Data Privacy Vocabulary in English

20 essential data privacy and data protection words with definitions and example sentences — ideal for B1–C1 learners in IT, law, compliance, and digital business.

Pedagogically reviewed by LexFizz Team

What You’ll Learn

Why Learn Data Privacy Vocabulary?

Data privacy has become one of the most significant areas of law, technology, and business in the 21st century. The introduction of the General Data Protection Regulation (GDPR) in Europe and equivalent laws around the world has made data privacy vocabulary essential for anyone working in business, law, IT, marketing, or HR. Terms like personal data, data controller, and lawful basis for processing appear in company policies, contracts, and regulatory communications every day.

For professionals working in compliance, legal, or technology roles in English-speaking organisations, this vocabulary is genuinely critical. A misunderstanding of terms such as pseudonymisation or data subject can have serious legal and financial consequences. Many organisations have dedicated Data Protection Officers (DPOs) whose role requires confident command of this vocabulary in both written and spoken English.

Data privacy vocabulary also matters to ordinary citizens who want to understand their rights. Knowing what a privacy notice says, understanding what you are consenting to when you agree to cookies, and knowing how to exercise your right to erasure are all important digital literacy skills. This vocabulary empowers you to navigate the digital world more safely and confidently.

The language of data privacy is largely technical and legal in origin, with many terms defined precisely in legislation. This precision makes it particularly rewarding to learn at B1–C1 level, as it demonstrates sophisticated lexical knowledge and the ability to handle technical English texts. For general definitions alongside the legal ones given here, the Oxford Learner's Dictionaries is a useful reference.

Data Privacy Word List

WordMeaningExample Sentence
personal dataany information that can identify a living individual, directly or indirectly, such as a name, email address, or IP addressUnder GDPR, personal data must be collected only for specified, explicit purposes.
data controllerthe organisation or person who determines the purposes and means of processing personal dataThe company acting as data controller is responsible for ensuring GDPR compliance.
data processoran organisation or person who processes personal data on behalf of a data controllerThe email marketing company acts as a data processor for its clients’ subscriber lists.
data subjectthe identified or identifiable living individual to whom personal data relatesThe data subject has the right to request access to their personal data at any time.
consenta freely given, specific, informed, and unambiguous indication by the data subject that they agree to their data being processedThe website obtained explicit consent before storing marketing cookies on visitors’ devices.
lawful basisone of the six legal grounds under GDPR on which a data controller may process personal dataThe organisation identified legitimate interests as its lawful basis for processing employee data for fraud prevention.
GDPRGeneral Data Protection Regulation; the EU law governing the collection, storage, and use of personal dataThe company was fined €50 million for GDPR violations related to its advertising practices.
data breacha security incident in which personal data is accessed, disclosed, lost, or destroyed without authorisationThe company reported the data breach to the Information Commissioner’s Office within 72 hours as required by law.
right to erasurethe right of a data subject to request that their personal data be deleted when it is no longer needed or when consent is withdrawn; also called the “right to be forgotten”The customer exercised their right to erasure and the company deleted all their personal data within the required timeframe.
right of accessthe right of a data subject to obtain confirmation of whether their data is being processed and to receive a copy of itHe submitted a subject access request to the bank to find out what data it held about him.
privacy noticea document that explains to individuals how an organisation collects, uses, stores, and shares their personal dataThe privacy notice must be written in clear, plain language and made available before data is collected.
pseudonymisationthe processing of personal data in a way that it can no longer be attributed to a specific individual without additional information kept separatelyThe research team used pseudonymisation to protect participants’ identities while still being able to analyse the data.
anonymisationthe irreversible process of removing identifying information so that an individual can no longer be identified from the dataOnce the data had been anonymised, it was no longer subject to GDPR requirements.
data retentionthe policy governing how long personal data is kept before it is deleted or anonymisedThe company’s data retention policy required customer records to be deleted after seven years.
data minimisationthe principle that only the minimum amount of personal data necessary for the specified purpose should be collected and processedApplying data minimisation, the form was redesigned to collect only the essential information.
Data Protection Officera designated individual in an organisation responsible for overseeing data protection strategy and ensuring compliance with data protection lawThe hospital appointed a Data Protection Officer to manage compliance with patient data regulations.
third partyan organisation or individual other than the data controller and data subject who may receive or process personal dataThe privacy notice listed all third parties with whom customer data might be shared.
data portabilitythe right of a data subject to receive their personal data in a structured, machine-readable format and to transfer it to another controllerData portability allows users to download their social media data and move it to a different platform.
legitimate interestsone of the lawful bases for processing personal data, used when the controller has a genuine reason that is not overridden by the individual’s rightsThe company relied on legitimate interests as its basis for processing employee data for internal fraud detection.
impact assessmenta Data Protection Impact Assessment (DPIA); a process to identify and minimise privacy risks before starting a new data processing activityA data protection impact assessment was required before deploying the new facial recognition system.

Practice with Free Exercises

Reinforce your data privacy vocabulary with these interactive exercises.

Ready to Practise All Your Vocabulary?

Explore all LexFizz exercises and vocabulary topics for free.

Browse All Exercises

Related Vocabulary Topics

Frequently Asked Questions

What is personal data under GDPR?

Personal data under GDPR is any information that relates to an identified or identifiable living individual. The definition is intentionally broad and includes obvious identifiers such as name, email address, and national insurance number, but also less obvious ones such as IP addresses, cookie identifiers, location data, and online behavioural profiles that could be used to identify a specific person. Data that is truly anonymous — meaning it is impossible to re-identify the individual from it, even with additional data — falls outside the scope of GDPR. The concept of “identifiable” includes both direct identification (knowing the person’s name) and indirect identification (combining data points that together identify an individual).

What is the difference between a data controller and a data processor?

A data controller is the organisation or individual who decides why and how personal data is processed. They set the purposes and means of processing and bear primary legal responsibility under GDPR. A data processor is an organisation or individual who processes personal data on behalf of the controller, following the controller’s instructions. For example, a business (the controller) might use a payroll software company (the processor) to process employee data. Both controllers and processors have obligations under GDPR, and the relationship must be governed by a written data processing agreement. Controllers can be held liable for the actions of processors who act outside their instructions.

What is consent under GDPR and when is it required?

Under GDPR, consent is one of six lawful bases on which personal data may be processed. For consent to be valid, it must be freely given (without coercion or detriment for refusing), specific (covering a particular purpose), informed (the individual must understand what they are consenting to), and unambiguous (requiring a clear positive action such as ticking a box — pre-ticked boxes do not count). Consent is not always required for processing personal data — organisations can rely on other lawful bases such as contract, legal obligation, or legitimate interests. However, consent is often the most appropriate basis for marketing activities, and individuals must be able to withdraw it at any time as easily as they gave it.

What is the right to erasure?

The right to erasure, also known as the “right to be forgotten”, allows individuals to request that an organisation delete their personal data in certain circumstances. These include when the data is no longer needed for the purpose it was collected, when consent has been withdrawn and there is no other lawful basis for processing, when the data has been processed unlawfully, or when erasure is required by law. The right is not absolute — organisations can refuse if they have overriding legitimate grounds to keep the data, for example if it is needed to comply with a legal obligation or to defend a legal claim. Requests must be responded to within one month.

What is the difference between pseudonymisation and anonymisation?

Pseudonymisation replaces identifying information in a dataset with an artificial identifier (a pseudonym), so the data can no longer be linked to a specific individual without access to separate additional information kept securely. Pseudonymised data is still personal data under GDPR because it is possible, in principle, to re-identify the individual. Anonymisation is the irreversible removal of identifying information so that it is no longer possible to identify the individual from the data, even using all available means. Truly anonymised data falls outside GDPR entirely. The distinction matters practically: pseudonymised data can be used to reduce risk while retaining the ability to re-link records if needed (as in clinical research), while anonymised data offers no route back to the individual.

What must organisations do when there is a data breach?

Under GDPR, if a data breach is likely to result in a risk to individuals’ rights and freedoms, the data controller must notify the relevant supervisory authority (in the UK, the Information Commissioner’s Office) within 72 hours of becoming aware of it. If the breach is likely to result in a high risk to individuals, the organisation must also notify the affected individuals without undue delay. The notification must describe the nature of the breach, the categories and approximate number of individuals and data records involved, the likely consequences, and the measures taken or proposed to address the breach. Organisations must also document all breaches, even those that do not require notification.

What is a Data Protection Impact Assessment (DPIA)?

A Data Protection Impact Assessment (DPIA) is a process required under GDPR before starting a new processing activity that is likely to result in a high risk to individuals’ privacy. It involves systematically identifying and assessing the risks of the proposed processing and documenting measures to reduce those risks to an acceptable level. A DPIA is mandatory for certain types of processing, including large-scale processing of sensitive data, systematic monitoring of publicly accessible areas (such as CCTV), and automated decision-making that significantly affects individuals. It is also good practice to carry one out for any significant new use of personal data, even where not strictly required. If risks cannot be adequately mitigated, the organisation must consult the supervisory authority before proceeding.

What is data minimisation?

Data minimisation is one of the key principles of GDPR, requiring that the personal data collected and processed should be limited to what is strictly necessary for the specified purpose. Organisations should not collect data “just in case” it might be useful later. In practice, this means reviewing registration forms, databases, and processes to ensure they do not gather unnecessary fields, shortening data retention periods, and not reusing data for new purposes without an appropriate lawful basis. Data minimisation reduces privacy risk: the less data an organisation holds, the less damage a breach can cause and the simpler it is to comply with data subject rights requests such as erasure or access.

What is data portability?

Data portability is the right under GDPR that allows individuals to receive a copy of their personal data in a structured, commonly used, machine-readable format (such as CSV or JSON), and to transfer that data to another controller without hindrance. The right applies specifically to data that the individual provided to the controller and that is processed on the basis of consent or contract. A practical example is downloading your data from a social media platform and uploading it to a rival service. Data portability promotes competition, individual autonomy, and reduces lock-in to particular service providers. The organisation must respond to portability requests within one month.

What is the best way to learn data privacy vocabulary in English?

Group the words into logical categories: people and roles (data subject, data controller, data processor, Data Protection Officer), legal concepts (GDPR, lawful basis, consent, legitimate interests), individual rights (right of access, right to erasure, data portability), technical concepts (pseudonymisation, anonymisation, encryption), and processes and documents (privacy notice, data breach, impact assessment, data retention). Use Flash Cards to build confident recall, then read real privacy notices, GDPR guidance from the ICO website, or published regulatory decisions. The ICO publishes case studies and guidance in clear English that is an excellent learning resource for this vocabulary in authentic regulatory context.