DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Reference · Vocabulary

The glossary

The working vocabulary of global privacy law, defined for people who buy and measure media.

Updated September 28, 2026 · digitalprivacyregs.com

58 terms, defined the way a practitioner uses them. Anchor links work for every entry.

Adequacy decision

A finding by the European Commission (or another jurisdiction's equivalent) that a country protects personal data well enough for transfers to flow without extra safeguards.

Adtech

The ecosystem of platforms, exchanges and intermediaries that automate ad buying and selling; the primary target of modern consent enforcement.

Anonymization

Processing that irreversibly prevents identification. Truly anonymous data falls outside most privacy laws; pseudonymized data does not.

APPI

Japan's Act on the Protection of Personal Information, a notice-and-purpose law amended on a triennial cycle.

BCRs

Binding Corporate Rules: internal group policies approved by EU regulators that authorize intra-group international transfers.

Behavioral advertising

Targeting based on observed conduct across sites, apps or devices. Requires consent in the EU; runs on opt-out in most US states.

Breach notification

The duty to report a personal data breach to a regulator (72 hours under the GDPR) and often to affected individuals.

CAN-SPAM

The 2003 US federal email law: an opt-out regime requiring honest headers, identification and a working unsubscribe.

CASL

Canada's Anti-Spam Legislation: express opt-in consent for commercial electronic messages with penalties to CAD 10M.

CCPA/CPRA

California's Consumer Privacy Act as amended by the California Privacy Rights Act; the strictest US state law, enforced by the CPPA.

Controller

The entity that decides why and how personal data is processed; carries primary compliance duties in GDPR-family laws.

CPPA

The California Privacy Protection Agency, the only dedicated privacy regulator in the United States.

Cross-border transfer

Moving personal data to another jurisdiction; the most heavily engineered compliance problem in global marketing stacks.

Dark patterns

Interface designs that steer users into consenting or sharing more than intended; explicitly targeted by the CPPA, FTC and EU regulators.

Data broker

A business that sells personal data about consumers with whom it has no direct relationship; registration laws exist in California, Vermont, Texas and Oregon.

Data localization

A legal requirement to store or process data on servers inside the country; hard rules exist in Russia, China (conditional), Kazakhstan, Uzbekistan, Rwanda and Zambia (sensitive data).

Data minimization

Collecting only what a stated purpose requires. Maryland's MODPA made it the operating default in a US law.

DPF

The EU-US Data Privacy Framework: the adequacy arrangement under which certified US companies may receive EU personal data.

DPIA

Data Protection Impact Assessment: a documented risk analysis required for high-risk processing under the GDPR and its descendants.

DPO

Data Protection Officer: a mandatory independent compliance role for certain controllers under the GDPR, Brazil's LGPD and others.

DPDP Act

India's Digital Personal Data Protection Act 2023, operational in phases from November 2025 to May 2027.

EDPB

The European Data Protection Board: the body of EU national regulators that issues binding dispute decisions and guidance.

ePrivacy Directive

The 2002 EU directive governing cookies and electronic marketing; its planned replacement regulation was withdrawn in 2025.

First-party data

Data a company collects from its own customers and properties; the strategic asset every privacy law makes more valuable.

GAID

Nigeria's General Application and Implementation Directive (2025), the operational rulebook under the NDPA.

GDPR

The EU General Data Protection Regulation (2016/679), the world's reference comprehensive privacy law.

Global Privacy Control

A browser-level opt-out signal that California, Colorado and a growing list of states require businesses to honor.

Habeas data

A constitutional right, common in Latin America, to access and correct one's data through the courts.

Legitimate interests

The flexible GDPR basis balancing business needs against individual rights; unavailable in China's PIPL, newly codified with named examples in the UK.

LGPD

Brazil's Lei Geral de Proteção de Dados, the GDPR's closest large-market cousin.

Localization

See data localization.

Lookalike audience

Targeting users statistically similar to an existing list; consent status of the seed data determines its legality in opt-in markets.

MHMD

Washington's My Health My Data Act: consumer health data protection with a private right of action, reaching wellness and inference data far beyond HIPAA.

NDPA

The Nigeria Data Protection Act 2023.

Opt-in

Permission before processing: the default posture of the GDPR world for tracking and marketing.

Opt-out

Processing until the individual objects: the default posture of US state privacy law for non-sensitive adult data.

PECR

The UK's Privacy and Electronic Communications Regulations, governing cookies and electronic marketing alongside the UK GDPR.

Personal data / personal information

Any information relating to an identified or identifiable person; the definitional gateway every law turns on.

PIPL

China's Personal Information Protection Law: consent-centric, no legitimate-interest basis, government-supervised transfers.

POPIA

South Africa's Protection of Personal Information Act.

Privacy notice

The disclosure describing what is collected, why, and with whom it is shared; the baseline transparency duty in every framework.

Processor

An entity processing personal data on a controller's instructions; carries direct security and contract duties in modern laws.

Profiling

Automated evaluation of personal aspects, especially to predict behavior; triggers opt-outs, transparency duties and sometimes objection rights.

Pseudonymization

Replacing identifiers so data cannot be attributed to a person without a separately kept key. It is a safeguard and leaves the data within the law's scope.

Retargeting

Advertising to users based on their prior visit or action; consent-dependent in the EU, opt-out-governed in the US.

Right to erasure

The right to have personal data deleted (the GDPR's Article 17), echoed in nearly every modern law.

SCCs

Standard Contractual Clauses: regulator-approved contract terms that authorize international transfers; the EU, UK, Brazil, Turkey and China each maintain their own versions.

Sensitive data / special categories

Data types (health, biometrics, race, religion, sexual orientation, precise location, and in some laws financial or children's data) that trigger opt-in consent or outright limits.

Server-side tagging

Routing tag data through a first-party server instead of the browser. It changes the technical surface of consent and leaves the legal requirement untouched.

Soft opt-in

The EU/UK exception allowing marketing to existing customers about similar products without fresh consent, always with an unsubscribe.

TCPA

The US Telephone Consumer Protection Act: prior express written consent for marketing calls and texts, with uncapped statutory damages.

Targeted advertising

Advertising selected using personal data; the specific activity most state laws attach an opt-out to and most opt-in laws attach consent to.

UOOM

Universal opt-out mechanism: a signal (like GPC) that expresses a consumer's opt-out across all sites; honoring is mandatory in a growing set of states.

Cite this page: "The Privacy Law Glossary." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/glossary.html. Accessed [date].