Skip to content

AI Compliance Glossary

Plain-English definitions for 29 compliance and AI governance terms. DPIA, FRIA, GPAI, SCC, ROPA — demystified.

A
AEDTAutomated Employment Decision Tool

Under New York City Local Law 144, an AEDT is a machine learning, statistical, or AI tool used to substantially assist or replace discretionary employment decisions — including screening, evaluating, or ranking candidates or employees. Employers using AEDTs must conduct an annual bias audit and notify candidates.

NYC Local Law 144
AI ActEU Artificial Intelligence Act

Regulation (EU) 2024/1689, the world's first comprehensive AI law. Applies to providers, deployers, importers, and distributors of AI systems in the EU. Classifies AI by risk: prohibited (e.g., social scoring), high-risk (Annex III), limited-risk (transparency obligations), and minimal-risk. Penalties up to €35M or 7% global turnover.

EU AI Act
Algorithmic Impact AssessmentAIA

A structured evaluation of an automated or AI system's potential effects on individuals and communities, especially for bias, discrimination, and due process concerns. Required or recommended in Canada's Directive on Automated Decision-Making and various US state bills.

GDPR Art.35EU AI Act Art.9
Annex IIIEU AI Act High-Risk List

The list in the EU AI Act of specific AI application areas classified as high-risk, including: biometric identification, critical infrastructure management, education access, employment decisions, essential services access, law enforcement, migration management, and justice administration. AI systems in these areas must undergo conformity assessments before deployment.

EU AI Act Annex III
Automated Decision-MakingADM

The use of algorithms or AI to make decisions about individuals without meaningful human involvement. GDPR Article 22 gives EU residents the right not to be subject to solely automated decisions that produce legal or similarly significant effects, and requires organisations to disclose when ADM is used.

GDPR Art.22EU AI Act
C
CCPACalifornia Consumer Privacy Act

A California privacy law (effective 2020, updated by CPRA 2023) giving California residents rights over their personal information: know, delete, correct, opt-out of sale, and limit use of sensitive personal information. Enforced by the California Privacy Protection Agency (CPPA).

CCPA/CPRA
Conformity AssessmentConformity Assessment

Under the EU AI Act, high-risk AI systems must undergo a conformity assessment before being placed on the market. This may be self-assessment (for most systems) or third-party assessment (for biometric, critical infrastructure, and some employment AI). The system must be CE marked and registered in the EU database.

EU AI Act Art.43
CPPACalifornia Privacy Protection Agency

The state agency responsible for enforcing the CCPA/CPRA. Issues regulations, investigates violations, and levies fines up to $7,500 per intentional violation. Developing regulations specifically for automated decision-making technologies (ADMT).

CCPA/CPRA
D
Data MinimisationData Minimisation

A GDPR principle (Art.5(1)(c)) requiring that personal data collected must be adequate, relevant, and limited to what is necessary for the specified purpose. For AI systems, this means not collecting training data or processing personal data beyond what the model actually needs to function.

GDPR Art.5(1)(c)
DPAData Processing Agreement

A legally required contract (under GDPR Art.28) between a data controller and a data processor. Required whenever an organisation uses a third party to process personal data on its behalf — including AI vendors like OpenAI, Google, and Microsoft. Must specify: nature/purpose of processing, data types, controller obligations, and processor duties.

GDPR Art.28
DPIAData Protection Impact Assessment

A structured risk assessment required by GDPR Art.35 when processing is "likely to result in high risk" to individuals. Mandatory for: systematic profiling, large-scale processing of sensitive data, or systematic monitoring of public areas. AI systems that process personal data and make automated decisions typically require a DPIA.

GDPR Art.35
DPOData Protection Officer

A mandatory role under GDPR Art.37 for organisations that: process data on a large scale as a core activity, or regularly and systematically monitor individuals at large scale, or process special category data at large scale. The DPO advises on GDPR compliance, monitors DPIAs, and is the contact point for supervisory authorities.

GDPR Art.37-39
DSR / DSARData Subject Request / Access Request

A formal request by an individual (data subject) exercising their GDPR rights: access (Art.15), rectification (Art.16), erasure (Art.17), restriction (Art.18), portability (Art.20), or objection (Art.21). Organisations must respond within 30 days. Failure triggers complaints to supervisory authorities.

GDPR Art.15-21
E
ECOAEqual Credit Opportunity Act

A US federal law prohibiting discrimination in credit decisions based on race, color, religion, national origin, sex, marital status, age, or use of public assistance. AI credit scoring models must comply with adverse action notice requirements and cannot use protected characteristics — directly or through proxies.

ECOA (US)
F
FRIAFundamental Rights Impact Assessment

A risk assessment required under EU AI Act Art.27 for deployers of high-risk AI systems that are public bodies or act on behalf of public bodies. Must cover impacts on fundamental rights including non-discrimination, privacy, freedom of expression, and access to justice.

EU AI Act Art.27
G
GDPRGeneral Data Protection Regulation

Regulation (EU) 2016/679, in force since May 2018. The primary EU law governing personal data processing. Applies to any organisation processing personal data of EU residents, regardless of where the organisation is located. Grants 8 individual rights; requires 6 legal bases for processing; penalties up to €20M or 4% global turnover.

GDPR
GPAIGeneral Purpose AI Model

Under the EU AI Act, a GPAI model is an AI model trained on large amounts of data that can perform a wide range of tasks and be integrated into other systems. OpenAI GPT-4, Google Gemini, and Anthropic Claude are examples. GPAI models above 10^25 FLOPs are classified as "systemic risk" models with additional obligations.

EU AI Act Art.3Art.51
H
High-Risk AIHigh-Risk AI System

Under the EU AI Act, AI systems listed in Annex III are "high-risk" and must undergo conformity assessment before deployment. Examples: AI for hiring/firing, credit scoring, school admissions, critical infrastructure, law enforcement. High-risk systems require technical documentation, human oversight, logging, transparency, and registration.

EU AI Act Annex III
Human OversightHuman Oversight

A core requirement under EU AI Act Art.14 for high-risk AI systems. The system must be designed so that appropriate human review is possible, individuals can intervene or override outputs, the system can be switched off, and operators understand the system's limitations and when to distrust it.

EU AI Act Art.14GDPR Art.22
I
ISO 42001ISO 42001 AI Management System

The international standard for AI management systems, published in 2023. Provides a framework for establishing, implementing, maintaining, and improving an organization's approach to developing and using AI responsibly. Maps closely to EU AI Act requirements. Clause 4-10 + Annex A controls.

ISO 42001:2023
L
LIALegitimate Interests Assessment

A three-part test required when relying on "legitimate interests" (Art.6(1)(f)) as legal basis for processing: (1) identify the legitimate interest, (2) show processing is necessary, (3) balance against data subjects' interests, rights, and freedoms. AI systems that process personal data often rely on this legal basis.

GDPR Art.6(1)(f)
N
NIST AI RMFNIST AI Risk Management Framework

A voluntary US framework from the National Institute of Standards and Technology (2023) for managing AI risk. Organized around four functions: GOVERN (culture, accountability), MAP (risk identification), MEASURE (metrics and monitoring), and MANAGE (response and improvement). Maps to EU AI Act requirements.

NIST AI RMF
P
PDPLUAE Personal Data Protection Law

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. UAE's primary privacy law, applicable to entities in the UAE and entities processing UAE residents' data. Art.11 specifically addresses automated processing and prohibits purely automated decisions about individuals without consent or legal basis.

UAE PDPL
PIPEDAPersonal Information Protection and Electronic Documents Act

Canada's federal privacy law governing how private-sector organizations collect, use, and disclose personal information in commercial activities. Being replaced by Bill C-27 (Consumer Privacy Protection Act / CPPA) which adds AI-specific provisions including algorithmic transparency.

PIPEDA / Bill C-27
Post-Market MonitoringPost-Market Monitoring

Under EU AI Act Art.72, providers of high-risk AI systems must implement a post-market monitoring plan to track system performance, detect risks, and report serious incidents. Must collect and analyse data about the system after deployment and update technical documentation when issues are found.

EU AI Act Art.72
R
ROPARecords of Processing Activities

Required under GDPR Art.30 for organisations with 250+ employees (or any organisation processing high-risk data). A register documenting all personal data processing activities: who processes what data, for what purpose, with what legal basis, how long it's retained, and with whom it's shared. Core audit document.

GDPR Art.30
S
SCCStandard Contractual Clauses

EU-approved model contract clauses that enable lawful transfer of personal data from the EU to third countries without an adequacy decision. Required for transfers to the US, India, and most non-EU countries. The 2021 updated SCCs cover controller-controller and controller-processor transfer scenarios.

GDPR Art.46GDPR Chapter V
SOC 2Service Organization Control 2

A trust-service certification for software companies. SOC 2 Type I verifies controls are designed correctly at a point in time. SOC 2 Type II verifies controls operated effectively over 6-12 months. Common audit criterion for enterprise buyers evaluating AI vendor compliance.

AICPA SOC 2
T
Technical DocumentationTechnical Documentation

Under EU AI Act Art.11 and Annex IV, providers of high-risk AI systems must prepare technical documentation covering: system description and design, training methods and datasets, validation/testing, risk management system, human oversight measures, and monitoring procedures.

EU AI Act Art.11Annex IV

Ready to turn these terms into action?

Take the GDPR + AI compliance scorecard →