcement

F

The act of ensuring compliance with privacy laws, typically through investigations, fines, and court orders. Enforcement actions are often public and can serve as warnings to other organizations.

Related:

F

Facial Recognition

G

A type of biometric technology that identifies individuals by analyzing their facial features. Highly regulated in many jurisdictions due to privacy and bias concerns.

Related:

FRIA (Fundamental Rights Impact Assessment)

Concepts

A type of impact assessment required under certain EU laws, including the EU AI Act. It evaluates the impact of technology on fundamental rights.

Related:

G

GDPR (General Data Protection Regulation)

Regulations

The European Union's comprehensive data protection law, effective May 25, 2018. It gives EU residents extensive rights over their personal data and imposes strict obligations on data controllers and processors.

Related:

GLBA (Gramm-Leach-Bliley Act)

Regulations

A federal law that requires financial institutions to protect consumer information and provide notice about their data-sharing practices. Also known as the Financial Privacy Rule.

Related:

GPC (Global Privacy Control)

H

A browser setting that signals to websites that you want to opt out of the sale or sharing of your personal information. Recognized under CCPA as a valid opt-out mechanism.

Related:

H

HIPAA (Health Insurance Portability and Accountability Act)

Regulations

A federal law that protects the privacy of patients' health information and establishes standards for electronic health data. Enforced by the Office for Civil Rights (OCR).

Related:

Human Review

I

The practice of having a person review and approve outputs of automated systems, particularly in AI. Under the EU AI Act, human review is required for high-risk AI systems.

Related:

I

Inference

Concepts

The process of deriving new information about an individual from data that has been collected. Profiling and predictive analytics rely on inference, which raises privacy concerns.

Related:

IP Address

L

A unique identifier assigned to devices connected to the internet. Under many privacy laws, IP addresses are considered personal information because they can be linked to individuals.

Related:

L

Lawful Basis

Concepts

The legal justification for processing personal data. Under GDPR, lawful bases include consent, contract, legal obligation, legitimate interest, vital interest, and public task.

Related:

Legitimate Interest

M

A lawful basis under GDPR that allows processing of personal data if it is necessary for the legitimate interests of the controller, provided it does not override the rights and freedoms of the data subject.

Related:

M

Model Privacy Form

N

A standardized privacy notice format required by GLBA for financial institutions. The form has specific formatting requirements and is designed to be easy for consumers to read.

Related:

N

NPI (Nonpublic Personal Information)

Concepts

Personally identifiable financial information that is not publicly available. Under GLBA, financial institutions must protect NPI and provide notice about their data-sharing practices.

Related:

NPP (Notice of Privacy Practices)

O

A document required under HIPAA that describes how a covered entity may use and disclose protected health information (PHI). Patients must be given the NPP and acknowledge receipt.

Related:

O

Opt-In

P

The practice of requiring individuals to actively consent to the collection or use of their personal information. Children under 16 typically require opt-in consent under CCPA.

Related:

Opt-Out

Concepts

The right of individuals to decline certain uses of their personal information. Under CCPA, consumers have the right to opt out of the sale or sharing of their personal information.

Related:

P

PHI (Protected Health Information)

Concepts

Individually identifiable health information, including medical records, billing data, and any health-related information that can be linked to a specific person. Protected under HIPAA.

Related:

PIA (Privacy Impact Assessment)

Concepts

A systematic process used to evaluate the privacy risks of a project, system, or initiative before it is implemented. PIAs help organizations identify and mitigate privacy risks proactively.

Related:

Processor

Concepts

An entity that processes personal data on behalf of a controller. Under GDPR, processors have specific obligations to protect personal data and maintain records of processing activities.

Related:

Profiling

Concepts

The automated processing of personal data to evaluate certain characteristics about an individual. Under GDPR, profiling that produces legal or significant effects is subject to specific protections.

Related:

Pseudonymization

R

The practice of replacing identifying information with pseudonyms so that data cannot be directly linked to individuals without additional information. A security measure recommended under GDPR.

Related:

R

Residual Risk

Concepts

The level of risk that remains after controls have been implemented. In privacy compliance, residual risk is assessed to determine whether additional measures are needed.

Related:

Risk

S

In privacy, the potential for harm to individuals resulting from the processing of their personal information. Risk assessments evaluate both the likelihood and severity of potential harm.

Related:

ROPA (Record of Processing Activity)

Concepts

A detailed inventory of an organization's data processing activities, including what data is collected, why, who has access, and how long it is retained. Required under GDPR and the foundation for privacy compliance.

Related:

S

SCCs (Standard Contractual Clauses)

Regulations

Standard contractual clauses approved by the European Commission for transferring personal data to third countries. SCCs are a legal mechanism for ensuring adequate data protection in cross-border transfers.

Related:

Sensitive Personal Information

Concepts

Categories of personal information that require enhanced protection, including biometric data, genetic data, health information, and government identifiers. Under CCPA, sensitive PI triggers additional obligations.

Related:

Subject

T

In privacy law, the individual whose personal information is being processed. Also known as a data subject under GDPR.

Related:

T

TIA (Transfer Impact Assessment)

Concepts

An assessment required under GDPR when transferring personal data to a third country. The TIA evaluates whether the destination country provides adequate protection for the data.

Related:

TPO (Treatment, Payment, Operations)

Concepts

A HIPAA term describing the three primary purposes for which covered entities may use and disclose protected health information without authorization.

Related:

Transparency

U

The principle that organizations should be open and honest about how they collect, use, and share personal information. Transparency is a core requirement of most privacy laws.

Related:

U

User

V

In privacy law, an individual who interacts with a website, application, or service. Users are often the data subjects whose personal information is collected.

Related:

V

Vendor Management

W

The process of overseeing third-party vendors to ensure they comply with privacy and security requirements. Vendor management is critical for managing risk and ensuring data protection.

Related:

W

Waitlist

Product

A feature of Doxa that allows users to register interest in upcoming features and receive notifications when they become available.

Related:

Workplace Monitoring

Concepts

The practice of tracking employee activities, including computer usage, location, and communications. Workplace monitoring raises significant privacy concerns and must comply with applicable laws.

Related: