Amanda Busse LawSet up a call

Reference

Glossary

Plain-English definitions for the AI, data privacy, and compliance terms that show up in contracts, policies, and regulation - each linked to its primary source.

Citations link to primary sources - statutes, regulations, and standards - so readers can consult the controlling text directly. This glossary is provided as general information, not legal advice, and its use does not create an attorney-client relationship with Amanda Busse Law, LLC.

TermMeaningSources
AccountabilityThe expectation that an organization can explain and justify how it collects uses shares and protects personal data and can demonstrate compliance with relevant laws and internal policies
ADMSee "Automated Decision Making"
Anonymization / De-IdentificationA process that removes or alters personal data so that an individual cannot be identified and is generally irreversible. The GDPR refers to this as "pseudonymisation"
Artificial Intelligence ModelA machine-based system, with varying levels of autonomy that may exhibit adaptiveness, trained on input data it receives to identify patterns, make predictions, inferences or generate outputs such as text, images, content, decisions or recommendations.
Automated Decision MakingDecisions made by technology without human involvement often using algorithms or AI models. This may include "profiling" which the GDPR defines as "any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;" Per Article 22 of the GDPR, "data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her." In the U.S., Colorado's SB 26-189 (2026) regulates automated decision-making technology used in consequential decisions, and California's FEHA regulations govern the use of automated-decision systems in employment.
Bias in AISystematic errors in an AI model that lead to unfair or inaccurate outcomes, often caused by imbalanced or unrepresentative training data. Bias can enter at any stage of the AI lifecycle: NIST Special Publication 1270 identifies systemic, statistical/computational, and human-cognitive sources of AI bias, and Suresh & Guttag map how bias is introduced through data collection, model development, and deployment.
Biometric DataPersonal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data;
CA SB 53California SB 53 Transparency in Frontier Artificial Intelligence Act
CCPAThe California Consumer Privacy Act of 2018 gives consumers certain rights over the personal information businesses collect about them and requires businesses to inform consumers about how they collect, use, and retain their personal information. This landmark legislation was the first comprehensive consumer privacy law passed in the United States.
CO SB26-189Colorado Senate Bill 26-189, the Automated Decision-Making Technology Act (signed May 2026; effective January 1, 2027). It repealed and replaced Colorado SB 24-205 (Consumer Protections for Artificial Intelligence), which never took effect, shifting from a duty-of-care and impact-assessment model to disclosure and record-keeping obligations for automated decision-making technology used in consequential decisions.
ControllerAn organization or individual that decides why and how personal data is processed
COPPAThe Children's Online Privacy Protection Act is a U.S. federal law the sets rules for how websites and online service providers collect, use and share personal inofmration from children.
CPRAThe California Privacy Rights Act of 2020. In 2020, California voters approved Proposition 24, which amended the CCPA by adding additional consumer privacy rights and obligations for businesses. It also established this Agency and tasked it with responsibilities including implementing and enforcing the law and educating the public on their rights and obligations under the law. The CPRA amended the CCPA; it did not create a separate, new law. As a result, the Agency typically refers to the law as “CCPA” or “CCPA, as amended.” The CPRA amendments to the CCPA went into effect on January 1, 2023.
Cross-Border Data TransferThe movement of personal data from one country to another (or to an international organization like the UN or WHO) subject to regional rules.
CybersecurityProtection of an IT-system from attacks or damage to its hardware, software or information, as well as from disruption or misdirection of the services.
Cybersecurity RiskAn effect of uncertainty on or within information and technology. Cybersecurity risks relate to the loss of confidentiality, integrity, or availability of information, data, or information (or control) systems and reflect the potential adverse impacts to organizational operations (i.e., mission, functions, image, or reputation) and assets, individuals, other organizations, and the Nation.
Data ActionA system/product/service data life cycle operation, including, but not limited to collection, retention, logging, generation, transformation, use, disclosure, sharing, transmission, and disposal.
Data Inventory and MappingA record of the systems tools and processes where personal data is collected stored or shared.
Data MinimizationCollecting and using only the data that is necessary for a specific purpose.
Data ProcessingAny action performed on personal data throughout the complete data lifecycle (including, but not limited to collecting, storing, retention, analyzing, logging, generation, transformation, use, disclosure, sharing, transmission, dispoal or deleting it).
Data Protection Impact AssessmentSee "Privacy Impact Assessment"
Data RetentionThe length of time an organization keeps personal data before deleting or anonymizing it.
Data SubjectA person whose personal data is being collected or processed.
DDQA due diligence questionnaire is part of a vendor assessment. It is a document issued by a legal, compliance or procurement team to assess a company’s overall risk profile. A DDQ can span financials, governance, legal obligations, and data protection. It’s designed to help determine whether a vendor aligns with internal policies and regulatory expectations.
DecryptionThe process of changing ciphertext into plaintext using a cryptographic algorithm and key.
Deletion Request or "Right to Erasure"A request from an individual asking an organization to delete their personal data
EncryptionA security method that protects data by converting it into unreadable code unless a person has the correct key.
Foundation ModelAn artificial intelligence model that is all of the following: (1) Trained on a broad data set. (2) Designed for generality of output. (3) Adaptable to a wide range of distinctive tasks.
Frontier ModelA foundation model trained using more than 10^26 individual calculations, indicating an extremely large amount of computing power and complexity.
Gramm-Leach Bliley ActThe Gramm‑Leach‑Bliley Act is a U.S. federal law that requires financial institutions to explain how they share and protect consumers’ personal information and to safeguard that data.
HIPAAThe Health Insurance Portability and Accountability Act is a U.S. law that sets national rules for protecting the privacy and security of individuals’ health information and limits how that information can be used or shared.
IECInternational Electrotechnical Commission. An organization that prepares and publishes International Standards for all electrical, electronic and related technologies – collectively known as “electrotechnology”.
Inference DataNew information generated about a person based on existing data such as predictions or classifications
ISOInternational Organization for Standardization is a non-governmental, international organization that develops and publishes international standards across nearly all areas of technology and manufacturing with members drawn from national standards organizations around the world.
ISO 27000 SeriesISO 27000 Series is a family of international standards that provides a structured framework and best practices for establishing, operating, and continually improving an information security and management system. ISO 27001, initially introduced in October 2005 is designed to certify an organization’s information security policies. ISO 27701, introducted in August 2019, focuses on data privacy.
ISO 31700-1:2023ISO 31700‑1:2023 sets out high‑level requirements for building privacy by design into consumer goods and services throughout their entire lifecycle. ISO 31700‑1:2023 is Part 1 of a series.
LLMLarge language model
Machine LearningA method of building AI models that learn patterns from data rather than being explicitly programmed
ManageabilityProviding the capability for granular administration of data, including alteration, deletion, and selective disclosure.
MetadataInformation describing the characteristics of data. This may include, for example, structural metadata describing data structures (i.e., data format, syntax, semantics) and descriptive metadata describing data contents.
Model WeightA numerical parameter in a frontier model that is adjusted through training and that helps determine how inputs are transformed into outputs.
NISTThe National Institute of Standards and Technology is a U.S. federal agency that develops standards, measurements and research across science and technology.
NIST CSF 2.0The NIST CSF (Cybersecurity Framework), introduced in February 2014 and updated to 2.0 in February 2024, is a set of guidelines, best practices, and standards designed to help organizations manage and reduce cybersecurity risks. The NIST Privacy Framework, first introduced in January 2020, is a complementary framework focused on managing privacy risks.
NIST Privacy FrameworkThe NIST Privacy Framework, introduced in January 2020, is complementary to the CSF framework and is focused on managing privacy risks.
Personal Data (also called Personal Information and PII - Personally Identifiable Information)Any information that identifies or can be linked to an individual
PIMSPrivacy Information Management System is a framework that addresses the protection of privacy as potentially affected by the processing of personally identifiable information
PredictabilityEnabling reliable assumptions by individuals, owners, and operators about data and their processing by a system, product, or service.
Privacy BreachA situation where personal data is processed in violation of one or more relevant privacy safeguarding laws or requirements.
Privacy by DesignA proactive data privacy framework that incorporates privacy considerations from the outset into every stage of the planning and development of products, services and processes. First developed by Dr. Ann Cavoukian, it has since been adopted by the ISO, GDPR and other data privacy laws and organizations. It includes 7 principles: (1) Preventative not Remedial; (2) Privacy as the Default; (3) Privacy Embedded into Design; (4) Full Functionality; (5) End-to-End Lifecycle Protection; (6) Open Transparency; (7) User-Centric Privacy
Privacy Impact Assessment or PIA / DPIA (also called a Privacy Risk Assessment)A structured review used to identify and reduce privacy risks before launching a new tool feature or process. The review analyzes how information is handled to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; to determine the risks and effects of creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, and disposing of information in identifiable form in an electronic information system; and to examine and evaluate protections and alternate processes for handling information to mitigate potential privacy concerns. A privacy impact assessment is both an analysis and a formal document detailing the process and the outcome of the analysis.
ProcessorAn organization or individual that processes personal data on behalf of a controller
Purpose LimitationUsing personal data only for the specific reason it was collected
Security QuestionnaireA security questionnaire is part of a vendor assessment, but focuses specifically on an organization’s technical and procedural security measures. Usually sent by IT or security departments, these questionnaires dig into topics like encryption protocols, infrastructure security, access controls, and incident response processes.
Sensitive Personal Data / InformationCategories of data that require extra protection such as health information biometric data or information about protected characteristics
Synthetic MediaSynthetic media, also referred to as generative media, is visual, auditory, or multimodal content that has been artificially generated or modified (commonly through artificial intelligence). Such outputs are often highly realistic, would not be identifiable as synthetic to the average person, and may simulate artifacts, persons, or events.
TPM (Third Party Management) or TPRM (Third Party Risk Management)See Vendor Assessment definition.
TRAIGATexas H.B. 149 Responsible Artificial Intelligence Governance Act
Training DataThe data used to teach an AI model how to perform a task
TransparencyProviding clear accessible information about how personal data is collected used shared and protected
VendorA commercial supplier of software or hardware.
Vendor AssessmentA review of third-party tools or service providers to ensure they meet privacy and security expectations during vendor selection, onboarding, and ongoing monitoring.

Definitions are summaries for general reference, not legal advice; the linked statutes, standards, and guidance control. Terms and citations current as of the date reviewed and may not reflect subsequent developments.