Legal Reference

Privacy & Legal Glossary

Plain-language definitions of GDPR, CCPA, and data privacy terms — written for founders, developers, and product teams who need compliance without a law degree.

California Consumer Privacy Act (CCPA)Cal. Civ. Code §1798.100

California's data privacy law granting consumers rights over their personal information collected by businesses.

Cookie ConsentGDPR, ePrivacy Directive

The requirement to obtain informed, freely given, and specific user consent before placing non-essential cookies on their device.

Data Breach NotificationGDPR Art. 33-34

The legal obligation to notify authorities and affected individuals when personal data is compromised.

Data ControllerGDPR Art. 4(7)

The entity that determines the purposes and means of processing personal data.

Data Processing Agreement (DPA)GDPR Art. 28

A legally binding contract between a data controller and a data processor that governs how personal data is handled.

Data ProcessorGDPR Art. 4(8)

An entity that processes personal data on behalf of a data controller.

End User License Agreement (EULA)

A license contract between a software publisher and the end user specifying the permitted uses of the software.

General Data Protection Regulation (GDPR)EU 2016/679

The EU's comprehensive data protection law that governs how personal data of EU residents must be collected, stored, and processed.

Legitimate InterestGDPR Art. 6(1)(f)

A legal basis for processing personal data under GDPR where the controller's interest outweighs the individual's privacy rights.

Personal DataGDPR Art. 4(1)

Any information that relates to an identified or identifiable natural person.

Personal Information Protection and Electronic Documents Act (PIPEDA)S.C. 2000, c. 5

Canada's federal privacy law governing how private sector organizations collect, use, and disclose personal information.

Privacy Policy

A legal document disclosing how an organization collects, uses, stores, and shares personal data.

Right to Be Forgotten (Right to Erasure)GDPR Art. 17

The right of individuals to request deletion of their personal data when it is no longer necessary for its original purpose.

SubprocessorGDPR Art. 28(4)

A third party engaged by a data processor to carry out specific processing activities on behalf of the data controller.

Terms of Service (ToS)

A legal agreement between a service provider and users that governs the rules for using the service.

Ready to comply?

Generate your policy in 60 seconds

Stop reading about compliance — start achieving it. Our AI drafts GDPR, CCPA, and PIPEDA-compliant policies tailored to your business.

Draft Free Policy