Glossary

The terms behind vendor privacy and risk, in plain words. Where a law, a regulator or a standard defines a term, the definition follows that text and links to it.

Adequacy decision
A European Commission decision that a country outside the EU ensures an adequate level of data protection, so personal data can flow there without further safeguards (GDPR Article 45).
Article 28 GDPR
The GDPR article that governs how controllers use processors: sufficient guarantees, a binding contract with set terms, and rules for engaging subprocessors.
Binding corporate rules
Data protection policies approved by a supervisory authority that let a group of companies transfer personal data within the group to countries outside the EU (GDPR Article 47).
CCPA
California's consumer privacy law, as amended by the California Privacy Rights Act (CPRA), which gives California residents rights over their personal information and regulates the businesses that collect it.
Data breach notification
The duty to report a personal data breach to the supervisory authority within 72 hours of becoming aware of it, and to the people affected when the risk to them is high (GDPR Articles 33 and 34).
Data controller
The person or organisation that decides why and how personal data is processed (GDPR Article 4(7)).
Data localization
A legal requirement that certain data be stored, and sometimes processed, inside a particular country.
Data mapping
Documenting what personal data an organisation holds, where it comes from, where it is stored, who it is shared with and where it flows.
Data processing agreement
The contract between a controller and a processor that sets out how the processor may handle personal data, as Article 28(3) of the GDPR requires.
Data processor
A person or organisation that processes personal data on behalf of a controller (GDPR Article 4(8)).
Data protection impact assessment
An assessment a controller must carry out before processing that is likely to result in a high risk to people's rights and freedoms (GDPR Article 35).
Data protection officer
The person an organisation designates to advise on and monitor its compliance with data protection law, and to be the contact point for regulators and data subjects (GDPR Articles 37–39).
Data residency
Where data is physically stored and processed, as chosen by a customer or promised by a vendor, such as EU-only hosting.
Data retention policy
An organisation's rules for how long each kind of data is kept, and how it is deleted when that time is up.
Data sovereignty
The idea that data is subject to the laws of the country where it is collected or stored, and the controls that keep it under them.
DORA
The EU regulation on digital operational resilience for the financial sector, which sets rules for managing ICT third-party risk (Regulation (EU) 2022/2554).
EU AI Act
The EU regulation laying down harmonised rules on artificial intelligence, with obligations that scale with the risk of the AI system (Regulation (EU) 2024/1689).
EU–US Data Privacy Framework
The framework under which the European Commission found that personal data sent to certified US companies is adequately protected (Commission Implementing Decision (EU) 2023/1795).
Fourth-party risk
The risk that comes from your vendors' own vendors: subprocessors and suppliers you have no contract with, whose failures still reach you.
ISO 27001
The international standard for information security management systems; organisations can be certified against it by accredited bodies.
ISO 27701
The international standard for privacy information management systems, for organisations that process personal data as controllers or processors.
Joint controllers
Two or more controllers that jointly decide the purposes and means of a processing, and must set out their respective responsibilities in an arrangement (GDPR Article 26).
Master service agreement
The framework contract that sets the general terms between a customer and a supplier, with later orders or statements of work adding the specifics.
NIS2
The EU directive on a high common level of cybersecurity, which requires essential and important entities to manage cybersecurity risks, including in their supply chain (Directive (EU) 2022/2555).
Personal data
Any information relating to an identified or identifiable natural person (GDPR Article 4(1)).
Privacy notice
The statement in which an organisation tells people what personal data it collects, why, who it shares it with and what rights they have (GDPR Articles 13 and 14).
Record of processing activities
The written record controllers and processors must keep of their processing, including purposes, categories of data, recipients and transfers (GDPR Article 30).
Schrems II
The 16 July 2020 judgment of the Court of Justice of the EU (Case C-311/18) that invalidated the EU–US Privacy Shield and required case-by-case checks when relying on standard contractual clauses.
SOC 2
An independent auditor's report on a service organisation's controls relevant to security, availability, processing integrity, confidentiality or privacy, under the AICPA's Trust Services Criteria.
Standard contractual clauses
Contract terms adopted by the European Commission that allow personal data to be transferred from the EU to a country without an adequacy decision (GDPR Article 46(2)(c)).
Subprocessor
A company that a processor engages to carry out part of its processing of personal data for a controller, such as a vendor's cloud host or email provider.
Subprocessor list
The public list in which a vendor names the subprocessors that handle its customers' personal data, usually with each one's purpose and location.
Terms of service
The contract a vendor sets for using its product, accepted by signing up or by continuing to use it.
Third-party risk management
Managing the risks that come from any outside party an organisation relies on, including vendors, suppliers, partners and service providers.
Transfer impact assessment
An assessment, before personal data is sent outside the EU under a transfer tool such as standard contractual clauses, of whether the destination country's law and practice let the importer honour it.
Vendor due diligence
The checks an organisation runs on a vendor before signing, to confirm it can meet the security, privacy and compliance obligations the relationship needs.
Vendor management
Selecting, contracting, overseeing and offboarding the vendors an organisation relies on.
Vendor risk management
Identifying, assessing and monitoring the risks that suppliers bring to an organisation, from onboarding to offboarding.
Vendor security assessment
A structured review of a vendor's security controls, usually through a questionnaire, evidence such as audit reports, and follow-up questions.