A
Accountability
Organisations must follow data protection rules and be able to show how they do this.
Anonymisation
Removing information that can identify a person so no one can tell who they are.
B
Biometric Data
Personal data based on someone’s physical features, like fingerprints or face scans.
C
Consent
When a person clearly agrees to the use of their personal data. They must be able to change their mind easily.
D
Data Breach (Personal Data Breach)
When personal data is lost, shared by mistake, changed, or accessed without permission.
Data Controller
The organisation that decides why and how personal data will be used. It is responsible for ensuring compliance with data protection law.
Data Minimisation
Only collecting the smallest amount of personal data necessary for the job.
Data Protection by Design and Default
Making sure privacy is built into systems and processes from the start.
Data Processing
Any action involving personal data, such as collecting, storing, using, sharing, or deleting it.
Data Processor
A person or organisation (not an employee) that processes personal data on behalf of the controller and under its instructions.
Data Protection Impact Assessment (DPIA)
A structured check to find and reduce risks to people’s personal data before starting new work.
Data Protection Officer (DPO)
The role of the data protection officer is to make sure that the organisation processes personal data in compliance with data protection law.
Data Subject
A living person who the personal data is about.
E
Encryption
A security method that converts information into a coded form so it cannot be read without the correct key.
I
ICO (Information Commissioner’s Office)
The UK’s independent authority that regulates data protection and privacy and enforces the UK GDPR and Data Protection Act 2018.
L
Lawful Basis
The legal reason an organisation needs to process personal data.
Legitimate Interests
A lawful basis where processing is needed for an organisation’s interests, unless it harms someone’s rights.
P
Personal Data
Any information that identifies, or could identify, a living person. This can include names, contact details, ID numbers, opinions, and online identifiers.
Processing
Any action performed on personal data, whether automated or manual. This includes collection, storage, use, sharing, alteration and deletion.
Profiling
Automated processing of personal data to analyse or predict aspects about an individual (e.g., behaviour, preferences, performance).
R
Recipient
A person or organisation that receives personal data, whether or not they are a third party.
Retention Period
The length of time personal data is kept before being securely deleted or anonymised.
Rights of the Individual
UK GDPR gives individuals rights including access, rectification, erasure, restriction, objection, and data portability.
S
Special Category Data
A type of personal data that needs extra protection due to its sensitivity. This includes information about health, ethnicity, religion, political views, sexuality, gender identity, genetics and biometrics used for identification.
Subject Access Request (SAR)
A request from someone asking to see the personal data an organisation holds about them.
T
Third Party
Any person or organisation that receives or uses personal data but is not the data subject, controller or processor.