Data Privacy Glossary
The terms that show up constantly in privacy policies and privacy law, defined in plain English, with a note on why each one actually matters for the statement you're writing.
Last updated: August 2026
Personal data (PII)
What it means: Any information that can identify a specific person, directly or indirectly. Names, email addresses, phone numbers, and IP addresses all count. So does anything that could be combined with other data to identify someone.
Why it matters here: This is the trigger for almost everything else in this glossary. If your site or app collects personal data, the rest of these terms start applying to you.
Data controller
What it means: The person or business that decides why and how personal data gets processed. If you run the website and decide what data to collect and what to do with it, you're the controller.
Why it matters here: Almost every small business using this generator is a data controller, not a processor. Controllers carry the primary legal responsibility for the data they collect, which is exactly what a privacy statement discloses.
Data processor
What it means: A person or company that processes personal data on a controller's behalf, following the controller's instructions, without deciding why the data is collected in the first place. Your email marketing platform or analytics provider is typically a processor.
Why it matters here: This is why your privacy statement names third-party services specifically. Each one is likely a processor acting on your behalf, and disclosing them is part of being transparent about who actually touches your visitors' data.
Data subject
What it means: The individual the personal data is about. In plain terms: your visitor, customer, or survey respondent.
Why it matters here: GDPR and similar laws are built around data subject rights, access, correction, deletion. That's the "rights" section in every privacy statement.
Consent
What it means: Permission given by a data subject to collect or use their personal data for a specific purpose. Under GDPR, consent has to be freely given, specific, informed, and unambiguous, a pre-checked box generally doesn't count.
Why it matters here: Consent is one of several valid legal bases for collecting data, not the only one (fulfilling a contract, like processing a payment, is another). Your privacy statement should be honest about which basis actually applies to each type of data you collect.
Third party
What it means: Anyone who isn't you, your visitor, or someone working under your direct authority. Your analytics provider, ad network, and payment processor are all third parties.
Why it matters here: Naming your actual third parties, not just saying "third-party service providers," is what separates a specific, trustworthy privacy statement from generic boilerplate.
Data breach
What it means: Personal data that's accessed, disclosed, altered, or destroyed without authorization. Under GDPR, businesses generally have to report a breach to their data protection authority within 72 hours if it poses a risk to the people affected.
Why it matters here: Most small business privacy statements don't need a detailed breach-response plan, but it's worth knowing this term exists before a real incident forces you to learn it under pressure.
Data subject access request (DSAR)
What it means: A formal request from a data subject asking to see, correct, or delete the personal data a business holds about them. Sometimes shortened to "subject access request" or SAR.
Why it matters here: This is what's actually happening when your rights section says visitors can "access, correct, or delete their data." A DSAR is the mechanism; your contact method is how it reaches you.
Data protection officer (DPO)
What it means: A person, required for some organizations under GDPR, responsible for overseeing data protection compliance. Typically required for public authorities and businesses doing large-scale monitoring or handling sensitive data at scale.
Why it matters here: Most small businesses using this generator don't need a DPO. It's included here because the term shows up often enough in GDPR content that it's worth knowing you probably don't need to worry about it.
Opt-in vs. opt-out
What it means: Opt-in means data isn't collected or used until someone actively agrees. Opt-out means it's collected or used by default, unless someone actively declines. GDPR generally works on an opt-in basis; CCPA/CPRA generally works on an opt-out basis for data sales and sharing.
Why it matters here: This distinction is the core difference between GDPR and CCPA covered in our GDPR and CCPA basics guide, and it affects how your privacy statement should be worded for each audience.
"Do not sell or share my personal information"
What it means: A specific right under CCPA/CPRA letting California residents tell a business to stop selling or sharing their personal information with third parties. Many sites implement this as a visible link in the footer.
Why it matters here: If you don't sell or share personal information (many small sites don't), your privacy statement can say so plainly, which is simpler than implementing an opt-out mechanism you don't actually need.
Aggregate data
What it means: Data combined across a group of people that can't be used to identify any single individual. "1,200 visitors read this page last month" is aggregate data; it doesn't say anything about any one visitor.
Why it matters here: Aggregate data generally falls outside personal data protections, since no individual can be identified from it. It's a useful distinction when explaining what your analytics actually show you.
Consumer
What it means: In privacy law, usually a natural person acting in a personal capacity, not on behalf of a business. CCPA specifically defines "consumer" as a California resident, which is narrower than how the word gets used day to day.
Why it matters here: Rights sections in privacy statements are often written in terms of "consumer rights." Knowing the term has a specific legal meaning, not just its everyday one, helps when you're reading the actual text of a law rather than a summary of it.
Disclosure
What it means: Sharing information with someone, whether that's telling a visitor what data you collect (a privacy disclosure) or telling a business partner something about a customer (a data disclosure). The word does double duty: it's both the act of sharing and the document that discloses.
Why it matters here: Most of what a privacy statement does is disclosure in this sense, it's the document that discloses your practices. When a law requires "disclosure" of something, it means telling people plainly, not technically mentioning it somewhere.
Dispute
What it means: A disagreement between two parties, here usually a business and a customer or user, about how data was handled or a request was resolved.
Why it matters here: A clear privacy statement and a working contact method are what most disputes need to get resolved before they become anything bigger. Vague disclosures and dead-end contact info are what usually turn a question into a dispute.
Warranty
What it means: A promise or guarantee about something, most often that a product or service will work as described. A "warranty disclaimer," which shows up in EULAs and terms of service, is a statement that no such promise is being made beyond what's legally required.
Why it matters here: If you've read the EULA generator's output, the warranty disclaimer section is what this term refers to, standard language limiting what you're promising about your own software.
Frequently asked questions
Do I need to understand all of these terms to write a privacy policy?
No. Most small businesses only need a working sense of "data controller," "third party," and "consent" to understand their own privacy statement. The rest are here for when you run into them elsewhere.
Are these definitions the same under every privacy law?
Mostly consistent in spirit, but the exact legal wording differs by law and jurisdiction. These are plain-English explanations meant to build general understanding, not precise legal definitions for any one statute.
Where can I see these terms used in an actual privacy statement?
Try the privacy statement generator, or see privacy policy examples explained for a clause-by-clause breakdown.
Sources
- General Data Protection Regulation (Regulation (EU) 2016/679), Articles 4 and 33
- California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)
These are foundational definitional concepts, not thresholds or figures, and have stayed stable across the laws' amendments to date.