Compliance Glossary
Privacy and compliance terms explained in plain language. Understand the concepts behind GDPR, CCPA, cookie consent, and data protection.
Cookie & Tracking
(12)Cookie Consent
Permission obtained from website visitors before setting non-essential cookies on their devices.
Third-Party Cookies
Cookies set by domains other than the website the user is currently visiting, typically used for cross-site tracking and advertising.
First-Party Cookies
Cookies set directly by the website domain that the user is currently visiting.
Tracking Pixels
Tiny invisible images or code snippets embedded in web pages or emails to monitor user behavior and collect analytics data.
Cookie Categories
Classification groups that organize cookies by their purpose, such as necessary, analytics, marketing, and functional.
Session Cookies
Temporary cookies that are automatically deleted when the user closes their web browser.
Persistent Cookies
Cookies that remain stored on a user’s device after the browser is closed, with a defined expiration date.
Cookie Banner
A user interface element displayed on websites to inform visitors about cookie usage and collect their consent preferences.
Cookie Policy
A document that explains what cookies a website uses, why it uses them, and how users can manage their preferences.
Cookie Audit
A systematic review and documentation of all cookies and tracking technologies used by a website.
Browser Fingerprinting
A tracking technique that identifies users by collecting unique combinations of browser and device characteristics without using cookies.
Local Storage Tracking
Using browser localStorage or sessionStorage mechanisms to store tracking data as an alternative to traditional cookies.
Consent & Compliance
(10)Consent Management Platform
Software that manages the collection, storage, and enforcement of user consent for cookies and data processing on websites.
Explicit Consent
Consent that is freely given, specific, informed, and unambiguous, demonstrated through a clear affirmative action by the user.
Implied Consent
Consent that is inferred from a user’s actions or inaction rather than explicitly stated, accepted in some jurisdictions for non-sensitive data.
Legitimate Interest
A legal basis under GDPR that allows data processing without consent when the controller’s interests are not overridden by the data subject’s rights.
Opt-In
A consent model where users must actively agree to data processing or cookie placement before it begins.
Opt-Out
A consent model where data processing begins by default and users must actively refuse or withdraw to stop it.
Consent Record
Documented proof that consent was obtained, including details of when, how, and what the individual consented to.
Granular Consent
The ability for users to accept or reject different categories of cookies or data processing activities individually.
Prior Consent
Consent that must be obtained before any data processing or cookie placement begins, not after.
Consent Withdrawal
A user’s right to revoke previously given consent for data processing at any time, as easily as it was given.
Data Protection
(10)Data Controller
The entity that determines the purposes and means of processing personal data.
Data Processor
An entity that processes personal data on behalf of and under the instructions of a data controller.
Data Subject
An identified or identifiable individual whose personal data is being collected or processed.
Data Protection Officer
A designated person responsible for overseeing an organization’s data protection strategy, practices, and compliance.
Data Protection Impact Assessment
A formal assessment required before processing activities that are likely to result in high risks to individuals’ rights and freedoms.
Data Breach Notification
The legal requirement to report data breaches to supervisory authorities and affected individuals within specified timeframes.
Data Minimization
The principle that organizations should collect and process only the personal data that is strictly necessary for the specified purpose.
Purpose Limitation
The principle that personal data should only be collected for specified, explicit, and legitimate purposes and not further processed in a way incompatible with those purposes.
Right to Erasure
An individual’s right to request the deletion of their personal data, also known as the right to be forgotten.
Data Subject Access Request
A formal request from an individual to obtain a copy of all personal data an organization holds about them.
Regulations
(8)General Data Protection Regulation (GDPR)
The European Union’s comprehensive data protection law, establishing strict rules for processing personal data and strong individual rights.
California Consumer Privacy Act (CCPA)
California’s landmark privacy law giving consumers the right to know, delete, and opt out of the sale of their personal information.
California Privacy Rights Act (CPRA)
The 2023 amendment to the CCPA that strengthened consumer privacy protections and created the California Privacy Protection Agency.
Personal Information Protection and Electronic Documents Act (PIPEDA)
Canada’s federal privacy law governing how private-sector organizations collect, use, and disclose personal information in commercial activities.
Lei Geral de Proteção de Dados (LGPD)
Brazil’s comprehensive data protection law modeled on the GDPR, establishing rules for processing personal data of individuals in Brazil.
ePrivacy Directive
The EU directive specifically governing electronic communications, cookies, and tracking technologies, working alongside the GDPR.
Protection of Personal Information Act (POPIA)
South Africa’s comprehensive data protection law establishing conditions for lawful processing of personal information.
Global Privacy Control (GPC)
A browser-level signal that communicates a user’s preference to opt out of the sale or sharing of their personal information.