Key takeaways

  • Controller and processor is the distinction that decides almost everything else, from which contract you need to who answers a regulator.
  • A data sharing agreement and a data processing agreement are not interchangeable, and picking the wrong one is the most common error we see in vendor paperwork.
  • Most of these terms carry a deadline or a formal step behind them, such as the 72-hour breach notification or the one-month response window on a data subject request.
  • Engage Compliance uses these terms the way regulators do, and every entry links to the page that explains what to do about it. Start at Pricing if you want to know what cover costs.

Key terms

Data Protection Officer (DPO)

A person responsible for overseeing an organization’s data protection compliance. Required under GDPR in certain circumstances. Can be internal or outsourced.

GDPR (General Data Protection Regulation)

The EU’s comprehensive data protection law, in effect since May 2018. Applies to organizations with an EU establishment processing personal data, or to organizations outside the EU that offer goods/services to or monitor the behavior of individuals in the EU.

UK GDPR

The UK’s version of GDPR, retained after Brexit. Nearly identical to EU GDPR but enforced by the ICO. Amended by the Data (Use and Access) Act 2025, in force from 5 February 2026, which retains the DPO role.

CCPA/CPRA (California Consumer Privacy Act / California Privacy Rights Act)

California’s consumer privacy law. CPRA amended and expanded the original CCPA.

DPIA (Data Protection Impact Assessment)

A formal assessment of the privacy risks of a processing activity. Required under GDPR where processing is likely to result in high risk, such as large-scale profiling, health data processing, or systematic monitoring.

RoPA (Records of Processing Activities)

A documented record of all personal data processing activities. Required under GDPR Article 30, subject to limited exceptions.

DSAR (Data Subject Access Request)

A request from an individual to access their personal data. Organizations must respond within one month under GDPR.

DPA (Data Processing Agreement)

A contract between a data controller and a data processor setting out the terms of data processing. Required under GDPR Article 28, and not GDPR-only: US state laws (CCPA and others) require processor or service-provider contracts, and HIPAA requires Business Associate Agreements.

SCCs (Standard Contractual Clauses)

EU-approved contract clauses for transferring personal data outside the EU to countries without an adequacy decision.

Supervisory Authority

The national data protection regulator (e.g., CNIL in France, ICO in UK, AP in Netherlands). Where a DPO is appointed, their contact details must be communicated to the relevant supervisory authority.

Data Controller

The entity that determines the purposes and means of processing personal data.

Data Processor

The entity that processes personal data on behalf of a controller.

The lawful ground for processing personal data under GDPR. Six options: consent, contract, legitimate interest, legal obligation, vital interests, or public task.

One of six legal bases under GDPR. Must be freely given, specific, informed, and unambiguous. Required in some contexts (e.g., certain marketing, non-essential cookies).

Legitimate Interest

A legal basis under GDPR allowing processing where the organization has a legitimate reason and it doesn’t override the individual’s rights. Requires a balancing test.

Privacy by Design

Building data protection into products and systems from the start, rather than adding it later. Required under GDPR Article 25.

Data Breach

A security incident leading to unauthorized access, alteration, disclosure, or destruction of personal data. Must be reported to the supervisory authority within 72 hours under GDPR if it poses a risk to individuals.

EU Representative

A designated representative in the EU for organizations based outside the EU that process EU personal data. Required under GDPR Article 27 in most cases, subject to limited exceptions. This is a separate function from a DPO. For how the two roles differ, see EU Representative vs DPO.

Article 27 representative

The EU or UK representative a company outside those territories must appoint under Article 27 of the GDPR or UK GDPR when it offers goods or services to, or monitors, people there. A local point of contact for supervisory authorities and individuals, named in the privacy notice, distinct from a DPO. The EU and UK are separate appointments: an EU representative does not cover the UK.

UK Representative

A representative established in the UK under Article 27 of the UK GDPR, required for most companies outside the UK that offer goods or services to, or monitor, people in the UK. Appointing an EU representative does not satisfy the UK obligation, and the reverse is also true.

Authorised representative

A person established in the EU that a non-EU manufacturer or provider appoints by written mandate to act on its behalf for a specific regulation. The term runs across several regimes, including the authorised representative for CE-marked goods under Regulation (EU) 2019/1020 and Decision 768/2008 and the EU AI Act authorised representative. Each is scoped to its own regulation and does not carry across to the others.

Responsible person (GPSR)

The economic operator established in the EU that must be responsible for a consumer product before it is placed on the EU market, under Article 16 of the General Product Safety Regulation, operating through Article 4 of Regulation (EU) 2019/1020. Verifies the declaration of conformity and technical documentation, gives information to authorities on request, and cooperates on corrective action.

GPSR (General Product Safety Regulation)

Regulation (EU) 2023/988 on general product safety, applicable since 13 December 2024. A consumer product with no EU-established manufacturer, importer or authorised representative needs an EU responsible person before it can be sold in the EU.

The legal representative a provider of intermediary services with no EU establishment must designate under Article 13 of the Digital Services Act (Regulation (EU) 2022/2065). A named point in a member state where the provider offers services, which can be held liable for the provider’s DSA compliance. Separate from the Article 11 point of contact, which every provider needs.

AI Act authorised representative

The representative a provider established outside the EU must appoint before placing an AI system or general-purpose AI model on the EU market. Two forms: the GPAI authorised representative under Article 54, in force now, and the high-risk authorised representative under Article 22, applying from 2 December 2027.

GPAI (General-Purpose AI model)

A general-purpose AI model under the EU AI Act. A provider outside the EU that places one on the EU market appoints a GPAI authorised representative under Article 54 before doing so, and that obligation is live now.

High-risk AI system

An AI system the EU AI Act treats as high risk, whether a stand-alone Annex III system or AI embedded in an Annex I regulated product. A non-EU provider needs a high-risk authorised representative under Article 22, applying from 2 December 2027 for stand-alone systems and 2 August 2028 for embedded ones under Regulation (EU) 2026/1744. See the high-risk classification guide.

NIS2 representative

The representative a non-EU entity in scope of NIS2 must designate in the EU under Article 26(3) of Directive (EU) 2022/2555, where it provides services in the Union without being established there.

Data Act representative

The legal representative a non-EU provider of connected products or related services must designate under Article 37(11) of the Data Act (Regulation (EU) 2023/2854).

Data intermediation service

A service under the Data Governance Act that connects data holders with data users. A provider outside the EU that offers one needs an EU representative under Article 11(3).

Data altruism organisation

An entity registered under the Data Governance Act to collect data made available voluntarily for public-interest purposes. A recognised entity not established in the EU needs an EU representative under Article 19(3).

e-Evidence designated establishment

The establishment or legal representative a service provider must designate in the EU to receive and act on production and preservation orders under Article 3 of Directive (EU) 2023/1544.

TCO hosting service provider

A hosting service provider under the Terrorist Content Online Regulation (EU) 2021/784. One with no EU establishment must designate a legal representative in the EU under Article 17 to receive removal orders.

FADP representative

The Swiss representative a controller outside Switzerland must appoint under Article 14 of the Swiss Federal Act on Data Protection, where its processing is large scale, regular, and high risk and relates to offering goods or services in Switzerland or monitoring behavior there. The representative must sit in Switzerland, so the appointment is held from a Swiss establishment rather than from the Amsterdam entity, and it is bought online in the same checkout as every other mandate.

PIPL Article 53 representative

The representative or dedicated body a controller outside China must establish inside China under Article 53 of the Personal Information Protection Law, where it processes the personal information of people in China. It requires in-country establishment, so Engage delivers it through a local partner.

KVKK VERBIS representative

The representative a data controller outside Turkey appoints for the Turkish data protection authority, alongside registration in VERBIS, the controllers’ registry under the KVKK (Law No. 6698). It requires a Turkey-established representative, delivered through a local partner.

One-stop shop

The GDPR mechanism that lets a company with cross-border processing deal with a single lead supervisory authority instead of every authority separately. It is available only to companies with an EU establishment, which is one reason a non-EU company’s Article 27 representative sits in a single member state and does not create one.

Lead supervisory authority

The single EU data protection authority that takes the lead on a company’s cross-border processing under the one-stop-shop mechanism, usually the authority where the company’s main establishment sits.

Article 30 record

The record of processing activities required under GDPR Article 30. See RoPA. An Article 27 representative keeps a copy of the controller’s or processor’s record available to the supervisory authority.

PRRC (Person Responsible for Regulatory Compliance)

The qualified person a medical device manufacturer or its authorised representative must have available under Article 15 of the Medical Device Regulation (EU) 2017/745. A specialized role with defined qualifications, separate from the product-safety responsible person. Engage does not offer medical device representation and refers it to a partner.

Technical documentation

The file a manufacturer compiles to show a product meets the applicable EU requirements. For CE-marked goods the EU authorised representative keeps it available to authorities, and it must be retained for ten years after the product is placed on the market.

Declaration of conformity

The manufacturer’s signed statement that a product meets the applicable EU legislation, a precondition for CE marking. The EU authorised representative for CE-marked goods verifies it exists and keeps it available.

CE marking

The conformity marking a manufacturer applies to show a product meets the EU rules for it. A manufacturer outside the EU often needs an EU authorised representative to hold the mandate and the technical documentation.

ePrivacy Directive

EU directive covering electronic communications, including cookie consent requirements. Often called the “cookie law.”

NIS2 (Network and Information Security Directive 2)

EU directive on cybersecurity for essential and important entities. Broader scope than the original NIS Directive.

DORA (Digital Operational Resilience Act)

EU regulation on digital operational resilience for the financial sector. Entered into application 17 January 2025.

EU AI Act

EU regulation on artificial intelligence, establishing a risk-based framework for AI systems. Entered into force August 2024; the 2026 Digital Omnibus (adopted June 2026) moved the high-risk obligations to 2 December 2027 (stand-alone) and 2 August 2028 (embedded in regulated products).

HIPAA (Health Insurance Portability and Accountability Act)

US law governing the privacy and security of health information.

GLBA (Gramm-Leach-Bliley Act)

US law requiring financial institutions to explain how they share and protect customer data.

LGPD (Lei Geral de Protecao de Dados)

Brazil’s general data protection law, modeled on GDPR.

PIPEDA (Personal Information Protection and Electronic Documents Act)

Canada’s federal privacy law for private sector organizations. Note: federal reform proposals (including the proposed CPPA under Bill C-27) did not complete the legislative process; PIPEDA remains the current federal law.

PDPA (Personal Data Protection Act)

Thailand’s data protection law.

PIPL (Personal Information Protection Law)

China’s comprehensive data protection law.

DPDPA (Digital Personal Data Protection Act)

India’s data protection law, enacted in 2023.

SOC 2

A security certification framework focused on controls for service organizations. Not a privacy law but often required alongside privacy compliance.

ISO 27001

International standard for information security management systems.

ISO 27701

Extension to ISO 27001 specifically for privacy information management.

TIA (Transfer Impact Assessment)

A risk assessment required when transferring personal data from the EU/UK to a country without an adequacy decision. Required under Schrems II post-2020, often required alongside SCCs.

Adequacy Decision

A European Commission decision that a non-EU country provides adequate data protection, allowing transfers without additional safeguards. Examples: UK, Switzerland, Japan, South Korea, and Brazil (adopted 2026).

DPF (Data Privacy Framework)

The EU-US Data Privacy Framework, adopted 2023 as successor to Privacy Shield. Provides adequacy for transfers to US organizations that self-certify.

Schrems II

The 2020 Court of Justice of the EU decision invalidating EU-US Privacy Shield. Established stricter requirements for international data transfers under SCCs.

Joint Controller

Two or more controllers who jointly determine the purposes and means of processing. Requires a written arrangement under GDPR Article 26.

Professional Indemnity Insurance

Insurance that covers a service provider against claims arising from professional negligence or errors. Relevant for outsourced DPO services because it provides financial recourse if advice is incorrect.

DPaaS (DPO as a Service)

See External DPO. Acronym form of the same service offering. A qualified Data Protection Officer provided by an external firm on a retainer basis under GDPR Article 37(6).

DPO esterno

The Italian term for External DPO and the dominant search term in Italy, where the role is the Responsabile della Protezione dei Dati (RPD). The same service offering in Italy under GDPR Article 37(6), with the Garante as supervisory authority. Functions identically to External DPO, Outsourced DPO, Fractional DPO, and DPaaS.

DPO externe

The French term for External DPO and the dominant search term in France. External DPO service, notified to the CNIL under GDPR Article 37(6) and the French Data Protection Act.

External DPO

A qualified Data Protection Officer provided by an external firm on a retainer basis, rather than a full-time employee, notified to the supervisory authority under GDPR Article 37(6). The dominant term in UK and EU markets. Also called outsourced DPO, fractional DPO, or DPaaS.

Externer Datenschutzbeauftragter

The German term for External DPO and the dominant search term for this service in Germany. Equivalent service offering under GDPR Article 37(6) and the German Bundesdatenschutzgesetz (BDSG). Functions identically to External DPO, Outsourced DPO, Fractional DPO, and DPaaS.

Fractional DPO

See External DPO. The same service is referred to as Fractional DPO in US startup parlance, External DPO in UK and EU markets, and Outsourced DPO in international contexts. Legal standing identical under GDPR Article 37(6).

Outsourced DPO

See External DPO. The same service is referred to as Outsourced DPO in international and US-EU contexts, External DPO in UK and EU markets, and Fractional DPO in US startup parlance. Legal standing and responsibilities identical under GDPR Article 37(6).


This page is general information, not legal advice. Definitions are simplified for accessibility. Consult a qualified professional for specific legal questions.