Compliance & Privacy Glossary
Plain-English definitions for the privacy, security, and compliance terms across Concord Learn, from DSAR and RoPA to the Trust Services Criteria.
These terms come up across privacy, security, and compliance work. Each is defined in plain language, answer first, with a link to the guides where you can go deeper. Use your browser's find to jump to one.
ADMT (Automated Decision-Making Technology)
Automated decision-making technology is software that makes, or substantially informs, a decision about a person without a human making the final call. Newer privacy rules give people rights to notice, access, and sometimes an opt-out when ADMT is used for significant decisions. See the US state privacy guides.
Annex A (ISO 27001)
Annex A is the catalog of reference security controls in ISO 27001. An organization selects the controls that apply to it and records the choice in a Statement of Applicability. See Annex A controls.
CCPA / CPRA
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, is California's privacy law. It gives residents rights over their personal information and requires businesses to honor opt-outs of the sale or sharing of that data. See what CCPA/CPRA is.
CMP (Consent Management Platform)
A consent management platform is the software that collects a visitor's cookie and tracker choices, stores the record, blocks non-essential trackers until consent, and signals the choice to other tools. See what a CMP is.
Consent
Consent is a person's freely given, specific, informed, and unambiguous agreement to a use of their data. Under GDPR it must be as easy to withdraw as to give, and silence or a pre-ticked box does not count. See the consent management guides.
Data Controller
A data controller is the organization that decides why and how personal data is processed. The controller carries most of the legal obligations under GDPR, distinct from the processor that acts on its instructions. See the GDPR guides.
Data Mapping
Data mapping is the practice of documenting what personal data an organization holds, where it lives, how it flows, and who it is shared with. It underpins records of processing, impact assessments, and responding to rights requests. See the DSAR guides.
Data Processor
A data processor is a vendor or party that processes personal data on a controller's behalf and under its instructions, such as a cloud host or an analytics provider. Processors have their own, narrower set of obligations under GDPR. See the GDPR guides.
Data Subject
A data subject is the individual a piece of personal data is about. Privacy laws grant data subjects rights, such as access and deletion, over that data. See the seven data subject rights.
DPIA (Data Protection Impact Assessment)
A data protection impact assessment is a structured review of the privacy risks of a processing activity, required under GDPR when that processing is likely to be high risk. It documents the risk and the steps taken to reduce it. See the GDPR guides.
DSAR (Data Subject Access Request)
A data subject access request is a request by an individual to see the personal data an organization holds about them, and often to correct or delete it. Most privacy laws set a deadline to respond. See what a DSAR is.
EU AI Act
The EU AI Act is the European Union's risk-based law governing artificial intelligence. It sets obligations that scale with how much risk an AI system poses and bans a small set of uses outright. See what the EU AI Act is.
GDPR
The General Data Protection Regulation is the European Union's core privacy law. It governs how organizations collect and use the personal data of people in the EU, sets a high bar for consent, and grants individuals a set of data subject rights. See what GDPR is.
GPC (Global Privacy Control)
The Global Privacy Control is a browser signal that automatically tells websites a person wants to opt out of the sale or sharing of their data. A growing number of US state laws require businesses to honor it. See the Global Privacy Control.
IAB TCF
The IAB Europe Transparency and Consent Framework is the advertising industry's shared standard for capturing consent and passing it, as a TC String, to the vendors in the programmatic advertising chain. See what the IAB TCF is.
ISO 27001
ISO/IEC 27001 is the international standard for an information security management system (ISMS). Organizations can be independently certified against it, which many buyers accept as proof of a mature security program. See the ISO 27001 guides.
ISO 42001
ISO/IEC 42001 is the international standard for an AI management system, and the first AI governance standard an organization can be certified against. See ISO 42001 and the NIST AI RMF.
Legitimate Interest
Legitimate interest is one of the lawful bases for processing personal data under GDPR, used when an organization has a genuine need that is not overridden by the individual's rights. It requires a documented balancing test rather than consent. See the GDPR guides.
LGPD
The Lei Geral de Proteção de Dados is Brazil's general data protection law, closely modeled on GDPR. It grants Brazilian residents similar rights and places similar obligations on organizations that handle their data. See the GDPR guides for the consent-first model it shares.
NIST AI RMF
The NIST AI Risk Management Framework is voluntary US guidance that organizes AI risk work into four functions: govern, map, measure, and manage. It is a structure to adopt, not a certification to earn. See ISO 42001 and the NIST AI RMF.
Personal Data / Personal Information
Personal data (the GDPR term) or personal information (the US term) is any information relating to an identified or identifiable person. It is broader than most people expect, covering things like device identifiers and IP addresses, not just names. See the GDPR guides.
RoPA (Records of Processing Activities)
A record of processing activities is the inventory GDPR Article 30 requires: a documented list of the personal data an organization processes, why, and with whom it is shared. See records of processing activities.
Sale or Sharing
Under US state privacy laws, "sale" and "sharing" are defined broadly enough to cover common advertising and analytics data flows, not just exchanging data for money. Businesses must let consumers opt out of both. See the US state privacy guides.
SOC 2
SOC 2 is an audit report, produced by an independent CPA firm, on how well a company's controls meet a set of Trust Services Criteria. It is the report most enterprise buyers ask for before trusting a vendor with their data. See the SOC 2 guides.
Statement of Applicability
The Statement of Applicability is the ISO 27001 document that lists which Annex A controls an organization applies, which it excludes, and why. It is central to certification. See the Statement of Applicability.
Trust Center
A trust center is a public page where a company publishes its security posture, certifications, and controls so buyers can answer their own security questions without a sales call. See the Trust Center guides.
Trust Services Criteria
The Trust Services Criteria are the five categories a SOC 2 report can cover: security, availability, processing integrity, confidentiality, and privacy. Security is always included; the rest are optional, based on what a company commits to. See the five Trust Services Criteria.