Glossary

The words LexLint uses for software law and legal risk, defined in United States legal usage first, and none of it is legal advice. Where another regime or a neighbouring field uses a different word for the same thing, or the same word for a different thing, the entry says so. The dotted underlines across the site open the same definitions. The terms behind agentic systems and the law that reaches them are also on two printable pages, each linked back to its entry here.

§ · Law

Age assurance

The family of methods for establishing that a user is above or below an age: self-declaration, age estimation from a face or from behaviour, and age verification against a document or a trusted third party. Laws name the level they require, and the levels are not interchangeable.

In software usage age gate. A self-declared date of birth screen; the weakest method and the one most laws now say is not enough.
United Kingdom highly effective age assurance. The Online Safety Act's standard for services that allow pornography, defined by Ofcom's guidance.

See also: Consent, Minors

Algorithmic impact assessment

A written assessment of an automated decision system's effects before it is deployed: its purpose, data, accuracy, bias, and the recourse available to people it decides about. Required by Canada's federal directive, by New York City for hiring tools (as a bias audit), and by several US state AI laws.

European Union fundamental rights impact assessment. AI Act Art. 27 requires one from deployers of high-risk systems that are public bodies or provide certain services.
Canada Algorithmic Impact Assessment. A capitalized proper noun in Canada: the Treasury Board's questionnaire under the Directive on Automated Decision-Making.

See also: Data protection impact assessment, Automated decision-making, High-risk AI system

Applies to

Whom an instrument binds: the private sector, government, or both. A duty written for public bodies is not a finding against a private app, and the corpus records the answer on every instrument rather than leaving a reader to infer it.

See also: Instrument, Finding

Authorized access

The line computer-misuse law draws between lawful and unlawful access to a system. Under the US federal statute the question is whether access exceeded what the owner permitted, and since the Supreme Court's 2021 decision a public page with no gate is not an unauthorized one.

United Kingdom unauthorised access. The Computer Misuse Act 1990 s. 1 turns on the accused knowing the access was unauthorised, with no public-page carve-out written into the statute.
European Union illegal access to information systems. Directive 2013/40 requires Member States to criminalize access without right where a security measure is infringed.

See also: robots.txt, Terms of service, Circumvention

Automated decision-making

A decision about a person made by a system without meaningful human involvement, with legal or similarly significant effects: credit, housing, employment, insurance, access to services. Most regimes give the person a right to an explanation, a human review, or an opt-out.

European Union solely automated processing, profiling. General Data Protection Regulation (GDPR) Art. 22 restricts decisions based solely on automated processing; profiling is the evaluation of personal aspects that often feeds them.
United States automated decision technology, automated decision-making technology (ADMT). California's rulemaking term; Colorado's AI Act says "consequential decision".

See also: Algorithmic impact assessment, High-risk AI system

Base rate

A published frequency of enforcement or private action under an instrument, banded from one to five by a written rule, used as the default likelihood before counsel adjusts it. LexLint derives the band from the instrument's enforcement record and never hand-picks it.

In cybersecurity usage loss event frequency. The Factor Analysis of Information Risk (FAIR) term for the same quantity.
In software usage prior probability. Statistics and epidemiology usage; the enforcement climate is the prior that fills in where an instrument has no base rate of its own.

See also: Enforcement record, Prior and evidence, Enforcement climate

Case law

Judicial decisions that construe an instrument: what counts as authorized access, whether publicly available personal data is fair game, when a biometric claim accrues. A decision that also sanctions a party is both case law and an enforcement action, and the corpus links it to both.

European Union jurisprudence of the Court of Justice. Civil-law systems do not bind later courts by precedent in the common-law sense, but the Court of Justice's rulings on EU law bind every Member State court.

See also: Settledness, Enforcement action

Circumvention

Getting past a technical barrier: a CAPTCHA, an IP block, a rate limit, a login. What happens legally escalates by jurisdiction from nothing, to a civil claim, to a crime, and the corpus records the escalation per jurisdiction.

United States anti-circumvention. The Digital Millennium Copyright Act (DMCA)'s anti-circumvention provision targets measures that control access to copyrighted works, a narrower thing than a rate limit.

See also: Authorized access, robots.txt

Class action

A suit brought by named plaintiffs on behalf of a class of people in the same position, under Federal Rule 23 and its state analogues. With statutory damages per person it is the engine of private enforcement of US privacy law; without them it is a much harder case to certify.

European Union representative action. Directive 2020/1828, applying since 2023, lets qualified entities such as consumer bodies sue for injunctions and redress on behalf of consumers; individuals cannot lead the action themselves.
United Kingdom collective proceedings, group litigation order. Opt-out collective proceedings exist only before the Competition Appeal Tribunal; a group litigation order in the High Court is opt-in and case-managed.
Germany Musterfeststellungsklage, Abhilfeklage. The model declaratory action (2018) settles common questions; the redress action (2023) can award compensation, both led by qualified consumer associations.
Netherlands WAMCA collective action. The Netherlands' 2020 act allows opt-out damages claims by representative foundations, which has made Dutch courts a preferred venue for EU-wide claims.
Australia representative proceeding. Federal Court class actions under Part IVA, opt-out by default, with litigation funders common.

See also: Private enforcement, Private right of action, Statutory damages, Venue

Competent authority

The government body empowered to enforce an instrument in a jurisdiction. In US usage this is the regulator or agency (the Federal Trade Commission (FTC), a state attorney general, the California Privacy Protection Agency (CPPA)); the phrase itself is EU drafting that LexLint adopts because it names the role regardless of the regime.

European Union supervisory authority. The General Data Protection Regulation (GDPR)'s term for a national data protection authority (Art. 51); the EU AI Act uses "market surveillance authority" and "notifying authority" for its enforcers.
United Kingdom the Commissioner. The Information Commissioner's Office is the data protection authority; the Competition and Markets Authority and Ofcom enforce the digital-markets and online-safety regimes.
Canada Privacy Commissioner. The federal Office of the Privacy Commissioner and the provincial commissioners (Quebec's CAI above all) enforce; the federal Commissioner's powers are largely recommendatory.
Australia the Commissioner (Office of the Australian Information Commissioner (OAIC)). The Office of the Australian Information Commissioner enforces the Privacy Act; the Australian Competition and Consumer Commission (ACCC) enforces consumer law against software as well.
Singapore Personal Data Protection Commission (PDPC). The Personal Data Protection Commission enforces the Personal Data Protection Act (PDPA) and publishes its decisions.

See also: Public enforcement, Enforcement capacity, Data protection authority

A settlement of a public enforcement action in which the respondent agrees to obligations, often for twenty years, without admitting liability. The Federal Trade Commission (FTC)'s standard outcome; a later breach of the order is what unlocks civil penalties.

United States consent decree. The same thing entered by a court rather than the agency.
European Union commitments. Competition-law usage; data protection authorities settle less often and publish decisions instead.

See also: Monetary sanction, Disposition

Counterparty

The party the software talks to: the sites and interfaces it reads, the recipients it writes to, the rightsholders whose content it uses, and the other users and devices it exchanges data with. One of the six parties the LexLint agents documents use, written there as the tag COUNTERPARTY.

See also: User, Overseer

Criminal exposure

Whether a breach of the instrument can be prosecuted as a crime, and on what terms. Recorded separately from civil and administrative penalties because the process, the defendants (individuals as well as the company), and the consequences differ.

See also: Prosecution, Penalty structure

Disposition

How an enforcement action ended: settled, upheld, annulled on appeal, reduced on appeal, withdrawn, dismissed, or still pending. The enforcement record's success rate is the share of decided actions that were settled or upheld rather than annulled, withdrawn, or dismissed.

See also: Enforcement action, Public enforcement record

Distributor

The party that puts the software into a market: the store or marketplace, the importer, the reseller, the integrator. One of the six parties the LexLint agents documents use, written there as the tag DISTRIBUTOR.

See also: Maker, Operator

Enforcement action

The unit of the public enforcement record: one proceeding by a competent authority against one respondent under an instrument. Its proceeding type is administrative, civil, or criminal. LexLint reserves "prosecution" for criminal proceedings only.

European Union corrective measure. General Data Protection Regulation (GDPR) Art. 58(2) lists the supervisory authority's corrective powers, from a warning to a ban on processing to an administrative fine; each exercise is one action.
United Kingdom enforcement notice, monetary penalty notice. The Information Commissioner's Office (ICO)'s formal instruments; a reprimand is also published but carries no penalty.
Australia civil penalty proceeding. The Office of the Australian Information Commissioner (OAIC) or Australian Competition and Consumer Commission (ACCC) applies to the Federal Court for a civil penalty; the court, not the regulator, sets the amount.

See also: Public enforcement, Monetary sanction, Disposition, Prosecution

Enforcement capacity

The budget and full-time headcount of a jurisdiction's competent authorities for software law. The supply side of enforcement: an authority with forty staff and a thousand complaints a year has a queue, and the queue is a fact about likelihood.

European Union resources of supervisory authorities. General Data Protection Regulation (GDPR) Art. 52(4) requires each Member State to resource its authority; the European Data Protection Board publishes the figures yearly.

See also: Competent authority, Enforcement climate

Enforcement climate

LexLint's composite for a jurisdiction: enforcement capacity, public and private enforcement intensity, the magnitude of sanctions, and the regulatory outlook, each banded from one to five by a written rule. It is the prior for a finding's likelihood where the instrument has no enforcement record of its own.

See also: Prior and evidence, Base rate, Regulatory outlook, LexLint Risk Score

Enforcement intensity

Enforcement actions and monetary sanctions per unit of regulated economy and per capita, on a rolling ten-year window. The normalisation is what makes a small jurisdiction with an active authority comparable to a large one with a passive one.

See also: Enforcement climate, Public enforcement record, Jurisdictional weight

Enforcement record

The structured account of how often an instrument is actually enforced: actions per year, fines per year, total and median and ninetieth-percentile fines, the first enforcement date, the trend, each with a source and an as-of date. It sits on the instrument; the base rate band is derived from it.

See also: Base rate, Public enforcement record, Penalty structure

EstablishmentEuropean Union

The effective and real exercise of activity through stable arrangements in a jurisdiction, in the General Data Protection Regulation (GDPR)'s words: an office, a subsidiary, staff. Establishment decides which authority leads and, with targeting, whether the regulation reaches a company at all.

United States doing business, minimum contacts. The US analogues: statutory thresholds for who a state act covers, and the constitutional test for whether a court has jurisdiction over an out-of-state defendant.

See also: One-stop-shop, Extraterritorial reach

Expected monetary value

Likelihood times loss, summed over scenarios. Inherent expected monetary value (EMV) takes the finding as it stands; residual EMV credits the control state of the work item and any insurance. Decision analysis and litigation risk analysis use the same term.

See also: LexLint Risk Score, Treatment

Exposure ceiling

The statutory maximum a finding could cost given the app's exposure profile: the penalty structure applied to the app's turnover, violation count, or affected persons. It bounds the loss term and is never the expected loss.

See also: Penalty structure, Exposure profile, LexLint Risk Score

Exposure profile

What the developer supplies about the app for the risk model: worldwide turnover, the small or medium-sized enterprise (SME) flag, per-jurisdiction status, data subjects, minors, special categories, insurance. Versioned per project so a score can be reproduced.

In cybersecurity usage asset and loss factors. Factor Analysis of Information Risk (FAIR)'s names for the analogous inputs.

See also: Exposure ceiling, LexLint Risk Score

Extraterritorial reach

How far an instrument binds companies outside the jurisdiction. The General Data Protection Regulation (GDPR) reaches any controller offering goods or services to people in the EU or monitoring their behaviour; the AI Act reaches providers whose output is used in the EU; US state acts reach companies doing business in the state above a threshold.

In law usage territorial scope. The heading under which EU instruments state it (GDPR Art. 3, AI Act Art. 2).

See also: Establishment, Jurisdiction

Fair use and fair dealing

The US doctrine that permits copying a work without permission when the purpose, nature, amount, and market effect weigh in favour, and the narrower Commonwealth doctrine that permits copying only for listed purposes such as research, criticism, and news reporting.

United Kingdom fair dealing. Purpose-limited; the EU's closed list of exceptions in Directive 2001/29 works the same way.
Canada fair dealing. Canada's list includes research, private study, education, parody, and satire, read generously by the Supreme Court.

See also: Text and data mining

Free band

The corpus-only band shown on the Free tier: High, Medium, Low, or None, derived from the instrument's status, its private right of action, and its penalty structure, with no exposure input from the developer.

See also: LexLint Risk Score, Private right of action

General-purpose AIEuropean Union

A model that can serve many different tasks, such as a large language model. The AI Act sets specific duties for providers of these models: technical documentation, a copyright policy that respects text-and-data-mining opt-outs, a training-data summary, and more for models with systemic risk.

In software usage foundation model, frontier model. Industry and US policy usage for the same class; the AI Act uses neither term.

See also: Provider and deployer, Text and data mining

High-risk AI systemEuropean Union

The AI Act's category for AI used in the areas its Annex III lists (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice) or as a safety component of a regulated product. Providers owe conformity assessment and a quality system; deployers owe human oversight and monitoring.

United States high-risk artificial intelligence system. Colorado's AI Act borrows the phrase for systems making consequential decisions, with a different list and a duty of reasonable care rather than conformity assessment.

See also: Provider and deployer, General-purpose AI, Automated decision-making

Human oversightEuropean Union

Two different things under one name. A duty on whoever runs a system to keep a person able to understand it, intervene in it and stop it, which is the AI Act's Article 14; and a right of the person a decision is about to have a human review it, which is the General Data Protection Regulation (GDPR)'s Article 22 and its counterparts in other privacy acts.

In software usage human in the loop, human on the loop. Design patterns rather than duties. In the loop, a person must act before the agent proceeds; on the loop, a person watches and may act. Neither is by itself the oversight a statute asks for, which turns on whether the person can really intervene.

See also: Automated decision-making, Kill switch, High-risk AI system

Sources: Agentic AI Foundation, Taxonomy and Landscape workstream

In force

An instrument's status: enacted and effective, enacted but not yet effective, proposed, repealed, or struck down. Only an in-force duty raises a warning; the rest raise information findings so a reader can see what is coming.

European Union entry into force, application. EU acts enter into force on a date and apply from a later one, sometimes years later and in stages; the applying date is the one that binds.

See also: Instrument, Finding

Instrument

One statute, regulation, ordinance, directive, or binding guidance document in the corpus, with its citation, status, effective date, the parties it binds, and its attributes. A lint finding cites an instrument, not a topic.

European Union regulation, directive. A regulation binds directly in every Member State; a directive binds only once transposed into national law, so the national act is the instrument that reaches an app.
United Kingdom Act, statutory instrument. Primary legislation and the secondary rules made under it; both are instruments in the corpus.

See also: Legal area, Applies to, In force

Jurisdiction

A body of law together with the authorities and courts that apply it. LexLint keys every law to one jurisdiction at one of four levels: supranational (the EU), national, subnational (a US state, a province, a Land), or local (a city).

European Union Member State. An EU Member State is a national jurisdiction in LexLint's model, sitting under the EU's supranational rung, so an EU-wide regulation and a Member State's own act are two jurisdictions.
United Kingdom nation. England and Wales, Scotland and Northern Ireland are separate legal systems; LexLint keys UK-wide statutes to the national rung and does not yet split the nations.
In software usage region. Cloud and CDN "regions" are data-center locations, not jurisdictions; where data sits is one input to which jurisdiction applies, never the answer.

See also: Jurisdiction level, Competent authority, Venue

Jurisdiction level

Where a jurisdiction sits in the hierarchy: supranational, national, subnational, or local. The level, not the label, is what the model reads, because "state" means a sovereign country in one regime and a subnational unit in another.

European Union Union, Member State, region. Regional and municipal law exists across the EU but reaches LexLint's corpus only where it binds software; the local rung is US-first today.

See also: Jurisdiction, Own-level and consolidated

The corpus topic a finding belongs to: age, aggregation, AI, cybersecurity, privacy, or scraping. Derived from the app's declared activities and overridable with a reason.

In law usage practice area. A firm's practice areas are broader (privacy and data security, technology transactions); a legal area is one corpus topic.

See also: Finding, Instrument, Software law

LexLint Risk Score

Likelihood times impact on a one-to-twenty-five scale, banded, per finding and rolled up per app. LexLint supplies statutory magnitude and a published enforcement base rate as cited defaults; the developer supplies exposure; counsel adjusts likelihood and impact with a written justification. It is a modelled exposure under stated assumptions, never a prediction.

In cybersecurity usage risk score. A security register scores likelihood times impact on a system; the LexLint Risk Score (LRS) prices the same product in money and in legal terms, and the two should never be merged into one number.

See also: Expected monetary value, Base rate, Exposure ceiling, Register row

Maker

The party that makes the software: the developer or publisher whose name is on it, the provider of a model behind a feature, the suppliers of libraries, kits and tool interfaces, and the open-source projects whose code was taken in. One of the six parties the LexLint agents documents use, written there as the tag MAKER.

See also: Distributor, Operator, Agent

Matter

A legal team's unit of work: a client question with a status, a practice area, a responsible attorney, stages, tasks, and documents. LexLint's legal view presents an app under review as a matter, using the field names practice-management tools already use.

See also: Memo, Playbook

Memo

The written analysis of one risk scenario in the convention of legal writing: question presented, brief answer, facts, applicable law, analysis, recommendation.

See also: Matter, Finding

Minors

People below the age of majority, whom software law treats as a protected class at several thresholds: under 13 for the US children's privacy statute, under 16 for parental consent in the General Data Protection Regulation (GDPR)'s default, under 18 for most age-appropriate design and social-media laws.

United States children, teens. Children's Online Privacy Protection Act (COPPA) says children (under 13); the state acts add teens (13 to 17) with opt-in rules of their own.

See also: Age assurance, Consent

Monetary sanction

Money ordered or agreed as the outcome of a public enforcement action. LexLint records the kind: a fine, a civil penalty, a settlement, disgorgement, restitution, or an order with no money attached.

United States civil penalty. The Federal Trade Commission (FTC) cannot fine for a first violation of Section 5 and must sue for civil penalties under a rule or an existing order; state attorneys general have direct penalty authority under their consumer-protection acts.
European Union administrative fine. General Data Protection Regulation (GDPR) Art. 83 and AI Act Art. 99; imposed by the authority directly in most Member States, by a court in Denmark and Estonia.
United Kingdom monetary penalty. Issued by notice; appealable to the First-tier Tribunal.

See also: Enforcement action, Penalty structure, Disposition

Obligation class

What kind of duty an instrument imposes: a prohibition, a disclosure, a consent requirement, a process duty such as an assessment, a technical requirement, or a governance duty. The class shapes what a remediation looks like.

See also: Finding, Work item

Operator

The party that runs the software: the operator of a service, a self-hosting customer, the hosting and cloud providers, and the services on the request path. The party most statutes bind by default. One of the six parties the LexLint agents documents use, written there as the tag OPERATOR.

See also: Maker, User, Agent

Overseer

The party that oversees the software: regulators and courts, auditors and certifiers, standards bodies, and the platform rule-setters whose rules bind by contract. One of the six parties the LexLint agents documents use, written there as the tag OVERSEER.

See also: Operator, Counterparty

Own-level and consolidated

Two scopes for reading an enforcement record. The own-level record of the United States counts federal authorities and courts only; the consolidated record counts every body at or below it, the states and cities included. The EU has the same pair.

In economics usage consolidation. Borrowed from group accounting, where a parent's consolidated statements fold in its subsidiaries.

See also: Jurisdiction level, Public enforcement record

Penalty structure

The statutory arithmetic of a fine: a fixed cap, a percentage of worldwide turnover, the rule for choosing between them (the higher of the two, or the lower for small and medium enterprises where the instrument says so), and any per-violation or per-person amount.

European Union administrative fine tiers. General Data Protection Regulation (GDPR) Art. 83 and AI Act Art. 99 set tiers as the higher of a fixed sum and a share of worldwide annual turnover; the AI Act gives small or medium-sized enterprises (SMEs) the lower of the two.
United States civil penalty schedule. US statutes set per-violation amounts, adjusted for inflation by rule, with the count of violations doing the work a turnover percentage does in the EU.

See also: Monetary sanction, Exposure ceiling, Statutory damages

Playbook

Per legal area or instrument class, the preferred position, the fallback, the escalation trigger, and the approver. Contract-review tools use the word the same way; LexLint's playbooks are inherited by shared profiles.

See also: Matter, Treatment

Prior and evidence

The order LexLint reads likelihood in. An instrument's own enforcement record is the evidence and wins where it exists; the jurisdiction's enforcement climate is the prior, used where the instrument has none. The finding says which one it used, and a jurisdiction nobody has researched yields neither.

In software usage prior. Bayesian usage, where a prior is the belief before the data arrives; the climate plays that role for the instrument's own record.

See also: Enforcement climate, Base rate, Enforcement record

Private enforcement

Action by a private party under a private right of action: an individual's suit, a class action, a competitor's claim. The other half of the enforcement record, counted separately because it answers to different incentives than a regulator does.

See also: Public enforcement, Private right of action, Class action, Private enforcement record

Private enforcement record

Every private action under software law venued in a jurisdiction, one row per suit with its court, instrument, plaintiff class, resolution, and any disclosed amount, aggregated over a rolling ten-year window. Undisclosed settlements are counted as filings and reported as undisclosed rather than dropped.

See also: Private enforcement, Venue, Class action

Private right of action

A statutory right of a private party to sue for a breach of the instrument, as opposed to enforcement by a public body alone. Whether one exists is the single largest driver of private enforcement, and LexLint records it on every instrument.

In law usage standing. Standing is the separate question of whether this plaintiff may bring the claim, which in US federal court turns on a concrete injury even where the statute grants the right.
European Union right to an effective judicial remedy and to compensation. General Data Protection Regulation (GDPR) Arts. 79 and 82 give every data subject a right to sue the controller or processor and to be compensated for material or non-material damage.

See also: Private enforcement, Statutory damages, Class action

Prosecution

A criminal proceeding brought by the state. In everyday speech "prosecute" covers any enforcement, and LexLint does not use it that way: an administrative fine is an enforcement action, not a prosecution, and the distinction matters because criminal exposure is its own risk attribute.

See also: Enforcement action, Criminal exposure

Provider and deployerEuropean Union

The AI Act's two main roles: the provider develops an AI system or model and places it on the market under its name; the deployer uses it under its own authority. Distributors and importers have narrower duties. Most US laws say developer and deployer.

United States developer and deployer. Colorado's and Utah's terms; the National Institute of Standards and Technology (NIST) AI Risk Management Framework speaks of actors across the lifecycle rather than fixing two roles.
In software usage model provider, operator. Industry usage; an operator that fine-tunes and re-releases a model becomes a provider under the AI Act.

See also: High-risk AI system, General-purpose AI

Public enforcement

Action by a government body under an instrument: a regulator's administrative proceeding, an attorney general's civil suit, a prosecutor's criminal case. The law-and-economics term, used in LexLint for the government half of the enforcement record.

In software usage regulatory enforcement. Industry usage; the same thing, minus the contrast with private enforcement that the model needs.

See also: Private enforcement, Enforcement action, Public enforcement record

Public enforcement record

Every public enforcement action under software law in a jurisdiction, one row per action with its authority, instrument, respondent, proceeding type, monetary sanction, and disposition, aggregated over a rolling ten-year window.

See also: Public enforcement, Enforcement action, Enforcement record

Pricing a legal risk as a probability times a loss rather than as a label. LexLint's model follows ISO 31022, the guideline for managing legal risk, for its frame and borrows the frequency-times-magnitude structure of the Factor Analysis of Information Risk (FAIR) standard for its arithmetic.

In cybersecurity usage FAIR. Factor Analysis of Information Risk, the Open Group standard that decomposes cyber risk into loss event frequency and loss magnitude; LexLint uses the structure and its own legal inputs.

See also: LexLint Risk Score, Expected monetary value, Base rate

Register row

The risk-register entry behind a work item: likelihood and impact on one to five, inherent and residual scores, treatment, owner, justification, identification date, review date, and status. Shaped to export straight into a governance tool.

In cybersecurity usage risk register entry. ISO 31000 and the governance, risk, and compliance (GRC) tools use the same shape; LexLint keeps the field names so an export needs no mapping.

See also: Work item, Treatment, Risk decision

Regulatory outlook

Forward-looking signals about how a jurisdiction intends to enforce, scored by people from what legislators, ministers, commissioners, and agency heads say. History says what a jurisdiction did; the outlook says what it has announced. It can move a climate band one step at most.

See also: Enforcement climate

Risk decision

The recorded acceptance of a residual risk: the scenario, the treatment, the role that decided, the justification, the review date, and the hash of the exposure profile it was decided against.

In law usage risk acceptance. ISO Guide 73's term for the decision itself.

See also: Register row, Treatment

Settledness

How much interpretation stands between an instrument's text and knowing whether it binds an app: whether official guidance exists, whether a court has construed it, whether it is under challenge, and what questions remain open. Banded as settled, developing, or unsettled, and the band routes a finding to counsel by rule.

See also: Case law, Finding

Software law

LexLint's name for the law it holds: the instruments that govern what software must do, across its six topics (AI, scraping, privacy, cybersecurity, age-gating, and news aggregation). The term names the collection; an individual law keeps its own name and kind, so a finding cites an Act, a regulation, a directive, or a privacy law, never "software law".

In law usage software law (licensing and IP). In general legal usage the phrase means the law of software as property, licences, copyright, patents and contracts. None of that is in the corpus; LexLint's sense is the law that binds what an application does.
In law usage technology law, digital regulation. Practice-area and policy labels that reach further than the corpus, into telecom, e-commerce, platform and IP law. LexLint does not use them for its collection.

See also: Legal area, Instrument, Applies to

Statutory damages

A fixed sum per person or per violation set by the statute, owed without proof of actual loss. They are what make a class action under a privacy statute worth bringing, since the arithmetic is the class size times the amount.

European Union compensation for material or non-material damage. General Data Protection Regulation (GDPR) Art. 82 requires an infringement, damage, and a causal link; the Court of Justice has held there is no seriousness threshold but also no damages without damage, which is not statutory damages.
United Kingdom damages for distress. Recoverable under the UK GDPR and the Data Protection Act 2018, assessed by the court on the facts.

See also: Private right of action, Class action, Penalty structure

Terms of service

The contract a site offers its users. Whether it binds a crawler depends on how it was presented: terms behind a link nobody clicked (browsewrap) rarely bind; terms accepted by an act such as creating an account (clickwrap) usually do.

In law usage browsewrap, clickwrap. US case-law labels for the two presentations; the corpus records enforceability of each per jurisdiction.
European Union terms and conditions, unfair contract terms. Consumer-protection law limits what standard terms can impose on consumers, but a crawler is rarely a consumer.

See also: Authorized access, robots.txt

Text and data mining

Automated analysis of text or data to extract information or to train a model, including crawling pages to do it. Whether it is lawful without a licence turns on the jurisdiction's copyright exception, and on whether the rightsholder has opted out where opt-outs count.

United States fair use. The US has no text and data mining (TDM) exception; the question is whether the copying is a fair use, decided case by case on purpose, nature, amount, and market effect.
United Kingdom text and data analysis for non-commercial research. The UK exception (s. 29A) covers non-commercial research only; a wider exception was proposed and withdrawn.
European Union TDM exception with opt-out. Directive 2019/790 Art. 4 permits commercial TDM unless the rightsholder has reserved the right, machine-readably for online content.
Japan Article 30-4. Japan's exception permits use for information analysis regardless of purpose, with no opt-out, which is why it is the widest in the corpus.

See also: Fair use and fair dealing, robots.txt, General-purpose AI

Treatment

What is done about a risk once it is assessed: avoid, modify, share, or retain, in ISO 31000's words. LexLint adds "not applicable (determined)" for a finding counsel has routed out on the facts.

In cybersecurity usage mitigate, transfer, avoid, accept. The governance, risk, and compliance (GRC) labels for the same four options.

See also: Register row, Risk decision

User

The party the software acts for or upon: the user as principal, the affected person reached by its output, the data subject whose personal data flows through it, and a minor, whom the law treats apart. One of the six parties the LexLint agents documents use, written there as the tag USER.

See also: Operator, Counterparty, Agent

Venue

The jurisdiction whose court a private action was filed in. LexLint's private enforcement record is keyed by venue, because the court a defendant can be reached in is what decides where the risk sits.

In law usage forum, situs. Near-synonyms in US practice; "forum selection" is the contract clause that picks the venue in advance.

See also: Private enforcement, Private enforcement record

§ · Software

Agent

Software that pursues a goal by choosing and taking actions through tools, across more than one step, with limited human intervention between the steps. The software in the middle of the six parties in the LexLint agents documents, written there as the tag AGENT. The Agentic AI Foundation publishes no definition of its own; this one is written to sit inside its governance working group's phrase "agentic AI systems".

See also: Operator, User, Maker, Harness, Delegation

AI bill of materials

An inventory of what an AI system is built from: models, datasets, tools, libraries and services, with where each came from. The software version, a software bill of materials, is what the EU Cyber Resilience Act asks the manufacturer of a product with digital elements to draw up.

See also: Maker, Harness

Sources: Agentic AI Foundation, Taxonomy and Landscape workstream

Attestation

A claim about who or what something is, or about what happened, made in a form others can verify. The law's nearest things are a declaration of conformity, a certification and an audit report, each of which a statute names and none of which the word alone implies.

See also: Overseer, Delegation

Sources: Agentic AI Foundation, Taxonomy and Landscape workstream

Autonomy level

How much an agent may do without a person approving it, from suggesting an action to taking it alone. Laws do not grade autonomy. They tier by use and by risk, so the same level can be lawful in one use and prohibited in another.

See also: High-risk AI system, Human oversight

Sources: Agentic AI Foundation, Taxonomy and Landscape workstream

Delegation

Granting an agent authority to act on behalf of a person, an organisation or a system, within a stated scope. An agent has no legal role of its own, so a duty lands on the party that delegated or the party that runs it, and the record of who authorised what is the evidence either will need.

See also: Agent, User, Operator, Attestation

Sources: Agentic AI Foundation, Taxonomy and Landscape workstream

Finding

One obligation in one jurisdiction under one instrument, as a lint raises it against an app. Its severity is warn or info; its kind is obligation, posture, coverage, or pending. Numbers in the risk model live on the finding.

In law usage issue. A legal memo's "issues" are the questions presented; a lint finding is narrower, one duty against one declared fact about the app.

See also: Work item, Register row, Obligation class

Harness

The software control layer between a model and the outside world: it runs the loop, connects the tools, keeps state across steps and records what happened. Where a law asks for a record or a control while the software is running, the harness is usually where that has to live.

See also: Agent, Delegation, Kill switch

Sources: Agentic AI Foundation, Taxonomy and Landscape workstream

Kill switch

A control that lets a person halt an agent at once, whatever it is doing. The EU AI Act asks for the legal equivalent on a high-risk system: a person must be able to interrupt it through a stop button or a similar procedure that brings it to a halt in a safe state.

See also: Human oversight, Harness

Sources: Agentic AI Foundation, Taxonomy and Landscape workstream

robots.txt

A file at the root of a site stating which paths crawlers may fetch, under a convention that is a published standard but not a law. Its legal weight varies: evidence of a site's wishes everywhere, a machine-readable opt-out in the EU, and a factor in authorization in some US cases.

European Union machine-readable reservation of rights. Directive 2019/790 Art. 4(3) makes an opt-out expressed in a machine-readable way effective against commercial text and data mining (TDM); robots.txt is the common vehicle.

See also: Text and data mining, Authorized access, Terms of service

Work item

The developer's triage unit for a set of findings, in one of three lanes: code, documentation, or counsel. It carries the register row, so nothing is re-triaged for the legal view.

See also: Finding, Register row, Treatment

§ · Cybersecurity

Incident

Any event that compromises the confidentiality, integrity, or availability of a system or its data. A security team counts incidents; privacy law counts the subset that are breaches of personal data. The two logs should agree on which is which.

See also: Breach

§ · Privacy

Biometric identifier

Data derived from a person's physical characteristics that can identify them: a face geometry, a fingerprint, a voiceprint, an iris scan. Illinois requires written consent before collection and gives a private right of action with statutory damages per person, which is why it produces the most private enforcement of any US privacy law.

European Union biometric data. A special category under General Data Protection Regulation (GDPR) Art. 9 when processed to uniquely identify a person; the AI Act separately restricts remote biometric identification.

See also: Special categories, Statutory damages

Breach

In privacy law, a defined trigger: unauthorized access to, or disclosure or loss of, personal data, which starts notification clocks to the authority and to affected people. In everyday usage a breach is any violation of a duty, and LexLint says "breach of the instrument" for that meaning.

In cybersecurity usage incident. An incident is any event that compromises a system's security; only an incident that reaches personal data is a breach in the legal sense, and the notification duty attaches to the legal one.
United States breach of the security of the system. The fifty state breach-notification statutes each define it; most exclude encrypted data where the key was not taken.

See also: Personal data, Incident

A freely given, specific, informed, and unambiguous indication of the data subject's wishes, in the General Data Protection Regulation (GDPR)'s formulation. It is one lawful basis among several and is often the weakest, because it can be withdrawn and because bundled or pre-ticked consent is invalid.

United States opt-in, affirmative authorization. Required for sensitive data under the state acts, for children's data under Children's Online Privacy Protection Act (COPPA), and for biometric identifiers under Illinois law.
In software usage consent banner. The cookie banner is one consent mechanism, for one duty, and is not the same thing as a lawful basis for the processing behind it.

See also: Lawful basis, Age assurance

Controller and processor

The two roles personal-data law assigns: the controller decides why and how personal data is processed, the processor processes it on the controller's instructions. Most duties fall on the controller; a processor has its own, narrower set.

United States business and service provider. California's terms under the California Consumer Privacy Act (CCPA); other state acts say controller and processor.
In software usage data owner and vendor. Engineering and procurement usage that maps loosely; a vendor that decides what to do with the data is a controller whatever the contract calls it.

See also: Personal data, Data subject

Data protection authority

The competent authority for personal-data law in a jurisdiction, a data protection authority (DPA). The US has none at the federal level; the Federal Trade Commission (FTC) acts under its unfairness and deception authority and sector statutes, and California created a dedicated agency, the California Privacy Protection Agency (CPPA), in 2020.

European Union supervisory authority. One per Member State (Germany has one per Land plus a federal one); they coordinate through the European Data Protection Board.

See also: Competent authority, One-stop-shop

Data protection impact assessmentEuropean Union

A written assessment of a processing operation's risks to the people whose data it uses, required by the General Data Protection Regulation (GDPR) before high-risk processing and by several US state acts for profiling, sale, and sensitive data. A data protection impact assessment (DPIA) is about harm to individuals, not to the company.

United States data protection assessment, privacy impact assessment. The state acts say data protection assessment; US federal agencies have done privacy impact assessments under the E-Government Act since 2002, which is where the older privacy impact assessment (PIA) term comes from.
Canada privacy impact assessment. Required of federal institutions by Treasury Board policy and of private organizations by Quebec's Law 25.

See also: Algorithmic impact assessment, Special categories

Data subject

The person the personal data is about. The rights regimes grant (access, deletion, correction, portability, objection, opting out of sale or profiling) belong to the data subject.

United States consumer. The state privacy acts say consumer, and several exclude employees and business contacts from the definition.
In software usage user. A user is whoever operates the product; a data subject is whoever the data describes, which includes people who never used it.

See also: Personal data, Controller and processor

Lawful basisEuropean Union

The justification a controller must have before processing personal data. The General Data Protection Regulation (GDPR) lists six, of which consent, contract, legal obligation, and legitimate interests carry most software processing. US law mostly runs the other way: processing is permitted unless a statute restricts it or the consumer opts out.

United States notice and choice, opt-out. The US default; sensitive data and minors' data are the places US law flips to opt-in consent.

See also: Consent, Personal data

One-stop-shopEuropean Union

The General Data Protection Regulation (GDPR)'s rule that a controller established in more than one Member State answers to a single lead supervisory authority, the one where its main establishment is. It is why so many actions against US technology companies run through Ireland.

See also: Data protection authority, Establishment

Personal dataEuropean Union

Any information relating to an identified or identifiable person, the definition most regimes now share. Identifiers, location data, online identifiers, and inferences all count. Biometric data, health data, and other special categories carry extra duties.

United States personal information, personally identifiable information (PII). Personally identifiable information is the older, narrower US notion built around identifiers; the state privacy acts define "personal information" broadly enough to match the EU term.
In cybersecurity usage PII. Security frameworks still use PII as a data classification label; it under-includes inferences and pseudonymous identifiers that privacy law covers.

See also: Controller and processor, Data subject, Special categories

Special categories

Personal data whose processing is restricted or needs an explicit lawful basis: health, biometrics used to identify, genetic data, racial or ethnic origin, political opinions, religion, trade-union membership, sex life or orientation. Minors' data is treated as a special case in most regimes without being a category.

United States sensitive personal information. The California Consumer Privacy Act (CCPA)'s term, which adds precise geolocation, account credentials, and the contents of communications.

See also: Personal data, Biometric identifier

§ · Economics

Jurisdictional weight

The population, nominal GDP, and software value added behind a jurisdiction's law. Used to rank findings, to normalise the enforcement record, and to roll jurisdictions up; never used on its own as a likelihood.

See also: Enforcement intensity, Software value added

Software value added

The gross value added by software and IT services in a jurisdiction, the size of the regulated sector itself. LexLint splits it into what is produced there and what is merely booked there, because turnover- based fines reach the booked figure while establishment follows the produced one.

In economics usage gross value added (GVA), International Standard Industrial Classification (ISIC) J62 and J63. Gross value added is output minus intermediate consumption; the sector is divisions J58.2, J62, and J63 of the international industrial classification, and North American Industry Classification System (NAICS) 5112, 5415, and 518 in North America.
In economics usage modified gross national income, gross national income (GNI)*. Ireland's statistical office publishes GNI* to strip out the profit and intellectual property that multinationals route through the country, the canonical measure of the produced-versus-booked gap.

See also: Jurisdictional weight

§ · Acronyms

Every acronym the site annotates, with the sentence its tooltip carries. The same sentence appears wherever the acronym does.

ACCC Australian Competition and Consumer Commission

Australian Competition and Consumer Commission: the national consumer-protection and competition regulator, which also acts against software under the Australian Consumer Law.

ADMT automated decision-making technology

Automated decision-making technology: the term California's privacy rulemaking uses for systems that make or substantially replace human decisions about people.

AEDE

Asociación de Editores de Diarios Españoles, the Spanish newspaper publishers' association the 2014 press levy was named after.

BIPA Biometric Information Privacy Act

Biometric Information Privacy Act: the Illinois statute that requires written consent before a biometric identifier such as a faceprint or voiceprint is collected, and gives the person a private right of action.

CAI

Commission d'accès à l'information: Quebec's access-to-information and privacy regulator, the strongest of Canada's provincial commissioners since Law 25.

CAPTCHA

A challenge a site shows to tell people from automated visitors; defeating one is the clearest example of circumventing a technical barrier.

CCPA California Consumer Privacy Act

California Consumer Privacy Act: the state privacy law, amended by the CPRA in 2020, that the other US state acts are modelled on or written against.

CFAA Computer Fraud and Abuse Act

Computer Fraud and Abuse Act: the main United States federal statute on unauthorised access to computer systems.

COPPA Children's Online Privacy Protection Act

Children's Online Privacy Protection Act: the US federal statute requiring verifiable parental consent before collecting personal information from children under 13.

CPPA California Privacy Protection Agency

California Privacy Protection Agency: the dedicated privacy regulator California created in 2020, the only one of its kind in the United States.

CPRA California Privacy Rights Act

California Privacy Rights Act: the 2020 ballot measure that amended the CCPA and created the CPPA.

CRA Cyber Resilience Act

Cyber Resilience Act: the EU regulation that makes the manufacturer of a product with digital elements, software included, responsible for its security, its vulnerability handling and its incident reporting.

DMCA Digital Millennium Copyright Act

Digital Millennium Copyright Act: the United States statute whose section 1201 prohibits circumventing technological measures that control access to copyrighted works.

DPA data protection authority

Data protection authority: the competent authority for personal-data law in a jurisdiction, called a supervisory authority in the GDPR.

DPIA data protection impact assessment

Data protection impact assessment: the written risk assessment the GDPR requires before high-risk processing, about harm to the people whose data is used.

DSA Digital Services Act

Digital Services Act: the EU regulation on online intermediaries, with the heaviest duties on very large online platforms and search engines.

DSM Digital Single Market

Digital Single Market: the EU's 2019 copyright directive, whose Article 4 lets rightsholders reserve their works against text and data mining.

ECOA Equal Credit Opportunity Act

Equal Credit Opportunity Act: the United States fair-lending statute whose adverse-action notice duty applies however a credit decision was made, including by a model.

EDPB European Data Protection Board

European Data Protection Board: the EU body that issues guidance and binding decisions on how data protection law is applied across member states.

EMV expected monetary value

Expected monetary value: likelihood times loss, summed over scenarios; the number the LexLint Risk Score is built on.

FAIR Factor Analysis of Information Risk

Factor Analysis of Information Risk: the Open Group standard that prices cyber risk as loss event frequency times loss magnitude; LexLint borrows its structure.

FTC Federal Trade Commission

Federal Trade Commission: the US consumer-protection regulator that enforces privacy and data security through its unfairness and deception authority and sector rules.

GDPR General Data Protection Regulation

General Data Protection Regulation: the EU's data protection law, which governs any processing of personal data about people in the EU, wherever the processor is.

GEMA

The German collecting society that licenses performance and reproduction rights in music on behalf of composers, lyricists and publishers.

GLBA Gramm-Leach-Bliley Act

Gramm-Leach-Bliley Act: the United States statute whose safeguards rule governs how financial institutions protect customer data, with a breach-notification duty since 2024.

GNI gross national income

Gross national income: GDP plus net income from abroad; Ireland's modified version, GNI*, strips out what multinationals route through the country.

GPAI general-purpose AI

General-purpose AI: a model that can serve many different tasks, such as a large language model; the EU AI Act sets specific duties for providers of these models.

GRC governance, risk, and compliance

Governance, risk, and compliance: the category of tool a risk register is exported to, and the vocabulary its fields are named in.

GVA gross value added

Gross value added: an industry's output minus what it bought in, the measure LexLint uses for the size of a jurisdiction's software sector.

HIPAA Health Insurance Portability and Accountability Act

Health Insurance Portability and Accountability Act: the United States statute whose privacy, security and breach-notification rules govern protected health information.

ICO Information Commissioner's Office

Information Commissioner's Office: the United Kingdom's data protection authority, which also enforces the electronic-marketing rules.

IETF Internet Engineering Task Force

Internet Engineering Task Force: the open standards body that develops the core protocols of the internet, published as numbered documents in the RFC series.

ISIC International Standard Industrial Classification

International Standard Industrial Classification: the United Nations industry taxonomy whose divisions J62 and J63 are software and information services.

LGPD

Lei Geral de Proteção de Dados: Brazil's general data protection law, in force since 2020, which includes a right to review of decisions made solely by automated processing.

LLM large language model

Large language model: an AI model that reads and generates text, the kind behind coding agents and chatbots.

LRS LexLint Risk Score

LexLint Risk Score: likelihood times impact on a one-to-twenty-five scale, banded, from cited corpus defaults and the app's own exposure inputs.

MCP Model Context Protocol

Model Context Protocol: the open standard coding agents use to discover and call external tools such as LexLint.

NAICS North American Industry Classification System

North American Industry Classification System: the US, Canadian, and Mexican industry taxonomy; software publishers are 5112 and computer systems design is 5415.

NDJSON newline-delimited JSON

Newline-delimited JSON: a file holding one JSON record per line, so it can be streamed and filtered without loading the whole thing.

NIS2

The second Network and Information Security Directive: the EU directive that sets cybersecurity risk-management and incident-reporting duties for essential and important entities.

NIST National Institute of Standards and Technology

National Institute of Standards and Technology: the US standards body whose AI Risk Management Framework supplies the role names in AI governance.

OAIC Office of the Australian Information Commissioner

Office of the Australian Information Commissioner: Australia's privacy regulator under the Privacy Act 1988.

OSAA Open Secure AI Alliance

Open Secure AI Alliance: an industry coalition, a Linux Foundation directed fund since September 2026, working on the security of AI agent systems.

PDPA Personal Data Protection Act

Personal Data Protection Act: Singapore's personal-data statute of 2012, enforced by the PDPC; Thailand and Malaysia have acts of the same name.

PDPC Personal Data Protection Commission

Personal Data Protection Commission: Singapore's data protection authority, which publishes its enforcement decisions in full.

PIA privacy impact assessment

Privacy impact assessment: the older, public-sector name for a data protection impact assessment, still the term in Canada and in US federal agencies.

PII personally identifiable information

Personally identifiable information: the older US term for personal data, narrower than the legal definition because it is built around identifiers.

QA quality assurance

Quality assurance: the testing that decides software is fit to ship.

RFC Request for Comments

Request for Comments: the numbered document series in which internet standards are published.

RSL Really Simple Licensing

Really Simple Licensing: an industry-consortium scheme, launched in 2025, for publishing machine-readable licence terms for AI use of web content.

SAFE Shared AI Findings Exchange

Shared AI Findings Exchange: the Open Secure AI Alliance's proposed scheme for reporting and learning from AI incidents. A proposal, not law.

SEC Securities and Exchange Commission

Securities and Exchange Commission: the United States regulator of listed companies, whose Form 8-K Item 1.05 makes a registrant disclose a material cybersecurity incident.

SME small or medium-sized enterprise

Small or medium-sized enterprise: under the EU AI Act an SME pays the lower of a fine's fixed cap and its turnover percentage, not the higher.

SOCAN Society of Composers, Authors and Music Publishers of Canada

Society of Composers, Authors and Music Publishers of Canada: the Canadian performing-rights society that licenses music on behalf of its members.

SSE server-sent events

Server-sent events: a one-way stream from server to client over HTTP, used by the older MCP transport that streamable HTTP replaced.

TCPA Telephone Consumer Protection Act

Telephone Consumer Protection Act: the United States statute on automated calls and texts, which the Federal Communications Commission has read to cover calls made with an AI-generated voice.

TDM text and data mining

Text and data mining: automated analysis of text or data, such as crawling pages to extract information or to train a model.

TLD top-level domain

Top-level domain: the last part of a domain name, such as .com or .ai.

UETA Uniform Electronic Transactions Act

Uniform Electronic Transactions Act: the model United States state law under which a contract may be formed by the interaction of electronic agents, with no person reviewing the exchange.

URN Uniform Resource Name

Uniform Resource Name: the permanent, location-independent name UnGovr assigns to every government entity, which stays valid even if the entity's page moves.

VLOP very large online platform

Very large online platform: a platform the European Commission has designated as reaching 45 million or more monthly users in the EU, which the Digital Services Act gives extra duties.

VLOSE very large online search engine

Very large online search engine: a search engine designated on the same 45 million user threshold as a very large online platform, and carrying the same extra Digital Services Act duties.

WAMCA

The Dutch collective-action act of 2020 that allows opt-out damages claims by representative foundations, which made the Netherlands a preferred venue for EU-wide claims.

How the words are chosen. One definition per term, in the usage of the United States bar, because that is where most of LexLint's readers meet the law. A regime that says it differently gets a row under the definition rather than a second definition, so a reader who declares a home jurisdiction can be shown their own word in the text with ours underneath it. None of this is legal advice.