Glossary
The terms behind vendor privacy and risk, in plain words. Where a law, a regulator or a standard defines a term, the definition follows that text and links to it.
A
- Adequacy decision
- A European Commission decision that a country outside the EU ensures an adequate level of data protection, so personal data can flow there without further safeguards (GDPR Article 45).
- Article 28 GDPR
- The GDPR article that governs how controllers use processors: sufficient guarantees, a binding contract with set terms, and rules for engaging subprocessors.
B
- Binding corporate rules
- Data protection policies approved by a supervisory authority that let a group of companies transfer personal data within the group to countries outside the EU (GDPR Article 47).
C
- CCPA
- California's consumer privacy law, as amended by the California Privacy Rights Act (CPRA), which gives California residents rights over their personal information and regulates the businesses that collect it.
D
- Data breach notification
- The duty to report a personal data breach to the supervisory authority within 72 hours of becoming aware of it, and to the people affected when the risk to them is high (GDPR Articles 33 and 34).
- Data controller
- The person or organisation that decides why and how personal data is processed (GDPR Article 4(7)).
- Data localization
- A legal requirement that certain data be stored, and sometimes processed, inside a particular country.
- Data mapping
- Documenting what personal data an organisation holds, where it comes from, where it is stored, who it is shared with and where it flows.
- Data processing agreement
- The contract between a controller and a processor that sets out how the processor may handle personal data, as Article 28(3) of the GDPR requires.
- Data processor
- A person or organisation that processes personal data on behalf of a controller (GDPR Article 4(8)).
- Data protection impact assessment
- An assessment a controller must carry out before processing that is likely to result in a high risk to people's rights and freedoms (GDPR Article 35).
- Data protection officer
- The person an organisation designates to advise on and monitor its compliance with data protection law, and to be the contact point for regulators and data subjects (GDPR Articles 37–39).
- Data residency
- Where data is physically stored and processed, as chosen by a customer or promised by a vendor, such as EU-only hosting.
- Data retention policy
- An organisation's rules for how long each kind of data is kept, and how it is deleted when that time is up.
- Data sovereignty
- The idea that data is subject to the laws of the country where it is collected or stored, and the controls that keep it under them.
- DORA
- The EU regulation on digital operational resilience for the financial sector, which sets rules for managing ICT third-party risk (Regulation (EU) 2022/2554).
E
- EU AI Act
- The EU regulation laying down harmonised rules on artificial intelligence, with obligations that scale with the risk of the AI system (Regulation (EU) 2024/1689).
- EU–US Data Privacy Framework
- The framework under which the European Commission found that personal data sent to certified US companies is adequately protected (Commission Implementing Decision (EU) 2023/1795).
F
- Fourth-party risk
- The risk that comes from your vendors' own vendors: subprocessors and suppliers you have no contract with, whose failures still reach you.
I
- ISO 27001
- The international standard for information security management systems; organisations can be certified against it by accredited bodies.
- ISO 27701
- The international standard for privacy information management systems, for organisations that process personal data as controllers or processors.
J
- Joint controllers
- Two or more controllers that jointly decide the purposes and means of a processing, and must set out their respective responsibilities in an arrangement (GDPR Article 26).
M
- Master service agreement
- The framework contract that sets the general terms between a customer and a supplier, with later orders or statements of work adding the specifics.
N
- NIS2
- The EU directive on a high common level of cybersecurity, which requires essential and important entities to manage cybersecurity risks, including in their supply chain (Directive (EU) 2022/2555).
P
- Personal data
- Any information relating to an identified or identifiable natural person (GDPR Article 4(1)).
- Privacy notice
- The statement in which an organisation tells people what personal data it collects, why, who it shares it with and what rights they have (GDPR Articles 13 and 14).
R
- Record of processing activities
- The written record controllers and processors must keep of their processing, including purposes, categories of data, recipients and transfers (GDPR Article 30).
S
- Schrems II
- The 16 July 2020 judgment of the Court of Justice of the EU (Case C-311/18) that invalidated the EU–US Privacy Shield and required case-by-case checks when relying on standard contractual clauses.
- SOC 2
- An independent auditor's report on a service organisation's controls relevant to security, availability, processing integrity, confidentiality or privacy, under the AICPA's Trust Services Criteria.
- Standard contractual clauses
- Contract terms adopted by the European Commission that allow personal data to be transferred from the EU to a country without an adequacy decision (GDPR Article 46(2)(c)).
- Subprocessor
- A company that a processor engages to carry out part of its processing of personal data for a controller, such as a vendor's cloud host or email provider.
- Subprocessor list
- The public list in which a vendor names the subprocessors that handle its customers' personal data, usually with each one's purpose and location.
T
- Terms of service
- The contract a vendor sets for using its product, accepted by signing up or by continuing to use it.
- Third-party risk management
- Managing the risks that come from any outside party an organisation relies on, including vendors, suppliers, partners and service providers.
- Transfer impact assessment
- An assessment, before personal data is sent outside the EU under a transfer tool such as standard contractual clauses, of whether the destination country's law and practice let the importer honour it.
V
- Vendor due diligence
- The checks an organisation runs on a vendor before signing, to confirm it can meet the security, privacy and compliance obligations the relationship needs.
- Vendor management
- Selecting, contracting, overseeing and offboarding the vendors an organisation relies on.
- Vendor risk management
- Identifying, assessing and monitoring the risks that suppliers bring to an organisation, from onboarding to offboarding.
- Vendor security assessment
- A structured review of a vendor's security controls, usually through a questionnaire, evidence such as audit reports, and follow-up questions.