Privacy Glossary
50 privacy and data protection terms, defined in plain English for eCommerce teams. Every term has its own in-depth page: a direct definition, how the law treats it, why it matters for your store, and answers to common questions.
CIPA & Wiretap Litigation
- CIPA (California Invasion of Privacy Act)The California Invasion of Privacy Act (CIPA) is a 1967 California wiretapping statute, codified at Penal Code section 630 and following, that plaintiffs now…
- Trap and Trace DeviceA trap and trace device is defined by California Penal Code section 638.50(c) as a device or process that captures incoming electronic impulses identifying t…
- Pen RegisterA pen register is defined by California Penal Code section 638.50(b) as a device or process that records dialing, routing, addressing, or signaling informati…
- Wiretapping (California Penal Code § 631)California Penal Code section 631 is CIPA's wiretapping provision, which prohibits intercepting or reading the contents of a communication in transit without…
- Session ReplaySession replay is a website analytics technology that records a visitor's clicks, mouse movements, scrolling, and keystrokes so the session can be played bac…
- VPPA (Video Privacy Protection Act)The Video Privacy Protection Act (VPPA) is a 1988 federal law, 18 U.S.C. section 2710, that prohibits video tape service providers from disclosing personally…
Tracking Technologies
- Tracking PixelA tracking pixel is a tiny, usually invisible image or JavaScript snippet embedded in a web page or email that sends data about the viewer — such as their IP…
- Meta PixelThe Meta Pixel (formerly Facebook Pixel) is Meta's JavaScript tracking snippet that websites install to measure ad conversions and build retargeting audience…
- First-Party CookiesFirst-party cookies are cookies set by the website the user is actually visiting — the domain in the address bar — and are typically used for sign-in session…
- Third-Party CookiesThird-party cookies are cookies set by a domain other than the website the user is visiting — typically by embedded advertising and tracking scripts — enabli…
- Cross-Site TrackingCross-site tracking is the practice of following the same user across multiple unrelated websites — using third-party cookies, pixels, fingerprinting, or sha…
- RetargetingRetargeting (or remarketing) is a digital advertising technique that shows ads to people who previously visited your website or viewed specific products, usi…
- Server-Side TrackingServer-side tracking is a data collection architecture in which events are sent from the website's own server to analytics and advertising platforms — instea…
- Tag ManagerA tag manager is a tool — Google Tag Manager being the dominant example — that lets teams deploy and control third-party scripts ('tags') like analytics and…
- Cookie ScannerA cookie scanner is a tool that automatically crawls a website to detect and inventory the cookies, pixels, and tracking scripts it sets — including which on…
Privacy Laws
- GDPR (General Data Protection Regulation)The General Data Protection Regulation (GDPR) is the European Union's comprehensive data protection law, in force since May 25, 2018, which governs how organ…
- CCPA (California Consumer Privacy Act)The California Consumer Privacy Act (CCPA) is California's landmark privacy law, effective January 1, 2020, that gives California residents rights to know, d…
- CPRA (California Privacy Rights Act)The California Privacy Rights Act (CPRA) is the 2020 ballot initiative (Proposition 24) that amended and strengthened the CCPA — adding the rights to correct…
- VCDPA (Virginia Consumer Data Protection Act)The Virginia Consumer Data Protection Act (VCDPA) is Virginia's comprehensive privacy law, effective January 1, 2023, which grants Virginia residents rights…
- Washington My Health My Data Act (MHMD)Washington's My Health My Data Act (MHMD) is a consumer health privacy law — in force March 31, 2024 for regulated entities and June 30, 2024 for small busin…
Privacy Rights & Requests
- DSAR (Data Subject Access Request)A DSAR (data subject access request) is a formal request from an individual asking an organization to act on their privacy rights — most commonly to disclose…
- Right to Be Forgotten (Right to Delete)The right to be forgotten — formally the right to erasure under GDPR Article 17, and the right to delete under the CCPA — is an individual's right to have an…
- Right to Access (Right to Know)The right to access — GDPR Article 15's access right and the CCPA's 'right to know' — entitles an individual to obtain confirmation that an organization proc…
Governance & Operations
- Data ControllerA data controller is the organization that determines the purposes and means of processing personal data — the 'why' and 'how' — and therefore bears primary…
- Data ProcessorA data processor is an organization that processes personal data on behalf of and under the instructions of a data controller — such as a cloud host, email p…
- DPO (Data Protection Officer)A Data Protection Officer (DPO) is an independent privacy expert that GDPR Articles 37-39 require certain organizations to appoint — to advise on obligations…
- DPIA (Data Protection Impact Assessment)A DPIA (data protection impact assessment) is a structured analysis, required by GDPR Article 35 before high-risk processing begins, that documents a planned…
- RoPA (Records of Processing Activities)A RoPA (record of processing activities) is the internal inventory GDPR Article 30 requires organizations to maintain, documenting every processing activity…
- Data MappingData mapping is the process of discovering and documenting where personal data lives in an organization and how it flows — what is collected, where it is sto…
- Data Breach NotificationData breach notification is the legal obligation to inform regulators and affected individuals when personal data is exposed, stolen, or destroyed — within 7…
- Privacy PolicyA privacy policy is the public document in which an organization discloses what personal data it collects, why, how it is used and shared, how long it is kep…
- Cookie PolicyA cookie policy is the disclosure document that lists the cookies and tracking technologies a website uses — each with its provider, purpose, and duration —…
Privacy Principles
- Data MinimizationData minimization is the privacy principle — codified in GDPR Article 5(1)(c) — that personal data collected must be adequate, relevant, and limited to what…
- Purpose LimitationPurpose limitation is the privacy principle — GDPR Article 5(1)(b) — that personal data must be collected for specified, explicit, and legitimate purposes an…
- Privacy by DesignPrivacy by design is the principle that privacy protections should be built into systems, products, and processes from the start rather than bolted on afterw…
- Personal Data vs PIIPersonal data and PII (personally identifiable information) are overlapping but distinct concepts: PII is the narrower, traditional US term for data that ide…
- Sensitive Personal InformationSensitive personal information is the class of personal data that laws single out for stronger protection — such as health, biometric, precise geolocation, r…
- Legitimate InterestLegitimate interest is one of the six lawful bases for processing personal data under GDPR Article 6(1)(f), allowing processing necessary for a genuine busin…
See where your site stands
Definitions are the start — a free scan shows every tracker firing on your storefront before consent, graded against CIPA, GDPR, CCPA/CPRA, and Washington MHMD.
Run a Free Compliance Scan