Term Kind Topic What it is
Suppression List Do-Not-Reprocess List, Erasure Tombstone Registry pattern Data Subject Rights A durable record of identifiers that must not be re-ingested, preventing an in-flight or replayed pipeline from recreating data that was just erased.
Third-Party Risk Assessment Vendor Risk, Supplier Assurance practice Third-Party Risk Evaluating the security, resilience and compliance posture of suppliers whose failure would become your incident.
Transfer Mechanism concept Cross-Border Transfer The specific legal instrument permitting personal data to leave a jurisdiction, which must exist per flow and which architecture must make identifiable.
Unintentional Transfer Incidental Transfer, Shadow Data Flow concept Cross-Border Transfer Personal data crossing a jurisdictional boundary through a path nobody classified as a transfer - telemetry, support access, backups, or a processor's staff - which is what audits actually find.
Use-Time Enforcement Check at the Point of Use, Consent as a Service concept Consent Architecture Checking permission at the moment data is used rather than at the moment it is collected, because a copied permission flag is stale the moment it is made.