Privacy Glossary
Plain-language explanations of privacy terms and concepts.
A
ADMT (Automated Decision-Making Technology)
RegulationsTechnology that makes decisions or assists in making decisions about individuals without direct human involvement. Under CCPA, businesses must provide notice and opt-out rights for certain ADMT uses.
AI (Artificial Intelligence)
ConceptsSystems that simulate human intelligence to perform tasks like decision-making, pattern recognition, and predictions. In privacy, AI raises concerns about bias, transparency, and automated decision-making.
Algorithm
BA set of rules or instructions that a computer follows to solve a problem or perform a task. Algorithms are the foundation of AI systems and can introduce bias if not properly designed and tested.
B
B2B (Business-to-Business)
ConceptsTransactions and relationships between businesses rather than between a business and consumers. B2B privacy considerations often differ from B2C, with different legal obligations and expectations.
B2C (Business-to-Consumer)
CTransactions and relationships between a business and individual consumers. B2C privacy is heavily regulated under laws like CCPA and GDPR.
Bias (Algorithmic)
ConceptsSystematic and unfair discrimination in the outputs of AI systems, often resulting from biased training data or flawed algorithm design.
Biometric Data
ConceptsPhysical or behavioral characteristics that can be used to identify an individual, including fingerprints, facial recognition, voiceprints, and iris scans. Under CCPA, biometric data is considered sensitive personal information.
C
CalOPPA (California Online Privacy Protection Act)
RegulationsA California law requiring commercial websites and online services that collect personally identifiable information from California residents to conspicuously post a privacy policy. Effective 2004.
CCPA (California Consumer Privacy Act)
RegulationsA California law that gives consumers rights over their personal information, including the right to know what data is collected, to delete it, and to opt out of its sale. Effective January 1, 2020.
CI (Contextual Integrity)
FrameworksA privacy framework developed by Helen Nissenbaum that evaluates whether an information flow is appropriate based on the context of the situation — not just whether the information is "personal" or "anonymous."
Contextual Integrity
FrameworksA privacy framework developed by Helen Nissenbaum that evaluates information flows based on the norms of the context in which they occur. Privacy is not about keeping information secret — it's about ensuring information flows appropriately according to contextual norms.
CPPA (California Privacy Protection Agency)
DThe agency responsible for enforcing the CCPA and CPRA in California. It has authority to investigate violations and impose fines.
CPRA (California Privacy Rights Act)
RegulationsAn amendment to the CCPA passed in 2020 that expanded consumer rights and established the California Privacy Protection Agency (CPPA). Effective January 1, 2023.
D
Data Minimization
ConceptsThe principle that organizations should collect only the personal information they actually need for a specific purpose, and retain it only as long as necessary.
Data Subject
EThe individual to whom personal information relates. In privacy law, data subjects have rights over their personal information.
DNT (Do Not Track)
ConceptsA browser setting that signals to websites that you do not want to be tracked across different websites or online services. CalOPPA requires websites to disclose how they respond to DNT signals.
E
EDPB (European Data Protection Board)
RegulationsThe EU body responsible for ensuring consistent application of the GDPR across member states. It issues guidelines and binding decisions on data protection matters.
Enforcement
FThe act of ensuring compliance with privacy laws, typically through investigations, fines, and court orders. Enforcement actions are often public and can serve as warnings to other organizations.
F
Facial Recognition
GA type of biometric technology that identifies individuals by analyzing their facial features. Highly regulated in many jurisdictions due to privacy and bias concerns.
FRIA (Fundamental Rights Impact Assessment)
ConceptsA type of impact assessment required under certain EU laws, including the EU AI Act. It evaluates the impact of technology on fundamental rights.
G
GDPR (General Data Protection Regulation)
RegulationsThe European Union's comprehensive data protection law, effective May 25, 2018. It gives EU residents extensive rights over their personal data and imposes strict obligations on data controllers and processors.
GLBA (Gramm-Leach-Bliley Act)
RegulationsA federal law that requires financial institutions to protect consumer information and provide notice about their data-sharing practices. Also known as the Financial Privacy Rule.
GPC (Global Privacy Control)
HA browser setting that signals to websites that you want to opt out of the sale or sharing of your personal information. Recognized under CCPA as a valid opt-out mechanism.
H
HIPAA (Health Insurance Portability and Accountability Act)
RegulationsA federal law that protects the privacy of patients' health information and establishes standards for electronic health data. Enforced by the Office for Civil Rights (OCR).
Human Review
IThe practice of having a person review and approve outputs of automated systems, particularly in AI. Under the EU AI Act, human review is required for high-risk AI systems.
I
Inference
ConceptsThe process of deriving new information about an individual from data that has been collected. Profiling and predictive analytics rely on inference, which raises privacy concerns.
IP Address
LA unique identifier assigned to devices connected to the internet. Under many privacy laws, IP addresses are considered personal information because they can be linked to individuals.
L
Lawful Basis
ConceptsThe legal justification for processing personal data. Under GDPR, lawful bases include consent, contract, legal obligation, legitimate interest, vital interest, and public task.
Legitimate Interest
MA lawful basis under GDPR that allows processing of personal data if it is necessary for the legitimate interests of the controller, provided it does not override the rights and freedoms of the data subject.
M
Model Privacy Form
NA standardized privacy notice format required by GLBA for financial institutions. The form has specific formatting requirements and is designed to be easy for consumers to read.
N
NPI (Nonpublic Personal Information)
ConceptsPersonally identifiable financial information that is not publicly available. Under GLBA, financial institutions must protect NPI and provide notice about their data-sharing practices.
NPP (Notice of Privacy Practices)
OA document required under HIPAA that describes how a covered entity may use and disclose protected health information (PHI). Patients must be given the NPP and acknowledge receipt.
O
Opt-In
PThe practice of requiring individuals to actively consent to the collection or use of their personal information. Children under 16 typically require opt-in consent under CCPA.
Opt-Out
ConceptsThe right of individuals to decline certain uses of their personal information. Under CCPA, consumers have the right to opt out of the sale or sharing of their personal information.
P
PHI (Protected Health Information)
ConceptsIndividually identifiable health information, including medical records, billing data, and any health-related information that can be linked to a specific person. Protected under HIPAA.
PIA (Privacy Impact Assessment)
ConceptsA systematic process used to evaluate the privacy risks of a project, system, or initiative before it is implemented. PIAs help organizations identify and mitigate privacy risks proactively.
Processor
ConceptsAn entity that processes personal data on behalf of a controller. Under GDPR, processors have specific obligations to protect personal data and maintain records of processing activities.
Profiling
ConceptsThe automated processing of personal data to evaluate certain characteristics about an individual. Under GDPR, profiling that produces legal or significant effects is subject to specific protections.
Pseudonymization
RThe practice of replacing identifying information with pseudonyms so that data cannot be directly linked to individuals without additional information. A security measure recommended under GDPR.
R
Residual Risk
ConceptsThe level of risk that remains after controls have been implemented. In privacy compliance, residual risk is assessed to determine whether additional measures are needed.
Risk
SIn privacy, the potential for harm to individuals resulting from the processing of their personal information. Risk assessments evaluate both the likelihood and severity of potential harm.
ROPA (Record of Processing Activity)
ConceptsA detailed inventory of an organization's data processing activities, including what data is collected, why, who has access, and how long it is retained. Required under GDPR and the foundation for privacy compliance.
S
SCCs (Standard Contractual Clauses)
RegulationsStandard contractual clauses approved by the European Commission for transferring personal data to third countries. SCCs are a legal mechanism for ensuring adequate data protection in cross-border transfers.
Sensitive Personal Information
ConceptsCategories of personal information that require enhanced protection, including biometric data, genetic data, health information, and government identifiers. Under CCPA, sensitive PI triggers additional obligations.
Subject
TIn privacy law, the individual whose personal information is being processed. Also known as a data subject under GDPR.
T
TIA (Transfer Impact Assessment)
ConceptsAn assessment required under GDPR when transferring personal data to a third country. The TIA evaluates whether the destination country provides adequate protection for the data.
TPO (Treatment, Payment, Operations)
ConceptsA HIPAA term describing the three primary purposes for which covered entities may use and disclose protected health information without authorization.
Transparency
UThe principle that organizations should be open and honest about how they collect, use, and share personal information. Transparency is a core requirement of most privacy laws.
U
User
VIn privacy law, an individual who interacts with a website, application, or service. Users are often the data subjects whose personal information is collected.
V
Vendor Management
WThe process of overseeing third-party vendors to ensure they comply with privacy and security requirements. Vendor management is critical for managing risk and ensuring data protection.
W
Waitlist
ProductA feature of Doxa that allows users to register interest in upcoming features and receive notifications when they become available.
Workplace Monitoring
ConceptsThe practice of tracking employee activities, including computer usage, location, and communications. Workplace monitoring raises significant privacy concerns and must comply with applicable laws.