Personal Data Privacy: The Complete Reference Glossary
Photo credit: Telecom360.net | Connecting You To The Latest In Telecom
In this article
From metadata to data brokers, this reference glossary defines the key terms used in online privacy — clearly and without technical overload.
How to Use This Glossary
Privacy documentation — from app permission screens to cookie consent banners — relies on a shared vocabulary that most people were never taught. This reference glossary defines the core terms used in personal data privacy, so you can read policies, news coverage, and security guidance with genuine comprehension rather than guesswork.
Terms are grouped thematically below. For a broader introduction to why this language matters in practice, see what online privacy actually means. If you're newer to the subject, Online Privacy From Scratch offers a no-jargon entry point before diving into definitions.
| Primary US Federal Privacy Law | No single comprehensive federal law; sector-specific laws apply (HIPAA, COPPA, FERPA) |
| EU Privacy Framework | General Data Protection Regulation (GDPR), in effect since May 2018 |
| Data Broker Industry Size | Thousands of companies operate globally; U.S. market estimated at several billion dollars annually (International Association of Privacy Professionals (IAPP)) |
| Most Common Breach Vector | Stolen or compromised credentials (Verizon Data Breach Investigations Report) |
| Right to Erasure Jurisdiction | Available under GDPR (EU) and CCPA (California); not universally guaranteed in the US |
Core Data and Identity Terms
These foundational terms define what personal data is, how it's categorized, and what makes it sensitive. They appear frequently in privacy policies, legal frameworks, and breach disclosures.
The distinction between pseudonymization and full anonymization matters in legal contexts: pseudonymized data is still regulated as personal data under frameworks like the GDPR, because re-identification remains technically possible.
For a deeper look at how data collection connects to legal rights and practical defences, see Online Privacy in Depth.
Tracking, Surveillance, and the Data Economy
Understanding how data moves — and who profits from it — requires familiarity with both tracking technologies and the commercial ecosystem built around them.
US Privacy Law Varies by State
Unlike the European Union's GDPR, the United States does not have a single federal privacy law governing all personal data. Protections vary significantly by state — California's CCPA, Virginia's CDPA, and Colorado's CPA each carry different rights and obligations. Understanding which laws apply to you depends on where you live and where the organizations handling your data are based.
Browser fingerprinting has grown as a tracking method precisely because users have become more effective at blocking cookies. Because it leaves no local trace, it is considerably harder to detect or prevent than traditional cookie-based tracking.
Data brokers represent one of the least visible but most expansive parts of the data economy. Most individuals have never heard of the specific companies holding detailed profiles on them. Learn what data brokers know and how to limit their reach.
Privacy terminology also overlaps with cloud and device contexts. The language of cloud storage and mobile OS terminology each carry their own privacy-relevant vocabulary worth understanding alongside this glossary. For device-level protections, the device security hub covers practical hardening steps.
81%
Adults concerned about company data use
According to Pew Research Center surveys, a substantial majority of US adults report concern about how companies collect and use their personal data.
~1,800
Publicly reported US data breaches in a recent year
The Identity Theft Resource Center tracks data compromise events annually; figures fluctuate year to year based on reporting thresholds.
