Glossary
- 21st Century Cures Act
Law including provisions promoting interoperability and prohibiting information blocking of electronic health information.
- Access and Correction
Individual rights to review personal information held about them and to request corrections.
- Accountability
The principle that organizations are responsible for, and can demonstrate, compliance with privacy obligations.
- Adequacy
A determination that a non-EU country provides an adequate level of data protection, permitting transfers without additional safeguards.
- Adequacy Decision
- A determination by the European Commission that a non-EU country, territory, or sector ensures an adequate level of data protection, allowing transfers there without additional safeguards.
- Adversarial Attack
- Deliberately crafted inputs designed to fool, evade, or manipulate an AI model's behavior.
- Adverse Action
A denial or unfavorable change (e.g., credit, employment) based on a consumer report, triggering FCRA notice requirements.
- Aggregation
Combining individual data points into group-level statistics that do not identify specific individuals.
- AI Governance
- The policies, processes, roles, and controls an organization uses to develop, procure, and deploy AI systems responsibly, lawfully, and in line with ethical principles.
- Algorithmic Bias
- Systematic and unfair discrimination in the outputs of an algorithm, often arising from skewed training data or design choices, which can reproduce or amplify social inequities.
- Americans with Disabilities Act (ADA)
Limits employer medical inquiries and exams and requires confidentiality of employee medical information.
- Anonymization
- Processing data so that individuals can no longer be identified from it, irreversibly and by any reasonably likely means. Truly anonymized data falls outside most privacy laws.
- Appropriation
A privacy tort for using a person's name or likeness for commercial benefit without consent; related to the right of publicity.
- Article 29 Working Party (WP29)
- The former EU advisory body of national data protection authorities on data protection matters, whose guidance was influential; replaced by the EDPB when the GDPR took effect.
- Artificial Intelligence (AI)
- Computer systems that perform tasks normally associated with human intelligence — such as perception, reasoning, learning, and decision-making.
- Automated Decision System (ADS)
- A system that uses automation to make, or materially support, decisions that affect people.
- Automated Decision-Making
- Decisions produced by algorithms with little or no human involvement (e.g. credit, hiring, or content decisions). Several laws grant rights to explanation or human review of such decisions.
- Automated Individual Decision-Making
- GDPR Article 22 gives individuals the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, absent specific safeguards.
- Automatic Telephone Dialing System (ATDS)
Equipment that stores or produces and dials numbers; its use to call cell phones without consent is restricted under the TCPA.
- Background Screening
Pre-employment checks (criminal, credit, references); when done via a CRA, governed by the FCRA and state 'ban-the-box' laws.
- Bank Secrecy Act (BSA)
Anti-money-laundering law requiring financial institutions to report certain transactions, in tension with financial privacy.
- Binding Corporate Rules (BCRs)
Internal data-transfer rules approved by EU regulators for transfers within a corporate group.
- Biometric Information Privacy Act (BIPA)
Illinois law requiring notice and consent for collecting biometric identifiers; notable for its private right of action.
- Breach Notification Law
State (and some federal) laws requiring notice to affected individuals (and sometimes regulators) after a breach of personal information.
- Bring Your Own Device (BYOD)
Policies allowing personal devices for work, raising privacy and security issues around monitoring and data separation.
- Browser Fingerprinting
- Identifying and tracking a device by combining many configuration attributes (fonts, screen size, extensions, etc.) into a distinctive signature — without needing cookies.
- Business
The entity that collects personal information from California consumers and determines the purposes and means of processing. Roughly equivalent to a data controller.
Course relevance: Only applies in California. The gap: no federal equivalent means businesses face different obligations depending on where their users are located.
- Business Associate
A person or entity that performs functions involving PHI on behalf of a covered entity; bound by a business associate agreement.
- Business Associate Agreement (BAA)
A required contract obligating a business associate to safeguard PHI consistent with HIPAA.
- Business Associate of a Business Associate
HIPAA equivalent of a sub-processor: a third party engaged by the business associate. Required to sign agreements flowing down from the business associate.
Course relevance: In practice these agreements are often inadequate or missing. Accountability thins with each link in the chain.
- Cable Communications Policy Act
1984 law restricting cable operators' collection and disclosure of subscriber personally identifiable information.
- California Consumer Privacy Act (CCPA)
2018 California law granting consumers rights to know, delete, and opt out of the sale of their personal information.
- California Privacy Protection Agency (CPPA)
The agency created by the CPRA to implement and enforce California consumer privacy law.
- California Privacy Rights Act (CPRA)
2020 ballot measure amending the CCPA; added rights (correction, limiting sensitive PI), new categories, and the California Privacy Protection Agency.
- CAN-SPAM Act
2003 law regulating commercial email; requires accurate headers, a functioning opt-out, identification as an ad, and a valid physical address.
- Carpenter v. United States
2018 Supreme Court case holding that accessing historical cell-site location information is a Fourth Amendment search requiring a warrant, narrowing the third-party doctrine.
- CCPA / CPRA
- The California Consumer Privacy Act (2020), expanded by the California Privacy Rights Act, giving California residents rights to know about, delete, correct, and opt out of the sale or sharing of their personal information — the leading US state privacy framework.
- Charter of Fundamental Rights of the European Union
- The EU instrument that recognizes respect for private life (Article 7) and protection of personal data (Article 8) as fundamental rights.
- Children's Online Privacy Protection Act (COPPA)
1998 law requiring verifiable parental consent before collecting personal information online from children under 13; enforced by the FTC.
- Chilling Effect
- The deterrence of lawful behavior — speech, association, inquiry — caused by surveillance or the fear of being monitored.
- Choice / Consent
Giving individuals control over the use of their data, through opt-in (affirmative) or opt-out (default-permitted) mechanisms.
- Common Rule
Federal policy (45 CFR 46) governing the ethical conduct of human-subjects research, including informed consent and IRB review.
- Communications Assistance for Law Enforcement Act (CALEA)
1994 law requiring telecom carriers to build interception capabilities into their networks for lawful surveillance.
- Computer Fraud and Abuse Act (CFAA)
Federal anti-hacking statute prohibiting unauthorized access to protected computers.
- Conformity Assessment
- The process of verifying that a high-risk AI system meets the EU AI Act's requirements before it is placed on the market.
- Consent
- A person’s agreement to the processing of their data. Under stricter regimes like the GDPR, valid consent must be freely given, specific, informed, and unambiguous, and it must be as easy to withdraw as to give.
- Consent Decree / Consent Order
A binding settlement (often 20 years) the FTC enters with a company, imposing privacy/security obligations and audits without an admission of liability.
- Consumer Financial Protection Bureau (CFPB)
Federal agency created by Dodd-Frank that regulates consumer financial products and shares GLBA-related authority.
- Consumer Report
Information from a CRA bearing on a consumer's creditworthiness, character, or reputation used for credit, employment, insurance, or similar purposes.
- Consumer Reporting Agency (CRA)
An entity that compiles and sells consumer reports (e.g., credit bureaus); regulated under the FCRA.
- Content Provenance / Watermarking
- Techniques for marking, disclosing, or tracing AI-generated content to signal its origin and authenticity.
- Contextual Integrity
- Helen Nissenbaum’s theory that privacy is not secrecy but the appropriate flow of information according to the norms of the specific social context in which it was shared.
- Contractor
Added by the CPRA. Similar to a service provider but for different processing contexts. Expands the category of entities subject to contractual data protection obligations.
Course relevance: An attempt to close the gap that allows entities to receive data without taking on service-provider obligations. Whether it succeeds is a live legal question.
- Convention 108
- The Council of Europe's binding international treaty on the protection of individuals with regard to automatic processing of personal data (1981), modernized as Convention 108+.
A small file a website stores in a browser to remember information; central to online tracking and behavioral advertising debates.
- COPPA
- The US Children’s Online Privacy Protection Act, which requires verifiable parental consent before online services collect personal information from children under 13.
- Covered Entity
Under HIPAA, a health plan, health care clearinghouse, or health care provider that transmits health information electronically.
- Customer Proprietary Network Information (CPNI)
Telecom data about a customer's use of services (e.g., call detail); protected under the Telecommunications Act and FCC rules.
- Data Breach
- A security incident in which personal data is accessed, disclosed, altered, or lost without authorization. Many laws require prompt notification of regulators and affected individuals.
- Data Broker
- A company whose business is collecting personal information from many sources and selling or licensing it — often without any direct relationship with, or awareness by, the people it profiles.
- Data Controller
- The organization or person that determines the purposes and means of processing personal data. Controllers bear primary legal responsibility for compliance.
- Data Custodian
The technical role responsible for storing and maintaining data safely. Distinct from the data owner or steward who makes decisions about it — the IT function in the chain.
Course relevance: The accountability question: when harm occurs, is the custodian responsible for how the data was stored, or only for following the owner's instructions?
- Data Fiduciary
An emerging concept: an entity that owes a legal duty of loyalty to the data subject, similar to how a financial advisor owes a fiduciary duty to a client. Not yet standard in US law.
Course relevance: The argument that controllers should be legally obligated to act in the interest of the data subject, not just their own commercial interest. India has experimented with this; it appears in some US legislative proposals.
- Data Minimization
- The principle that an organization should collect and retain only the personal data that is actually necessary for a specified purpose, and no more.
- Data Owner
The business unit or individual accountable for a specific data asset within an organization. Decides who can access it and approves its use. A governance term, not a legal one.
Course relevance: Internal accountability anchor. When governance structures fail, identifying who the data owner was — and whether they fulfilled their obligations — is often where the analysis starts.
- Data Portability
- The right to receive one’s personal data in a structured, commonly used, machine-readable format and to transmit it to another service provider.
- Data pro
A company that aggregates and sells personal information about consumers, often without a direct relationship with them.
- Data Processing Agreement (DPA)
A contract between a controller and processor specifying what the processor can and cannot do with the data. Required under GDPR. Defines purpose limitation, security obligations, sub-processor authorization, and breach notification.
Course relevance: The governance document that is supposed to make the processor relationship accountable. The course examines what happens when DPAs are absent, inadequate, or unenforced.
- Data Processor
- A party that processes personal data on behalf of, and under the instructions of, a controller (for example a cloud vendor or payroll provider).
- Data Protection by Design and by Default
- The GDPR Article 25 obligation to embed data-protection measures into processing activities and to default to the most privacy-protective settings and minimal data.
- Data Protection Impact Assessment (DPIA)
- A structured process for identifying and mitigating the privacy risks of a project or system before deployment, required under the GDPR for high-risk processing.
- Data Protection Officer (DPO)
A designated individual within an organization responsible for overseeing data protection compliance. Required under GDPR for certain organizations.
Course relevance: The person whose job is to ask whether what the organization is doing is legal and ethical. Week 13 asks what happens when they are ignored.
- Data Recipient
Any entity to whom data is disclosed. Broader than 'processor' — includes third parties who receive data as part of legitimate business operations.
Course relevance: The aggregation problem lives here. Each recipient may recombine data with their own sources in ways the data subject never anticipated.
- Data Sovereignty
- The idea that data is subject to the laws and governance of the nation in which it is collected or stored, which shapes where and how data may be processed.
- Data Steward
An internal role responsible for the quality, integrity, and appropriate use of specific data assets within an organization. Not a legal term — a governance term.
Course relevance: The person inside the organization who is supposed to care about the data as a professional obligation. Week 13 asks what happens when they are overruled.
- Data Subject
- The living individual whom a given set of personal data is about, and whose rights the privacy laws are designed to protect.
- Data Subject Access Request (DSAR)
- A request by an individual to obtain a copy of the personal data an organization holds about them, along with information about how and why it is being processed.
- Datasheet for Datasets
- Documentation describing a dataset's composition, collection process, intended uses, and limitations to support transparency and accountability.
- De-identification
- The general practice of removing or obscuring identifiers from a dataset to reduce the risk of linking records to individuals; strength ranges from weak masking to formal anonymization.
- Deep Learning
- A form of machine learning that uses multi-layered (deep) neural networks to model complex patterns in large datasets.
- Deepfake
- Synthetic media in which a person's likeness or voice is convincingly fabricated or manipulated using AI.
- Department of Health and Human Services (HHS)
Federal agency that issues and enforces HIPAA rules, primarily through its Office for Civil Rights.
- Deployer (AI Act)
- Under the EU AI Act, the entity that uses an AI system under its own authority (referred to as the 'user' in earlier drafts).
- Differential Privacy
- A rigorous mathematical framework that adds carefully calibrated random noise to data or query results, so that analysts can learn population-level patterns while provably limiting what can be inferred about any single individual.
- Digital Advertising Alliance (DAA)
Self-regulatory body for online behavioral advertising, known for the AdChoices icon and opt-out program.
- Digital Markets Act (DMA)
- The EU regulation imposing obligations on large 'gatekeeper' platforms to keep digital markets fair and contestable.
- Digital Services Act (DSA)
- The EU regulation governing online intermediaries and platforms, addressing illegal content, advertising transparency, and systemic risks of very large platforms.
- Disposal Rule
FACTA rule requiring reasonable measures to properly dispose of consumer report information to protect against unauthorized access.
- Dodd-Frank Act
2010 financial-reform law that created the CFPB and added consumer financial protections.
- Driver's Privacy Protection Act (DPPA)
1994 law restricting disclosure and use of personal information from state motor-vehicle records.
- E-Government Act of 2002
Law requiring federal agencies to conduct Privacy Impact Assessments for systems handling personal information.
- Electronic Communications Privacy Act (ECPA)
1986 law governing interception and access to electronic communications; includes the Wiretap Act, Stored Communications Act, and Pen Register Act.
- Employee Polygraph Protection Act (EPPA)
Generally prohibits private employers from using lie-detector tests on employees and applicants.
- Encryption
- Encoding information so that only parties holding the correct key can read it. End-to-end encryption keeps data unreadable to intermediaries, including the service provider.
- ePrivacy Directive
- The EU directive governing privacy in electronic communications — including the consent rules for cookies and similar technologies — intended to be replaced by the ePrivacy Regulation.
- Established Business Relationship (EBR)
A prior or existing relationship that can serve as a limited exception to certain Do-Not-Call/telemarketing restrictions.
- EU AI Act
- The European Union's risk-based regulation of AI systems (adopted 2024), imposing tiered obligations ranging from prohibited to high-risk to minimal-risk uses.
- EU-U.S. Data Privacy Framework (DPF)
Mechanism allowing certified U.S. organizations to receive personal data from the EU consistent with EU adequacy requirements.
- EU-US Data Privacy Framework
- The 2023 adequacy mechanism permitting transfers of personal data from the EU to certified US organizations, succeeding the invalidated Privacy Shield.
- European Data Protection Board (EDPB)
- The EU body composed of the national supervisory authorities that ensures consistent application of the GDPR and issues guidance; it replaced the Article 29 Working Party in 2018.
- European Data Protection Supervisor (EDPS)
- The independent supervisory authority responsible for monitoring the processing of personal data by EU institutions and bodies.
- Explainability (XAI)
- The degree to which an AI system's outputs and behavior can be described in human-understandable terms.
- Fair and Accurate Credit Transactions Act (FACTA)
2003 FCRA amendment adding identity-theft protections, free annual credit reports, the Red Flags Rule, and the Disposal Rule.
- Fair Credit Reporting Act (FCRA)
1970 law regulating consumer reporting agencies and the collection, use, and accuracy of consumer report (credit) information.
- Fair Information Practice Principles (FIPPs)
- A foundational set of privacy principles — notice, choice, access, accuracy, data minimization, security, and accountability — that underpin most modern privacy law and policy.
- Fairness (AI)
- The goal that an AI system not produce unjustified discriminatory or inequitable outcomes across individuals or groups.
- Family Educational Rights and Privacy Act (FERPA)
1974 law protecting the privacy of student education records and giving parents/eligible students access and amendment rights.
- FCRA in Employment
When employers use third parties for background checks, the FCRA requires disclosure, written consent, and pre/post-adverse-action notices.
- Federal Communications Commission (FCC)
Regulates interstate communications; enforces telecom privacy rules such as CPNI, the TCPA, and Do-Not-Call provisions.
- Federal Information Security Management Act (FISMA)
Law requiring federal agencies to develop and implement information security programs.
- Federal Trade Commission (FTC)
Primary U.S. federal privacy and consumer-protection regulator; enforces against unfair or deceptive practices under Section 5 of the FTC Act.
- Federated Learning
- A technique that trains a shared model across decentralized devices or servers holding local data, without centralizing the raw data.
- FERPA
- The US Family Educational Rights and Privacy Act, which protects the privacy of student education records and gives parents and eligible students rights over those records.
- First-Party vs. Third-Party Data
First-party data is collected by an organization directly from its users; third-party data is obtained from outside sources/trackers.
- Foreign Intelligence Surveillance Act (FISA)
1978 law establishing procedures and a special court (FISC) for foreign-intelligence surveillance.
- Foundation Model
- A large model trained on broad data that can be adapted or fine-tuned to a wide range of downstream tasks.
- Fourth Amendment
Constitutional protection against unreasonable searches and seizures by the government; the basis for many privacy protections against state actors.
- Freedom of Information Act (FOIA)
Law granting public access to federal agency records, subject to exemptions including one for personal privacy.
- FTC Act Section 5
Prohibits 'unfair or deceptive acts or practices' (UDAP) in commerce; the FTC's main authority to police broken privacy promises and unfair data practices.
- Fundamental Rights Impact Assessment (FRIA)
- An assessment of an AI system's potential impact on people's fundamental rights, required for certain high-risk deployments under the EU AI Act.
- GDPR
- The General Data Protection Regulation — the European Union’s comprehensive data-protection law, in force since 2018. It grants individuals broad rights over their data and imposes obligations (and large fines) on organizations worldwide that handle EU residents’ data.
- General-Purpose AI (GPAI)
- Under the EU AI Act, an AI model capable of performing a wide range of distinct tasks and being integrated into many downstream systems.
- Generally Accepted Privacy Principles (GAPP)
A privacy framework (AICPA/CICA) of ten principles for managing and evaluating privacy.
- Generative AI
- AI that produces new content — text, images, audio, video, or code — rather than only classifying or predicting from inputs.
- Genetic Information (Employment)
Under GINA, employers generally may not request, require, or use employees' genetic information.
- Genetic Information Nondiscrimination Act (GINA)
2008 law prohibiting discrimination based on genetic information in health insurance and employment.
- GLBA Privacy Rule
Requires financial institutions to give privacy notices and let consumers opt out of certain sharing of NPI with nonaffiliated third parties.
- GLBA Safeguards Rule
Requires financial institutions to maintain a written information security program to protect customer information.
- Gramm-Leach-Bliley Act (GLBA)
1999 law governing how financial institutions collect, use, and protect consumers' nonpublic personal information; includes the Privacy Rule and Safeguards Rule.
- Griswold v. Connecticut
1965 Supreme Court case recognizing a constitutional right to privacy in marital/contraceptive decisions, inferred from several amendments.
- Hallucination
- A confident but false or fabricated output produced by a generative AI model.
- Health Insurance Portability and Accountability Act (HIPAA)
1996 law that, with its rules, governs the privacy and security of protected health information held by covered entities and business associates.
- High-Risk AI System
- Under the EU AI Act, an AI use (e.g., in employment, credit, biometrics, education, or critical infrastructure) subject to strict requirements before and after being placed on the market.
- HIPAA
- The US Health Insurance Portability and Accountability Act, which sets national standards for protecting individuals’ medical records and other protected health information.
An individual's signed permission required for uses/disclosures of PHI not otherwise permitted, such as most marketing.
- HIPAA Privacy Rule
Sets national standards for the use and disclosure of PHI and gives individuals rights over their health information.
- HIPAA Security Rule
Requires administrative, physical, and technical safeguards to protect electronic PHI (ePHI).
- HITECH Act
2009 law that strengthened HIPAA, added breach-notification requirements, and extended direct liability to business associates.
- Human Oversight
- Governance measures ensuring people can monitor, intervene in, or override an AI system, particularly for high-risk uses.
- Human-in-the-Loop
- A design in which a human reviews, approves, or can override an AI system's outputs before they take effect.
- Identity Theft
The fraudulent use of another person's personal information, typically for financial gain.
- Incident Response Plan
A documented process for detecting, containing, investigating, and remediating privacy/security incidents and breaches.
- Inference
- The stage at which a trained model is used to generate outputs or predictions on new, unseen inputs.
- Information Privacy
The right or ability to determine what personal information is collected, how it is used, and to whom it is disclosed.
- Informed Consent
- Consent given by someone who genuinely understands what they are agreeing to — the nature of the data collected, how it will be used, and the risks involved. A central ethical standard often unmet in practice online.
- Interpretability
- The extent to which a human can understand the internal mechanics by which a model reaches its decisions.
- Intrusion Upon Seclusion
A privacy tort for intentionally intruding on someone's solitude or private affairs in a manner highly offensive to a reasonable person.
- Joint Controllers
Two or more entities that jointly determine the purposes and means of processing. They share accountability and liability.
Course relevance: Facebook and Cambridge Analytica were arguably joint controllers. Both pointed at each other; neither was adequately held accountable in real time.
- Junk Fax Prevention Act
2005 law amending the TCPA to restrict unsolicited fax advertisements and require opt-out notices.
- Katz v. United States
1967 Supreme Court case establishing that the Fourth Amendment protects people, not places, and creating the reasonable-expectation-of-privacy test.
- Large Language Model (LLM)
- A foundation model trained on vast text corpora to understand and generate natural language.
- For cross-border processing, the single supervisory authority — that of the controller's or processor's main establishment — that takes the lead under the one-stop-shop mechanism.
- Legitimate Interest Assessment (LIA)
- A documented balancing test an organization performs — purpose, necessity, and balancing against individuals' rights — before relying on the legitimate-interests basis.
- Legitimate Interests
- A GDPR lawful basis permitting processing necessary for the legitimate interests of the controller or a third party, provided those interests are not overridden by the data subject's interests or fundamental rights.
- Machine Learning (ML)
- A subfield of AI in which systems learn patterns from data to make predictions or decisions without being explicitly programmed for each case.
- Main Establishment
- The place of a controller's central administration in the EU (or where key processing decisions are taken), used to determine its lead supervisory authority.
- Metadata
- “Data about data” — information such as who contacted whom, when, from where, and for how long, as opposed to the content itself. Metadata can be deeply revealing even without message contents.
- Minimum Necessary
HIPAA principle that uses and disclosures of PHI be limited to the least amount needed to accomplish the purpose.
- Model Card
- A short document describing a model's intended uses, performance, limitations, and evaluation across relevant conditions and groups.
- Model Drift
- The degradation of a model's performance over time as real-world data diverges from the data it was trained on.
- National Do-Not-Call Registry
A list consumers join to stop most telemarketing calls; telemarketers must scrub their lists against it.
- National Labor Relations Act (NLRA)
Protects employees' concerted activity, which can limit how employers monitor or restrict workplace communications.
- Network Advertising Initiative (NAI)
Self-regulatory organization of third-party digital advertising companies offering an opt-out mechanism.
- Neural Network
- A computing model loosely inspired by the brain, composed of interconnected layers of 'neurons' that transform inputs into outputs.
- NIS2 Directive
- The EU directive strengthening and harmonizing cybersecurity risk-management and incident-reporting requirements across essential and important sectors.
- NIST AI Risk Management Framework (AI RMF)
- A voluntary US framework for identifying and managing AI risks across the lifecycle, organized around the functions Govern, Map, Measure, and Manage.
- NIST Privacy Framework
A voluntary NIST framework to help organizations identify and manage privacy risk.
- Nonpublic Personal Information (NPI)
Under the GLBA, personally identifiable financial information a consumer provides to a financial institution that is not publicly available.
- Notice
Informing individuals about an organization's information practices, typically via a privacy notice or policy.
- Notice and Choice
- The dominant US model of privacy self-management, in which companies post a privacy notice and users “choose” by continuing to use the service — widely criticized because few people read or can meaningfully evaluate such notices.
- OECD AI Principles
- Intergovernmental principles for trustworthy AI emphasizing human-centered values, transparency, robustness, safety, and accountability.
- Office for Civil Rights (OCR)
The HHS office that enforces the HIPAA Privacy, Security, and Breach Notification Rules.
- One-Stop-Shop Mechanism
- The GDPR system that lets an organization engaged in cross-border processing deal primarily with a single lead supervisory authority rather than each affected member state's authority.
- Online Behavioral Advertising (OBA)
Tracking a user's online activity over time to deliver targeted ads; subject to self-regulatory frameworks (DAA, NAI).
- Opt-In
A consent model requiring an individual's affirmative action before data is collected or used.
- Opt-Out
A consent model permitting use unless the individual takes action to decline.
- Overfitting
- When a model learns the noise and specifics of its training data too closely and therefore generalizes poorly to new data.
- Panopticon
- Jeremy Bentham’s prison design in which inmates can always be watched but never know when; adopted by Michel Foucault as a metaphor for how pervasive surveillance disciplines behavior.
- Pen Register / Trap and Trace
Devices/processes capturing dialing, routing, and signaling information (not content); governed by ECPA Title III.
- Permissible Purpose
Under the FCRA, the limited legitimate reasons (e.g., credit, employment, insurance) for which a consumer report may be obtained.
- Personal Data Breach Notification
- Under GDPR Articles 33-34, controllers must notify the supervisory authority of a personal data breach within 72 hours of awareness and inform affected individuals when the breach poses a high risk to their rights.
- Personally Identifiable Information (PII)
- Any information that can be used, alone or combined with other data, to identify a specific individual — e.g. a name, email, government ID, or device identifier.
- Preemption
When federal law overrides conflicting state law; many U.S. privacy laws set a federal floor while allowing stricter state laws (no field preemption).
- Pretexting
Obtaining personal information under false pretenses; prohibited by the GLBA.
- Prior Consultation
- The GDPR requirement to consult the supervisory authority before processing where a DPIA indicates a high risk that the controller cannot mitigate.
- Prior Express Written Consent
The TCPA standard required before sending telemarketing robocalls/texts to consumers.
- Privacy
The right to be let alone, and the ability of individuals to control the collection, use, and disclosure of their personal information.
- Privacy Act of 1974
Governs federal agencies' collection, use, and disclosure of personally identifiable records in systems of records; gives individuals access and amendment rights.
- Privacy by Design
- An approach that builds privacy protections into the design and architecture of systems and processes from the outset, rather than bolting them on afterward.
- Privacy Impact Assessment (PIA)
A process to evaluate and mitigate privacy risks of a system or initiative that handles personal information.
- Privacy Shield
Former EU-U.S. (and Swiss-U.S.) transfer framework invalidated by the Schrems II decision in 2020.
- Privacy Torts (Prosser)
Four common-law privacy torts: intrusion upon seclusion, public disclosure of private facts, false light, and appropriation of name or likeness.
- Private Right of Action
A statutory provision allowing individuals (not just regulators) to sue for violations; present in laws like the TCPA, VPPA, BIPA, and parts of the CCPA.
- Profiling
- Automated processing of personal data to evaluate, analyze, or predict aspects of a person, such as their interests, behavior, health, or reliability.
- Prohibited AI Practices
- AI uses banned under the EU AI Act, such as government social scoring and certain manipulative, exploitative, or untargeted biometric-surveillance systems.
- Protected Health Information (PHI)
Under HIPAA, individually identifiable health information held or transmitted by a covered entity or business associate.
- Protection of Pupil Rights Amendment (PPRA)
Law governing surveys, evaluations, and the collection of information from students for marketing purposes in schools.
- Provider (AI Act)
- Under the EU AI Act, the entity that develops an AI system (or has it developed) and places it on the market or puts it into service under its own name.
- Pseudonymization
- Replacing identifying fields with artificial identifiers (pseudonyms) so data cannot be attributed to a person without additional information kept separately. Unlike anonymization, it is reversible and the data remains “personal.”
- Purpose Limitation
- The principle that personal data collected for one stated purpose should not later be used for unrelated, incompatible purposes without a fresh basis.
- Re-identification
- The process of matching supposedly anonymous or de-identified data back to the individuals it describes, often by combining it with other available datasets — a key reason anonymization is hard.
- Reasonable Expectation of Privacy
Two-part test (from Katz) asking whether a person exhibited an actual expectation of privacy that society recognizes as reasonable.
- Records of Processing Activities (ROPA)
- The inventory of processing operations that controllers and processors must maintain and make available to supervisory authorities under GDPR Article 30.
- Red Flags Rule
Requires certain financial institutions and creditors to implement programs to detect and respond to identity-theft warning signs.
- Red-Teaming
- Structured adversarial testing of an AI system to surface harmful behaviors, vulnerabilities, and failure modes before deployment.
- Reinforcement Learning from Human Feedback (RLHF)
- A training technique that fine-tunes a model using human preference judgments to better align its outputs with desired behavior.
- Representative (Article 27)
- An EU-based representative that controllers and processors not established in the EU must designate when the GDPR applies to their processing.
- Right to be Informed
- The data subject's right to receive clear, transparent information about the collection and use of their data at the time it is obtained (GDPR Articles 13-14).
- Right to Erasure (Right to Be Forgotten)
- An individual’s right, under laws like the GDPR, to request deletion of their personal data when it is no longer necessary or when consent is withdrawn, subject to certain exceptions.
- Right to Financial Privacy Act (RFPA)
1978 law limiting federal government access to customers' financial records held by banks.
- Right to Object
- A data subject's right to object to certain processing of their data, including processing for direct marketing (absolute) and processing based on legitimate interests or public task.
- Right to Rectification
- A data subject's right to have inaccurate personal data corrected and incomplete data completed.
- Right to Restriction of Processing
- A data subject's right to have the processing of their personal data limited — stored but not otherwise used — in specified circumstances.
- Robustness
- An AI system's ability to maintain reliable performance under noise, distribution shifts, or adversarial conditions.
- Safe Harbor (Encryption)
Many breach-notification laws excuse notice if the breached data was encrypted and the key was not compromised.
- Schrems II
2020 EU Court of Justice decision invalidating Privacy Shield and adding scrutiny to SCC-based transfers to the U.S.
- Sectoral Approach
The U.S. model of regulating privacy industry-by-industry (health, finance, telecom) rather than via one comprehensive law.
- Self-Regulation
Industry-developed privacy codes and enforcement (e.g., DAA, NAI, PCI DSS) supplementing or filling gaps in law.
- Sensitive Personal Data
- Categories of data treated as especially high-risk and given extra legal protection — such as health, race or ethnicity, religion, sexual orientation, political views, and biometric or genetic data (called “special category data” under the GDPR).
- Sensitive Personal Information (SPI)
PII that carries heightened risk if disclosed, such as Social Security numbers, financial account data, health information, biometrics, or precise geolocation.
- Service Provider
Processes personal information on behalf of the business. Roughly equivalent to a data processor. Must be bound by a contract prohibiting use of the data for other purposes.
Course relevance: The contractual prohibition is only as strong as the enforcement mechanism behind it. The course asks: who enforces it, and what happens when they don't?
- SHIELD Act
New York law expanding breach-notification requirements and mandating reasonable data-security safeguards.
- Smith v. Maryland
1979 Supreme Court case establishing the third-party doctrine: no reasonable expectation of privacy in numbers dialed and shared with the phone company.
- Special Categories of Personal Data
- GDPR Article 9 data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetics, biometrics, health, or sex life/orientation, whose processing is prohibited unless a specific condition applies.
- Standard Contractual Clauses (SCCs)
- Pre-approved contractual terms that organizations use to legally transfer personal data out of the EU to countries without an “adequacy” determination.
- State Attorneys General
State officials with authority to enforce many federal privacy laws (e.g., HIPAA, COPPA) and state privacy and breach-notification statutes.
- Stored Communications Act (SCA)
ECPA Title II, governing government and third-party access to stored electronic communications and records held by service providers.
- Sub-processor
A third party engaged by the processor to assist with processing. Often invisible to the data subject. The controller may not know who sub-processors are.
Course relevance: Where accountability goes dark. You consented to the app — not to its three analytics vendors, cloud provider, and AI partner.
The regulatory body that enforces data protection law in each EU member state (ICO in the UK, CNIL in France, etc.). An external check on the whole chain.
Course relevance: The enforcement mechanism. The course asks repeatedly: what happens when this mechanism fails or is absent?
- Surveillance Capitalism
- A term coined by Shoshana Zuboff for an economic logic that claims human experience as free raw material, extracting behavioral data to build predictive products sold in “behavioral futures” markets.
- Synthetic Data
- Artificially generated data that mimics the statistical properties of real data, used to train or test models while reducing privacy risk.
- System of Records
Under the Privacy Act, a group of agency records retrieved by an individual's name or identifier; requires a published System of Records Notice (SORN).
- Telecommunications Act of 1996
Major telecom-reform law containing privacy protections including CPNI.
- Telemarketing Sales Rule (TSR)
FTC rule implementing the Telemarketing and Consumer Fraud and Abuse Prevention Act; governs telemarketing conduct and the Do-Not-Call Registry.
- Telephone Consumer Protection Act (TCPA)
1991 law restricting telemarketing calls, autodialers, prerecorded messages, and texts; includes a private right of action.
- The Right to Privacy (Warren & Brandeis)
Influential 1890 Harvard Law Review article by Samuel Warren and Louis Brandeis articulating a legal 'right to be let alone'; foundational to U.S. privacy tort law.
- Third Party
Any entity other than the data subject, controller, processor, or supervisory authority — the catch-all for everyone else in the chain. Under the CCPA, an entity that receives personal information but is not a service provider; the key distinction is that third parties can use data for their own purposes, while service providers cannot.
Course relevance: The unregulated space — third parties are not bound by the same obligations as processors, and this is where purpose limitation breaks down. The CCPA permission structure that makes data-broker operations legal: a third party is not bound by the purpose limitation that governs service providers.
- Third Party Recipient
Receives data at the end of the chain. May use it for purposes the data subject never anticipated.
Course relevance: The aggregation-problem endpoint.
- A small file set by a domain other than the site being visited, historically used to track users across many sites for advertising and profiling.
- Third-Party Doctrine
Principle that information voluntarily shared with a third party generally loses Fourth Amendment protection.
- Training Data
- The dataset used to teach a model; its quality, representativeness, and provenance strongly shape the model's behavior and bias.
- Transfer Impact Assessment (TIA)
- An assessment, required after Schrems II, of whether the destination of an international data transfer provides protection essentially equivalent to the EU's, and what supplementary measures are needed.
- Treatment, Payment, and Health Care Operations (TPO)
Core activities for which HIPAA permits PHI use/disclosure without individual authorization.
- Trustworthy AI
- AI that is lawful, ethical, and robust — commonly framed around fairness, transparency, accountability, safety, and privacy.
- Unfair or Deceptive Acts or Practices (UDAP)
Conduct that is deceptive (a material misrepresentation likely to mislead) or unfair (causing substantial, unavoidable consumer injury not outweighed by benefits).
- USA FREEDOM Act
2015 law that curtailed bulk collection of telephone metadata and reformed certain PATRIOT Act surveillance authorities.
- USA PATRIOT Act
2001 law that expanded government surveillance and information-sharing powers after 9/11.
- Vendor / Third-Party Management
Due diligence and contractual controls (e.g., DPAs) over service providers that process personal information.
- Verifiable Parental Consent
The reasonable-effort consent COPPA requires operators to obtain from a parent before collecting a child's personal information.
- Video Privacy Protection Act (VPPA)
1988 law restricting disclosure of consumers' video rental/viewing records; includes a private right of action.
- Wiretap Act
ECPA Title I, restricting real-time interception of the contents of wire, oral, and electronic communications.
- Workplace Monitoring
Employer surveillance of communications and activity; constrained by ECPA exceptions (consent, business use) and state laws.