Operate

Legal, Privacy & Compliance

Privacy, data protection, and the other rules you can't ignore.

The territory

28 core terms mapped for this field, ranked by how often builders reach for them. Each one is a future entry. Want to bust one? One entry, one file, one pull request.

  • Privacy policyPublic document stating what data you collect and why"the legal page every site has" · "the data blurb in the footer"
  • Terms of Service (ToS)Contract users accept to use your product"the rules page" · "the thing nobody reads before signing up"
  • Cookie consent bannerOverlay asking permission before setting non-essential cookies"that annoying popup about cookies" · "the accept-all bar"
  • Cookie policyNotice explaining cookies, purposes, providers, lifetimes, and user controls"the page explaining the cookies" · "cookie list page"
  • Consent Management Platform (CMP)Tool that collects, stores, and enforces user consent choices"the thing that runs the cookie popup" · "consent tool"
  • GDPREU law governing personal data collection, use, and rights"the European privacy law" · "why everyone asks about cookies"
  • CCPA, as amended by the CPRACalifornia privacy law giving residents data access and opt-out rights"CCPA/CPRA" · "the California privacy law"
  • Personal data / PIIData that identifies a specific person"sensitive user info" · "stuff you can't leak"
  • Data subject rightsRights to access, correct, delete, restrict, object, and port data"what users can legally demand" · "the GDPR rights list"
  • Data subject request (DSR)User request to see, export, or delete their data"DSAR" · "the download-my-data request"
  • Right to erasure / right to be forgottenUser's right to have their data deleted"delete my account for real" · "wipe me from your database"
  • Lawful basisThe legal justification you rely on to process data"the reason I'm allowed to collect this" · "consent or legitimate interest"
  • Data controller and data processorWho decides data use vs. who merely handles it"am I the owner or the middleman" · "whose responsibility is the data"
  • Data Processing Agreement (DPA)Contract binding a vendor handling data on your behalf"the paperwork vendors ask for" · "the privacy contract with subprocessors"
  • SubprocessorThird-party vendor processing data downstream of you"the vendors my vendor uses" · "the tool list I have to publish"
  • Data retention policyRule for how long you keep data before deleting"how long do I keep this" · "the auto-delete-after-X rule"
  • Data minimizationCollect only what you actually need"stop collecting stuff I don't use" · "less data less risk"
  • Privacy by designBuilding privacy protections in from the start, not bolted on"bake privacy in from day one" · "don't bolt privacy on later"
  • Anonymization vs. pseudonymizationIrreversibly stripping identity vs. replacing it with a key"is it really anonymous" · "hashed but still traceable"
  • Data breach notificationLegal duty to inform users/regulators after a leak"the email you send after a hack" · "72-hour rule"
  • Do Not Sell or Share My Personal InformationRequired opt-out link for ad-related data sharing"that footer link about selling data" · "the opt-out link"
  • Cross-border data transferMoving personal data between legal jurisdictions"can I host EU users in the US" · "data leaving the country"
  • Standard Contractual Clauses (SCCs)Pre-approved contract terms enabling international data transfers"the EU transfer clauses" · "boilerplate for sending data abroad"
  • Clickwrap vs. browsewrapExplicit checkbox agreement vs. implied consent by usage"the I-agree checkbox" · "does using the site count as agreeing"
  • Limitation of liability clauseContract cap on how much you can be sued for"the clause that saves me if it breaks" · "liability cap"
  • Indemnification clausePromise to cover someone's losses from your acts"who pays if we get sued" · "the hold-harmless bit"
  • Non-Disclosure Agreement (NDA)Contract protecting confidential information shared between parties"the don't-tell-anyone contract" · "sign this before I show you"
  • Work made for hire; IP assignmentClause transferring ownership of created work to the client"who owns the code I built" · "handing ownership to the client"

Deeper in the field

  • Legitimate interest assessment (LIA) Written justification for processing without consent
  • Record of Processing Activities (ROPA) Inventory of what data you process and why
  • Data inventory / data map Record of personal data, locations, flows, purposes, recipients, and systems
  • Data Protection Officer (DPO) Designated adviser overseeing data-protection compliance and regulator contact
  • Supervisory authority / data protection authority Regulator responsible for enforcing data-protection law
  • ePrivacy Directive EU rules for cookies and electronic communications alongside GDPR
  • Notice at collection Timely notice given when personal data is collected
  • Consent record / proof of consent Evidence of who consented, when, how, and to what
  • Opt-in vs. opt-out Whether permission precedes processing or continues until refusal
  • Sensitive personal data / information Higher-risk data categories receiving additional legal protections
  • Data Protection Impact Assessment (DPIA) Formal risk review before high-risk data processing
  • Data residency Requirement that data physically stay in a region
  • EU-U.S. Data Privacy Framework Certification enabling EU-to-US personal data transfers
  • COPPA US law restricting data collection from children under 13
  • Age assurance Blocking or verifying underage users before access
  • HIPAA; Business Associate Agreement (BAA) US health data rules and required vendor contract
  • SOC 2 report Audited report proving security controls to enterprise buyers
  • ISO 27001 International certification for information security management systems
  • Trust center / trust page Public page listing your security, privacy, and compliance posture
  • Security questionnaire Long vendor form enterprise buyers send before purchase
  • Accessibility Conformance Report (ACR) Document declaring your product's accessibility compliance level
  • EU AI Act EU law classifying and regulating AI systems by risk
  • AI transparency obligation Duty to tell users content or decisions are AI-generated
  • Digital Services Act (DSA) EU rules for platforms on content, ads, and transparency
  • Right of publicity Control over commercial use of someone's name, face, or voice
  • DMCA takedown / safe harbor Copyright removal process shielding hosts from liability
  • Model release / property release Signed permission to commercially use someone's likeness or property
  • Content moderation and notice-and-action Process for reporting, reviewing, and removing user content
  • Acceptable Use Policy (AUP) Rules defining prohibited uses of a product or service
  • Intellectual property license Permission defining how intellectual property may be used
  • Warranty disclaimer Clause denying promises beyond those expressly provided
  • Governing law and forum clause Specifies which law and courts govern disputes