Resources

Privacy glossary

Plain-language definitions of terms you will encounter in privacy notices and the Data Protection Act 2020. Hover over underlined terms in any notice to see a quick definition.

Anonymisation

Key concepts

Altering personal data so that individuals can no longer be identified, directly or indirectly.

Anti-money laundering

Obligations

Legal obligations requiring firms to detect and report financial crime.

Also: AML, anti-money laundering, money laundering prevention

Automated decision-making

Key concepts

Making decisions solely by automated means, without human involvement, that significantly affect individuals.

Beneficial ownership

Key concepts

The natural person who ultimately owns or controls a legal entity.

Also: UBO, ultimate beneficial owner, beneficial owner

Biometric data

Key concepts

Unique physical or behavioural characteristics used to identify an individual, such as fingerprints.

Conflict of interest

Obligations

A situation where a professional's duty to one client may be compromised by duties to another party.

Also: COI, conflict check

Consent

Key concepts

A freely given, specific, informed, and unambiguous agreement to the processing of personal data.

Cookie

Key concepts

A small file placed on a user's device by a website to store information or track activity.

Data breach

Key concepts

A security incident leading to unauthorised access, loss, or disclosure of personal data.

Also: personal data breach, security breach

Data breach notification

Obligations

The legal requirement to report personal data breaches to the OIC within 72 hours.

Data controller

Key concepts

The person or organisation that determines the purposes and means of processing personal data.

Also: controller

Data minimisation

Obligations

The principle that personal data collected should be limited to what is necessary for the stated purpose.

Data processor

Key concepts

A person or organisation that processes personal data on behalf of a controller.

Also: processor

Data protection by design

Obligations

The obligation to build data protection into systems and processes from the start, not as an afterthought.

Data protection impact assessment

Obligations

A process to identify and minimise privacy risks before starting high-risk data processing.

Also: DPIA

Data protection officer

Entities

A designated individual responsible for overseeing an organisation's data protection compliance.

Also: DPO

Data subject

Key concepts

The living individual to whom personal data relates.

Engagement letter

Key concepts

A written agreement setting out the terms on which a professional firm will provide services.

Also: letter of engagement, retainer letter, terms of engagement

Health data

Key concepts

Personal data relating to an individual's physical or mental health, including medical history.

International transfer

Obligations

The sending or making available of personal data to a recipient in a country outside Jamaica.

Also: cross-border transfer, transfer

Know Your Customer

Obligations

The process of verifying a client's identity and assessing risk before and during a business relationship.

Also: KYC, customer due diligence, CDD, client due diligence

Lawful basis

Legal basis

The legal ground that justifies the processing of personal data under the DPA 2020.

Also: legal basis

Legitimate interests

Legal basis

A lawful basis for processing where it is necessary for the controller's genuine interests and does not override individual rights.

Office of the Information Commissioner

Entities

Jamaica's independent data protection authority responsible for enforcing the DPA 2020.

Also: OIC, Information Commissioner

Personal data

Key concepts

Any information relating to an identified or identifiable living individual.

Privacy by default

Obligations

The obligation to ensure that only the minimum personal data necessary is processed by default.

Also: data protection by default

Privacy notice

Obligations

A document informing individuals about how their personal data is collected, used, and protected.

Also: privacy policy

Processing

Key concepts

Any operation performed on personal data, including collection, storage, use, disclosure, or erasure.

Professional indemnity insurance

Key concepts

Insurance that protects a professional firm against claims of negligence or errors in the services it provides.

Also: PI insurance, professional liability insurance, E&O insurance

Profiling

Key concepts

Automated processing of personal data to evaluate personal aspects such as behaviour or preferences.

Pseudonymisation

Key concepts

Processing personal data so it cannot be attributed to an individual without separate additional information.

Public task

Legal basis

A lawful basis for processing necessary to perform a task in the public interest or exercise official authority.

Purpose limitation

Obligations

The principle that personal data must only be used for the purpose it was originally collected for.

Retention period

Obligations

The length of time a controller stores personal data before it is deleted or anonymised.

Right of access

Rights

The right to obtain confirmation that your personal data is being processed and receive a copy of it.

Also: subject access request, SAR

Right to data portability

Rights

The right to receive your personal data in a structured, machine-readable format and transfer it to another controller.

Right to erasure

Rights

The right to request deletion of your personal data in certain circumstances.

Also: right to be forgotten

Right to object

Rights

The right to object to the processing of your personal data for certain purposes.

Right to rectification

Rights

The right to have inaccurate personal data corrected or incomplete data completed.

Right to restrict processing

Rights

The right to request that the use of your personal data is limited in certain circumstances.

Right to withdraw consent

Rights

The right to withdraw consent to data processing at any time, without affecting prior lawful processing.

Sensitive personal data

Key concepts

A special category of personal data requiring stricter protection, such as health, race, religion, or biometrics.

Also: special category data

Third party

Key concepts

Any person other than the data subject, controller, processor, or persons authorised by them.

Vital interests

Legal basis

A lawful basis for processing necessary to protect someone's life.

44 of 44 terms