58 terms, defined the way a practitioner uses them. Anchor links work for every entry.
Adequacy decision
A finding by the European Commission (or another jurisdiction's equivalent) that a country protects personal data well enough for transfers to flow without extra safeguards.
Adtech
The ecosystem of platforms, exchanges and intermediaries that automate ad buying and selling; the primary target of modern consent enforcement.
Anonymization
Processing that irreversibly prevents identification. Truly anonymous data falls outside most privacy laws; pseudonymized data does not.
APPI
Japan's Act on the Protection of Personal Information, a notice-and-purpose law amended on a triennial cycle.
BCRs
Binding Corporate Rules: internal group policies approved by EU regulators that authorize intra-group international transfers.
Behavioral advertising
Targeting based on observed conduct across sites, apps or devices. Requires consent in the EU; runs on opt-out in most US states.
Breach notification
The duty to report a personal data breach to a regulator (72 hours under the GDPR) and often to affected individuals.
CAN-SPAM
The 2003 US federal email law: an opt-out regime requiring honest headers, identification and a working unsubscribe.
CASL
Canada's Anti-Spam Legislation: express opt-in consent for commercial electronic messages with penalties to CAD 10M.
CCPA/CPRA
California's Consumer Privacy Act as amended by the California Privacy Rights Act; the strictest US state law, enforced by the CPPA.
Consent
Freely given, specific, informed and unambiguous agreement to processing. The GDPR sets the global benchmark definition; many laws add 'explicit' for sensitive data.
Consent manager
A registered intermediary (a formal role under India's DPDP framework) through which individuals give, manage and withdraw consent.
Consent mode
A signaling framework in which tags read the user's consent state and adjust what they collect.
Controller
The entity that decides why and how personal data is processed; carries primary compliance duties in GDPR-family laws.
Cookie wall
Blocking access unless the user accepts tracking. Prohibited or restricted in much of the EU unless a genuine alternative exists.
CPPA
The California Privacy Protection Agency, the only dedicated privacy regulator in the United States.
Cross-border transfer
Moving personal data to another jurisdiction; the most heavily engineered compliance problem in global marketing stacks.
Dark patterns
Interface designs that steer users into consenting or sharing more than intended; explicitly targeted by the CPPA, FTC and EU regulators.
Data broker
A business that sells personal data about consumers with whom it has no direct relationship; registration laws exist in California, Vermont, Texas and Oregon.
Data localization
A legal requirement to store or process data on servers inside the country; hard rules exist in Russia, China (conditional), Kazakhstan, Uzbekistan, Rwanda and Zambia (sensitive data).
Data minimization
Collecting only what a stated purpose requires. Maryland's MODPA made it the operating default in a US law.
DPF
The EU-US Data Privacy Framework: the adequacy arrangement under which certified US companies may receive EU personal data.
DPIA
Data Protection Impact Assessment: a documented risk analysis required for high-risk processing under the GDPR and its descendants.
DPO
Data Protection Officer: a mandatory independent compliance role for certain controllers under the GDPR, Brazil's LGPD and others.
DPDP Act
India's Digital Personal Data Protection Act 2023, operational in phases from November 2025 to May 2027.
EDPB
The European Data Protection Board: the body of EU national regulators that issues binding dispute decisions and guidance.
ePrivacy Directive
The 2002 EU directive governing cookies and electronic marketing; its planned replacement regulation was withdrawn in 2025.
First-party data
Data a company collects from its own customers and properties; the strategic asset every privacy law makes more valuable.
GAID
Nigeria's General Application and Implementation Directive (2025), the operational rulebook under the NDPA.
GDPR
The EU General Data Protection Regulation (2016/679), the world's reference comprehensive privacy law.
Global Privacy Control
A browser-level opt-out signal that California, Colorado and a growing list of states require businesses to honor.
Habeas data
A constitutional right, common in Latin America, to access and correct one's data through the courts.
Legal basis
The justification (consent, contract, legitimate interests, legal obligation, vital interests, public task) that GDPR-family laws demand for any processing.
Legitimate interests
The flexible GDPR basis balancing business needs against individual rights; unavailable in China's PIPL, newly codified with named examples in the UK.
LGPD
Brazil's Lei Geral de Proteção de Dados, the GDPR's closest large-market cousin.
Localization
See data localization.
Lookalike audience
Targeting users statistically similar to an existing list; consent status of the seed data determines its legality in opt-in markets.
MHMD
Washington's My Health My Data Act: consumer health data protection with a private right of action, reaching wellness and inference data far beyond HIPAA.
NDPA
The Nigeria Data Protection Act 2023.
Opt-in
Permission before processing: the default posture of the GDPR world for tracking and marketing.
Opt-out
Processing until the individual objects: the default posture of US state privacy law for non-sensitive adult data.
PECR
The UK's Privacy and Electronic Communications Regulations, governing cookies and electronic marketing alongside the UK GDPR.
Personal data / personal information
Any information relating to an identified or identifiable person; the definitional gateway every law turns on.
PIPL
China's Personal Information Protection Law: consent-centric, no legitimate-interest basis, government-supervised transfers.
POPIA
South Africa's Protection of Personal Information Act.
Privacy notice
The disclosure describing what is collected, why, and with whom it is shared; the baseline transparency duty in every framework.
Processor
An entity processing personal data on a controller's instructions; carries direct security and contract duties in modern laws.
Profiling
Automated evaluation of personal aspects, especially to predict behavior; triggers opt-outs, transparency duties and sometimes objection rights.
Pseudonymization
Replacing identifiers so data cannot be attributed to a person without a separately kept key. It is a safeguard and leaves the data within the law's scope.
Retargeting
Advertising to users based on their prior visit or action; consent-dependent in the EU, opt-out-governed in the US.
Right to erasure
The right to have personal data deleted (the GDPR's Article 17), echoed in nearly every modern law.
SCCs
Standard Contractual Clauses: regulator-approved contract terms that authorize international transfers; the EU, UK, Brazil, Turkey and China each maintain their own versions.
Sensitive data / special categories
Data types (health, biometrics, race, religion, sexual orientation, precise location, and in some laws financial or children's data) that trigger opt-in consent or outright limits.
Server-side tagging
Routing tag data through a first-party server instead of the browser. It changes the technical surface of consent and leaves the legal requirement untouched.
Soft opt-in
The EU/UK exception allowing marketing to existing customers about similar products without fresh consent, always with an unsubscribe.
TCPA
The US Telephone Consumer Protection Act: prior express written consent for marketing calls and texts, with uncapped statutory damages.
Targeted advertising
Advertising selected using personal data; the specific activity most state laws attach an opt-out to and most opt-in laws attach consent to.
UOOM
Universal opt-out mechanism: a signal (like GPC) that expresses a consumer's opt-out across all sites; honoring is mandatory in a growing set of states.