0-9
A
- Accountability (GDPR)
The principle under Article 5(2) GDPR requiring controllers to be able to demonstrate compliance with all data protection principles. Accountability is not a passive obligation. It requires documented policies, records, staff training, and the ability to produce evidence of compliance on demand.
- Adequacy decision
A formal determination by the European Commission under Article 45 GDPR that a third country provides essentially equivalent data protection to the EU. Enables personal data transfers without additional safeguards. Current adequacy decisions include the UK, Switzerland, Japan, South Korea, and the US under the EU-US Data Privacy Framework, the last of which is under legal challenge following Trump v. Slaughter (2026).
- AI Board
The European Artificial Intelligence Board established under Article 65 of the EU AI Act. Composed of one representative from each member state’s national supervisory authority and one representative from the European Data Protection Supervisor. Coordinates national enforcement, issues opinions and recommendations, and facilitates consistent application of the AI Act.
- AI literacy
The obligation under Article 4 of the EU AI Act requiring all providers and deployers of AI systems to ensure that staff dealing with those systems have a sufficient level of understanding of their capabilities, limitations, and applicable obligations. Applies universally regardless of risk tier. In force since 2 February 2025.
- AI Office
The European AI Office, established within the European Commission in January 2024. The primary supervisory authority for general-purpose AI model providers across the EU. Responsible for GPAI model supervision, guidelines, codes of practice, model evaluations, and enforcement.
- AI regulatory sandbox
A controlled environment established under Article 57 of the EU AI Act allowing providers, particularly SMEs and start-ups, to develop and test AI systems under regulatory supervision with reduced compliance obligations during the testing period. Each EU member state must establish at least one sandbox.
- AI system
Under Article 3(1) of the EU AI Act: a machine-based system that infers from inputs how to generate outputs such as predictions, recommendations, decisions, or content, operating with varying degrees of autonomy. Based on the OECD AI system definition.
- Algorithmic impact assessment
A structured evaluation of an automated decision-making system’s potential effects on individuals or groups, covering fairness, accuracy, and fundamental rights impacts. Required in various forms under Article 27 of the EU AI Act (as the FRIA) and Article 35 GDPR (as the DPIA) for high-risk processing.
- Annex III (EU AI Act)
The list of eight high-risk AI use case domains. Systems falling within these domains are presumptively classified as high-risk under Article 6(2). Covers biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. Subject to ongoing Commission review under Article 7 delegation.
- Annex IV (EU AI Act)
The technical documentation requirements for high-risk AI systems. Specifies the mandatory content of technical documentation including system description, architecture, data governance, risk management, testing results, and applicable standards.
- Article 22 (GDPR)
The provision giving data subjects the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. Requires human oversight and provides the right to express views and contest the decision. Heavily relevant to AI-assisted decision-making in employment, credit, and similar contexts.
- Authorised representative (EU AI Act)
Under Article 3(5): a natural or legal person established in the EU who has received and accepted a written mandate from a non-EU provider of an AI system or GPAI model to act on its behalf in fulfilling compliance obligations. UK establishment does not qualify post-Brexit.
- Automated decision-making (ADM)
Processing that uses personal data to make decisions about individuals without meaningful human involvement. Subject to Article 22 GDPR restrictions and increasingly scrutinised under the EU AI Act, UK GDPR, and the proposed DUAA. The EDPB has identified ADM compliance as its 2026 coordinated enforcement priority.
B
- BCR (Binding Corporate Rules)
A transfer mechanism under Article 47 GDPR allowing multinational corporate groups to transfer personal data within the group to countries outside the EU without additional safeguards. Must be approved by a lead supervisory authority. Binding on all group members.
- Biometric data
Under Article 4(14) GDPR: personal data resulting from specific technical processing relating to physical, physiological, or behavioural characteristics that allows unique identification of a natural person. Special category data under Article 9 GDPR. Subject to specific restrictions under the EU AI Act including outright prohibition of certain biometric categorisation systems under Article 5.
- Breach notification
The obligation under Article 33 GDPR to notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach likely to result in risk to individuals. Article 34 requires notification to affected individuals where the risk is high. A separate incident reporting obligation applies to high-risk AI system providers under Article 73 of the EU AI Act.
C
- C2PA (Coalition for Content Provenance and Authenticity)
An open technical standard for content provenance developed by Adobe, Microsoft, and others. Provides cryptographic manifests binding content to its origin. Relevant to EU AI Act Article 50 machine-readable marking obligations for synthetic content.
- CADA (Cloud and AI Development Act)
A proposed EU regulation currently in Parliament aimed at reducing Europe’s dependence on non-European cloud infrastructure, expanding EU data centre capacity, and defining sovereign cloud. Rapporteur appointed mid-2026.
- CE marking
The conformity marking that providers of high-risk AI systems must affix before market placement under Article 48 of the EU AI Act, indicating compliance with all applicable requirements. Affixing CE marking without completing conformity assessment is an infringement.
- CER Directive
Critical Entities Resilience Directive (EU) 2022/2557. Requires member states to identify critical entities in ten sectors and impose resilience obligations including physical protection, cybersecurity measures, incident reporting, and business continuity planning.
- CLOUD Act
Clarifying Lawful Overseas Use of Data Act. A 2018 US federal law allowing US authorities to compel American technology companies to produce data stored anywhere in the world. Creates extraterritorial jurisdiction conflicting with EU data sovereignty objectives. Central to sovereignty arguments around CADA and the EU-US Data Privacy Framework.
- Codes of conduct (EU AI Act)
Voluntary compliance instruments under Article 95 for providers and deployers of AI systems that are not high-risk. Distinct from codes of practice under Article 56, which address GPAI model obligations and carry presumptions of conformity.
- Codes of practice (EU AI Act)
Compliance instruments for GPAI model providers under Article 56, developed through a multi-stakeholder process facilitated by the AI Office. The GPAI Code of Practice entered into operation on 2 August 2025. Adherence creates a presumption of conformity with Articles 53 and 55.
- Conformity assessment
The procedure under Article 43 of the EU AI Act by which providers of high-risk AI systems demonstrate compliance before market placement. May be self-assessment under Annex VI or third-party assessment by a notified body under Annex VII depending on system type.
- Consumer Duty (FCA)
The FCA’s overarching principle requiring UK financial services firms to deliver good outcomes for retail customers. Applies to AI-assisted product design, customer communications, and automated decision-making. Operates alongside UK GDPR and sector-specific AI expectations.
- Controller
Under Article 4(7) GDPR: the natural or legal person that determines the purposes and means of processing personal data. Bears primary responsibility for GDPR compliance. Distinct from the processor, which processes data on the controller’s behalf.
- Cookie consent
The requirement under the EU ePrivacy Directive (2002/58/EC) and national implementing laws to obtain informed, specific, and freely given consent before placing non-essential cookies on a user’s device. Enforced alongside GDPR. Subject to ongoing harmonisation proposals under the Digital Omnibus.
- CRA (Cyber Resilience Act)
Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements. Applies to connected hardware and software products including most IoT devices. Requires security by design, vulnerability handling, and incident reporting. Applies from 11 December 2027 for most products.
- Critical third-party provider (CTPP)
Under DORA Article 31: an ICT third-party service provider designated as critical by the Joint Committee of the ESAs based on systemic importance to the EU financial sector. Subject to direct oversight by a Lead Overseer.
D
- Dark patterns
Interface design choices that manipulate users into actions they did not intend, including accepting data processing they would otherwise reject. Prohibited under GDPR as compromising the validity of consent. Enforcement priority for multiple EU supervisory authorities in 2025-2026.
- Data Act
- Regulation (EU) 2023/2854. Applies since 12 September 2025. Creates binding obligations for manufacturers of connected products covering user data access rights, third-party data sharing, contractual fairness requirements, and cloud switching obligations.
- Data governance
Under Article 10 of the EU AI Act: the obligation on providers of high-risk AI systems to implement appropriate practices for training, validation, and testing datasets, covering relevance, representativeness, error minimisation, and bias examination.
- Data minimisation
Under Article 5(1)(c) GDPR: personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Applies to AI training datasets and operational AI systems processing personal data.
- Data portability
Under Article 20 GDPR: the right of a data subject to receive personal data they have provided to a controller in a structured, commonly used, machine-readable format and to transmit it to another controller. Extended to product-generated data under the Data Act.
- Data Processing Agreement (DPA)
The contract required under Article 28 GDPR between a controller and a processor. Must specify the subject matter, duration, nature and purpose of processing, categories of data and data subjects, and impose specific obligations on the processor including processing only on instructions, confidentiality, security, sub-processing restrictions, and audit rights.
- Data Protection Act 2018 (DPA 2018)
The UK statute that implemented the GDPR into domestic law, exercised national discretions, provided regimes for law enforcement and intelligence services data processing, and established the ICO’s regulatory powers. Operates alongside the UK GDPR as the combined UK data protection framework.
- Data Protection Authority (DPA)
The independent national supervisory authority responsible for enforcing data protection law in a given jurisdiction. In the UK, this is the ICO. In the EU, each member state has its own DPA.
- Data Protection Impact Assessment (DPIA)
Under Article 35 GDPR: a structured assessment required before processing likely to result in high risk to individuals. Mandatory for systematic profiling, large-scale special category data processing, and systematic monitoring of publicly accessible areas. Must be coordinated with the FRIA under the EU AI Act where both apply.
- Data Protection Officer (DPO)
Under Articles 37-39 GDPR: a designated officer required for public authorities, organisations carrying out large-scale systematic monitoring, and organisations processing special categories at scale. Advises on data protection obligations and acts as contact point for supervisory authorities.
- Data subject
Under Article 4(1) GDPR: an identified or identifiable natural person to whom personal data relates. Holds rights including access, rectification, erasure, restriction, portability, and objection.
- Declaration of Conformity
Under Article 47 of the EU AI Act: a written document in which a provider of a high-risk AI system declares compliance with all applicable requirements. Must be prepared before market placement and retained for 10 years.
- Deployer (EU AI Act)
Under Article 3(4): a natural or legal person that uses an AI system under their own authority in a professional context. Carries independent compliance obligations under Article 26 including human oversight, FRIA, log retention, and individual notification.
- Digital Markets Act (DMA)
Regulation (EU) 2022/1925. Applies to designated gatekeepers, large platform companies meeting size and user thresholds. Imposes obligations including interoperability requirements, data access obligations, and prohibitions on self-preferencing. In force since 2 May 2023.
- Digital Omnibus
Regulation (EU) 2026/1744. The amendment to the EU AI Act that moved the stand-alone Annex III high-risk AI deadline from 2 August 2026 to 2 December 2027, the Annex I product safety route deadline to August 2028, and added two new Article 5 prohibitions. Entered into force 18 July 2026.
- Digital Services Act (DSA)
Regulation (EU) 2022/2065. Imposes obligations on online intermediaries and platforms regarding illegal content, systemic risk, and transparency. Very large online platforms face annual risk assessments and independent audits. AliExpress was fined €550 million under the DSA in July 2026.
- DORA (Digital Operational Resilience Act)
Regulation (EU) 2022/2554. Applies since 17 January 2025 to EU financial entities including banks, insurers, and investment firms. Covers ICT risk management, incident reporting, resilience testing, and third-party risk management.
- DPF (Data Privacy Framework)
- The EU-US Data Privacy Framework was established by adequacy decision in July 2023. Enables transfers of personal data from the EU to certified US organisations. Under legal challenge following Trump v. Slaughter (2026), which undermined the premise of FTC independence.
- DUAA (Data Use and Access Act)
UK legislation restructuring the automated decision-making framework under UK GDPR. Amends Article 22 equivalent provisions and introduces new rules on AI-assisted decision-making for UK-regulated organisations.
E
- EBA (European Banking Authority)
One of three European Supervisory Authorities. Responsible for prudential regulation of the EU banking sector. Plays a role in DORA oversight as part of the Joint Committee of ESAs.
- EDPB (European Data Protection Board)
The independent EU body established under Article 68 GDPR, composed of the heads of national DPAs and the European Data Protection Supervisor. Issues guidelines, recommendations, and binding decisions on GDPR interpretation. Identified ADM compliance as its 2026 coordinated enforcement priority.
- eIDAS 2.0
Regulation (EU) 2024/1183 revising the eIDAS framework for electronic identification and trust services. Introduces the European Digital Identity Wallet, enabling EU citizens to use a single digital identity across member states. Relevant to AI systems using digital identity for authentication.
- Electronic Privacy Directive (ePrivacy)
Directive 2002/58/EC governing confidentiality of electronic communications, cookies, and direct marketing. Pending replacement by the ePrivacy Regulation, which has been in negotiation since 2017. Currently enforced alongside GDPR.
- Enforcement action
A formal regulatory measure taken by a supervisory authority against a controller, processor, or AI system operator for breach of applicable law. May include warnings, reprimands, orders to comply, orders to suspend processing, or administrative fines.
- ePrivacy Regulation
The proposed EU regulation replacing the ePrivacy Directive, governing cookies, electronic communications metadata, and direct marketing. Long-delayed; as of August 2026, not yet adopted.
- ePrivacy Regulation
The proposed EU regulation replacing the ePrivacy Directive, governing cookies, electronic communications metadata, and direct marketing. Long-delayed; as of August 2026, not yet adopted.
- ESAs (European Supervisory Authorities)
The three EU financial supervisory bodies: EBA (banking), ESMA (securities), and EIOPA (insurance and pensions). Play a joint role in DORA oversight through the Joint Committee.
- EU-US Data Privacy Framework (DPF)
See Data Privacy Framework.
F
- FCA (Financial Conduct Authority)
The UK financial services conduct regulator. Applies AI governance expectations through existing frameworks including SM&CR personal accountability for AI outcomes, Consumer Duty requirements, and model risk management expectations. Does not have a standalone AI regulatory framework.
- FLOPs (Floating-point operations)
The unit used to measure training compute for AI models. Under Article 51(2) of the EU AI Act, a GPAI model trained using compute exceeding 10²⁵ FLOPs is presumed to have systemic risk.
- FRIA (Fundamental Rights Impact Assessment)
Required under Article 27 of the EU AI Act for certain deployers of Annex III high-risk AI systems before deployment. Must document affected individuals, potential impacts on fundamental rights, mitigation measures, and human oversight arrangements. Must be coordinated with any DPIA required under GDPR.
- FTC (Federal Trade Commission)
The primary US federal consumer protection and competition authority. Designated as the independent oversight body responsible for enforcing US commitments under the EU-US Data Privacy Framework. Its independence was undermined by the US Supreme Court ruling in Trump v. Slaughter (2026).
G
- GDPR (General Data Protection Regulation
Regulation (EU) 2016/679. The primary EU data protection law, applicable since 25 May 2018. Governs processing of personal data of EU residents regardless of where the processing organisation is established. Maximum fines of €20 million or 4% of worldwide annual turnover for serious violations.
- GPAI model (General-purpose AI model)
Under Article 3(63) of the EU AI Act: an AI model trained with large amounts of data using self-supervision at scale that displays significant generality and is capable of competently performing a wide range of distinct tasks, and that can be integrated into a variety of downstream systems.
- GPAI model with systemic risk
A GPAI model classified as posing systemic risk under Article 51 of the EU AI Act. Triggered by training compute exceeding 10²⁵ FLOPs or AI Office designation. Subject to additional obligations including adversarial testing, incident reporting, and cybersecurity measures.
H
- High-risk AI system
Under Article 6 of the EU AI Act: an AI system that is either a safety component of an Annex I regulated product requiring third-party conformity assessment, or an AI system used in one of the eight domains in Annex III. Subject to the most extensive compliance obligations in the Act.
- Human oversight
Under Article 14 of the EU AI Act: the requirement that high-risk AI systems be designed to enable effective oversight by natural persons during operation. Encompasses the ability to understand capabilities and limitations, detect anomalies, interpret outputs, override decisions, and interrupt the system.
I
- ICO (Information Commissioner’s Office)
The UK’s independent data protection and information rights regulator. Enforces UK GDPR, the DPA 2018, PECR, and other digital legislation. Has powers to impose fines of up to £17.5 million or 4% of worldwide annual turnover for serious violations.
- ICT risk
Under Article 3(5) of DORA: any reasonably identifiable circumstance relating to the use of network and information systems which, if materialised, may compromise the security of those systems and the services provided by a financial entity.
- Importer (EU AI Act)
Under Article 3(6): a natural or legal person established in the EU that places on the EU market an AI system bearing the name or trademark of a person established outside the EU. Carries pre-market verification obligations.
- Incident reporting
The obligation to notify relevant authorities of security incidents or AI system malfunctions within prescribed timeframes. Under GDPR Article 33, personal data breaches must be reported to the supervisory authority within 72 hours. Under DORA Article 19, major ICT incidents must be reported within 4 hours. Under EU AI Act Article 73, serious AI incidents must be reported within 15 days.
- ISO/IEC 42001:2023
The first international standard for AI management systems, published in December 2023. Certifiable standard providing a framework for establishing, implementing, maintaining, and improving an AI management system. Referenced as relevant to quality management system design under Article 17 of the EU AI Act.
J
- Joint controller
Under Article 26 GDPR: two or more controllers that jointly determine the purposes and means of processing. Must enter into an arrangement setting out their respective responsibilities for GDPR compliance and provide a point of contact to data subjects.
K
L
- Lawful basis
Under Article 6 GDPR: one of six legal grounds on which personal data may be processed. Includes consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. Processing without a lawful basis is unlawful. Legitimate interests faces heightened scrutiny for AI training data uses.
- Lead supervisory authority
Under Article 56 GDPR: the supervisory authority of the EU member state where a controller or processor has its main establishment, responsible for leading cross-border enforcement under the one-stop-shop mechanism.
- Legitimate interests
Under Article 6(1)(f) GDPR: a lawful basis for processing where the controller or a third party has a legitimate interest that is not overridden by the interests or fundamental rights and freedoms of the data subject. Requires a three-part balancing test: purpose test, necessity test, and balancing test. Faces heightened regulatory scrutiny as a basis for AI training data processing.
- LGPD
Lei Geral de Proteção de Dados. Brazil’s data protection law, in force since September 2020. Broadly modelled on GDPR. Covers processing of personal data of Brazilian residents. Enforced by the ANPD.
M
- Machine-readable marking
Under Article 50(2) of the EU AI Act: the requirement to label AI-generated synthetic audio, image, video, or text content in a machine-readable format detectable as artificially generated. Deadline for systems already on market extended to 2 December 2026 by the Digital Omnibus.
- Market surveillance authority
Under Article 70 of the EU AI Act: the national authority designated by each EU member state to supervise the Act’s application in relation to high-risk AI systems. Must cooperate with other member state authorities and the AI Office.
- MiCA (Markets in Crypto-Assets Regulation)
Regulation (EU) 2023/1114. The EU framework for crypto-asset service providers and issuers. Fully applicable since 30 December 2024. Crypto-asset service providers using AI systems are within scope of both MiCA and the EU AI Act.
N
- NIS2 Directive
Directive (EU) 2022/2555. Imposes cybersecurity obligations on essential and important entities across energy, transport, banking, health, digital infrastructure, and public administration. For financial entities in scope of both NIS2 and DORA, DORA takes precedence as the sector-specific act.
- NIST AI RMF
- NIST Artificial Intelligence Risk Management Framework. A voluntary US framework published by the National Institute of Standards and Technology in January 2023. Organises AI risk management around four functions: Govern, Map, Measure, and Manage. Widely adopted in the US and referenced internationally.
- Notified body
Under Articles 28-39 of the EU AI Act: an independent conformity assessment body designated by a member state to conduct third-party conformity assessments for certain high-risk AI systems. Capacity constraints are a significant practical bottleneck as of 2026.
O
- One-stop-shop
The GDPR mechanism under Article 56 whereby cross-border data processing cases are handled by the lead supervisory authority of the controller’s main establishment, with concerned authorities from other member states participating.
- Operator (EU AI Act)
Under Article 3(8): the collective term covering providers, deployers, authorised representatives, importers, and distributors of AI systems. Used when obligations apply across multiple role categories.
P
- PAN (Primary Account Number)
The payment card number. The central element of cardholder data under PCI DSS. Must never be stored unencrypted after authorisation.
- PCI DSS (Payment Card Industry Data Security Standard)
A contractual security standard maintained by the PCI SSC. Applies to all organisations storing, processing, or transmitting payment card data. Not a statutory legal obligation but a contractual requirement imposed through merchant agreements. Version 4.0.1 is the current operative version.
- PECR (Privacy and Electronic Communications Regulations)
The UK implementation of the ePrivacy Directive. Governs cookies, direct marketing, and electronic communications confidentiality. Enforced by the ICO. Fines now aligned with UK GDPR maximums.
- Personal data
Under Article 4(1) GDPR: any information relating to an identified or identifiable natural person. An identifiable person is one who can be identified directly or indirectly by reference to an identifier such as a name, number, location data, or online identifier.
- PIPEDA
Personal Information Protection and Electronic Documents Act. Canada’s federal private sector data protection law. Applies to commercial activities involving personal information of Canadian residents.
- Post-market monitoring
Under Article 72 of the EU AI Act: the obligation on providers of high-risk AI systems to collect and review experience from deployed systems to identify risks requiring corrective action. Must be supported by a documented post-market monitoring plan.
- Privacy by design
Under Article 25 GDPR: the obligation to implement appropriate technical and organisational measures to give effect to data protection principles and integrate necessary safeguards into processing operations by design and by default.
- Processor
Under Article 4(8) GDPR: a natural or legal person that processes personal data on behalf of a controller. Must act only on documented controller instructions. Has direct GDPR obligations under Articles 28 and 32.
- Profiling
Under Article 4(4) GDPR: any form of automated processing of personal data to evaluate certain personal aspects of a natural person, including analysis or prediction of work performance, economic situation, health, personal preferences, behaviour, or location. Subject to restrictions under Article 22 and scrutinised under the EU AI Act’s high-risk classification framework.
- Provider (EU AI Act)
Under Article 3(3): a natural or legal person that develops an AI system or GPAI model and places it on the market or puts it into service under their own name or trademark. Carries the most extensive compliance obligations under the Act.
- Pseudonymisation
Under Article 4(5) GDPR: processing personal data so that it can no longer be attributed to a specific data subject without additional information, kept separately subject to technical and organisational measures. Reduces but does not eliminate GDPR obligations; pseudonymised data remains personal data.
Q
- QMS (Quality Management System)
Under Article 17 of the EU AI Act: the organisational framework that providers of high-risk AI systems must establish, document, and maintain to ensure compliance across the system lifecycle. ISO/IEC 42001 provides a recognised reference framework.
- QSA (Qualified Security Assessor)
An organisation certified by the PCI SSC to conduct PCI DSS assessments for Level 1 merchants and service providers.
R
- Records of Processing Activities (RoPA)
Under Article 30 GDPR: a documented register that controllers and processors must maintain setting out their processing activities, purposes, data categories, recipients, transfers, retention periods, and security measures. Must be made available to supervisory authorities on request.
- Representative Actions Directive
Directive (EU) 2020/1828 on representative actions for protection of collective consumer interests. Extended to EU AI Act infringements by Article 110 of the Act, enabling collective redress actions by qualified organisations against AI Act infringers.
- Right of access
Under Article 15 GDPR: the right of a data subject to obtain confirmation of whether their personal data is being processed, access to that data, and information about the processing including purposes, recipients, retention periods, and rights.
- Right to be forgotten
Under Article 17 GDPR: the right of a data subject to obtain erasure of personal data without undue delay where the data is no longer necessary, consent is withdrawn, or the data has been unlawfully processed.
- Right to explanation (EU AI Act)
Under Article 86 of the EU AI Act: the right of an individual subject to a decision based on a high-risk Annex III AI system output to obtain from the deployer a meaningful explanation of the AI system’s role and the main elements of the decision.
- Right to object
Under Article 21 GDPR: the right of a data subject to object to processing based on legitimate interests or for direct marketing purposes. Where objection is made to direct marketing, processing must cease without qualification.
- ROC (Report on Compliance)
The formal assessment report produced by a QSA following a PCI DSS assessment of a Level 1 merchant or service provider.
- RTO / RPO
Recovery Time Objective and Recovery Point Objective. Under DORA Article 12: the maximum acceptable time to restore a critical function (RTO) and maximum acceptable period of data loss (RPO) following an ICT disruption. Must be defined and documented in business continuity plans.
S
- SAQ (Self-Assessment Questionnaire)
The self-validation tool used by merchants and service providers below Level 1 for PCI DSS compliance. Different SAQ types apply depending on how card payments are processed.
- SCCs (Standard Contractual Clauses)
Model contract clauses approved by the European Commission for use as a transfer mechanism for personal data from the EU to third countries without an adequacy decision. Current SCCs adopted June 2021. Must be supplemented by a Transfer Impact Assessment where the destination country’s laws may undermine their effectiveness.
- SM&CR (Senior Managers and Certification Regime)
The FCA and PRA framework imposing personal accountability on senior managers in UK financial services firms for the areas they control, including AI systems used in their functions.
- SOC 2 (System and Organisation Controls 2)
An auditing standard developed by the AICPA covering security, availability, processing integrity, confidentiality, and privacy. Widely required in enterprise procurement. Subject to scrutiny following the Delve scandal (2026) in which templated assessments and rubber-stamp auditing practices were alleged.
- Special categories of data
Under Article 9 GDPR: data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership; genetic data; biometric data for identification; health data; and data concerning sex life or sexual orientation. Processing is prohibited unless an Article 9(2) exception applies.
- Substantial modification
Under Article 3(23) of the EU AI Act: a change to a high-risk AI system that affects its compliance with the Act’s requirements or changes its intended purpose. Triggers full compliance obligations for the modified system from the date of modification.
- Systemic risk
Under Article 3(65) of the EU AI Act: a risk specific to high-impact GPAI models with the potential for significant negative effects on public health, safety, public security, or fundamental rights at Union scale.
T
- Technical documentation
Under Article 11 and Annex IV of the EU AI Act: documentation providers of high-risk AI systems must prepare before market placement covering system description, architecture, data governance, risk management, testing results, and applicable standards. Must be retained for 10 years.
- TIA (Transfer Impact Assessment)
An assessment required when using SCCs or other transfer mechanisms for personal data from the EU to third countries, evaluating whether the laws and practices of the destination country undermine the effectiveness of the transfer mechanism.
- TLPT (Threat-Led Penetration Testing)
Under Article 26 of DORA: advanced resilience testing for significant financial entities using real-world threat intelligence to design and execute controlled attacks on live production systems. Required at least every three years.
- Trade secret
Under Article 2(1) of Directive (EU) 2016/943: information that is secret, has commercial value because it is secret, and has been subject to reasonable steps to keep it secret. Providers of high-risk AI systems and GPAI models may protect genuine trade secrets but cannot use trade secret protection as a blanket refusal to share data with regulators.
- Transfer mechanism
A legal instrument enabling personal data transfers from the EU to third countries where no adequacy decision exists. Includes SCCs, BCRs, binding corporate rules, codes of conduct, and certification mechanisms under Article 46 GDPR.
U
- UK GDPR
The version of the GDPR retained in UK domestic law following Brexit, as modified by the Data Protection Act 2018 and the European Union (Withdrawal) Act 2018. Substantially equivalent to EU GDPR but a distinct legal instrument. Enforced by the ICO. Covered by an EU adequacy decision subject to periodic review.
V
- Vital interests
Under Article 6(1)(d) GDPR: a lawful basis for processing where processing is necessary to protect the vital interests of the data subject or another natural person. Limited to life-or-death situations. Cannot be relied upon where the data subject is capable of giving consent.
W
- Whistleblower protection
Under Article 87 of the EU AI Act: individuals reporting AI Act infringements to national authorities or the AI Office are protected from retaliation under Directive (EU) 2019/1937. Also relevant to data protection enforcement under GDPR where breaches are reported internally or externally.
X
Y
Z
- Zero-day vulnerability
A software vulnerability unknown to the vendor and for which no patch exists at the time of discovery. Relevant to CRA obligations requiring manufacturers to address known vulnerabilities and to DORA obligations requiring financial entities to monitor and respond to emerging threats. Disclosure obligations vary by framework.
