Reference
Glossary
Plain-English definitions for the AI, data privacy, and compliance terms that show up in contracts, policies, and regulation - each linked to its primary source.
Citations link to primary sources - statutes, regulations, and standards - so readers can consult the controlling text directly. This glossary is provided as general information, not legal advice, and its use does not create an attorney-client relationship with Amanda Busse Law, LLC.
| Term | Meaning | Sources |
|---|---|---|
| Accountability | The expectation that an organization can explain and justify how it collects uses shares and protects personal data and can demonstrate compliance with relevant laws and internal policies | |
| ADM | See "Automated Decision Making" | |
| Anonymization / De-Identification | A process that removes or alters personal data so that an individual cannot be identified and is generally irreversible. The GDPR refers to this as "pseudonymisation" | |
| Artificial Intelligence Model | A machine-based system, with varying levels of autonomy that may exhibit adaptiveness, trained on input data it receives to identify patterns, make predictions, inferences or generate outputs such as text, images, content, decisions or recommendations. | |
| Automated Decision Making | Decisions made by technology without human involvement often using algorithms or AI models. This may include "profiling" which the GDPR defines as "any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;" Per Article 22 of the GDPR, "data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her." In the U.S., Colorado's SB 26-189 (2026) regulates automated decision-making technology used in consequential decisions, and California's FEHA regulations govern the use of automated-decision systems in employment. | |
| Bias in AI | Systematic errors in an AI model that lead to unfair or inaccurate outcomes, often caused by imbalanced or unrepresentative training data. Bias can enter at any stage of the AI lifecycle: NIST Special Publication 1270 identifies systemic, statistical/computational, and human-cognitive sources of AI bias, and Suresh & Guttag map how bias is introduced through data collection, model development, and deployment. | |
| Biometric Data | Personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data; | |
| CA SB 53 | California SB 53 Transparency in Frontier Artificial Intelligence Act | |
| CCPA | The California Consumer Privacy Act of 2018 gives consumers certain rights over the personal information businesses collect about them and requires businesses to inform consumers about how they collect, use, and retain their personal information. This landmark legislation was the first comprehensive consumer privacy law passed in the United States. | |
| CO SB26-189 | Colorado Senate Bill 26-189, the Automated Decision-Making Technology Act (signed May 2026; effective January 1, 2027). It repealed and replaced Colorado SB 24-205 (Consumer Protections for Artificial Intelligence), which never took effect, shifting from a duty-of-care and impact-assessment model to disclosure and record-keeping obligations for automated decision-making technology used in consequential decisions. | |
| Consent | A person’s clear and informed agreement to the collection or use of their data | |
| Controller | An organization or individual that decides why and how personal data is processed | |
| COPPA | The Children's Online Privacy Protection Act is a U.S. federal law the sets rules for how websites and online service providers collect, use and share personal inofmration from children. | |
| CPRA | The California Privacy Rights Act of 2020. In 2020, California voters approved Proposition 24, which amended the CCPA by adding additional consumer privacy rights and obligations for businesses. It also established this Agency and tasked it with responsibilities including implementing and enforcing the law and educating the public on their rights and obligations under the law. The CPRA amended the CCPA; it did not create a separate, new law. As a result, the Agency typically refers to the law as “CCPA” or “CCPA, as amended.” The CPRA amendments to the CCPA went into effect on January 1, 2023. | |
| Cross-Border Data Transfer | The movement of personal data from one country to another (or to an international organization like the UN or WHO) subject to regional rules. | |
| Cybersecurity | Protection of an IT-system from attacks or damage to its hardware, software or information, as well as from disruption or misdirection of the services. | |
| Cybersecurity Risk | An effect of uncertainty on or within information and technology. Cybersecurity risks relate to the loss of confidentiality, integrity, or availability of information, data, or information (or control) systems and reflect the potential adverse impacts to organizational operations (i.e., mission, functions, image, or reputation) and assets, individuals, other organizations, and the Nation. | |
| Data Action | A system/product/service data life cycle operation, including, but not limited to collection, retention, logging, generation, transformation, use, disclosure, sharing, transmission, and disposal. | |
| Data Inventory and Mapping | A record of the systems tools and processes where personal data is collected stored or shared. | |
| Data Minimization | Collecting and using only the data that is necessary for a specific purpose. | |
| Data Processing | Any action performed on personal data throughout the complete data lifecycle (including, but not limited to collecting, storing, retention, analyzing, logging, generation, transformation, use, disclosure, sharing, transmission, dispoal or deleting it). | |
| Data Protection Impact Assessment | See "Privacy Impact Assessment" | |
| Data Retention | The length of time an organization keeps personal data before deleting or anonymizing it. | |
| Data Subject | A person whose personal data is being collected or processed. | |
| DDQ | A due diligence questionnaire is part of a vendor assessment. It is a document issued by a legal, compliance or procurement team to assess a company’s overall risk profile. A DDQ can span financials, governance, legal obligations, and data protection. It’s designed to help determine whether a vendor aligns with internal policies and regulatory expectations. | |
| Decryption | The process of changing ciphertext into plaintext using a cryptographic algorithm and key. | |
| Deletion Request or "Right to Erasure" | A request from an individual asking an organization to delete their personal data | |
| Encryption | A security method that protects data by converting it into unreadable code unless a person has the correct key. | |
| Foundation Model | An artificial intelligence model that is all of the following: (1) Trained on a broad data set. (2) Designed for generality of output. (3) Adaptable to a wide range of distinctive tasks. | |
| Frontier Model | A foundation model trained using more than 10^26 individual calculations, indicating an extremely large amount of computing power and complexity. | |
| Gramm-Leach Bliley Act | The Gramm‑Leach‑Bliley Act is a U.S. federal law that requires financial institutions to explain how they share and protect consumers’ personal information and to safeguard that data. | |
| HIPAA | The Health Insurance Portability and Accountability Act is a U.S. law that sets national rules for protecting the privacy and security of individuals’ health information and limits how that information can be used or shared. | |
| IEC | International Electrotechnical Commission. An organization that prepares and publishes International Standards for all electrical, electronic and related technologies – collectively known as “electrotechnology”. | |
| Inference Data | New information generated about a person based on existing data such as predictions or classifications | |
| ISO | International Organization for Standardization is a non-governmental, international organization that develops and publishes international standards across nearly all areas of technology and manufacturing with members drawn from national standards organizations around the world. | |
| ISO 27000 Series | ISO 27000 Series is a family of international standards that provides a structured framework and best practices for establishing, operating, and continually improving an information security and management system. ISO 27001, initially introduced in October 2005 is designed to certify an organization’s information security policies. ISO 27701, introducted in August 2019, focuses on data privacy. | |
| ISO 31700-1:2023 | ISO 31700‑1:2023 sets out high‑level requirements for building privacy by design into consumer goods and services throughout their entire lifecycle. ISO 31700‑1:2023 is Part 1 of a series. | |
| LLM | Large language model | |
| Machine Learning | A method of building AI models that learn patterns from data rather than being explicitly programmed | |
| Manageability | Providing the capability for granular administration of data, including alteration, deletion, and selective disclosure. | |
| Metadata | Information describing the characteristics of data. This may include, for example, structural metadata describing data structures (i.e., data format, syntax, semantics) and descriptive metadata describing data contents. | |
| Model Weight | A numerical parameter in a frontier model that is adjusted through training and that helps determine how inputs are transformed into outputs. | |
| NIST | The National Institute of Standards and Technology is a U.S. federal agency that develops standards, measurements and research across science and technology. | |
| NIST CSF 2.0 | The NIST CSF (Cybersecurity Framework), introduced in February 2014 and updated to 2.0 in February 2024, is a set of guidelines, best practices, and standards designed to help organizations manage and reduce cybersecurity risks. The NIST Privacy Framework, first introduced in January 2020, is a complementary framework focused on managing privacy risks. | |
| NIST Privacy Framework | The NIST Privacy Framework, introduced in January 2020, is complementary to the CSF framework and is focused on managing privacy risks. | |
| Personal Data (also called Personal Information and PII - Personally Identifiable Information) | Any information that identifies or can be linked to an individual | |
| PIMS | Privacy Information Management System is a framework that addresses the protection of privacy as potentially affected by the processing of personally identifiable information | |
| Predictability | Enabling reliable assumptions by individuals, owners, and operators about data and their processing by a system, product, or service. | |
| Privacy Breach | A situation where personal data is processed in violation of one or more relevant privacy safeguarding laws or requirements. | |
| Privacy by Design | A proactive data privacy framework that incorporates privacy considerations from the outset into every stage of the planning and development of products, services and processes. First developed by Dr. Ann Cavoukian, it has since been adopted by the ISO, GDPR and other data privacy laws and organizations. It includes 7 principles: (1) Preventative not Remedial; (2) Privacy as the Default; (3) Privacy Embedded into Design; (4) Full Functionality; (5) End-to-End Lifecycle Protection; (6) Open Transparency; (7) User-Centric Privacy | |
| Privacy Impact Assessment or PIA / DPIA (also called a Privacy Risk Assessment) | A structured review used to identify and reduce privacy risks before launching a new tool feature or process. The review analyzes how information is handled to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; to determine the risks and effects of creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, and disposing of information in identifiable form in an electronic information system; and to examine and evaluate protections and alternate processes for handling information to mitigate potential privacy concerns. A privacy impact assessment is both an analysis and a formal document detailing the process and the outcome of the analysis. | |
| Processor | An organization or individual that processes personal data on behalf of a controller | |
| Purpose Limitation | Using personal data only for the specific reason it was collected | |
| Security Questionnaire | A security questionnaire is part of a vendor assessment, but focuses specifically on an organization’s technical and procedural security measures. Usually sent by IT or security departments, these questionnaires dig into topics like encryption protocols, infrastructure security, access controls, and incident response processes. | |
| Sensitive Personal Data / Information | Categories of data that require extra protection such as health information biometric data or information about protected characteristics | |
| Synthetic Media | Synthetic media, also referred to as generative media, is visual, auditory, or multimodal content that has been artificially generated or modified (commonly through artificial intelligence). Such outputs are often highly realistic, would not be identifiable as synthetic to the average person, and may simulate artifacts, persons, or events. | |
| TPM (Third Party Management) or TPRM (Third Party Risk Management) | See Vendor Assessment definition. | |
| TRAIGA | Texas H.B. 149 Responsible Artificial Intelligence Governance Act | |
| Training Data | The data used to teach an AI model how to perform a task | |
| Transparency | Providing clear accessible information about how personal data is collected used shared and protected | |
| Vendor | A commercial supplier of software or hardware. | |
| Vendor Assessment | A review of third-party tools or service providers to ensure they meet privacy and security expectations during vendor selection, onboarding, and ongoing monitoring. |
Definitions are summaries for general reference, not legal advice; the linked statutes, standards, and guidance control. Terms and citations current as of the date reviewed and may not reflect subsequent developments.
