The vocabulary, in plain words

Every term carries what it is and why a practitioner cares. The second line is the part that makes it usable. Free at every tier, because vocabulary is the first barrier into this work and the wrong thing to charge for.

B C D G L P R S T

B

Business associate agreement BAA

The contract HIPAA requires between a covered entity and anyone handling protected health information on its behalf, flowing down to subcontractors.

Signing it brings direct statutory obligations, including incident reporting on a deadline and returning or destroying data at the end, which a security certification does not cover.

Taught in PRV-203 · See also: Processor terms, Protected health information

C

D

Data protection impact assessment DPIA, PIA

An assessment required where processing is likely to result in a high risk to people, covering necessity, proportionality, risks and mitigations.

Its practical purpose is to change the design while changing it is still cheap. Completed after the design is fixed, it can only document.

Taught in PRV-250 · See also: Record of processing activities, Legitimate interests

G

Global Privacy Control GPC

A browser signal indicating that the user opts out of the sale or sharing of their personal information.

In several US states a received signal is a valid opt-out. It arrives as a header, so it has to be handled by code before any tag fires, not by a banner.

Taught in PRV-230 · See also: Sale and sharing, Consent management platform

L

Legitimate interests LIA, balancing test

A lawful basis allowing processing necessary for a genuine interest, provided that interest is not overridden by the rights of the person.

It is a positive claim rather than a residual category, and the balancing test can come out against you. The assessment has to exist on paper.

Taught in PRV-201 · See also: Data protection impact assessment, Processor terms

P

Personal data personal information

Anything that identifies a living person or can be linked back to one, including identifiers, device data and opinions recorded about someone.

It is broader than most people assume. Data separated from names but still linkable remains personal data.

Taught in PRV-201 · See also: Special category data, data-map

Processor terms Article 28, DPA

The mandatory contractual terms between a controller and a processor: documented instructions, confidentiality, security, sub-processors, rights support, deletion and audit.

The clauses are specific enough to check against, and a missing one is a finding a regulator can write in a sentence.

Taught in PRV-203 · See also: Business associate agreement, Transfer mechanism

Protected health information PHI

Individually identifiable health information held or transmitted by a covered entity or a business associate.

It turns up where nobody designed for it: support tickets, application logs, error tracking and test environments loaded from production.

Taught in PRV-203 · See also: Business associate agreement, Personal data

R

Record of processing activities RoPA, Article 30 record

The register of what personal data an organization processes, for what purposes, with whom it is shared, for how long and under what safeguards.

A regulator can ask for it by name and expect it immediately. Built by survey it is wrong on the day it is finished; built from systems it survives.

Taught in PRV-220 · See also: data-map, Data protection impact assessment

Retention schedule

The record of how long each category of data is kept, why, what triggers deletion and where every copy lives.

A schedule nobody executes is a written commitment you are visibly failing to meet. The hard part is the copies, not the primary system.

Taught in PRV-270 · See also: Legal hold, data-map

S

Sale and sharing

Disclosing personal information for money or other value (sale), or so that advertising can follow a person across sites (sharing or targeted advertising).

Most organizations that say they do not sell data are sharing it through advertising tags, which is where unexpected scope comes from.

Taught in PRV-202 · See also: Global Privacy Control, Consent management platform

Special category data sensitive data

Categories carrying extra protection: health, racial or ethnic origin, beliefs, union membership, sexual orientation, biometric and genetic data.

Misuse causes disproportionate harm, so the handling rules are stricter wherever these appear, including inside an ordinary support ticket.

Taught in PRV-201 · See also: Personal data

T

Transfer impact assessment TIA

The assessment of whether the destination's law and practice undermine the protection a transfer mechanism promises.

Written per destination it is maintainable; written per vendor it becomes a template with the name changed.

Taught in PRV-280 · See also: Transfer mechanism

Transfer mechanism SCCs, adequacy

The legal basis for moving personal data outside a jurisdiction: an adequacy decision, standard contractual clauses, binding corporate rules or a derogation.

Remote access counts as a transfer. Most registers list storage locations only and understate the position substantially.

Taught in PRV-280 · See also: Transfer impact assessment, Processor terms

Transparency and Consent Framework TCF

An industry standard for passing a user's consent choices through the advertising supply chain, encoded as a consent string.

It is a transport format, not legal cover. A string saying the user consented does not make the consent valid if the banner that produced it was misleading.

Taught in PRV-230 · See also: Consent management platform

Maintained by the association. A term here is a summary; the course named beside it is where the practice is taught.