Why These Terms Matter
Privacy conversations online are full of jargon — terms like metadata, cookies, and end-to-end encryption appear constantly in news headlines, app agreements, and privacy settings menus. Without a working understanding of what these words actually mean, it's difficult to make informed choices about your digital life.
This glossary defines the most common personal-data and internet-privacy terms in plain English. No technical background required. Think of it as a reference card you can return to whenever an unfamiliar term appears.
For a deeper look at how common privacy beliefs can mislead you, see our guide to online privacy myths. And if you're ready to put this vocabulary to work, our personal privacy checklist walks you through a practical review of your accounts and settings.
| What counts as personal data | Name, email, IP address, location, behavioral patterns |
| Common tracker type | Third-party cookies placed by advertisers |
| US state breach notification laws | All 50 states have some form of breach notification law (National Conference of State Legislatures) |
| Strong account security standard | Two-factor authentication (2FA) |
| Default data collection model (US) | Opt-out — data collected unless you actively stop it |
Key Terms, Defined
The definitions below cover concepts you're likely to encounter across apps, browsers, and news coverage. They're grouped loosely by theme — data collection, security, and your rights — but each stands on its own.
Personal Data
Any information that can identify you — directly or indirectly. This includes your name, email address, IP address, location history, and even patterns of behavior that, when combined, point to a specific individual.
Metadata
Data about data. A text message's metadata includes when it was sent, to whom, and from where — but not the message's content. Metadata can reveal a great deal about habits and relationships even without the underlying content.
Cookie
A small text file a website stores on your device to remember information about you — such as login status or browsing preferences. Third-party cookies, placed by advertisers rather than the site you're visiting, are widely used to track you across multiple websites.
Data Broker
A company that collects personal information from many sources — public records, social media, purchase histories — and sells or licenses it to other businesses. Most people have profiles with multiple data brokers without ever interacting with them directly.
End-to-End Encryption
A method of securing communication so that only the sender and intended recipient can read it. Even the service provider cannot access the content. It's commonly used in messaging apps and file storage.
IP Address
A numerical label assigned to your device when it connects to the internet. Your IP address can reveal your approximate geographic location and is logged by websites and services you visit.
Privacy Policy
A legal document disclosing how an organization collects, uses, shares, and stores your personal data. Privacy policies are often long and technical; key things to look for include what data is collected and whether it is sold to third parties.
Two-Factor Authentication (2FA)
A security process requiring two forms of verification before granting account access — typically your password plus a one-time code sent to your phone or generated by an app. It significantly reduces the risk of unauthorized access.
VPN (Virtual Private Network)
A service that routes your internet traffic through an encrypted tunnel, masking your IP address from the sites you visit. A VPN does not make you anonymous — the VPN provider itself can still see your traffic — but it does add a layer of privacy on public networks.
Opt-In vs. Opt-Out
Opt-in means you must actively consent before your data is collected or shared. Opt-out means your data is collected by default unless you take action to stop it. Most ad-targeting systems in the US operate on an opt-out basis.
Data Minimization
The principle that only the data strictly necessary for a given purpose should be collected. It's a cornerstone of privacy-protective design and is required under some data protection regulations.
Breach Notification
A legal requirement, in many US states, that organizations inform affected individuals when their personal data has been exposed or stolen in a security incident. Timelines and thresholds vary by state law.
Understanding how data brokers fit into this picture is especially useful. These companies sit at the intersection of several terms above — collecting personal data, building profiles, and selling access to third parties. For a detailed look, see our explainer on data brokers.
If this glossary is your starting point, our starter framework for online privacy builds on these concepts with actionable first steps for everyday users.
Glossaries Help, But Context Matters
Knowing what a term means is a strong foundation — but privacy decisions depend on context. A VPN is useful on public Wi-Fi but won't protect data you've already shared with an app. End-to-end encryption secures messages in transit but not your backup if stored unencrypted in the cloud. Use this glossary as a starting point, then look at how each concept applies to your specific tools and habits.
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.

