Glossary category
Security and compliance
What gets asked before a tool is approved.
18 terms
- PII
Information that identifies a particular person, such as a name, email address or identity number, and the category most rules are written around.
- GDPR
The European data protection regime, which shapes how personal data may be used and is often applied by companies well outside Europe.
- EU AI Act
European legislation regulating AI by how risky its use is, placing the heaviest obligations on the highest-risk applications.
- SOC 2
An independent audit report on how a vendor handles security and availability, commonly requested before a tool is approved.
- ISO 27001
An international certification for running an information security management system, often accepted alongside or instead of a SOC 2 report.
- Data governance
How an organisation decides who owns which data, who may use it and to what standard it is kept.
- Audit trail
A durable record of who did what and when, which is what turns a claim about how a system was used into evidence.
- Single sign on (SSO)
Letting staff reach a tool with their existing work login, so access is granted and removed centrally rather than tool by tool.
- Data processing agreement (DPA)
The contract setting out what a vendor may do with personal data you send it, and usually a requirement before any real data moves.
- Enterprise indemnification
A vendor agreeing to stand behind you if generated output leads to a legal claim, offered mainly on business plans.
- Licence terms
The conditions attached to using a model or its output, including whether commercial use is allowed and what may be trained on.
- Regulated data
Information carrying legal obligations of its own, such as health or financial records, where the rules decide the tool rather than preference.
- Access review
Periodically rechecking who still needs access to what, and removing the rest, which audits ask for and organisations routinely postpone.
- Sub processor
Another company your vendor passes your data to in order to deliver the service, which is why the published list is worth reading.
- Security questionnaire
The standard set of questions a buyer sends a vendor before approval, and often the slowest step in adopting a new tool.
- Penetration test
An authorised attempt to break into a system in order to find weaknesses first, usually reported on annually to customers.
- Consent
Permission given freely and specifically for a stated use of someone's data, one of several lawful grounds and not always the right one.
- Data subject request
A person exercising their right to see, correct or delete the data an organisation holds on them, within a deadline set by law.
Checked quarterly