Term Kind Topic What it is
Access Geography Access as Transfer, Remote Viewing concept Cross-Border Transfer The recognition that viewing data from another jurisdiction is a cross-border transfer, which makes access control and the location of the people using it a transfer control.
Compliance Perimeter Scope, In-Scope Estate concept PCI-DSS Scoping The set of systems subject to a compliance regime - whose size is the dominant cost of that regime, and which is determined by architectural decisions rather than by the assessment.
Concentration Risk Systemic Dependency, Single-Provider Exposure, Vendor Concentration concept Third-Party Risk The exposure created when many organisations, or many parts of one organisation, depend on the same provider - so that a single failure is correlated across the system rather than isolated.
Cross-Border Transfer Mechanism SCCs, Adequacy Decision, Transfer Impact Assessment concept Cross-Border Transfer The legal basis required to move personal data from one jurisdiction to another, and the architectural evidence needed to support it.
Data Minimisation concept Lawful Basis & Purpose Limitation Collecting and retaining only the personal data actually necessary for the stated purpose, treated as an architectural constraint rather than a policy statement.
Data Residency Data Localisation concept Data Residency A requirement that data be stored, and sometimes processed, within a specified geography.
Data Subject Access Request DSAR, SAR concept Data Subject Rights An individual's request for a copy of the personal data an organisation holds about them, which must be fulfilled completely within a statutory deadline.
Differential Privacy Budget concept Privacy-Enhancing Technologies The cumulative privacy loss permitted across all queries against a dataset, which must be tracked and exhausted rather than applied per query.
Digital Sovereignty concept Digital Sovereignty Requirements that data and the ability to operate on it remain under a jurisdiction's control — a stronger and more architecturally demanding constraint than residency.
Exit and Concentration Risk concept Exit & Concentration Risk The regulatory concern that an institution cannot leave a critical provider, and that too much of the sector depends on the same few providers.
Financial Services Regulation concept Financial Services Regulation Architecture under financial regulation — where record-keeping, demonstrable resilience, and the ability to exit a provider are structural requirements.
Fourth Party Risk concept Third-Party Risk The dependencies of your dependencies, which you did not choose, may not know about, and remain accountable for.
Functional Equivalence Switching Equivalence, Same-Service-Type Equivalence concept Sector Cloud Rules The standard that a destination service must deliver the same output at the same performance and security after a switch, which is defined only between services of the same type and therefore does not rescue a…
Geo-Blocking Accuracy concept Geo-Restriction & Sanctions The reliability of determining a user's jurisdiction from network signals, which is imperfect in both directions and therefore needs a designed handling of errors.
Healthcare Data Protection concept Healthcare Data Protection Architecture for health information — where access must be broad enough for care, auditable in detail, and safe when the system is unavailable.
Immutable Store Erasure Conflict concept Erasure vs Immutability The direct contradiction between architectures designed never to forget and obligations requiring data to be removed, which must be resolved in the design rather than in policy.
In-Country Processing concept Data Residency Keeping data within a jurisdiction across every path it takes — including backups, logs, telemetry, support access and the disaster recovery region.
Minimum Necessary Access concept Healthcare Data Protection Restricting each user to the health information required for their specific role and, in the strong form, to the patients they are actually treating.
Operational Resilience Requirement concept Financial Services Regulation A supervisory expectation that a firm can continue delivering critical business services through disruption, expressed as an impact tolerance it must evidence.
Operator Independence concept Digital Sovereignty The requirement that no foreign entity can be compelled to access or disclose data, which goes beyond where the bytes are stored to who controls the operator.
Privacy Enhancing Technology PETs concept Privacy-Enhancing Technologies Techniques that allow useful computation over data without exposing the underlying records — differential privacy, secure multi-party computation, homomorphic encryption, federated learning.
Processor Instruction Boundary Controller-Processor Line, Own-Purpose Test concept Third-Party Risk The line at which a vendor stops acting only on your documented instructions and starts pursuing purposes of its own - which decides your lawful basis, your consent gating and your breach clock.
Purpose Limitation Use Constraint, Purpose Binding, Secondary Use Control concept Lawful Basis & Purpose Limitation The requirement that personal data collected for one stated purpose is not used for another, which architecture enforces by binding a purpose to every dataset and evaluating it at the point of use rather than …
Quasi-Identifier Set Indirect Identifiers, Re-identification Vector concept Pseudonymisation The combination of attributes that singles out an individual even after direct identifiers are removed - which is why deleting names and ids does not anonymise a dataset, and why free text and behavioural hist…
Re-Identification Risk concept Pseudonymisation The probability that pseudonymised data can be linked back to individuals, which is what keeps such data within the scope of data protection law.
Regulatory Architecture concept Regulatory & Data Protection Architecture Designing so regulatory obligations are properties of the system rather than commitments the organisation makes on its behalf.
Regulatory Reporting Pipeline concept Regulatory Reporting Pipelines A data pipeline whose output goes to a regulator, where correctness, reproducibility and demonstrable lineage matter more than latency or elegance.
Retention Clock Retention Trigger Event, Governing Event concept Records Retention & Legal Hold The business event from which a retention period is measured - not the row's creation - which must be recomputed rather than stored because late events move it.
Right to Erasure Right to be Forgotten concept Erasure vs Immutability An individual's right to have their personal data deleted, which collides directly with append-only and immutable architectures.
Sector Cloud Rules concept Sector Cloud Rules Sector-specific rules governing cloud use — outsourcing notification, audit rights, concentration risk and exit — which shape provider and service choices.
Submission Deadline Architecture concept Regulatory Reporting Pipelines Designing a reporting pipeline around a fixed external deadline, where late is a breach and the recovery window is part of the schedule rather than a contingency.
Transfer Mechanism concept Cross-Border Transfer The specific legal instrument permitting personal data to leave a jurisdiction, which must exist per flow and which architecture must make identifiable.
Unintentional Transfer Incidental Transfer, Shadow Data Flow concept Cross-Border Transfer Personal data crossing a jurisdictional boundary through a path nobody classified as a transfer - telemetry, support access, backups, or a processor's staff - which is what audits actually find.
Use-Time Enforcement Check at the Point of Use, Consent as a Service concept Consent Architecture Checking permission at the moment data is used rather than at the moment it is collected, because a copied permission flag is stale the moment it is made.