Data protection glossary
Plain-English definitions of the acronyms and terms that come up most often in data protection, GDPR (UK and EU) and information governance, each linked through to a fuller guide where we have one.
What is a DPO (Data Protection Officer)?
A Data Protection Officer is an independent oversight role required under Article 37 of the UK GDPR for public authorities and organisations that carry out large-scale monitoring or process special category data at scale. A DPO monitors compliance, advises on data protection obligations and DPIAs, and acts as a contact point for the ICO and for individuals. Article 37(6) allows the role to be carried out on an outsourced basis, under a service contract, rather than in-house.
Read about our outsourced DPO serviceWhat is a DPIA (Data Protection Impact Assessment)?
A Data Protection Impact Assessment is a process required under Article 35 of the GDPR for processing likely to result in high risk to individuals, such as large-scale monitoring or processing of special category data. It identifies and helps to reduce the data protection risks of a project before it starts, rather than after.
Read about our DPIA serviceWhat is a SAR or DSAR (Subject Access Request)?
A Subject Access Request, sometimes shortened to DSAR, is a request made by an individual under Article 15 of the GDPR for a copy of the personal data an organisation holds about them, together with information about how it is used. Organisations normally have one calendar month to respond.
Read our guide to managing SARsWhat is a DPA (Data Processing Agreement)?
In a data protection context, DPA usually refers to a Data Processing Agreement: the contract required under Article 28 of the GDPR between a controller and a processor, setting out the processor's obligations. The same initials are also sometimes used for the Data Protection Act 2018, the UK law that sits alongside the UK GDPR, so it's worth checking which one a question is actually about.
Read our full guide to DPAsWhat is the difference between a data controller and a data processor?
Under Article 4 of the GDPR, a controller decides the purposes and means of processing personal data, while a processor processes personal data on the controller's behalf and under its instructions. The distinction matters because controllers and processors carry different legal responsibilities.
More on this in our insightsWhat is the DSPT (Data Security and Protection Toolkit)?
The Data Security and Protection Toolkit is an online self-assessment tool that health and social care organisations in England use to measure their performance against the National Data Guardian's data security standards. Most organisations working with NHS data or systems are expected to complete it annually.
Read about our DSPT supportWhat does SIRO stand for?
SIRO stands for Senior Information Risk Owner: a senior member of an organisation, most often in the public sector or NHS, who takes ownership of information risk and provides assurance that it is being managed effectively across the organisation.
See our SIRO trainingWhat is a Caldicott Guardian?
A Caldicott Guardian is a senior person, required in NHS and social care organisations, responsible for protecting the confidentiality of patient and service-user information and for enabling appropriate information sharing, in line with the Caldicott Principles.
See our Caldicott Guardian trainingWhat is UK GDPR?
UK GDPR is the UK General Data Protection Regulation: the version of the EU's GDPR retained in UK law after Brexit, which sits alongside the Data Protection Act 2018 to set out the rules for how personal data must be collected, used and protected in the UK.
Can't find what you're looking for?
No sales teams. No account managers. Speak directly to an experienced data protection specialist.