| Accessibility reporting |
An operation that consists of identifying and documenting barriers that prevent people with disabilities from using digital products and services effectively. Common issues include missing alternative text for images, poor keyboard navigation, insufficient color contrast, inaccessible forms, and content incompatible with screen readers. Laws like the Americans with Disabilities Act (ADA), Section 508, and the European Accessibility Act require organizations to provide accessible digital experiences and address reported barriers. Accessibility reporting may come from users with disabilities, automated testing tools, manual audits, or assistive technology evaluations. Organizations that actively solicit, track, and remediate accessibility issues demonstrate commitment to inclusion, reduce legal risk, and make sure their services are usable by the widest possible audience. |
| Accessibility statement |
A public declaration that explains how accessible a website, application, or digital service is for people with disabilities, and demonstrates the organization's commitment to digital accessibility. Usually it includes a commitment to accessibility, the conformance level, known limitations, alternatives and workarounds and other technical specifications. |
| Age gating |
The practice of restricting access to websites, apps, or content based on a user's age to protect minors from unsuitable material, such as alcohol, tobacco, or adult content. It involves tools like birthdate entry forms or yes/no pop-ups. These mechanisms are increasingly mandated by law globally to enhance online safety but raise significant privacy and censorship concerns. |
| Bounty hunting |
Also called bug bounty programs, bounty hunting represents programs that incentivize independent security researchers to identify and report vulnerabilities in your systems before malicious actors can exploit them. Organizations can offer monetary rewards (bounties) based on the severity and impact of discovered security flaws. This crowdsourced approach to security testing provides access to diverse expertise and perspectives that internal teams might miss. Properly managed bounty programs help improve security posture, demonstrate commitment to user safety, and build positive relationships with the security research community. Common vulnerabilities reported through bounty programs include SQL injection, cross-site scripting (XSS), authentication bypass, and data exposure issues. |
| Browser fingerprint |
The unique digital profile of your web browser and device, including the browser type and version, operating system and version, screen resolution, color depth, installed fonts and so on. |
| CCPA |
California Consumer Privacy Act, a comprehensive data privacy law that went into effect on January 1, 2020, which gives California residents significant rights over their personal information and requires businesses to be transparent about how they collect, use, and share consumer data. |
| CMP |
Google-certified Consent Management Platform, a system that manages consent for serving ads in the EEA, the UK, and Switzerland (for publishers). |
| Content takedown |
A type of formal demands to remove or restrict access to specific content, typically due to legal violations, policy breaches, or rights infringement. Common reasons include copyright or trademark infringement (often submitted as DMCA notices), defamatory material, privacy violations, illegal content, or terms of service violations. Many jurisdictions impose legal obligations on platforms to respond to takedown requests within specific timeframes and provide mechanisms for counter-notices or appeals. Properly managing takedown requests helps to protect your organization from legal liability, respects intellectual property rights, and maintains platform integrity. Organizations must balance the need to address legitimate concerns with protecting free expression and avoiding over-removal of lawful content. |
| CSV |
Comma-Separated Values, a widely used, plain-text file format that stores tabular data. Each line in a CSV file represents a single data record, with individual fields separated by commas. It is used in DSR to export flat, straightforward personal data (e.g., basic account info, transaction histories, allowing data subjects to easily open, read, and understand their data using standard spreadsheet software like Microsoft Excel or Google Sheets. |
| Custom links |
Displays links such as "Privacy Center" and "Do not sell or share my personal information" in the footer of your site |
| CVC |
A card security code (CSC; also known as CVC, CVV, or several other names) is a series of numbers that, in addition to the bank card number, is printed (but not embossed) on a credit or debit card. It is used as a security feature for card-not-present transactions, where a personal identification number (PIN) cannot be manually entered by the cardholder (as they would during point-of-sale or card present transactions). |
| DPO |
Data Protection Officer, an expert responsible for overseeing an organization’s General Data Protection Regulation (GDPR) compliance, advising on data obligations, and acting as a contact point for authorities and individuals. Mandatory for many organizations, DPOs ensure lawful data processing, monitor compliance, and provide guidance on Data Protection Impact Assessments (DPIAs). |
| DSR |
Data Subject Request, a formal request from an individual asking an organization to take action regarding their personal data, such as Right to access (request a copy of all personal data the organization holds about them), right to deletion/erasure (also called "right to be forgotten") and so on. The Control Center helps you track, manage, and respond to data subject requests in a compliant and efficient manner. |
| EEA |
European Economic Area. |
| GDPR |
General Data Protection Regulation, a law that governs how the personal data of individuals in the European Union may be processed and transferred. |
| GPC |
Global Privacy Control, a standard that allows internet users to easily convey their privacy preferences across the web with just one action rather than multiple. GPC enables users to communicate their desire to avoid being tracked or having their data sold or shared directly to websites and online services. |
| GPP |
IAB Global Privacy Platform, a Tech Lab standardized framework designed to streamline the transmission of user privacy consent and choice signals from websites/apps to ad tech vendors across multiple global jurisdictions. As part of Project Rearc, it simplifies compliance with diverse regulations (GDPR, CCPA, MSPA) using a unified, machine-readable format. |
| GTM |
Google Tag Manager container, a snippet of code installed on a website or app that acts as a container for all marketing, analytics, and third-party tags. It allows marketers to manage, add, and update tags without editing website code, supporting web, iOS, Android, AMP, and server-side platforms. |
| Guardrails |
Automated technical and organizational controls that help to control website access based on age gating and VPN/proxy settings. |
| GVL |
Global Vendor List, a central registry managed by IAB Europe (Interactive Advertising Bureau) as part of their Transparency and Consent Framework (TCF). |
| IAB |
The Interactive Advertising Bureau, an American advertising business organization that develops industry standards, conducts research, and provides legal support for the online advertising industry. See also: MSPA. |
| IAB |
The IAB Transparency and Consent Framework is an initiative designed to support the digital advertising ecosystem in complying with GDPR (General Data Protection Regulation) and the ePrivacy Directive. |
| IBAN |
International Bank Account Number, a standardized international numbering system used to identify bank accounts across countries, primarily in Europe and other regions. The IBAN format varies by country but typically includes a country code, check digits, and the account details. |
| JSON |
JavaScript Object Notation, a lightweight, text-based data format that stores information in organized, human-readable key-value pairs and nested lists.It is used in DSR to export complex, hierarchical personal data (e.g., granular user preferences, nested activity logs, device metadata) as it fulfills data portability requirements by providing a highly structured, machine-readable format that preserves the relationships within the data. |
| Metadata Data processor |
The company that processes the user data retrieved via embedded content. Depending on who you embed content from, this can be major content providers (Meta, Google etc.). Select whatever is applicable based on your geographical settings. |
| MSPA |
The IAB Multi-State Privacy Agreement, an industry contractual framework intended to aid advertisers, publishers, agencies, and ad tech intermediaries in complying with five state privacy laws (California, Virginia, Colorado, Connecticut, Utah). The MSPA is not a “model contract” or a template agreement; instead, it is a set of privacy-protective terms that spring into place among a network of signatories and that follow the data as it flows through the digital ad supply chain. |
| NGO/NGPO |
A Non-Governmental Organization/Non-Governmental Private Organization is an entity that is not part of the government. This can include nonprofit and for-profit entities. |
| PCI |
Payment Card Industry Data Security Standard, a security standard set by major card networks that governs how payment card data (card numbers, expiration dates, CVV codes) must be stored, processed, and transmitted to prevent fraud and breaches. |
| Property |
In the Control center, a property is a subdomain of a website, usually what comes either before or after the mail domain. For example, www.company.com can have blog.company.com and shop.company.com as properties (subdomains). |
| Slug |
A URL that functions as the unique, human-readable part of a web address that comes after the domain name. It identifies a specific page on a website. Example: In the URL https://example.com/what-is-a-url-slug, the slug is what-is-a-url-slug. |
| SRI |
Subresource Integrity, a browser security feature that protects your website from being compromised when it loads external files (like JavaScript or CSS) from a third-party server, such as a Content Delivery Network (CDN). |
| SSO |
Single Sign-On, an authentication method that allows users to log in once and gain access to multiple applications or systems without needing to enter their credentials again. Instead of managing separate usernames and passwords for each platform, users authenticate through a single trusted identity provider, which then grants access across all connected services. |
| SWIFT |
The Society for Worldwide Interbank Financial Telecommunication, an internationally recognized code used to identify banks worldwide, particularly for international wire transfers. The SWIFT code is typically 8 or 11 characters long. |
| TCF |
Transparency and Consent Framework, an open-standard technical and legal framework developed by IAB Europe in collaboration with IAB Tech Lab. It is specifically designed to help digital publishers, advertisers, and ad-tech vendors comply with the European Union's General Data Protection Regulation (GDPR) and the ePrivacy Directive. |
| UI |
User Interface |
| VPPA |
Video Privacy Protection Act, a US federal law enacted in 1988 that protects the privacy of individuals' video viewing records. The VPPA prohibits video service providers (originally video rental stores, now including streaming services and online platforms) from disclosing personally identifiable information about what videos a person watches or rents without their written consent. |
| Whistleblowing |
The act of reporting suspected wrongdoing, illegal activity, ethical violations, or compliance failures within an organization. Whistleblowers may be employees, contractors, customers, or other stakeholders who observe concerning practices such as fraud, safety violations, data breaches, harassment, or regulatory non-compliance. Many jurisdictions legally protect whistleblowers from retaliation and require organizations to provide secure reporting channels. Effective whistleblowing programs help organizations identify and address problems early, demonstrate commitment to ethical conduct, and maintain regulatory compliance. Organizations must handle whistleblower reports with confidentiality, conduct fair investigations, and take appropriate corrective action when misconduct is confirmed. |
| Widget |
A website tool that helps your website comply with global data privacy (like GDPR, CCPA) and accessibility regulations by managing cookie consent, data subject requests (DSRs), and legal documents through a customizable interface that adapts to your location and needs. The widget appears as a small, brandable banner or icon on a website, allowing visitors to easily manage their privacy choices, understand data usage, and access policies, while also handling specific requirements like HIPAA consent. |