{"id":24819,"date":"2018-02-12T09:22:55","date_gmt":"2018-02-12T09:22:55","guid":{"rendered":"https:\/\/www.highspeedtraining.co.uk\/hub\/?p=24819"},"modified":"2024-05-17T13:48:13","modified_gmt":"2024-05-17T12:48:13","slug":"gdpr-glossary","status":"publish","type":"post","link":"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/","title":{"rendered":"GDPR Glossary of Key Terms"},"content":{"rendered":"<p>The introduction of the General Data Protection Regulation (GDPR) in May 2018 resulted in big changes to how companies can processes people\u2019s data. By now, all businesses should be fully compliant with its requirements. However, if you still have ways to improve, this glossary might help you understand the key aspects of data protection law. It may also be useful if you&#8217;re adopting more responsibilities regarding data protection in your organisation and want to develop your knowledge.<\/p>\n<p>Some of the terminology may feel a little overwhelming and confusing if you\u2019ve never encountered them before, so we\u2019ve created this GDPR glossary of key terms to help.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-24891 size-full\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2018\/01\/gdpr-terminology.jpg\" alt=\"employees explaining gdpr terminology\" width=\"685\" height=\"295\" \/><\/p>\n<hr \/>\n<p><strong>Accountability<\/strong> \u2013 the data controller is responsible for compliance with the data protection principles. They must be able to demonstrate the steps the business takes to ensure compliance.<\/p>\n<p><strong>Binding Corporate Rules (BCRs)<\/strong> \u2013 a set of rules that allow multinational organisations to transfer personal data from the EU to their affiliates outside of the EU.<\/p>\n<p><strong>Consent<\/strong> \u2013 consent is defined as receiving a data subject\u2019s agreement to process their data. Agreement must be freely given, informed, specific and unambiguous. This consent could be given several ways, such as via a written statement (including by electronic means) or an oral statement.\u00a0Gaining consent must be clear and unambiguous. The data subject must understand implicitly what they are providing their data for, how it will be processed, who will process it and how long it will be stored.<\/p>\n<p><strong>Data Breach<\/strong> \u2013 any accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access of a subject\u2019s data.<\/p>\n<p><strong>Data Controller<\/strong> \u2013 \u2018controller\u2019 means the legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-24878 size-full\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2018\/01\/gdpr-compliance.jpg\" alt=\"employees checking gdpr compliance\" width=\"685\" height=\"295\" \/><\/p>\n<p><strong>Data Erasure<\/strong>\u2013 (also known as the Right to be Forgotten) this entitles the data subject to request that the data controller erase their personal.<\/p>\n<p><strong>Data Minimisation<\/strong> \u2013 this means that you can only collect personal data if it\u2019s needed to achieve the intended purpose. Personal data should be adequate, relevant and limited to what is necessary. Where appropriate, such data should also be kept up to date.<\/p>\n<p><strong>Data Processor<\/strong> \u2013\u00a0\u2018processing\u2019 means any operation, or set of operations, which is performed on personal data or on sets of personal data. It is considered processing whether these operations occur by automated or manual means. Processing includes the following activities: collecting, recording, organising, using, structuring, storing, adapting, retrieving, consulting, destroying and more. The data processor can be an organisation or third-party provider who manages and processes personal data on behalf of the controller. Data processors have specific legal obligations, such as maintaining personal records, and are liable in the event of a data breach.<\/p>\n<p><strong>Data Protection Authority<\/strong> \u2013 the national authority who protects data privacy.<\/p>\n<p><strong>Data Protection Officer<\/strong> \u2013 an appointed individual who works to ensure you implement and comply with the policies and procedures set by GDPR.<\/p>\n<p><strong>Data Subject<\/strong> \u2013 someone whose personal data is processed by a controller or processor.<\/p>\n<p><strong>Encrypted Data<\/strong> \u2013 personal data which has been translated into another form or code so that only people with specific access can read it.<\/p>\n<div class=\"tip__box\">\n<div class=\"tip__title__container\">\n<div class=\"tip__title__text\">\n<div class=\"tip__title__icon\"><img decoding=\"async\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2019\/11\/expert-tip-icon.png\" alt=\"expert icon\" \/><\/div>\n<h3>Need a Course?<\/h3>\n<\/div>\n<\/div>\n<p>Our <a href=\"https:\/\/www.highspeedtraining.co.uk\/courses\/business-essentials\/gdpr-training\/\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR Training Course<\/a> \u00a0is suitable for anyone who has responsibility for implementing the changes brought about by the GDPR.<\/p>\n<\/div>\n<p><strong>EU-US Privacy Shield<\/strong> \u2013 this refers to a new set of GDPR standards that allow for the legal transfer of personal data between the EU and US for commercial reasons.<\/p>\n<p><strong>Fairness Principle<\/strong> \u2013 this is a principle that states the data subject should have the right to:<br \/>\n1. Access the data.<br \/>\n2. Rectify the data.<br \/>\n3. Request that the data be erased.<br \/>\n4. Restrict processing.<br \/>\n5. Data portability.<br \/>\n6. Object to the processing of data.<br \/>\n7. Not to be subject to a decision based solely on automated processing.<\/p>\n<p><strong>Integrity &amp; Confidentiality Principle<\/strong> \u2013 personal data must be processed using appropriate technical, organisational and security measures.<\/p>\n<p><strong>Legality Principle<\/strong> \u2013 for any personal data processed, the organisation must be able to specify that it has been processed on one of the legal grounds specified by GDPR. These grounds are:<br \/>\n1. Individuals consent.<br \/>\n2. Contract with the individual.<br \/>\n3. Complying with an existing obligation.<br \/>\n4. Complying with an existing obligation.<br \/>\n5. Necessary for a task in public interest or authority.<br \/>\n6. Necessary in the legitimate interest of an organisation or third party.<\/p>\n<p><strong>Personal Data <\/strong>\u2013 any direct or indirect information relating to an identified person that could be used as a means of identifying them. This includes their name, ID number, location data or an online identifier.<\/p>\n<p><strong>Privacy Impact Assessment<\/strong> \u2013 a tool used to identify the privacy risks.<\/p>\n<p><strong>Profiling<\/strong> \u2013 the automated processing of personal data.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-24880 size-full\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2018\/01\/assessing-gdpr-requirements.jpg\" alt=\"employees assessing gdpr requirements\" width=\"685\" height=\"295\" \/><\/p>\n<p><strong>Processing<\/strong> \u2013 \u00a0this refers to any activity relating to personal data, from initial collection through to the final destruction. It includes the organising, altering, consulting, using, disclosing, combining and holding of data, either electronically or manually.<\/p>\n<p><strong>Pseudonymisation<\/strong> \u2013 processing data so it can no longer be attributed to a data subject without the use of additional data.<\/p>\n<p><strong>Purpose Limitation Principle<\/strong> \u2013\u00a0 this refers to using information only for the specified, explicit and legitimate purposes for which the data was collected and not for any other purpose.<\/p>\n<p><strong>Sensitive Personal Data<\/strong> \u2013 other factors specific to physical, physiological, genetic, mental, economic, cultural or social identity.\u00a0This can include genetic data, biometric data, and criminal convictions and offences that, when processed, can uniquely identify a person.<\/p>\n<p><strong>Third Party<\/strong> \u2013 a legal body or authority other than the data subject, controller or processor who is authorised to process personal data under authority of the data controller or processor.<\/p>\n<hr \/>\n<p><em>The terminology used when describing GDPR can be confusing, but it&#8217;s important that you understand them all. Knowing what responsibilities GDPR places on different individuals and what policies and procedures you must comply with is important if you want to avoid severe legal fines and a lost reputation. Use the information contained in this article to ensure you understand what is expected of you.<\/em><\/p>\n<hr \/>\n<h3>What to Read Next:<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-consent-requirements\/\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR Consent Requirements<\/a><\/li>\n<li><a href=\"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-quiz\/\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR Quiz<\/a><\/li>\n<li><a href=\"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-guide-to-the-key-changes\/\">GDPR: A Guide to the Key Changes<\/a><\/li>\n<li><a href=\"https:\/\/www.highspeedtraining.co.uk\/courses\/business-essentials\/gdpr-training\/\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR Online Training<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>This GDPR glossary covers the definitions of key terms relating to the General Data Protection Regulation. Further information and resources provided.<\/p>\n","protected":false},"author":22,"featured_media":24873,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[70,3386],"class_list":["post-24819","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","tag-business-law","tag-data-protection"],"acf":{"schema_disabled":false,"schema_properties_FAQPage_question_answer":null,"schema_properties_HowTo_howto_tools":null,"schema_properties_HowTo_howto_supplies":null,"schema_properties_HowTo_howto_steps":null,"schema_properties_WebPage_cssSelector":null,"schema_sameAs_repeater":null,"schema_custom_json_repeater":null,"schema_custom_json_override":false},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v19.5 (Yoast SEO v19.12) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>GDPR Glossary - Explaining the Terminology | High Speed Training<\/title>\n<meta name=\"description\" content=\"This GDPR glossary covers the definitions of key terms relating to the General Data Protection Regulation. Further information and resources provided.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GDPR Glossary of Key Terms\" \/>\n<meta property=\"og:description\" content=\"This GDPR glossary covers the definitions of key terms relating to the General Data Protection Regulation. Further information and resources provided.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/\" \/>\n<meta property=\"og:site_name\" content=\"The Hub | High Speed Training\" \/>\n<meta property=\"article:publisher\" content=\"http:\/\/www.facebook.com\/highspeedtraining\/\" \/>\n<meta property=\"article:published_time\" content=\"2018-02-12T09:22:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-05-17T12:48:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2018\/01\/gdpr-glossary.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"627\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Katie Martinelli\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@hst\" \/>\n<meta name=\"twitter:site\" content=\"@hst\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Katie Martinelli\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"GDPR Glossary - Explaining the Terminology | High Speed Training","description":"This GDPR glossary covers the definitions of key terms relating to the General Data Protection Regulation. Further information and resources provided.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/","og_locale":"en_GB","og_type":"article","og_title":"GDPR Glossary of Key Terms","og_description":"This GDPR glossary covers the definitions of key terms relating to the General Data Protection Regulation. Further information and resources provided.","og_url":"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/","og_site_name":"The Hub | High Speed Training","article_publisher":"http:\/\/www.facebook.com\/highspeedtraining\/","article_published_time":"2018-02-12T09:22:55+00:00","article_modified_time":"2024-05-17T12:48:13+00:00","og_image":[{"width":1200,"height":627,"url":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2018\/01\/gdpr-glossary.jpg","type":"image\/jpeg"}],"author":"Katie Martinelli","twitter_card":"summary_large_image","twitter_creator":"@hst","twitter_site":"@hst","twitter_misc":{"Written by":"Katie Martinelli","Estimated reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/#article","isPartOf":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/"},"author":{"name":"Katie Martinelli","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#\/schema\/person\/bcadcd619cc2fa3c756f9a73b2f40eff"},"headline":"GDPR Glossary of Key Terms","datePublished":"2018-02-12T09:22:55+00:00","dateModified":"2024-05-17T12:48:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/"},"wordCount":992,"commentCount":3,"publisher":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#organization"},"keywords":["Business Law and Compliance","Data Protection"],"articleSection":["Business"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/","url":"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/","name":"GDPR Glossary - Explaining the Terminology | High Speed Training","isPartOf":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#website"},"datePublished":"2018-02-12T09:22:55+00:00","dateModified":"2024-05-17T12:48:13+00:00","description":"This GDPR glossary covers the definitions of key terms relating to the General Data Protection Regulation. Further information and resources provided.","breadcrumb":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/gdpr-glossary\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.highspeedtraining.co.uk\/hub\/"},{"@type":"ListItem","position":2,"name":"GDPR Glossary of Key Terms"}]},{"@type":"WebSite","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#website","url":"https:\/\/www.highspeedtraining.co.uk\/hub\/","name":"The Hub | High Speed Training","description":"Welcome to the Hub, the company blog from High Speed Training.","publisher":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.highspeedtraining.co.uk\/hub\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#organization","name":"The Hub | High Speed Training","url":"https:\/\/www.highspeedtraining.co.uk\/hub\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#\/schema\/logo\/image\/","url":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2021\/05\/HST_Logo_Dark-Blue_CMYK_AW-scaled.jpg","contentUrl":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2021\/05\/HST_Logo_Dark-Blue_CMYK_AW-scaled.jpg","width":2560,"height":1206,"caption":"The Hub | High Speed Training"},"image":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#\/schema\/logo\/image\/"},"sameAs":["http:\/\/www.facebook.com\/highspeedtraining\/","https:\/\/twitter.com\/hst"]},{"@type":"Person","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#\/schema\/person\/bcadcd619cc2fa3c756f9a73b2f40eff","name":"Katie Martinelli","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b77ddee9cd8d30230cfb16b01571f0c8?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b77ddee9cd8d30230cfb16b01571f0c8?s=96&d=mm&r=g","caption":"Katie Martinelli"},"description":"As the Content Production Manager and Construction Specialist for High Speed Training, Katie Martinelli uses her experience in Health &amp; Safety to provide guidance and best practice for people across a range of disciplines. Katie holds a Masters\u2019 Degree in Chemistry from the University of York, where she completed advanced training in a range of chemical sciences. She holds a Level 5 CIPD Diploma in Learning and Development and is an Associate CIPD member.","sameAs":["https:\/\/www.highspeedtraining.co.uk"],"url":"https:\/\/www.highspeedtraining.co.uk\/hub\/author\/katie\/"}]}},"_links":{"self":[{"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/posts\/24819","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/comments?post=24819"}],"version-history":[{"count":6,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/posts\/24819\/revisions"}],"predecessor-version":[{"id":75107,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/posts\/24819\/revisions\/75107"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/media\/24873"}],"wp:attachment":[{"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/media?parent=24819"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/categories?post=24819"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/tags?post=24819"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}