Resources
Privacy glossary
Plain-language definitions of terms you will encounter in privacy notices and the Data Protection Act 2020. Hover over underlined terms in any notice to see a quick definition.
Anonymisation
Key conceptsAltering personal data so that individuals can no longer be identified, directly or indirectly.
Anti-money laundering
ObligationsLegal obligations requiring firms to detect and report financial crime.
Also: AML, anti-money laundering, money laundering prevention
Automated decision-making
Key conceptsMaking decisions solely by automated means, without human involvement, that significantly affect individuals.
Beneficial ownership
Key conceptsThe natural person who ultimately owns or controls a legal entity.
Also: UBO, ultimate beneficial owner, beneficial owner
Biometric data
Key conceptsUnique physical or behavioural characteristics used to identify an individual, such as fingerprints.
Conflict of interest
ObligationsA situation where a professional's duty to one client may be compromised by duties to another party.
Also: COI, conflict check
Consent
Key conceptsA freely given, specific, informed, and unambiguous agreement to the processing of personal data.
Cookie
Key conceptsA small file placed on a user's device by a website to store information or track activity.
Data breach
Key conceptsA security incident leading to unauthorised access, loss, or disclosure of personal data.
Also: personal data breach, security breach
Data breach notification
ObligationsThe legal requirement to report personal data breaches to the OIC within 72 hours.
Data controller
Key conceptsThe person or organisation that determines the purposes and means of processing personal data.
Also: controller
Data minimisation
ObligationsThe principle that personal data collected should be limited to what is necessary for the stated purpose.
Data processor
Key conceptsA person or organisation that processes personal data on behalf of a controller.
Also: processor
Data protection by design
ObligationsThe obligation to build data protection into systems and processes from the start, not as an afterthought.
Data protection impact assessment
ObligationsA process to identify and minimise privacy risks before starting high-risk data processing.
Also: DPIA
Data protection officer
EntitiesA designated individual responsible for overseeing an organisation's data protection compliance.
Also: DPO
Data subject
Key conceptsThe living individual to whom personal data relates.
Engagement letter
Key conceptsA written agreement setting out the terms on which a professional firm will provide services.
Also: letter of engagement, retainer letter, terms of engagement
Health data
Key conceptsPersonal data relating to an individual's physical or mental health, including medical history.
International transfer
ObligationsThe sending or making available of personal data to a recipient in a country outside Jamaica.
Also: cross-border transfer, transfer
Know Your Customer
ObligationsThe process of verifying a client's identity and assessing risk before and during a business relationship.
Also: KYC, customer due diligence, CDD, client due diligence
Lawful basis
Legal basisThe legal ground that justifies the processing of personal data under the DPA 2020.
Also: legal basis
Legitimate interests
Legal basisA lawful basis for processing where it is necessary for the controller's genuine interests and does not override individual rights.
Office of the Information Commissioner
EntitiesJamaica's independent data protection authority responsible for enforcing the DPA 2020.
Also: OIC, Information Commissioner
Personal data
Key conceptsAny information relating to an identified or identifiable living individual.
Privacy by default
ObligationsThe obligation to ensure that only the minimum personal data necessary is processed by default.
Also: data protection by default
Privacy notice
ObligationsA document informing individuals about how their personal data is collected, used, and protected.
Also: privacy policy
Processing
Key conceptsAny operation performed on personal data, including collection, storage, use, disclosure, or erasure.
Professional indemnity insurance
Key conceptsInsurance that protects a professional firm against claims of negligence or errors in the services it provides.
Also: PI insurance, professional liability insurance, E&O insurance
Profiling
Key conceptsAutomated processing of personal data to evaluate personal aspects such as behaviour or preferences.
Pseudonymisation
Key conceptsProcessing personal data so it cannot be attributed to an individual without separate additional information.
Public task
Legal basisA lawful basis for processing necessary to perform a task in the public interest or exercise official authority.
Purpose limitation
ObligationsThe principle that personal data must only be used for the purpose it was originally collected for.
Retention period
ObligationsThe length of time a controller stores personal data before it is deleted or anonymised.
Right of access
RightsThe right to obtain confirmation that your personal data is being processed and receive a copy of it.
Also: subject access request, SAR
Right to data portability
RightsThe right to receive your personal data in a structured, machine-readable format and transfer it to another controller.
Right to erasure
RightsThe right to request deletion of your personal data in certain circumstances.
Also: right to be forgotten
Right to object
RightsThe right to object to the processing of your personal data for certain purposes.
Right to rectification
RightsThe right to have inaccurate personal data corrected or incomplete data completed.
Right to restrict processing
RightsThe right to request that the use of your personal data is limited in certain circumstances.
Right to withdraw consent
RightsThe right to withdraw consent to data processing at any time, without affecting prior lawful processing.
Sensitive personal data
Key conceptsA special category of personal data requiring stricter protection, such as health, race, religion, or biometrics.
Also: special category data
Third party
Key conceptsAny person other than the data subject, controller, processor, or persons authorised by them.
Vital interests
Legal basisA lawful basis for processing necessary to protect someone's life.
44 of 44 terms
