- Privacy by design
- Building privacy into a system from the start instead of adding it later.
- Privacy by default
- The most protective setting applies without the user doing anything.
- Data minimisation
- Collecting and keeping only what the purpose needs.
- Anonymisation
- Removing the link to a person for good, so the data is no longer personal.
- Pseudonymisation
- Replacing identifiers so that data cannot be linked to a person without extra information kept apart.
- Re-identification
- Linking data that was de-identified back to a person.
- k-anonymity
- Each record is indistinguishable from at least k minus one others.
- Differential privacy
- Adding statistical noise so that results reveal nothing about any one person.
- Homomorphic encryption
- Computing on data while it stays encrypted.
- Privacy-enhancing technology
- A technique that reduces the personal data a system needs or exposes.
- Threat modelling
- A structured search for what can go wrong in a design.
- Dark pattern
- An interface that steers people into a choice they would not otherwise make.
- Secondary use
- Using data for a purpose other than the one it was collected for.
- Aggregation
- Combining pieces of data about a person into a fuller picture.
- Data life cycle
- Collection, use, disclosure, retention and destruction.
- Access control
- Deciding who may see or change which data, and enforcing it.