Glossary
The words LexLint uses for software law and legal risk, defined in United States legal usage first. Where another regime or a neighbouring field uses a different word for the same thing, or the same word for a different thing, the entry says so. The dotted underlines across the site open the same definitions.
§ · Law
- Age assurance
-
The family of methods for establishing that a user is above or below an age: self-declaration, age estimation from a face or from behaviour, and age verification against a document or a trusted third party. Laws name the level they require, and the levels are not interchangeable.
In software usage age gate. A self-declared date of birth screen; the weakest method and the one most laws now say is not enough. United Kingdom highly effective age assurance. The Online Safety Act's standard for services that allow pornography, defined by Ofcom's guidance. - Algorithmic impact assessment
-
A written assessment of an automated decision system's effects before it is deployed: its purpose, data, accuracy, bias, and the recourse available to people it decides about. Required by Canada's federal directive, by New York City for hiring tools (as a bias audit), and by several US state AI laws.
European Union fundamental rights impact assessment. AI Act Art. 27 requires one from deployers of high-risk systems that are public bodies or provide certain services. Canada Algorithmic Impact Assessment. A capitalized proper noun in Canada: the Treasury Board's questionnaire under the Directive on Automated Decision-Making. See also: Data protection impact assessment, Automated decision-making, High-risk AI system
- Applies to
-
Whom an instrument binds: the private sector, government, or both. A duty written for public bodies is not a finding against a private app, and the corpus records the answer on every instrument rather than leaving a reader to infer it.
See also: Instrument, Finding
-
The line computer-misuse law draws between lawful and unlawful access to a system. Under the US federal statute the question is whether access exceeded what the owner permitted, and since the Supreme Court's 2021 decision a public page with no gate is not an unauthorized one.
United Kingdom unauthorised access. The Computer Misuse Act 1990 s. 1 turns on the accused knowing the access was unauthorised, with no public-page carve-out written into the statute. European Union illegal access to information systems. Directive 2013/40 requires Member States to criminalize access without right where a security measure is infringed. See also: robots.txt, Terms of service, Circumvention
- Automated decision-making
-
A decision about a person made by a system without meaningful human involvement, with legal or similarly significant effects: credit, housing, employment, insurance, access to services. Most regimes give the person a right to an explanation, a human review, or an opt-out.
European Union solely automated processing, profiling. General Data Protection Regulation (GDPR) Art. 22 restricts decisions based solely on automated processing; profiling is the evaluation of personal aspects that often feeds them. United States automated decision technology, automated decision-making technology (ADMT). California's rulemaking term; Colorado's AI Act says "consequential decision". See also: Algorithmic impact assessment, High-risk AI system
- Base rate
-
A published frequency of enforcement or private action under an instrument, banded from one to five by a written rule, used as the default likelihood before counsel adjusts it. LexLint derives the band from the instrument's enforcement record and never hand-picks it.
In cybersecurity usage loss event frequency. The Factor Analysis of Information Risk (FAIR) term for the same quantity. In software usage prior probability. Statistics and epidemiology usage; the enforcement climate is the prior that fills in where an instrument has no base rate of its own. See also: Enforcement record, Prior and evidence, Enforcement climate
- Case law
-
Judicial decisions that construe an instrument: what counts as authorized access, whether publicly available personal data is fair game, when a biometric claim accrues. A decision that also sanctions a party is both case law and an enforcement action, and the corpus links it to both.
European Union jurisprudence of the Court of Justice. Civil-law systems do not bind later courts by precedent in the common-law sense, but the Court of Justice's rulings on EU law bind every Member State court. See also: Settledness, Enforcement action
- Circumvention
-
Getting past a technical barrier: a CAPTCHA, an IP block, a rate limit, a login. What happens legally escalates by jurisdiction from nothing, to a civil claim, to a crime, and the corpus records the escalation per jurisdiction.
United States anti-circumvention. The Digital Millennium Copyright Act (DMCA)'s anti-circumvention provision targets measures that control access to copyrighted works, a narrower thing than a rate limit. See also: Authorized access, robots.txt
- Class action
-
A suit brought by named plaintiffs on behalf of a class of people in the same position, under Federal Rule 23 and its state analogues. With statutory damages per person it is the engine of private enforcement of US privacy law; without them it is a much harder case to certify.
European Union representative action. Directive 2020/1828, applying since 2023, lets qualified entities such as consumer bodies sue for injunctions and redress on behalf of consumers; individuals cannot lead the action themselves. United Kingdom collective proceedings, group litigation order. Opt-out collective proceedings exist only before the Competition Appeal Tribunal; a group litigation order in the High Court is opt-in and case-managed. Germany Musterfeststellungsklage, Abhilfeklage. The model declaratory action (2018) settles common questions; the redress action (2023) can award compensation, both led by qualified consumer associations. Netherlands WAMCA collective action. The Netherlands' 2020 act allows opt-out damages claims by representative foundations, which has made Dutch courts a preferred venue for EU-wide claims. Australia representative proceeding. Federal Court class actions under Part IVA, opt-out by default, with litigation funders common. See also: Private enforcement, Private right of action, Statutory damages, Venue
-
The government body empowered to enforce an instrument in a jurisdiction. In US usage this is the regulator or agency (the Federal Trade Commission (FTC), a state attorney general, the California Privacy Protection Agency (CPPA)); the phrase itself is EU drafting that LexLint adopts because it names the role regardless of the regime.
European Union supervisory authority. The General Data Protection Regulation (GDPR)'s term for a national data protection authority (Art. 51); the EU AI Act uses "market surveillance authority" and "notifying authority" for its enforcers. United Kingdom the Commissioner. The Information Commissioner's Office is the data protection authority; the Competition and Markets Authority and Ofcom enforce the digital-markets and online-safety regimes. Canada Privacy Commissioner. The federal Office of the Privacy Commissioner and the provincial commissioners (Quebec's CAI above all) enforce; the federal Commissioner's powers are largely recommendatory. Australia the Commissioner (Office of the Australian Information Commissioner (OAIC)). The Office of the Australian Information Commissioner enforces the Privacy Act; the Australian Competition and Consumer Commission (ACCC) enforces consumer law against software as well. Singapore Personal Data Protection Commission (PDPC). The Personal Data Protection Commission enforces the Personal Data Protection Act (PDPA) and publishes its decisions. See also: Public enforcement, Enforcement capacity, Data protection authority
- Consent order
-
A settlement of a public enforcement action in which the respondent agrees to obligations, often for twenty years, without admitting liability. The Federal Trade Commission (FTC)'s standard outcome; a later breach of the order is what unlocks civil penalties.
United States consent decree. The same thing entered by a court rather than the agency. European Union commitments. Competition-law usage; data protection authorities settle less often and publish decisions instead. See also: Monetary sanction, Disposition
- Criminal exposure
-
Whether a breach of the instrument can be prosecuted as a crime, and on what terms. Recorded separately from civil and administrative penalties because the process, the defendants (individuals as well as the company), and the consequences differ.
See also: Prosecution, Penalty structure
- Disposition
-
How an enforcement action ended: settled, upheld, annulled on appeal, reduced on appeal, withdrawn, dismissed, or still pending. The enforcement record's success rate is the share of decided actions that were settled or upheld rather than annulled, withdrawn, or dismissed.
See also: Enforcement action, Public enforcement record
- Enforcement action
-
The unit of the public enforcement record: one proceeding by a competent authority against one respondent under an instrument. Its proceeding type is administrative, civil, or criminal. LexLint reserves "prosecution" for criminal proceedings only.
European Union corrective measure. General Data Protection Regulation (GDPR) Art. 58(2) lists the supervisory authority's corrective powers, from a warning to a ban on processing to an administrative fine; each exercise is one action. United Kingdom enforcement notice, monetary penalty notice. The Information Commissioner's Office (ICO)'s formal instruments; a reprimand is also published but carries no penalty. Australia civil penalty proceeding. The Office of the Australian Information Commissioner (OAIC) or Australian Competition and Consumer Commission (ACCC) applies to the Federal Court for a civil penalty; the court, not the regulator, sets the amount. See also: Public enforcement, Monetary sanction, Disposition, Prosecution
- Enforcement capacity
-
The budget and full-time headcount of a jurisdiction's competent authorities for software law. The supply side of enforcement: an authority with forty staff and a thousand complaints a year has a queue, and the queue is a fact about likelihood.
European Union resources of supervisory authorities. General Data Protection Regulation (GDPR) Art. 52(4) requires each Member State to resource its authority; the European Data Protection Board publishes the figures yearly. See also: Competent authority, Enforcement climate
- Enforcement climate
-
LexLint's composite for a jurisdiction: enforcement capacity, public and private enforcement intensity, the magnitude of sanctions, and the regulatory outlook, each banded from one to five by a written rule. It is the prior for a finding's likelihood where the instrument has no enforcement record of its own.
See also: Prior and evidence, Base rate, Regulatory outlook, LexLint Risk Score
- Enforcement intensity
-
Enforcement actions and monetary sanctions per unit of regulated economy and per capita, on a rolling ten-year window. The normalisation is what makes a small jurisdiction with an active authority comparable to a large one with a passive one.
See also: Enforcement climate, Public enforcement record, Jurisdictional weight
- Enforcement record
-
The structured account of how often an instrument is actually enforced: actions per year, fines per year, total and median and ninetieth-percentile fines, the first enforcement date, the trend, each with a source and an as-of date. It sits on the instrument; the base rate band is derived from it.
See also: Base rate, Public enforcement record, Penalty structure
- Establishment
-
The effective and real exercise of activity through stable arrangements in a jurisdiction, in the General Data Protection Regulation (GDPR)'s words: an office, a subsidiary, staff. Establishment decides which authority leads and, with targeting, whether the regulation reaches a company at all.
United States doing business, minimum contacts. The US analogues: statutory thresholds for who a state act covers, and the constitutional test for whether a court has jurisdiction over an out-of-state defendant. See also: One-stop-shop, Extraterritorial reach
- Expected monetary value
-
Likelihood times loss, summed over scenarios. Inherent expected monetary value (EMV) takes the finding as it stands; residual EMV credits the control state of the work item and any insurance. Decision analysis and litigation risk analysis use the same term.
See also: LexLint Risk Score, Treatment
- Exposure ceiling
-
The statutory maximum a finding could cost given the app's exposure profile: the penalty structure applied to the app's turnover, violation count, or affected persons. It bounds the loss term and is never the expected loss.
See also: Penalty structure, Exposure profile, LexLint Risk Score
- Exposure profile
-
What the developer supplies about the app for the risk model: worldwide turnover, the small or medium-sized enterprise (SME) flag, per-jurisdiction status, data subjects, minors, special categories, insurance. Versioned per project so a score can be reproduced.
In cybersecurity usage asset and loss factors. Factor Analysis of Information Risk (FAIR)'s names for the analogous inputs. See also: Exposure ceiling, LexLint Risk Score
- Extraterritorial reach
-
How far an instrument binds companies outside the jurisdiction. The General Data Protection Regulation (GDPR) reaches any controller offering goods or services to people in the EU or monitoring their behaviour; the AI Act reaches providers whose output is used in the EU; US state acts reach companies doing business in the state above a threshold.
In law usage territorial scope. The heading under which EU instruments state it (GDPR Art. 3, AI Act Art. 2). See also: Establishment, Jurisdiction
- Fair use and fair dealing
-
The US doctrine that permits copying a work without permission when the purpose, nature, amount, and market effect weigh in favour, and the narrower Commonwealth doctrine that permits copying only for listed purposes such as research, criticism, and news reporting.
United Kingdom fair dealing. Purpose-limited; the EU's closed list of exceptions in Directive 2001/29 works the same way. Canada fair dealing. Canada's list includes research, private study, education, parody, and satire, read generously by the Supreme Court. See also: Text and data mining
- Free band
-
The corpus-only band shown on the Free tier: High, Medium, Low, or None, derived from the instrument's status, its private right of action, and its penalty structure, with no exposure input from the developer.
See also: LexLint Risk Score, Private right of action
- General-purpose AI
-
A model that can serve many different tasks, such as a large language model. The EU AI Act sets specific duties for providers of these models: technical documentation, a copyright policy that respects text-and-data-mining opt-outs, a training-data summary, and more for models with systemic risk.
In software usage foundation model, frontier model. Industry and US policy usage for the same class; the AI Act uses neither term. See also: Provider and deployer, Text and data mining
- High-risk AI system
-
The EU AI Act's category for AI used in listed domains (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice) or as a safety component of a regulated product. Providers owe conformity assessment and a quality system; deployers owe human oversight and monitoring.
United States high-risk artificial intelligence system. Colorado's AI Act borrows the phrase for systems making consequential decisions, with a different list and a duty of reasonable care rather than conformity assessment. See also: Provider and deployer, General-purpose AI, Automated decision-making
- In force
-
An instrument's status: enacted and effective, enacted but not yet effective, proposed, repealed, or struck down. Only an in-force duty raises a warning; the rest raise information findings so a reader can see what is coming.
European Union entry into force, application. EU acts enter into force on a date and apply from a later one, sometimes years later and in stages; the applying date is the one that binds. See also: Instrument, Finding
- Instrument
-
One statute, regulation, ordinance, directive, or binding guidance document in the corpus, with its citation, status, effective date, the parties it binds, and its attributes. A lint finding cites an instrument, not a topic.
European Union regulation, directive. A regulation binds directly in every Member State; a directive binds only once transposed into national law, so the national act is the instrument that reaches an app. United Kingdom Act, statutory instrument. Primary legislation and the secondary rules made under it; both are instruments in the corpus. See also: Legal area, Applies to, In force
- Jurisdiction
-
A body of law together with the authorities and courts that apply it. LexLint keys every law to one jurisdiction at one of four levels: supranational (the EU), national, subnational (a US state, a province, a Land), or local (a city).
European Union Member State. An EU Member State is a national jurisdiction in LexLint's model, sitting under the EU's supranational rung, so an EU-wide regulation and a Member State's own act are two jurisdictions. United Kingdom nation. England and Wales, Scotland and Northern Ireland are separate legal systems; LexLint keys UK-wide statutes to the national rung and does not yet split the nations. In software usage region. Cloud and CDN "regions" are data-center locations, not jurisdictions; where data sits is one input to which jurisdiction applies, never the answer. See also: Jurisdiction level, Competent authority, Venue
- Jurisdiction level
-
Where a jurisdiction sits in the hierarchy: supranational, national, subnational, or local. The level, not the label, is what the model reads, because "state" means a sovereign country in one regime and a subnational unit in another.
European Union Union, Member State, region. Regional and municipal law exists across the EU but reaches LexLint's corpus only where it binds software; the local rung is US-first today. See also: Jurisdiction, Own-level and consolidated
- Legal area
-
The corpus topic a finding belongs to: age, aggregation, AI, cybersecurity, privacy, or scraping. Derived from the app's declared activities and overridable with a reason.
In law usage practice area. A firm's practice areas are broader (privacy and data security, technology transactions); a legal area is one corpus topic. See also: Finding, Instrument, Software law
- LexLint Risk Score
-
Likelihood times impact on a one-to-twenty-five scale, banded, per finding and rolled up per app. LexLint supplies statutory magnitude and a published enforcement base rate as cited defaults; the developer supplies exposure; counsel adjusts likelihood and impact with a written justification. It is a modelled exposure under stated assumptions, never a prediction.
In cybersecurity usage risk score. A security register scores likelihood times impact on a system; the LexLint Risk Score (LRS) prices the same product in money and in legal terms, and the two should never be merged into one number. See also: Expected monetary value, Base rate, Exposure ceiling, Register row
- Matter
-
A legal team's unit of work: a client question with a status, a practice area, a responsible attorney, stages, tasks, and documents. LexLint's legal view presents an app under review as a matter, using the field names practice-management tools already use.
- Memo
-
The written analysis of one risk scenario in the convention of legal writing: question presented, brief answer, facts, applicable law, analysis, recommendation.
- Minors
-
People below the age of majority, whom software law treats as a protected class at several thresholds: under 13 for the US children's privacy statute, under 16 for parental consent in the General Data Protection Regulation (GDPR)'s default, under 18 for most age-appropriate design and social-media laws.
United States children, teens. Children's Online Privacy Protection Act (COPPA) says children (under 13); the state acts add teens (13 to 17) with opt-in rules of their own. See also: Age assurance, Consent
- Monetary sanction
-
Money ordered or agreed as the outcome of a public enforcement action. LexLint records the kind: a fine, a civil penalty, a settlement, disgorgement, restitution, or an order with no money attached.
United States civil penalty. The Federal Trade Commission (FTC) cannot fine for a first violation of Section 5 and must sue for civil penalties under a rule or an existing order; state attorneys general have direct penalty authority under their consumer-protection acts. European Union administrative fine. General Data Protection Regulation (GDPR) Art. 83 and AI Act Art. 99; imposed by the authority directly in most Member States, by a court in Denmark and Estonia. United Kingdom monetary penalty. Issued by notice; appealable to the First-tier Tribunal. See also: Enforcement action, Penalty structure, Disposition
- Obligation class
-
What kind of duty an instrument imposes: a prohibition, a disclosure, a consent requirement, a process duty such as an assessment, a technical requirement, or a governance duty. The class shapes what a remediation looks like.
- Own-level and consolidated
-
Two scopes for reading an enforcement record. The own-level record of the United States counts federal authorities and courts only; the consolidated record counts every body at or below it, the states and cities included. The EU has the same pair.
In economics usage consolidation. Borrowed from group accounting, where a parent's consolidated statements fold in its subsidiaries. See also: Jurisdiction level, Public enforcement record
- Penalty structure
-
The statutory arithmetic of a fine: a fixed cap, a percentage of worldwide turnover, the rule for choosing between them (the higher of the two, or the lower for small and medium enterprises where the instrument says so), and any per-violation or per-person amount.
European Union administrative fine tiers. General Data Protection Regulation (GDPR) Art. 83 and AI Act Art. 99 set tiers as the higher of a fixed sum and a share of worldwide annual turnover; the AI Act gives small or medium-sized enterprises (SMEs) the lower of the two. United States civil penalty schedule. US statutes set per-violation amounts, adjusted for inflation by rule, with the count of violations doing the work a turnover percentage does in the EU. See also: Monetary sanction, Exposure ceiling, Statutory damages
- Playbook
-
Per legal area or instrument class, the preferred position, the fallback, the escalation trigger, and the approver. Contract-review tools use the word the same way; LexLint's playbooks are inherited by shared profiles.
- Prior and evidence
-
The order LexLint reads likelihood in. An instrument's own enforcement record is the evidence and wins where it exists; the jurisdiction's enforcement climate is the prior, used where the instrument has none. The finding says which one it used, and a jurisdiction nobody has researched yields neither.
In software usage prior. Bayesian usage, where a prior is the belief before the data arrives; the climate plays that role for the instrument's own record. See also: Enforcement climate, Base rate, Enforcement record
- Private enforcement
-
Action by a private party under a private right of action: an individual's suit, a class action, a competitor's claim. The other half of the enforcement record, counted separately because it answers to different incentives than a regulator does.
See also: Public enforcement, Private right of action, Class action, Private enforcement record
- Private enforcement record
-
Every private action under software law venued in a jurisdiction, one row per suit with its court, instrument, plaintiff class, resolution, and any disclosed amount, aggregated over a rolling ten-year window. Undisclosed settlements are counted as filings and reported as undisclosed rather than dropped.
See also: Private enforcement, Venue, Class action
- Private right of action
-
A statutory right of a private party to sue for a breach of the instrument, as opposed to enforcement by a public body alone. Whether one exists is the single largest driver of private enforcement, and LexLint records it on every instrument.
In law usage standing. Standing is the separate question of whether this plaintiff may bring the claim, which in US federal court turns on a concrete injury even where the statute grants the right. European Union right to an effective judicial remedy and to compensation. General Data Protection Regulation (GDPR) Arts. 79 and 82 give every data subject a right to sue the controller or processor and to be compensated for material or non-material damage. See also: Private enforcement, Statutory damages, Class action
- Prosecution
-
A criminal proceeding brought by the state. In everyday speech "prosecute" covers any enforcement, and LexLint does not use it that way: an administrative fine is an enforcement action, not a prosecution, and the distinction matters because criminal exposure is its own risk attribute.
See also: Enforcement action, Criminal exposure
- Provider and deployer
-
The EU AI Act's two main roles: the provider develops an AI system or model and places it on the market under its name; the deployer uses it under its own authority. Distributors and importers have narrower duties. Most US laws say developer and deployer.
United States developer and deployer. Colorado's and Utah's terms; the National Institute of Standards and Technology (NIST) AI Risk Management Framework speaks of actors across the lifecycle rather than fixing two roles. In software usage model provider, operator. Industry usage; an operator that fine-tunes and re-releases a model becomes a provider under the AI Act. See also: High-risk AI system, General-purpose AI
- Public enforcement
-
Action by a government body under an instrument: a regulator's administrative proceeding, an attorney general's civil suit, a prosecutor's criminal case. The law-and-economics term, used in LexLint for the government half of the enforcement record.
In software usage regulatory enforcement. Industry usage; the same thing, minus the contrast with private enforcement that the model needs. See also: Private enforcement, Enforcement action, Public enforcement record
- Public enforcement record
-
Every public enforcement action under software law in a jurisdiction, one row per action with its authority, instrument, respondent, proceeding type, monetary sanction, and disposition, aggregated over a rolling ten-year window.
See also: Public enforcement, Enforcement action, Enforcement record
- Quantitative legal risk analysis
-
Pricing a legal risk as a probability times a loss rather than as a label. LexLint's model follows ISO 31022, the guideline for managing legal risk, for its frame and borrows the frequency-times-magnitude structure of the Factor Analysis of Information Risk (FAIR) standard for its arithmetic.
In cybersecurity usage FAIR. Factor Analysis of Information Risk, the Open Group standard that decomposes cyber risk into loss event frequency and loss magnitude; LexLint uses the structure and its own legal inputs. See also: LexLint Risk Score, Expected monetary value, Base rate
- Register row
-
The risk-register entry behind a work item: likelihood and impact on one to five, inherent and residual scores, treatment, owner, justification, identification date, review date, and status. Shaped to export straight into a governance tool.
In cybersecurity usage risk register entry. ISO 31000 and the governance, risk, and compliance (GRC) tools use the same shape; LexLint keeps the field names so an export needs no mapping. See also: Work item, Treatment, Risk decision
- Regulatory outlook
-
Forward-looking signals about how a jurisdiction intends to enforce, scored by people from what legislators, ministers, commissioners, and agency heads say. History says what a jurisdiction did; the outlook says what it has announced. It can move a climate band one step at most.
See also: Enforcement climate
- Risk decision
-
The recorded acceptance of a residual risk: the scenario, the treatment, the role that decided, the justification, the review date, and the hash of the exposure profile it was decided against.
In law usage risk acceptance. ISO Guide 73's term for the decision itself. See also: Register row, Treatment
- Settledness
-
How much interpretation stands between an instrument's text and knowing whether it binds an app: whether official guidance exists, whether a court has construed it, whether it is under challenge, and what questions remain open. Banded as settled, developing, or unsettled, and the band routes a finding to counsel by rule.
- Software law
-
LexLint's name for the law it holds: the instruments that govern what software must do, across its six topics (AI, scraping, privacy, cybersecurity, age-gating, and news aggregation). The term names the collection; an individual law keeps its own name and kind, so a finding cites an Act, a regulation, a directive, or a privacy law, never "software law".
In law usage software law (licensing and IP). In general legal usage the phrase means the law of software as property, licences, copyright, patents and contracts. None of that is in the corpus; LexLint's sense is the law that binds what an application does. In law usage technology law, digital regulation. Practice-area and policy labels that reach further than the corpus, into telecom, e-commerce, platform and IP law. LexLint does not use them for its collection. See also: Legal area, Instrument, Applies to
- Statutory damages
-
A fixed sum per person or per violation set by the statute, owed without proof of actual loss. They are what make a class action under a privacy statute worth bringing, since the arithmetic is the class size times the amount.
European Union compensation for material or non-material damage. General Data Protection Regulation (GDPR) Art. 82 requires an infringement, damage, and a causal link; the Court of Justice has held there is no seriousness threshold but also no damages without damage, which is not statutory damages. United Kingdom damages for distress. Recoverable under the UK GDPR and the Data Protection Act 2018, assessed by the court on the facts. See also: Private right of action, Class action, Penalty structure
- Terms of service
-
The contract a site offers its users. Whether it binds a crawler depends on how it was presented: terms behind a link nobody clicked (browsewrap) rarely bind; terms accepted by an act such as creating an account (clickwrap) usually do.
In law usage browsewrap, clickwrap. US case-law labels for the two presentations; the corpus records enforceability of each per jurisdiction. European Union terms and conditions, unfair contract terms. Consumer-protection law limits what standard terms can impose on consumers, but a crawler is rarely a consumer. See also: Authorized access, robots.txt
- Text and data mining
-
Automated analysis of text or data to extract information or to train a model, including crawling pages to do it. Whether it is lawful without a licence turns on the jurisdiction's copyright exception, and on whether the rightsholder has opted out where opt-outs count.
United States fair use. The US has no text and data mining (TDM) exception; the question is whether the copying is a fair use, decided case by case on purpose, nature, amount, and market effect. United Kingdom text and data analysis for non-commercial research. The UK exception (s. 29A) covers non-commercial research only; a wider exception was proposed and withdrawn. European Union TDM exception with opt-out. Directive 2019/790 Art. 4 permits commercial TDM unless the rightsholder has reserved the right, machine-readably for online content. Japan Article 30-4. Japan's exception permits use for information analysis regardless of purpose, with no opt-out, which is why it is the widest in the corpus. See also: Fair use and fair dealing, robots.txt, General-purpose AI
- Treatment
-
What is done about a risk once it is assessed: avoid, modify, share, or retain, in ISO 31000's words. LexLint adds "not applicable (determined)" for a finding counsel has routed out on the facts.
In cybersecurity usage mitigate, transfer, avoid, accept. The governance, risk, and compliance (GRC) labels for the same four options. See also: Register row, Risk decision
- Venue
-
The jurisdiction whose court a private action was filed in. LexLint's private enforcement record is keyed by venue, because the court a defendant can be reached in is what decides where the risk sits.
In law usage forum, situs. Near-synonyms in US practice; "forum selection" is the contract clause that picks the venue in advance. See also: Private enforcement, Private enforcement record
§ · Software
- Finding
-
One obligation in one jurisdiction under one instrument, as a lint raises it against an app. Its severity is warn or info; its kind is obligation, posture, coverage, or pending. Numbers in the risk model live on the finding.
In law usage issue. A legal memo's "issues" are the questions presented; a lint finding is narrower, one duty against one declared fact about the app. See also: Work item, Register row, Obligation class
- robots.txt
-
A file at the root of a site stating which paths crawlers may fetch, under a convention that is a published standard but not a law. Its legal weight varies: evidence of a site's wishes everywhere, a machine-readable opt-out in the EU, and a factor in authorization in some US cases.
European Union machine-readable reservation of rights. Directive 2019/790 Art. 4(3) makes an opt-out expressed in a machine-readable way effective against commercial text and data mining (TDM); robots.txt is the common vehicle. See also: Text and data mining, Authorized access, Terms of service
- Work item
-
The developer's triage unit for a set of findings, in one of three lanes: code, documentation, or counsel. It carries the register row, so nothing is re-triaged for the legal view.
See also: Finding, Register row, Treatment
§ · Cybersecurity
- Incident
-
Any event that compromises the confidentiality, integrity, or availability of a system or its data. A security team counts incidents; privacy law counts the subset that are breaches of personal data. The two logs should agree on which is which.
See also: Breach
§ · Privacy
- Biometric identifier
-
Data derived from a person's physical characteristics that can identify them: a face geometry, a fingerprint, a voiceprint, an iris scan. Illinois requires written consent before collection and gives a private right of action with statutory damages per person, which is why it produces the most private enforcement of any US privacy law.
European Union biometric data. A special category under General Data Protection Regulation (GDPR) Art. 9 when processed to uniquely identify a person; the AI Act separately restricts remote biometric identification. See also: Special categories, Statutory damages
- Breach
-
In privacy law, a defined trigger: unauthorized access to, or disclosure or loss of, personal data, which starts notification clocks to the authority and to affected people. In everyday usage a breach is any violation of a duty, and LexLint says "breach of the instrument" for that meaning.
In cybersecurity usage incident. An incident is any event that compromises a system's security; only an incident that reaches personal data is a breach in the legal sense, and the notification duty attaches to the legal one. United States breach of the security of the system. The fifty state breach-notification statutes each define it; most exclude encrypted data where the key was not taken. See also: Personal data, Incident
- Consent
-
A freely given, specific, informed, and unambiguous indication of the data subject's wishes, in the General Data Protection Regulation (GDPR)'s formulation. It is one lawful basis among several and is often the weakest, because it can be withdrawn and because bundled or pre-ticked consent is invalid.
United States opt-in, affirmative authorization. Required for sensitive data under the state acts, for children's data under Children's Online Privacy Protection Act (COPPA), and for biometric identifiers under Illinois law. In software usage consent banner. The cookie banner is one consent mechanism, for one duty, and is not the same thing as a lawful basis for the processing behind it. See also: Lawful basis, Age assurance
- Controller and processor
-
The two roles personal-data law assigns: the controller decides why and how personal data is processed, the processor processes it on the controller's instructions. Most duties fall on the controller; a processor has its own, narrower set.
United States business and service provider. California's terms under the California Consumer Privacy Act (CCPA); other state acts say controller and processor. In software usage data owner and vendor. Engineering and procurement usage that maps loosely; a vendor that decides what to do with the data is a controller whatever the contract calls it. See also: Personal data, Data subject
-
The competent authority for personal-data law in a jurisdiction, a data protection authority (DPA). The US has none at the federal level; the Federal Trade Commission (FTC) acts under its unfairness and deception authority and sector statutes, and California created a dedicated agency, the California Privacy Protection Agency (CPPA), in 2020.
European Union supervisory authority. One per Member State (Germany has one per Land plus a federal one); they coordinate through the European Data Protection Board. See also: Competent authority, One-stop-shop
- Data protection impact assessment
-
A written assessment of a processing operation's risks to the people whose data it uses, required by the General Data Protection Regulation (GDPR) before high-risk processing and by several US state acts for profiling, sale, and sensitive data. A data protection impact assessment (DPIA) is about harm to individuals, not to the company.
United States data protection assessment, privacy impact assessment. The state acts say data protection assessment; US federal agencies have done privacy impact assessments under the E-Government Act since 2002, which is where the older privacy impact assessment (PIA) term comes from. Canada privacy impact assessment. Required of federal institutions by Treasury Board policy and of private organizations by Quebec's Law 25. See also: Algorithmic impact assessment, Special categories
- Data subject
-
The person the personal data is about. The rights regimes grant (access, deletion, correction, portability, objection, opting out of sale or profiling) belong to the data subject.
United States consumer. The state privacy acts say consumer, and several exclude employees and business contacts from the definition. In software usage user. A user is whoever operates the product; a data subject is whoever the data describes, which includes people who never used it. See also: Personal data, Controller and processor
- Lawful basis
-
The justification a controller must have before processing personal data. The General Data Protection Regulation (GDPR) lists six, of which consent, contract, legal obligation, and legitimate interests carry most software processing. US law mostly runs the other way: processing is permitted unless a statute restricts it or the consumer opts out.
United States notice and choice, opt-out. The US default; sensitive data and minors' data are the places US law flips to opt-in consent. See also: Consent, Personal data
- One-stop-shop
-
The General Data Protection Regulation (GDPR)'s rule that a controller established in more than one Member State answers to a single lead supervisory authority, the one where its main establishment is. It is why so many actions against US technology companies run through Ireland.
See also: Data protection authority, Establishment
- Personal data
-
Any information relating to an identified or identifiable person, the EU definition that most regimes now share. Identifiers, location data, online identifiers, and inferences all count. Biometric data, health data, and other special categories carry extra duties.
United States personal information, personally identifiable information (PII). Personally identifiable information is the older, narrower US notion built around identifiers; the state privacy acts define "personal information" broadly enough to match the EU term. In cybersecurity usage PII. Security frameworks still use PII as a data classification label; it under-includes inferences and pseudonymous identifiers that privacy law covers. See also: Controller and processor, Data subject, Special categories
- Special categories
-
Personal data whose processing is restricted or needs an explicit lawful basis: health, biometrics used to identify, genetic data, racial or ethnic origin, political opinions, religion, trade-union membership, sex life or orientation. Minors' data is treated as a special case in most regimes without being a category.
United States sensitive personal information. The California Consumer Privacy Act (CCPA)'s term, which adds precise geolocation, account credentials, and the contents of communications. See also: Personal data, Biometric identifier
§ · Economics
- Jurisdictional weight
-
The population, nominal GDP, and software value added behind a jurisdiction's law. Used to rank findings, to normalise the enforcement record, and to roll jurisdictions up; never used on its own as a likelihood.
See also: Enforcement intensity, Software value added
- Software value added
-
The gross value added by software and IT services in a jurisdiction, the size of the regulated sector itself. LexLint splits it into what is produced there and what is merely booked there, because turnover- based fines reach the booked figure while establishment follows the produced one.
In economics usage gross value added (GVA), International Standard Industrial Classification (ISIC) J62 and J63. Gross value added is output minus intermediate consumption; the sector is divisions J58.2, J62, and J63 of the international industrial classification, and North American Industry Classification System (NAICS) 5112, 5415, and 518 in North America. In economics usage modified gross national income, gross national income (GNI)*. Ireland's statistical office publishes GNI* to strip out the profit and intellectual property that multinationals route through the country, the canonical measure of the produced-versus-booked gap. See also: Jurisdictional weight
§ · Acronyms
Every acronym the site annotates, with the sentence its tooltip carries. The same sentence appears wherever the acronym does.
- ACCC Australian Competition and Consumer Commission
Australian Competition and Consumer Commission: the national consumer-protection and competition regulator, which also acts against software under the Australian Consumer Law.
- ADMT automated decision-making technology
Automated decision-making technology: the term California's privacy rulemaking uses for systems that make or substantially replace human decisions about people.
- AEDE
Asociación de Editores de Diarios Españoles, the Spanish newspaper publishers' association the 2014 press levy was named after.
- CAI
Commission d'accès à l'information: Quebec's access-to-information and privacy regulator, the strongest of Canada's provincial commissioners since Law 25.
- CAPTCHA
A challenge a site shows to tell people from automated visitors; defeating one is the clearest example of circumventing a technical barrier.
- CCPA California Consumer Privacy Act
California Consumer Privacy Act: the state privacy law, amended by the CPRA in 2020, that the other US state acts are modelled on or written against.
- CFAA Computer Fraud and Abuse Act
Computer Fraud and Abuse Act: the main United States federal statute on unauthorised access to computer systems.
- COPPA Children's Online Privacy Protection Act
Children's Online Privacy Protection Act: the US federal statute requiring verifiable parental consent before collecting personal information from children under 13.
- CPPA California Privacy Protection Agency
California Privacy Protection Agency: the dedicated privacy regulator California created in 2020, the only one of its kind in the United States.
- CPRA California Privacy Rights Act
California Privacy Rights Act: the 2020 ballot measure that amended the CCPA and created the CPPA.
- DMCA Digital Millennium Copyright Act
Digital Millennium Copyright Act: the United States statute whose section 1201 prohibits circumventing technological measures that control access to copyrighted works.
- DPA data protection authority
Data protection authority: the competent authority for personal-data law in a jurisdiction, called a supervisory authority in the GDPR.
- DPIA data protection impact assessment
Data protection impact assessment: the written risk assessment the GDPR requires before high-risk processing, about harm to the people whose data is used.
- DSM Digital Single Market
Digital Single Market: the EU's 2019 copyright directive, whose Article 4 lets rightsholders reserve their works against text and data mining.
- EDPB European Data Protection Board
European Data Protection Board: the EU body that issues guidance and binding decisions on how data protection law is applied across member states.
- EMV expected monetary value
Expected monetary value: likelihood times loss, summed over scenarios; the number the LexLint Risk Score is built on.
- FAIR Factor Analysis of Information Risk
Factor Analysis of Information Risk: the Open Group standard that prices cyber risk as loss event frequency times loss magnitude; LexLint borrows its structure.
- FTC Federal Trade Commission
Federal Trade Commission: the US consumer-protection regulator that enforces privacy and data security through its unfairness and deception authority and sector rules.
- GDPR General Data Protection Regulation
General Data Protection Regulation: the EU's data protection law, which governs any processing of personal data about people in the EU, wherever the processor is.
- GEMA
The German collecting society that licenses performance and reproduction rights in music on behalf of composers, lyricists and publishers.
- GNI gross national income
Gross national income: GDP plus net income from abroad; Ireland's modified version, GNI*, strips out what multinationals route through the country.
- GPAI general-purpose AI
General-purpose AI: a model that can serve many different tasks, such as a large language model; the EU AI Act sets specific duties for providers of these models.
- GRC governance, risk, and compliance
Governance, risk, and compliance: the category of tool a risk register is exported to, and the vocabulary its fields are named in.
- GVA gross value added
Gross value added: an industry's output minus what it bought in, the measure LexLint uses for the size of a jurisdiction's software sector.
- ICO Information Commissioner's Office
Information Commissioner's Office: the United Kingdom's data protection authority, which also enforces the electronic-marketing rules.
- IETF Internet Engineering Task Force
Internet Engineering Task Force: the open standards body that develops the core protocols of the internet, published as numbered documents in the RFC series.
- ISIC International Standard Industrial Classification
International Standard Industrial Classification: the United Nations industry taxonomy whose divisions J62 and J63 are software and information services.
- LLM large language model
Large language model: an AI model that reads and generates text, the kind behind coding agents and chatbots.
- LRS LexLint Risk Score
LexLint Risk Score: likelihood times impact on a one-to-twenty-five scale, banded, from cited corpus defaults and the app's own exposure inputs.
- MCP Model Context Protocol
Model Context Protocol: the open standard coding agents use to discover and call external tools such as LexLint.
- NAICS North American Industry Classification System
North American Industry Classification System: the US, Canadian, and Mexican industry taxonomy; software publishers are 5112 and computer systems design is 5415.
- NDJSON newline-delimited JSON
Newline-delimited JSON: a file holding one JSON record per line, so it can be streamed and filtered without loading the whole thing.
- NIST National Institute of Standards and Technology
National Institute of Standards and Technology: the US standards body whose AI Risk Management Framework supplies the role names in AI governance.
- OAIC Office of the Australian Information Commissioner
Office of the Australian Information Commissioner: Australia's privacy regulator under the Privacy Act 1988.
- PDPA Personal Data Protection Act
Personal Data Protection Act: Singapore's personal-data statute of 2012, enforced by the PDPC; Thailand and Malaysia have acts of the same name.
- PDPC Personal Data Protection Commission
Personal Data Protection Commission: Singapore's data protection authority, which publishes its enforcement decisions in full.
- PIA privacy impact assessment
Privacy impact assessment: the older, public-sector name for a data protection impact assessment, still the term in Canada and in US federal agencies.
- PII personally identifiable information
Personally identifiable information: the older US term for personal data, narrower than the legal definition because it is built around identifiers.
- QA quality assurance
Quality assurance: the testing that decides software is fit to ship.
- RFC Request for Comments
Request for Comments: the numbered document series in which internet standards are published.
- RSL Really Simple Licensing
Really Simple Licensing: an industry-consortium scheme, launched in 2025, for publishing machine-readable licence terms for AI use of web content.
- SME small or medium-sized enterprise
Small or medium-sized enterprise: under the EU AI Act an SME pays the lower of a fine's fixed cap and its turnover percentage, not the higher.
- SOCAN Society of Composers, Authors and Music Publishers of Canada
Society of Composers, Authors and Music Publishers of Canada: the Canadian performing-rights society that licenses music on behalf of its members.
- SSE server-sent events
Server-sent events: a one-way stream from server to client over HTTP, used by the older MCP transport that streamable HTTP replaced.
- TDM text and data mining
Text and data mining: automated analysis of text or data, such as crawling pages to extract information or to train a model.
- TLD top-level domain
Top-level domain: the last part of a domain name, such as .com or .ai.
- URN Uniform Resource Name
Uniform Resource Name: the permanent, location-independent name UnGovr assigns to every government entity, which stays valid even if the entity's page moves.
- VLOP very large online platform
Very large online platform: a platform the European Commission has designated as reaching 45 million or more monthly users in the EU, which the Digital Services Act gives extra duties.
- VLOSE very large online search engine
Very large online search engine: a search engine designated on the same 45 million user threshold as a very large online platform, and carrying the same extra Digital Services Act duties.
- WAMCA
The Dutch collective-action act of 2020 that allows opt-out damages claims by representative foundations, which made the Netherlands a preferred venue for EU-wide claims.