Glossary

GDPR. FISA 702. Cloud Act. Privacy pages are full of terms like these, and most sites never really explain them. This glossary breaks each one down in plain language for people that don't have a law degree.

Legal jurisdiction

  • Adequacy decision

    An adequacy decision is an EU ruling that a non-EU country protects data well enough to allow data transfers there without extra safeguards.

  • CLOUD Act

    The CLOUD Act is a US law. It lets US authorities request data from US companies, even when the data sits on servers in Europe.

  • EU-US Data Privacy Framework

    The EU-US Data Privacy Framework is the current agreement that lets data flow from Europe to US companies that sign up to it.

  • FISA 702

    FISA 702 is a US surveillance law. It lets US intelligence agencies collect data from foreign users of US tech services, without a warrant for each person.

  • Schrems II

    Schrems II is a 2020 EU court ruling. It found that standard tools for sending data to the US did not protect Europeans enough from US surveillance laws.

  • Standard Contractual Clauses (SCCs)

    Standard Contractual Clauses are pre-approved legal contracts. Companies use them to send data outside the EU while still meeting GDPR requirements.

Ownership

  • Subsidiary / parent company

    A subsidiary is a company owned or controlled by another, larger company. What looks like a European brand can be a subsidiary of a US parent.

Data sovereignty

  • Data residency

    Data residency means where your data is physically stored. It does not decide which country's laws apply to it.

  • Data sovereignty

    Data sovereignty means your data follows the laws of the country where it is stored, and stays under that country's legal control.

  • EuroPoints

    EuroPoints is PickEurope's scoring system. It rates each service out of 100, across legal jurisdiction, ownership, data sovereignty, and accountability.

Accountability & trust

  • DMA / DSA

    The DMA and DSA are EU laws that regulate large tech platforms, covering fair competition and how they handle illegal content and user data.

  • E2E encryption

    End-to-end encryption means only the sender and receiver can read a message. Not even the company running the service can access it.

  • GDPR

    GDPR is the EU's main data protection law. It gives Europeans rights over their personal data and sets strict rules for companies that handle it.

  • NIS2 Directive

    NIS2 is an EU law that sets minimum cybersecurity standards for important services, from energy to digital infrastructure.

  • Open source

    Open source software has publicly available code, which anyone can inspect, so claims about privacy and security can be independently checked.

  • Zero-knowledge encryption

    Zero-knowledge encryption means the service provider never holds the key to your data. They store it, but they cannot read it, even if compelled to.