Glossary category
Privacy and deployment
Where AI runs and where your data goes.
29 terms
A deployment with no connection to the internet at all, used where data must not leave the room and updates arrive by hand.
Altering data so no individual can be identified from it again, which if genuinely achieved takes it outside most privacy law.
A model you can only use through its owner's service, with the trained file itself never released.
AI that runs on a provider's servers and reaches you over the internet, which is how nearly every well-known assistant works.
Moving personal data between countries, which usually requires a specific legal mechanism rather than being a matter of where servers happen to be.
Stripping or replacing personal details before text reaches a model, so a name or account number never leaves your control.
Collecting and keeping only what the purpose actually requires, which is both a legal principle and the cheapest way to reduce exposure.
What happens to the text, files and recordings you put into an AI tool: who can see them, how long they are kept, and whether they train the model.
A structured assessment of privacy risk carried out before a higher-risk processing activity begins, and often expected before an AI deployment touching personal data.
A commitment about which country your data is stored in, usually the first question asked in regulated work and in the public sector.
Whose laws your data falls under, which is not settled by storage location alone because the provider's own jurisdiction can still reach it.
AI that runs on or beside the device producing the data, such as a phone, camera or vehicle, rather than sending it away to be processed.
The legal ground you rely on to process someone's personal data, of which consent is only one and often not the most appropriate.
A lawful basis relying on a genuine business need balanced against the individual's rights, which has to be assessed and recorded rather than assumed.
A model running on the machine in front of you, so what you type never leaves it.
Running software on hardware you control, in your own building or data centre, rather than reaching it as a service over the internet.
Software whose code is published under a licence that lets anyone read, change and redistribute it.
A model whose trained parameters are published for anyone to download and run, unlike closed models used only through a provider's service.
A setting that tells a provider not to use your conversations to train its models.
A private route to a hosted model that avoids the public internet, sitting between ordinary cloud access and running the thing yourself.
Replacing identifying details with references that can still be reversed with separate information, which reduces risk without removing the data from scope.
Using data only for the purpose it was collected for, which is what makes reusing an existing dataset to train a model a question rather than a given.
The internal register of what personal data an organisation handles, why and where it goes, which regulators expect to exist before they ask for it.
A vendor offering to run the service in a chosen part of the world, which is how a data residency promise is usually delivered.
How long a vendor keeps your inputs and outputs before deleting them, and whether you can change that period.
Running an AI model on computers you control, whether your own servers or a private cloud, instead of sending data to a provider's service.
Pre-approved contract terms used to make an international data transfer lawful, and a routine item in vendor agreements.
Keeping each customer's data separated inside a shared service, the assurance behind a vendor saying your content stays yours.
A vendor commitment to discard your inputs and outputs immediately after answering, usually available on enterprise terms and worth getting in writing.