EUVERIFY

Regulatory Compliance Glossary

Your reference for compliance, identity verification, and regulatory terminology. Clear definitions of key terms.

All Blogs

Tag
  • All
Open Graph image

Data Protection Impact Assessment (DPIA)

A Data Protection Impact Assessment (DPIA) is a documented risk assessment required when processing is likely to result in high risks to individuals’ rights and freedoms. It evaluates potential privacy risks and outlines measures to mitigate them before processing begins.
Open Graph image

Consent (GDPR)

Consent under GDPR must be freely given, specific, informed, and unambiguous. Individuals must take a clear affirmative action to indicate agreement, and they must be able to withdraw consent easily at any time. Pre-ticked boxes or implied consent do not meet GDPR standards.
Open Graph image

Data Protection Officer (DPO)

A Data Protection Officer (DPO) is a designated individual responsible for overseeing an organisation’s data protection strategy and ensuring GDPR compliance. A DPO is mandatory in certain situations, such as large-scale monitoring or processing of sensitive data. The DPO acts independently and serves as a contact point for supervisory authorities.
Open Graph image

Lawful Basis for Processing

Under GDPR, organisations must have a valid legal basis before processing personal data. These include consent, contractual necessity, legal obligation, legitimate interests, vital interests, or public tasks. Identifying and documenting the correct lawful basis is a core compliance requirement.
Open Graph image

Data Processor

A Data Processor is a third party that processes personal data on behalf of a Data Controller. Processors act only under the controller’s instructions and must implement appropriate security measures. Their relationship with the controller must be governed by a compliant Data Processing Agreement (DPA).
Open Graph image

Data Controller

A Data Controller is the organisation or entity that determines the purposes and means of processing personal data. In simple terms, the controller decides why personal data is collected and how it will be used. Controllers carry primary responsibility for GDPR compliance.
Open Graph image

Data Breach Notification

GDPR requires organisations to notify the relevant supervisory authority of certain personal data breaches without undue delay, and where feasible, within 72 hours of becoming aware of the breach. In some cases, affected individuals must also be informed.
Open Graph image

GDPR Article 27 Representative

A GDPR Article 27 Representative is an EU or UK-based contact appointed by certain non-EU organisations that process personal data of EU or UK residents. The representative acts as a point of contact for supervisory authorities and data subjects. This requirement applies where organisations are subject to GDPR but have no establishment within the EU or UK.
Open Graph image

General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) is EU law governing how organisations collect, use, store, and protect personal data. It applies to businesses established in the EU, as well as non-EU organisations offering goods or services to, or monitoring, EU residents. GDPR sets strict rules on transparency, lawful processing, data subject rights, and accountability.

Ready to simplify your compliance?

Euverify Helps Businesses Automate Identity Verification And Regulatory
Compliance. Get Started Today.