Operate
Legal, Privacy & Compliance
Privacy, data protection, and the other rules you can't ignore.
Busted
- Acceptable Use Policy (AUP)The rulebook listing what users may not do with a product, from spam and harassment to malware, fraud, rights violations, and resource abuse.
- Accessibility Conformance Report (ACR)The filled-out accessibility report, often made from a VPAT, that tells buyers which standards a specific product version meets.
- Age assuranceThe checks used to decide whether someone is old enough for a product, from a birthday question to ID or facial age estimation.
- AI transparency obligationThe duty to tell people when they are dealing with AI or seeing certain AI-made content, instead of letting the machine pass as human or real.
- Anonymization vs. pseudonymizationAnonymized data cannot reasonably be traced back to a person, so privacy law stops applying. Pseudonymized data hides the name behind a key.
- CCPA, as amended by the CPRACalifornia's privacy law: residents can ask what you collected, demand deletion, and opt out of you selling or sharing it with ad platforms.
- Clickwrap vs. browsewrapClickwrap makes users tick a box to accept your terms. Browsewrap just links them in the footer and hopes. Clickwrap holds up far more reliably.
- Consent Management Platform (CMP)The tool behind the cookie banner: it collects consent choices, stores the proof, and stops tagged scripts firing until someone says yes.
- Consent record / proof of consentThe audit trail proving who consented, when, how, for which purposes, under which wording, and when they withdrew.
- Content moderation and notice-and-actionThe report-review-decision-appeal loop a service uses to handle illegal or rule-breaking posts, uploads, listings, and messages.
- Cookie consent bannerThe overlay that asks permission before non-essential cookies and trackers load. The 'accept all' bar on every EU site.
- Cookie policyThe page listing every cookie and tracker you set: its name, who set it, what it does, how long it lasts, and how to switch it off.
- COPPAThe U.S. law that makes many child-directed services get a parent's permission before collecting data from a child under 13.
- Cross-border data transferPersonal data crossing a legal border, including a US vendor merely viewing an EU record. EU law needs a mechanism in place before it moves.
- Data breach notificationThe clock that starts the moment you learn of a leak: tell the regulator (often within 72 hours) and tell affected users when the risk is high.
- Data controller and data processorController decides why and how data gets used; processor just handles it on orders. The split decides who is legally on the hook.
- Data inventory / data mapThe living map of what personal data you hold, where it enters and lives, why it exists, who receives it, and how it gets deleted.
- Data minimizationCollect only the data you actually use, nothing 'just in case'. Every extra field is one more thing to protect, explain, and delete.
- Data Processing Agreement (DPA)The contract required before a vendor touches your users' data: what they may do with it, how they protect it, what happens when you leave.
- Data Protection Impact Assessment (DPIA)The formal privacy risk review done before high-risk processing, while the design can still change and harms can still be reduced.
- Data Protection Officer (DPO)The independent privacy adviser who monitors compliance, advises on DPIAs, and serves as a contact for people and regulators.
- Data residencyThe rule that customer data and its copies must stay in a named country or region, such as the EU.
- Data retention policyA written rule for how long each kind of data lives before deletion, plus the job that actually deletes it.
- Data subject request (DSR)A user formally asking to see, export, correct, or delete their data, and the clock that starts the moment it lands in your inbox.
- Data subject rightsThe list of things a user can legally demand about their own data: see it, fix it, delete it, export it, or make you stop using it.
- Digital Services Act (DSA)The EU rulebook that makes online intermediaries handle illegal-content reports, explain moderation, label ads, and disclose how platforms operate.
- DMCA takedown / safe harborThe US notice-and-takedown process that can protect hosts from copyright liability when they follow Section 512's conditions.
- Do Not Sell or Share My Personal InformationThe footer opt-out California law requires if you sell personal information at all, or share it for cross-context behavioral advertising.
- ePrivacy DirectiveThe EU rules behind cookie consent: non-essential storage or access on a device waits for permission, alongside GDPR.
- EU AI ActThe EU law that bans a few AI uses and adds heavier duties as an AI system's role and risk increase.
- EU-U.S. Data Privacy FrameworkThe U.S. certification program that can let a listed American company receive personal data from the EU without separate transfer clauses.
- GDPRThe EU law saying you need a legal reason to hold someone's personal data, and they can demand to see, correct, or delete it.
- Governing law and forum clauseThe contract clause choosing which jurisdiction's law interprets the deal and which courts may hear disputes.
- HIPAA; Business Associate Agreement (BAA)HIPAA governs protected U.S. health data; a BAA is the contract required when a vendor handles that data for a covered organization.
- Indemnification clauseA promise that if someone else sues them over something you did, you pay: the damages, the settlement, and usually their legal bills too.
- Intellectual property licensePermission to use intellectual property in specified ways without taking ownership of it, from code and fonts to photos, music, brands, and data.
- ISO 27001The international standard for running an audited, risk-based information security management system rather than a loose pile of controls.
- Lawful basisThe legal reason you are allowed to process someone's data at all. Under GDPR you pick one of six, before you collect, not after.
- Legitimate interest assessment (LIA)The written three-part test showing why your legitimate interest, necessity, and safeguards outweigh the privacy impact.
- Limitation of liability clauseThe contract paragraph that caps how much you can be made to pay when things go wrong, usually at the fees already paid to you.
- Model release / property releaseThe signed permission that clears a recognizable person or controlled property for specified commercial photo, video, or advertising uses.
- Non-Disclosure Agreement (NDA)The contract that says: I'll show you the confidential stuff, you won't repeat it or use it for anything else. Signed before the real conversation.
- Notice at collectionThe privacy disclosure shown when data is collected, telling people what you take, why, how long, and whether it is sold or shared.
- Opt-in vs. opt-outOpt-in waits for a clear yes before processing; opt-out processes until a person says no. The law decides which model fits each use.
- Personal data / PIIAny data relating to an identified or identifiable person, including data that just singles someone out: IP addresses, device IDs, cookie IDs.
- Privacy by designBuilding privacy into the product from the first sketch instead of patching it in before launch. Defaults process only what the purpose needs.
- Privacy policyThe public page telling users what data you collect, why, who you share it with, and how they can get it back or deleted.
- Record of Processing Activities (ROPA)The Article 30 register listing your real data-processing activities, their purposes, people, data, recipients, transfers, and retention.
- Right of publicityA person's control over commercial uses of their identity, such as putting their name, face, or recognizable voice in an ad.
- Right to erasure / right to be forgottenA user's right to make you actually delete their data wherever it lives, not just flip a flag, minus whatever you can prove you must keep.
- Security questionnaireThe long vendor-risk form an enterprise buyer sends to check your security controls before it purchases or shares data.
- Sensitive personal data / informationHigher-risk data such as health, biometrics, beliefs, precise location, or credentials that gets extra legal and security protection.
- SOC 2 reportAn independent CPA's report on whether a service company's security controls are well designed and, for Type II, worked over time.
- Standard Contractual Clauses (SCCs)Pre-approved EU contract text you bolt onto a vendor agreement so personal data can legally leave Europe. Fill in the annexes, never edit the clauses.
- SubprocessorA vendor your vendor uses. Your email tool runs on AWS, so AWS handles your users' data too, and you have to disclose it.
- Supervisory authority / data protection authorityThe independent privacy regulator that handles complaints, investigates misuse, receives breach notices, and can order changes or fines.
- Terms of Service (ToS)The contract users accept to use your product: what they may do, what you owe them, and what happens when things go wrong.
- Trust center / trust pageThe public security and compliance page where buyers check certifications, policies, subprocessors, and request private audit documents.
- Warranty disclaimerThe 'as is' clause saying the product comes without unstated promises that it will be flawless, uninterrupted, or fit for every user's purpose.
- Work made for hire; IP assignmentThe clause deciding who owns what you made: you by default, or the client the moment they pay. Two legal mechanisms, one outcome.
The territory
28 core terms mapped for this field, ranked by how often builders reach for them. Each one is a future entry. Want to bust one? One entry, one file, one pull request.
- Privacy policyPublic document stating what data you collect and why"the legal page every site has" · "the data blurb in the footer"
- Terms of Service (ToS)Contract users accept to use your product"the rules page" · "the thing nobody reads before signing up"
- Cookie consent bannerOverlay asking permission before setting non-essential cookies"that annoying popup about cookies" · "the accept-all bar"
- Cookie policyNotice explaining cookies, purposes, providers, lifetimes, and user controls"the page explaining the cookies" · "cookie list page"
- Consent Management Platform (CMP)Tool that collects, stores, and enforces user consent choices"the thing that runs the cookie popup" · "consent tool"
- GDPREU law governing personal data collection, use, and rights"the European privacy law" · "why everyone asks about cookies"
- CCPA, as amended by the CPRACalifornia privacy law giving residents data access and opt-out rights"CCPA/CPRA" · "the California privacy law"
- Personal data / PIIData that identifies a specific person"sensitive user info" · "stuff you can't leak"
- Data subject rightsRights to access, correct, delete, restrict, object, and port data"what users can legally demand" · "the GDPR rights list"
- Data subject request (DSR)User request to see, export, or delete their data"DSAR" · "the download-my-data request"
- Right to erasure / right to be forgottenUser's right to have their data deleted"delete my account for real" · "wipe me from your database"
- Lawful basisThe legal justification you rely on to process data"the reason I'm allowed to collect this" · "consent or legitimate interest"
- Data controller and data processorWho decides data use vs. who merely handles it"am I the owner or the middleman" · "whose responsibility is the data"
- Data Processing Agreement (DPA)Contract binding a vendor handling data on your behalf"the paperwork vendors ask for" · "the privacy contract with subprocessors"
- SubprocessorThird-party vendor processing data downstream of you"the vendors my vendor uses" · "the tool list I have to publish"
- Data retention policyRule for how long you keep data before deleting"how long do I keep this" · "the auto-delete-after-X rule"
- Data minimizationCollect only what you actually need"stop collecting stuff I don't use" · "less data less risk"
- Privacy by designBuilding privacy protections in from the start, not bolted on"bake privacy in from day one" · "don't bolt privacy on later"
- Anonymization vs. pseudonymizationIrreversibly stripping identity vs. replacing it with a key"is it really anonymous" · "hashed but still traceable"
- Data breach notificationLegal duty to inform users/regulators after a leak"the email you send after a hack" · "72-hour rule"
- Do Not Sell or Share My Personal InformationRequired opt-out link for ad-related data sharing"that footer link about selling data" · "the opt-out link"
- Cross-border data transferMoving personal data between legal jurisdictions"can I host EU users in the US" · "data leaving the country"
- Standard Contractual Clauses (SCCs)Pre-approved contract terms enabling international data transfers"the EU transfer clauses" · "boilerplate for sending data abroad"
- Clickwrap vs. browsewrapExplicit checkbox agreement vs. implied consent by usage"the I-agree checkbox" · "does using the site count as agreeing"
- Limitation of liability clauseContract cap on how much you can be sued for"the clause that saves me if it breaks" · "liability cap"
- Indemnification clausePromise to cover someone's losses from your acts"who pays if we get sued" · "the hold-harmless bit"
- Non-Disclosure Agreement (NDA)Contract protecting confidential information shared between parties"the don't-tell-anyone contract" · "sign this before I show you"
- Work made for hire; IP assignmentClause transferring ownership of created work to the client"who owns the code I built" · "handing ownership to the client"
Deeper in the field
- Legitimate interest assessment (LIA) Written justification for processing without consent
- Record of Processing Activities (ROPA) Inventory of what data you process and why
- Data inventory / data map Record of personal data, locations, flows, purposes, recipients, and systems
- Data Protection Officer (DPO) Designated adviser overseeing data-protection compliance and regulator contact
- Supervisory authority / data protection authority Regulator responsible for enforcing data-protection law
- ePrivacy Directive EU rules for cookies and electronic communications alongside GDPR
- Notice at collection Timely notice given when personal data is collected
- Consent record / proof of consent Evidence of who consented, when, how, and to what
- Opt-in vs. opt-out Whether permission precedes processing or continues until refusal
- Sensitive personal data / information Higher-risk data categories receiving additional legal protections
- Data Protection Impact Assessment (DPIA) Formal risk review before high-risk data processing
- Data residency Requirement that data physically stay in a region
- EU-U.S. Data Privacy Framework Certification enabling EU-to-US personal data transfers
- COPPA US law restricting data collection from children under 13
- Age assurance Blocking or verifying underage users before access
- HIPAA; Business Associate Agreement (BAA) US health data rules and required vendor contract
- SOC 2 report Audited report proving security controls to enterprise buyers
- ISO 27001 International certification for information security management systems
- Trust center / trust page Public page listing your security, privacy, and compliance posture
- Security questionnaire Long vendor form enterprise buyers send before purchase
- Accessibility Conformance Report (ACR) Document declaring your product's accessibility compliance level
- EU AI Act EU law classifying and regulating AI systems by risk
- AI transparency obligation Duty to tell users content or decisions are AI-generated
- Digital Services Act (DSA) EU rules for platforms on content, ads, and transparency
- Right of publicity Control over commercial use of someone's name, face, or voice
- DMCA takedown / safe harbor Copyright removal process shielding hosts from liability
- Model release / property release Signed permission to commercially use someone's likeness or property
- Content moderation and notice-and-action Process for reporting, reviewing, and removing user content
- Acceptable Use Policy (AUP) Rules defining prohibited uses of a product or service
- Intellectual property license Permission defining how intellectual property may be used
- Warranty disclaimer Clause denying promises beyond those expressly provided
- Governing law and forum clause Specifies which law and courts govern disputes