Published by Grecta | August 2026

This glossary covers key terms, abbreviations, and definitions used across EU and global digital compliance frameworks. Entries are organised alphabetically. Where a term has a specific statutory definition, the legal source is cited. Where a term is used across multiple frameworks with slightly different meanings, the most operative definition is given with a note on variations.


A

Adequacy decision

A formal determination by the European Commission that a third country, territory, sector, or international organisation provides a level of data protection essentially equivalent to that in the EU. Adequacy decisions enable personal data transfers from the EU without additional safeguards. Issued under Article 45 GDPR. Current adequacy decisions include those for the UK, Switzerland, Japan, South Korea, and the United States (under the EU-US Data Privacy Framework, currently under legal challenge).

AI literacy

The obligation under Article 4 of the EU AI Act requiring providers and deployers of AI systems to ensure that staff dealing with AI systems have a sufficient level of understanding of those systems, taking into account their technical knowledge, experience, education, and training. Applies to all providers and deployers regardless of the risk tier of the systems involved. In force since 2 February 2025.

AI Office

The European AI Office, established within the European Commission by Decision of 24 January 2024. The primary supervisory body for general-purpose AI model providers across the EU. Responsible for supervising GPAI obligations, facilitating codes of practice, conducting model evaluations, and coordinating with national market surveillance authorities.

AI system

Under Article 3(1) of the EU AI Act: a machine-based system that infers from inputs how to generate outputs such as predictions, recommendations, decisions, or content, and that operates with varying degrees of autonomy. The definition is based on the OECD AI system definition and was narrowed slightly by the Digital Omnibus amendment.

AIDA

Artificial Intelligence and Data Act. Canada’s proposed federal AI legislation, introduced as part of Bill C-27 in June 2022. AIDA died when Parliament was prorogued on 6 January 2025. No replacement legislation has been introduced as of August 2026. Canada currently relies on PIPEDA and sector-specific rules for AI governance.

Annex I (EU AI Act)

The list of EU harmonisation legislation whose regulated products trigger the product safety route to high-risk AI classification under Article 6(1). Includes medical devices, machinery, vehicles, radio equipment, civil aviation safety components, and others. Amended by the Digital Omnibus, which moved the Machinery Regulation from Section A to Section B.

Annex III (EU AI Act)

The list of eight high-risk AI use case domains triggering the use-based route to high-risk classification under Article 6(2). Covers biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. Subject to ongoing Commission review under Article 7 delegation.

Annex IV (EU AI Act)

The technical documentation requirements for high-risk AI systems. Sets out the specific content providers must include in technical documentation before market placement, covering system description, architecture, data governance, risk management, testing results, and standards applied.

AOC

Attestation of Compliance. A document signed by a merchant or service provider confirming their PCI DSS compliance status, with or without QSA countersignature depending on compliance level.

Article 6(3) exception

The provision in Article 6(3) of the EU AI Act allowing providers to argue their Annex III AI system does not pose a significant risk of harm and therefore does not require full high-risk compliance treatment. Requires documented reasoning and registration in the EU database under Article 49(2). Narrowed significantly by the Commission’s draft high-risk classification guidelines published in 2026.

Authorised representative

Under Article 3(5) of the EU AI Act: a natural or legal person established in the EU who has received and accepted a written mandate from a non-EU provider of an AI system or GPAI model to act on its behalf in fulfilling compliance obligations. Must be established in an EU member state. UK establishment does not qualify post-Brexit.


B

BCR Binding Corporate Rules. A mechanism under GDPR Article 47 allowing multinational corporate groups to transfer personal data within the group to countries outside the EU without additional safeguards, provided the BCRs are approved by a lead supervisory authority.

Biometric data Under Article 4(14) GDPR: personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that person.

Breach notification The obligation under GDPR Article 33 to notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of natural persons. Article 34 requires notification to affected data subjects where the breach is likely to result in a high risk.


C

CAIDA Colorado AI Act. The Colorado Artificial Intelligence Act, signed into law in May 2024 and effective from 1 February 2026. The first US state AI law imposing binding obligations on developers and deployers of high-risk AI systems, including algorithmic impact assessments and transparency requirements.

CADA Cloud and AI Development Act. A proposed EU regulation currently in Parliament, with a rapporteur appointed in mid-2026, aimed at reducing Europe’s dependence on non-European cloud infrastructure, tripling EU data centre capacity by 2030, and establishing a legal definition of sovereign cloud.

CDE Cardholder Data Environment. Under PCI DSS: the people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data, including any connected system components.

CE marking The conformity marking that high-risk AI system providers must affix to their systems before market placement under Article 48 of the EU AI Act, indicating the system complies with all applicable requirements of the Act. Affixing CE marking without completing conformity assessment is an infringement.

Certification Under ISO/IEC 42001:2023: formal confirmation by an accredited certification body that an organisation’s AI management system conforms to the requirements of the standard. Not required by the EU AI Act but increasingly requested in enterprise procurement and M&A due diligence.

CLOUD Act Clarifying Lawful Overseas Use of Data Act. A 2018 US federal law allowing US law enforcement and intelligence agencies to compel US-based technology companies to produce data stored anywhere in the world, regardless of the physical location of the data. Creates extraterritorial jurisdiction that conflicts with EU data sovereignty objectives and complicates GDPR transfer compliance for EU organisations using US cloud providers.

Codes of conduct Under Article 95 of the EU AI Act: voluntary codes developed by providers and deployers of AI systems that are not high-risk, to demonstrate compliance with ethical principles. Distinct from codes of practice under Article 56, which address GPAI model obligations and carry presumptions of conformity.

Codes of practice Under Article 56 of the EU AI Act: compliance instruments for GPAI model providers, developed through a multi-stakeholder process facilitated by the AI Office. Adherence to an approved code of practice creates a presumption of conformity with the corresponding obligations under Articles 53 and 55. The GPAI Code of Practice was finalised and entered into operation on 2 August 2025.

Conformity assessment The procedure by which providers of high-risk AI systems demonstrate compliance with the requirements of Chapter III, Section 2 of the EU AI Act before market placement. May be a self-assessment internal control procedure under Annex VI or a third-party assessment by a notified body under Annex VII, depending on the system type.

Controller Under Article 4(7) GDPR: the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

CRA Cyber Resilience Act. Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements, including most IoT devices and software products. Requires security by design, vulnerability handling processes, and incident reporting. Applies to products placed on the EU market from 11 December 2027, with earlier dates for specific obligations.

Critical entity Under the CER Directive (EU) 2022/2557: an entity providing essential services in critical sectors including energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, and space. Subject to enhanced resilience requirements including physical and cyber protection obligations.

CTPP Critical Third-Party Provider. Under DORA Article 31: an ICT third-party service provider designated as critical by the Joint Committee of the ESAs based on systemic importance to the EU financial sector. Subject to direct oversight by a Lead Overseer drawn from EBA, ESMA, or EIOPA.

CVV/CVC Card Verification Value / Card Verification Code. The three or four digit security code on a payment card. Classified as sensitive authentication data under PCI DSS. Must never be stored after transaction authorisation.


D

Data Act Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data. Applies since 12 September 2025. Creates binding obligations for manufacturers of connected products and related service providers covering user data access rights, third-party data sharing, contractual fairness, and cloud switching.

Data governance Under Article 10 of the EU AI Act: the obligation on providers of high-risk AI systems to implement appropriate practices for training, validation, and testing datasets, including relevance, representativeness, freedom from errors, and examination for bias.

Data minimisation Under Article 5(1)(c) GDPR: the principle that personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.

Data portability Under Article 20 GDPR: the right of a data subject to receive personal data they have provided to a controller in a structured, commonly used, machine-readable format and to transmit that data to another controller.

Data Protection Authority (DPA) The independent national supervisory authority responsible for monitoring the application of GDPR and other data protection laws within each EU member state. Also referred to as a supervisory authority. Examples include the ICO (UK), CNIL (France), BfDI (Germany), and DPC (Ireland).

Data Protection Impact Assessment (DPIA) Under Article 35 GDPR: a structured assessment required before processing that is likely to result in a high risk to the rights and freedoms of natural persons, including systematic profiling, large-scale processing of special categories of data, and systematic monitoring of publicly accessible areas.

Data Protection Officer (DPO) Under Articles 37-39 GDPR: a designated officer required for public authorities, organisations carrying out large-scale systematic monitoring, or organisations processing special categories of data at scale. Responsible for advising on data protection obligations and acting as a contact point for supervisory authorities.

Declaration of Conformity Under Article 47 of the EU AI Act: a written document in which the provider of a high-risk AI system declares that the system complies with all applicable requirements of the Act. Must be drawn up before market placement and retained for 10 years.

Deployer Under Article 3(4) of the EU AI Act: a natural or legal person that uses an AI system under their own authority in a professional context. Carries independent compliance obligations under Article 26, including human oversight, FRIA, log retention, and individual notification.

Digital Markets Act (DMA) Regulation (EU) 2022/1925. Applies to gatekeepers, large platform companies designated by the European Commission based on size, user base, and market position. Imposes obligations including interoperability requirements, data access obligations, and prohibitions on certain self-preferencing practices. Applies since 2 May 2023.

Digital Services Act (DSA) Regulation (EU) 2022/2065. Imposes obligations on online intermediaries and platforms regarding illegal content, transparency, and systemic risk. Very large online platforms and very large online search engines face the most extensive obligations including annual risk assessments. AliExpress was fined €550 million under the DSA in July 2026.

Digital Omnibus Regulation (EU) 2026/1744. The amendment to the EU AI Act that moved the stand-alone Annex III high-risk AI deadline from 2 August 2026 to 2 December 2027, the product safety route deadline from August 2027 to August 2028, and added two new Article 5 prohibitions. Entered into force 18 July 2026.

DORA Digital Operational Resilience Act. Regulation (EU) 2022/2554. Applies since 17 January 2025 to EU financial entities including banks, insurers, investment firms, and payment institutions, as well as designated critical ICT third-party service providers. Covers ICT risk management, incident reporting, resilience testing, and third-party risk management.

DPDP Act Digital Personal Data Protection Act. India’s primary data protection legislation, enacted in August 2023 with phased implementation through May 2027. Establishes obligations for data fiduciaries processing digital personal data of Indian residents, including consent requirements, purpose limitation, and data localisation provisions for certain categories.

DPF Data Privacy Framework. The EU-US Data Privacy Framework, established by adequacy decision in July 2023. Allows personal data transfers from the EU to certified US organisations. Under legal challenge following the US Supreme Court ruling in Trump v. Slaughter (2026), which undermined the premise of FTC independence on which the Framework’s adequacy finding rested.


E

EBA European Banking Authority. One of the three European Supervisory Authorities. Responsible for prudential regulation and supervision of the EU banking sector. Plays a role in DORA oversight as part of the Joint Committee of ESAs.

EDPB European Data Protection Board. The independent EU body established under Article 68 GDPR, composed of the heads of national DPAs and the European Data Protection Supervisor. Issues guidelines, recommendations, and binding decisions on GDPR interpretation and cross-border enforcement.

EIOPA European Insurance and Occupational Pensions Authority. One of the three European Supervisory Authorities. Responsible for insurance and occupational pensions regulation. Plays a role in DORA oversight.

ESMA European Securities and Markets Authority. One of the three European Supervisory Authorities. Responsible for securities markets regulation. Plays a role in DORA oversight and in AI Act enforcement for capital markets AI systems.

EU AI Act Regulation (EU) 2024/1689 on artificial intelligence, as amended by Regulation (EU) 2026/1744. The world’s first comprehensive, horizontally applicable AI regulation with binding enforcement and significant penalties. Risk-based framework covering prohibited practices, high-risk AI systems, GPAI models, and transparency obligations.


F

FLOPs Floating-point operations. The unit used to measure training compute for AI models. Under Article 51(2) of the EU AI Act, a GPAI model trained using compute exceeding 10²⁵ FLOPs is presumed to have high-impact capabilities and is classified as a GPAI model with systemic risk.

FRIA Fundamental Rights Impact Assessment. Required under Article 27 of the EU AI Act for deployers of certain Annex III high-risk AI systems before deployment. Must document affected individuals, potential impacts on fundamental rights, mitigation measures, and human oversight arrangements.

FTC Federal Trade Commission. The primary US federal consumer protection and competition authority. Designated as the independent oversight body responsible for enforcing US privacy commitments under the EU-US Data Privacy Framework. Its independence was undermined by the US Supreme Court ruling in Trump v. Slaughter (2026).


G

GDPR General Data Protection Regulation. Regulation (EU) 2016/679. The primary EU data protection law, applicable since 25 May 2018. Governs the processing of personal data of EU residents regardless of where the processing organisation is established. Maximum fines of €20 million or 4% of worldwide annual turnover for serious violations.

GPAI model General-purpose AI model. Under Article 3(63) of the EU AI Act: an AI model trained with large amounts of data using self-supervision at scale that displays significant generality and is capable of competently performing a wide range of distinct tasks, and that can be integrated into a variety of downstream systems or applications.

GPAI model with systemic risk A GPAI model classified as posing systemic risk under Article 51 of the EU AI Act, either because training compute exceeds 10²⁵ FLOPs or because the AI Office designates it based on high-impact capabilities or significant internal market reach. Subject to additional obligations including adversarial testing, incident reporting, and cybersecurity measures.


H

High-risk AI system Under Article 6 of the EU AI Act: an AI system that is either a safety component of an Annex I regulated product requiring third-party conformity assessment, or an AI system used in one of the eight domains listed in Annex III. Subject to the most extensive compliance obligations in the Act.

Human oversight Under Article 14 of the EU AI Act: the requirement that high-risk AI systems be designed to enable effective oversight by natural persons during operation. Encompasses the ability to understand system capabilities and limitations, detect anomalies, interpret outputs, override decisions, and interrupt or stop the system.


I

ICO Information Commissioner’s Office. The UK’s independent data protection regulator, responsible for enforcing the UK GDPR and Data Protection Act 2018. Also has powers under the Privacy and Electronic Communications Regulations and other digital legislation.

ICT risk Under Article 3(5) of DORA: any reasonably identifiable circumstance relating to the use of network and information systems which, if materialised, may compromise the security of those systems and the technology-dependent tools, operations, processes, or services provided by a financial entity.

Importer Under Article 3(6) of the EU AI Act: a natural or legal person established in the EU that places on the EU market an AI system bearing the name or trademark of a person established outside the EU. Carries pre-market verification obligations and may also serve as Authorised Representative.

Intended purpose Under Article 3(12) of the EU AI Act: the use for which an AI system is intended by the provider, including the specific context and conditions of use as specified in technical documentation, instructions for use, and promotional materials. Determines risk classification and applicable obligations.

ISO/IEC 42001:2023 The first international standard for AI management systems, published in December 2023. Certifiable standard providing a framework for organisations to establish, implement, maintain, and improve an AI management system. Referenced by the EU AI Act as a relevant standard for quality management system design under Article 17.


J

Joint Controller Under Article 26 GDPR: two or more controllers who jointly determine the purposes and means of processing. Must enter into an arrangement determining their respective responsibilities for compliance with GDPR obligations.


L

Lawful basis Under Article 6 GDPR: one of six legal grounds on which personal data may be processed. Includes consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. Processing without a lawful basis is unlawful.

Lead supervisory authority Under Article 56 GDPR: the supervisory authority of the EU member state in which a controller or processor has its main establishment, responsible for leading cross-border enforcement cases under the one-stop-shop mechanism.

LGPD Lei Geral de Proteção de Dados. Brazil’s data protection law, in force since September 2020. Broadly modelled on GDPR. Covers processing of personal data of Brazilian residents. Enforced by the ANPD (Autoridade Nacional de Proteção de Dados).

Limited risk AI system Under the EU AI Act: an AI system subject only to transparency obligations under Article 50, including chatbots, deepfake generators, and emotion recognition systems used outside prohibited contexts. Not subject to the full high-risk compliance framework.


M

Mandate Under the EU AI Act: the written instrument by which a non-EU provider confers authority on an Authorised Representative. Must specify the tasks the representative is empowered to carry out and must be made available to competent authorities upon request in an official EU language.

Market surveillance authority Under Article 70 of the EU AI Act: the national authority designated by each EU member state to supervise the application of the Act in relation to high-risk AI systems within that state. Must cooperate with other member state authorities and the AI Office.

MiCA Markets in Crypto-Assets Regulation. Regulation (EU) 2023/1114. The EU framework for crypto-asset service providers and issuers of crypto-assets including asset-referenced tokens and e-money tokens. Fully applicable since 30 December 2024. Crypto-asset service providers are within scope of the EU AI Act where they use AI systems.

Minimal risk AI system Under the EU AI Act: an AI system not classified as prohibited, high-risk, or limited risk. Subject only to the AI literacy obligation under Article 4. The majority of currently deployed AI systems fall into this category.


N

NIS2 Network and Information Security Directive 2. Directive (EU) 2022/2555. Replaced NIS1. Imposes cybersecurity obligations on essential and important entities across a wide range of sectors including energy, transport, banking, health, digital infrastructure, and public administration. Member states were required to transpose by 17 October 2024. For financial entities in scope of both NIS2 and DORA, DORA takes precedence as the sector-specific act.

NIST AI RMF NIST Artificial Intelligence Risk Management Framework. A voluntary US framework published by the National Institute of Standards and Technology in January 2023. Organises AI risk management around four functions: Govern, Map, Measure, and Manage. Widely adopted in the US and referenced internationally as a governance benchmark alongside mandatory frameworks.

Notified body Under Articles 28-39 of the EU AI Act: an independent conformity assessment body designated by a member state to conduct third-party conformity assessments for certain high-risk AI systems, particularly those embedded in Annex I regulated products and certain biometric systems. Capacity constraints are a significant practical bottleneck as of 2026.


O

One-stop-shop The GDPR mechanism under Article 56 whereby cross-border data processing cases are handled by the lead supervisory authority in the member state of the controller’s main establishment, with other concerned authorities participating as observers and reviewers.

Operator Under Article 3(8) of the EU AI Act: a collective term covering providers, deployers, authorised representatives, importers, and distributors. Used when obligations apply across multiple role categories simultaneously.


P

PAN Primary Account Number. The payment card number embossed or encoded on a payment card. The central element of cardholder data under PCI DSS. Must never be stored unencrypted.

PCI DSS Payment Card Industry Data Security Standard. A contractual security standard developed and maintained by the PCI Security Standards Council, founded by Visa, Mastercard, American Express, Discover, and JCB. Applies to all organisations that store, process, or transmit payment card data. Not a statutory legal obligation but a contractual requirement imposed through merchant agreements.

PCI SSC Payment Card Industry Security Standards Council. The body that develops and maintains PCI DSS and related standards. Manages the QSA and ASV accreditation programmes.

PDPA Personal Data Protection Act. Used by multiple jurisdictions including Singapore (PDPA 2012, amended 2020) and Thailand (PDPA 2019, effective 2022). Each is a distinct instrument; the abbreviation requires context to disambiguate.

PIPEDA Personal Information Protection and Electronic Documents Act. Canada’s federal private sector data protection law. Applies to the collection, use, and disclosure of personal information in the course of commercial activities. Canada’s AIDA legislative effort having collapsed, PIPEDA remains the primary federal AI governance instrument alongside sector-specific rules.

Post-market monitoring Under Article 72 of the EU AI Act: the obligation on providers of high-risk AI systems to collect and review experience from deployed systems to identify risks requiring corrective action. Must be supported by a post-market monitoring plan establishing methods, frequency, and scope of monitoring.

Processor Under Article 4(8) GDPR: a natural or legal person that processes personal data on behalf of a controller. Must act only on documented instructions from the controller and must implement appropriate technical and organisational security measures.

Profiling Under Article 4(4) GDPR: any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.

Provider Under Article 3(3) of the EU AI Act: a natural or legal person that develops an AI system or GPAI model and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. Carries the most extensive compliance obligations under the Act.

Pseudonymisation Under Article 4(5) GDPR: the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that additional information is kept separately and subject to technical and organisational measures.


Q

QMS Quality Management System. Under Article 17 of the EU AI Act: the organisational framework that providers of high-risk AI systems must establish, document, and maintain to ensure compliance with all applicable obligations across the system lifecycle.

QSA Qualified Security Assessor. An organisation certified by the PCI SSC to conduct PCI DSS assessments for Level 1 merchants and service providers.


R

Reasonably foreseeable misuse Under Article 9(2)(b) of the EU AI Act: use of a high-risk AI system in a way not intended by the provider but which may result from reasonably foreseeable human behaviour. Must be considered in the risk management system alongside intended purpose.

Representative Actions Directive Directive (EU) 2020/1828 on representative actions for the protection of the collective interests of consumers. Extended to EU AI Act infringements by Article 110 of the Act. Enables qualified entities including consumer organisations and NGOs to bring class-action-style collective redress actions against AI Act infringers.

Right to explanation Under Article 86 of the EU AI Act: the right of an individual subject to a decision based on a high-risk Annex III AI system output to obtain from the deployer a clear and meaningful explanation of the role of the AI system in the decision and the main elements of the decision.

ROC Report on Compliance. The formal assessment report produced by a QSA following a PCI DSS assessment of a Level 1 merchant or service provider.

RTO / RPO Recovery Time Objective / Recovery Point Objective. Under DORA Article 12: the maximum acceptable time to restore a critical function following an ICT disruption (RTO) and the maximum acceptable period of data loss measured in time (RPO). Must be defined and documented in business continuity plans.


S

SAQ Self-Assessment Questionnaire. The self-validation tool used by merchants and service providers below Level 1 to document their PCI DSS compliance. Different SAQ types (A, A-EP, B, B-IP, C, C-VT, D) apply depending on how the business processes card payments.

SCCs Standard Contractual Clauses. Model contract clauses approved by the European Commission for use as a transfer mechanism for personal data from the EU to third countries. Used where no adequacy decision exists. Current SCCs were adopted in June 2021. Must be supplemented by a Transfer Impact Assessment where laws of the destination country may undermine their effectiveness.

Sensitive authentication data Under PCI DSS: data elements including full magnetic stripe data, card verification codes (CVV/CVC), and PINs. Must never be stored after authorisation, even in encrypted form.

Serious incident Under Article 3(49) of the EU AI Act: an incident or malfunctioning of a high-risk AI system that directly or indirectly leads to death, serious harm to health, serious damage to property, serious disruption to essential services, breach of fundamental rights obligations, or serious damage to the environment. Must be reported by providers within 15 days of becoming aware.

SOC 2 System and Organisation Controls 2. An auditing standard developed by the American Institute of Certified Public Accountants (AICPA) covering security, availability, processing integrity, confidentiality, and privacy of data processed by service organisations. Not a legal requirement but widely required in enterprise procurement. Subject to scrutiny following the Delve scandal (2026) in which templated assessments and rubber-stamp auditing practices were alleged.

Special categories of data Under Article 9 GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic data; biometric data processed for identification; health data; and data concerning a natural person’s sex life or sexual orientation. Processing is prohibited unless one of the Article 9(2) exceptions applies.

Substantial modification Under Article 3(23) of the EU AI Act: a change to a high-risk AI system after market placement that affects its compliance with the Act’s requirements or changes its intended purpose. A substantially modified system is treated as a new system, triggering full conformity assessment and compliance obligations from the date of modification.

Systemic risk Under Article 3(65) of the EU AI Act: a risk specific to high-impact GPAI models with the potential for significant negative effects on public health, safety, public security, or fundamental rights at Union scale. GPAI models with systemic risk face additional obligations under Article 55 including adversarial testing, incident reporting, and cybersecurity measures.


T

Technical documentation Under Article 11 and Annex IV of the EU AI Act: the documentation providers of high-risk AI systems must prepare and maintain before market placement, covering system description, architecture, data governance, risk management, testing results, and standards applied. Must be retained for 10 years.

TIA Transfer Impact Assessment. An assessment required when using SCCs or other transfer mechanisms for personal data transfers from the EU to third countries, evaluating whether the laws and practices of the destination country undermine the effectiveness of the transfer mechanism.

TLPT Threat-Led Penetration Testing. Under Article 26 of DORA: advanced resilience testing for significant financial entities using real-world threat intelligence to design and execute controlled attacks on live production systems. Required at least every three years for entities designated by competent authorities.

Trade secret Under Article 2(1) of Directive (EU) 2016/943: information that is secret, has commercial value because it is secret, and has been subject to reasonable steps to keep it secret. Providers of high-risk AI systems and GPAI models may protect genuine trade secrets from public disclosure but cannot use trade secret protection as a blanket refusal to share data with regulators.


U

UK GDPR The version of the GDPR retained in UK domestic law following Brexit, as amended by the Data Protection Act 2018 and subsequent UK legislation. Substantially equivalent to EU GDPR but a distinct legal instrument. Enforced by the ICO. The UK is currently covered by an EU adequacy decision subject to periodic review.


V

Vietnam AI Law Law 134/2025, effective 1 March 2026. One of the strictest standalone AI statutes globally, covering high-risk AI systems, transparency obligations, and data governance requirements. Applies to any enterprise with Vietnamese user exposure. Receives limited coverage in Western compliance literature despite binding effect.


W

Whistleblower protection Under Article 87 of the EU AI Act: individuals who report infringements of the AI Act to national authorities or the AI Office are protected from retaliation, dismissal, or other adverse treatment under Directive (EU) 2019/1937, the EU Whistleblower Protection Directive.


Z

Zero-day vulnerability A software vulnerability unknown to the vendor and for which no patch exists at the time of discovery. Relevant to CRA obligations requiring manufacturers to address known vulnerabilities and to DORA obligations requiring financial entities to monitor and respond to emerging threats. Disclosure obligations vary by framework.


This glossary reflects EU and global regulatory frameworks as of August 2026. Definitions marked with a legal source reflect the statutory text of the cited instrument. Definitions without a source reflect common usage across the compliance profession. This glossary is published by European Compliance Suite for general informational purposes and does not constitute legal advice.