← Journal
Knowledge Base3 August 20263 min read
Security, Privacy and Compliance Terms: A Glossary
24 security, privacy and compliance terms, explained in plain English - part of the Five Stones knowledge base.
Part of the Five Stones knowledge base - 24 terms on security, privacy and compliance, in plain English.
Part of the Five Stones knowledge base - 24 terms on security, privacy and compliance, in plain English.
Part of the Five Stones knowledge base - 24 terms on security, privacy and compliance, in plain English.
- Data protection - The general practice and legal obligation of keeping personal and business data safe from misuse, loss or unauthorised access.
- PDPA (Personal Data Protection Act) - The data protection law governing how personal data must be collected, used and protected in both Singapore and Malaysia (each country has its own PDPA, with different specific rules).
- GDPR (General Data Protection Regulation) - The EU's data protection law, relevant to any Singapore or Malaysia SME that handles data belonging to EU customers.
- Consent management - Systematically tracking what a customer has agreed to (e.g. marketing messages, data use) and honouring it.
- Data encryption - Scrambling data so it cannot be read without the correct key, protecting it both when stored and when sent between systems.
- Two-factor authentication (2FA) - A login security step requiring a second proof of identity beyond just a password, such as a code sent to a phone.
- Access control - Rules determining which staff can view or edit which systems and data, limiting exposure if one account is compromised.
- Cybersecurity - The broader practice of protecting a business's systems, networks and data from attack or unauthorised access.
- Phishing - A scam attempt, often by email or message, designed to trick someone into revealing passwords or financial details.
- Ransomware - Malicious software that locks a business out of its own data until a ransom is paid, one of the most common SME cyber threats.
- Data breach notification - The legal requirement in many jurisdictions to inform affected individuals and regulators when personal data is compromised.
- Third-party risk - The security and compliance risk a business takes on by sharing data with an external vendor, such as an AI tool provider.
- Data processing agreement (DPA) - A contract that defines how a third-party vendor is allowed to handle a business's data on its behalf.
- AI governance - The internal policies a business sets for how AI tools may be used, what data they can access, and who is accountable for their output.
- Model transparency - How clearly an AI vendor discloses what data their model was trained on and how it makes decisions.
- Compliance - Meeting the legal, regulatory and industry standards that apply to a business's operations.
- Regulatory impact assessment - A formal review of how much a set of regulations or compliance costs actually load onto a business, increasingly proposed as a single combined measure rather than reviewing each rule separately.
- Audit trail - A recorded history of who did what and when within a system, important for both security and dispute resolution.
- Data retention policy - A business's defined rules for how long different types of data are kept before being deleted.
- Vendor due diligence - Checking a software or AI vendor's security, compliance and reliability before signing a contract with them.
- SOC 2 compliance - An independent certification showing a software vendor meets recognised standards for handling customer data securely.
- ISO 27001 - An international standard for information security management, sometimes required by larger clients before they will work with a smaller vendor.
- Privacy policy - The public document explaining what data a business collects, why, and how it is used and protected.
- Data subject access request (DSAR) - A request from an individual asking a business to disclose what personal data it holds about them, a right under most data protection laws.
Looking for a different topic? Browse the full knowledge base, or tell us what's missing.
- data privacy
- pdpa
- cybersecurity
- compliance
- knowledge base
