GDPR Glossary — Complete Guide to Key Terms and Definitions
Complete GDPR glossary of legal terms, definitions, and concepts. Article numbers, key terms, and practical explanations for non-EU businesses.
Key GDPR Terms for Non-EU Businesses
This glossary explains the GDPR terms most relevant to non-EU businesses needing Article 27 compliance. Terms are organized by relevance, not alphabetically.
Article 27 — EU Representative
A natural or legal person established in the EU, designated by a non-EU controller/processor in writing, mandated to be addressed by EU DPAs and data subjects on behalf of the controller/processor. Our service.
Article 3(2) — Territorial Scope
GDPR applies to non-EU entities if they offer goods/services to EU data subjects or monitor their behaviour. This is the gateway that triggers Article 27 and all other GDPR obligations for non-EU businesses.
Article 4(1) — Personal Data
Any information relating to an identified or identifiable natural person. Includes names, emails, IP addresses, cookies, ID numbers, location data, and online identifiers.
Article 4(7) — Data Controller
The entity that determines the purposes and means of personal data processing. If you decide what customer data to collect and why, you are the controller.
Article 4(8) — Data Processor
The entity that processes personal data on behalf of the controller. Your email platform, hosting provider, and analytics tool are processors.
Article 30 — Record of Processing Activities (ROPA)
The mandatory documentation every data controller must maintain, describing all processing activities. Template →
Article 33 — Data Breach Notification
Must notify the DPA within 72 hours of becoming aware of a personal data breach. Guide →
Article 35 — Data Protection Impact Assessment (DPIA)
Required for high-risk processing: profiling, special category data at scale, public monitoring. Identifies and mitigates privacy risks before processing begins.
Article 37 — Data Protection Officer (DPO)
A role required for public authorities, large-scale monitoring, and large-scale special category data processing. EU Rep vs DPO →
SCCs — Standard Contractual Clauses
EU-approved contract terms for data transfers from the EU to non-adequate countries. Required for cross-border data flows. Guide →
Adequacy Decision
EU Commission determination that a non-EU country provides adequate data protection. Enables free data flows without SCCs. 16 countries have adequacy. More →
DPA — Data Protection Authority
EU member state’s regulatory body for GDPR enforcement. Your EU Representative receives correspondence from DPAs on your behalf.
ePrivacy Directive
EU law governing electronic communications privacy — cookie consent, direct marketing, communications confidentiality. Applies alongside GDPR. Guide →
Schrems II (and III)
Landmark CJEU rulings that invalidated the EU-US Privacy Shield (Schrems II, 2020) and reinforced SCCs + Transfer Impact Assessments (Schrems III, 2024). Guide →
Consent (Article 4(11), Article 7)
Freely given, specific, informed, unambiguous indication of agreement. Requires affirmative action — pre-ticked boxes are invalid. Guide →
Ready to get compliant?
€490/year. 15-minute setup. Active next business day.