Glossary
The words LexLint uses for software law and legal risk, defined in United States legal usage first, and none of it is legal advice. Where another regime or a neighbouring field uses a different word for the same thing, or the same word for a different thing, the entry says so. The dotted underlines across the site open the same definitions. The terms behind agentic systems and the law that reaches them are also on two printable pages, each linked back to its entry here.
§ · Law
- Age assurance
-
The family of methods for establishing that a user is above or below an age: self-declaration, age estimation from a face or from behaviour, and age verification against a document or a trusted third party. Laws name the level they require, and the levels are not interchangeable.
In software usage age gate. A self-declared date of birth screen; the weakest method and the one most laws now say is not enough.
United Kingdomhighly effective age assurance. The Online Safety Act's standard for services that allow pornography, defined by Ofcom's guidance. - Algorithmic impact assessment
-
A written assessment of an automated decision system's effects before it is deployed: its purpose, data, accuracy, bias, and the recourse available to people it decides about. Required by Canada's federal directive, by New York City for hiring tools (as a bias audit), and by several US state AI laws.
European Unionfundamental rights impact assessment. AI Act Art. 27 requires one from deployers of high-risk systems that are public bodies or provide certain services.
CanadaAlgorithmic Impact Assessment. A capitalized proper noun in Canada: the Treasury Board's questionnaire under the Directive on Automated Decision-Making. See also: Data protection impact assessment, Automated decision-making, High-risk AI system
- Applies to
-
Whom an instrument binds: the private sector, government, or both. A duty written for public bodies is not a finding against a private app, and the corpus records the answer on every instrument rather than leaving a reader to infer it.
See also: Instrument, Finding
-
The line computer-misuse law draws between lawful and unlawful access to a system. Under the US federal statute the question is whether access exceeded what the owner permitted, and since the Supreme Court's 2021 decision a public page with no gate is not an unauthorized one.
United Kingdomunauthorised access. The Computer Misuse Act 1990 s. 1 turns on the accused knowing the access was unauthorised, with no public-page carve-out written into the statute.
European Unionillegal access to information systems. Directive 2013/40 requires Member States to criminalize access without right where a security measure is infringed. See also: robots.txt, Terms of service, Circumvention
- Automated decision-making
-
A decision about a person made by a system without meaningful human involvement, with legal or similarly significant effects: credit, housing, employment, insurance, access to services. Most regimes give the person a right to an explanation, a human review, or an opt-out.
European Unionsolely automated processing, profiling. General Data Protection Regulation (GDPR) Art. 22 restricts decisions based solely on automated processing; profiling is the evaluation of personal aspects that often feeds them.
United Statesautomated decision technology, automated decision-making technology (ADMT). California's rulemaking term; Colorado's AI Act says "consequential decision". See also: Algorithmic impact assessment, High-risk AI system
- Base rate
-
A published frequency of enforcement or private action under an instrument, banded from one to five by a written rule, used as the default likelihood before counsel adjusts it. LexLint derives the band from the instrument's enforcement record and never hand-picks it.
In cybersecurity usage loss event frequency. The Factor Analysis of Information Risk (FAIR) term for the same quantity. In software usage prior probability. Statistics and epidemiology usage; the enforcement climate is the prior that fills in where an instrument has no base rate of its own. See also: Enforcement record, Prior and evidence, Enforcement climate
- Case law
-
Judicial decisions that construe an instrument: what counts as authorized access, whether publicly available personal data is fair game, when a biometric claim accrues. A decision that also sanctions a party is both case law and an enforcement action, and the corpus links it to both.
European Unionjurisprudence of the Court of Justice. Civil-law systems do not bind later courts by precedent in the common-law sense, but the Court of Justice's rulings on EU law bind every Member State court. See also: Settledness, Enforcement action
- Circumvention
-
Getting past a technical barrier: a CAPTCHA, an IP block, a rate limit, a login. What happens legally escalates by jurisdiction from nothing, to a civil claim, to a crime, and the corpus records the escalation per jurisdiction.
United Statesanti-circumvention. The Digital Millennium Copyright Act (DMCA)'s anti-circumvention provision targets measures that control access to copyrighted works, a narrower thing than a rate limit. See also: Authorized access, robots.txt
- Class action
-
A suit brought by named plaintiffs on behalf of a class of people in the same position, under Federal Rule 23 and its state analogues. With statutory damages per person it is the engine of private enforcement of US privacy law; without them it is a much harder case to certify.
European Unionrepresentative action. Directive 2020/1828, applying since 2023, lets qualified entities such as consumer bodies sue for injunctions and redress on behalf of consumers; individuals cannot lead the action themselves.
United Kingdomcollective proceedings, group litigation order. Opt-out collective proceedings exist only before the Competition Appeal Tribunal; a group litigation order in the High Court is opt-in and case-managed.
GermanyMusterfeststellungsklage, Abhilfeklage. The model declaratory action (2018) settles common questions; the redress action (2023) can award compensation, both led by qualified consumer associations.
NetherlandsWAMCA collective action. The Netherlands' 2020 act allows opt-out damages claims by representative foundations, which has made Dutch courts a preferred venue for EU-wide claims.
Australiarepresentative proceeding. Federal Court class actions under Part IVA, opt-out by default, with litigation funders common. See also: Private enforcement, Private right of action, Statutory damages, Venue
-
The government body empowered to enforce an instrument in a jurisdiction. In US usage this is the regulator or agency (the Federal Trade Commission (FTC), a state attorney general, the California Privacy Protection Agency (CPPA)); the phrase itself is EU drafting that LexLint adopts because it names the role regardless of the regime.
European Unionsupervisory authority. The General Data Protection Regulation (GDPR)'s term for a national data protection authority (Art. 51); the EU AI Act uses "market surveillance authority" and "notifying authority" for its enforcers.
United Kingdomthe Commissioner. The Information Commissioner's Office is the data protection authority; the Competition and Markets Authority and Ofcom enforce the digital-markets and online-safety regimes.
CanadaPrivacy Commissioner. The federal Office of the Privacy Commissioner and the provincial commissioners (Quebec's CAI above all) enforce; the federal Commissioner's powers are largely recommendatory.
Australiathe Commissioner (Office of the Australian Information Commissioner (OAIC)). The Office of the Australian Information Commissioner enforces the Privacy Act; the Australian Competition and Consumer Commission (ACCC) enforces consumer law against software as well.
SingaporePersonal Data Protection Commission (PDPC). The Personal Data Protection Commission enforces the Personal Data Protection Act (PDPA) and publishes its decisions. See also: Public enforcement, Enforcement capacity, Data protection authority
- Consent order
-
A settlement of a public enforcement action in which the respondent agrees to obligations, often for twenty years, without admitting liability. The Federal Trade Commission (FTC)'s standard outcome; a later breach of the order is what unlocks civil penalties.
United Statesconsent decree. The same thing entered by a court rather than the agency.
European Unioncommitments. Competition-law usage; data protection authorities settle less often and publish decisions instead. See also: Monetary sanction, Disposition
- Counterparty
-
The party the software talks to: the sites and interfaces it reads, the recipients it writes to, the rightsholders whose content it uses, and the other users and devices it exchanges data with. One of the six parties the LexLint agents documents use, written there as the tag COUNTERPARTY.
- Criminal exposure
-
Whether a breach of the instrument can be prosecuted as a crime, and on what terms. Recorded separately from civil and administrative penalties because the process, the defendants (individuals as well as the company), and the consequences differ.
See also: Prosecution, Penalty structure
- Disposition
-
How an enforcement action ended: settled, upheld, annulled on appeal, reduced on appeal, withdrawn, dismissed, or still pending. The enforcement record's success rate is the share of decided actions that were settled or upheld rather than annulled, withdrawn, or dismissed.
See also: Enforcement action, Public enforcement record
- Distributor
-
The party that puts the software into a market: the store or marketplace, the importer, the reseller, the integrator. One of the six parties the LexLint agents documents use, written there as the tag DISTRIBUTOR.
- Enforcement action
-
The unit of the public enforcement record: one proceeding by a competent authority against one respondent under an instrument. Its proceeding type is administrative, civil, or criminal. LexLint reserves "prosecution" for criminal proceedings only.
European Unioncorrective measure. General Data Protection Regulation (GDPR) Art. 58(2) lists the supervisory authority's corrective powers, from a warning to a ban on processing to an administrative fine; each exercise is one action.
United Kingdomenforcement notice, monetary penalty notice. The Information Commissioner's Office (ICO)'s formal instruments; a reprimand is also published but carries no penalty.
Australiacivil penalty proceeding. The Office of the Australian Information Commissioner (OAIC) or Australian Competition and Consumer Commission (ACCC) applies to the Federal Court for a civil penalty; the court, not the regulator, sets the amount. See also: Public enforcement, Monetary sanction, Disposition, Prosecution
- Enforcement capacity
-
The budget and full-time headcount of a jurisdiction's competent authorities for software law. The supply side of enforcement: an authority with forty staff and a thousand complaints a year has a queue, and the queue is a fact about likelihood.
European Unionresources of supervisory authorities. General Data Protection Regulation (GDPR) Art. 52(4) requires each Member State to resource its authority; the European Data Protection Board publishes the figures yearly. See also: Competent authority, Enforcement climate
- Enforcement climate
-
LexLint's composite for a jurisdiction: enforcement capacity, public and private enforcement intensity, the magnitude of sanctions, and the regulatory outlook, each banded from one to five by a written rule. It is the prior for a finding's likelihood where the instrument has no enforcement record of its own.
See also: Prior and evidence, Base rate, Regulatory outlook, LexLint Risk Score
- Enforcement intensity
-
Enforcement actions and monetary sanctions per unit of regulated economy and per capita, on a rolling ten-year window. The normalisation is what makes a small jurisdiction with an active authority comparable to a large one with a passive one.
See also: Enforcement climate, Public enforcement record, Jurisdictional weight
- Enforcement record
-
The structured account of how often an instrument is actually enforced: actions per year, fines per year, total and median and ninetieth-percentile fines, the first enforcement date, the trend, each with a source and an as-of date. It sits on the instrument; the base rate band is derived from it.
See also: Base rate, Public enforcement record, Penalty structure
- Establishment
-
The effective and real exercise of activity through stable arrangements in a jurisdiction, in the General Data Protection Regulation (GDPR)'s words: an office, a subsidiary, staff. Establishment decides which authority leads and, with targeting, whether the regulation reaches a company at all.
United Statesdoing business, minimum contacts. The US analogues: statutory thresholds for who a state act covers, and the constitutional test for whether a court has jurisdiction over an out-of-state defendant. See also: One-stop-shop, Extraterritorial reach
- Expected monetary value
-
Likelihood times loss, summed over scenarios. Inherent expected monetary value (EMV) takes the finding as it stands; residual EMV credits the control state of the work item and any insurance. Decision analysis and litigation risk analysis use the same term.
See also: LexLint Risk Score, Treatment
- Exposure ceiling
-
The statutory maximum a finding could cost given the app's exposure profile: the penalty structure applied to the app's turnover, violation count, or affected persons. It bounds the loss term and is never the expected loss.
See also: Penalty structure, Exposure profile, LexLint Risk Score
- Exposure profile
-
What the developer supplies about the app for the risk model: worldwide turnover, the small or medium-sized enterprise (SME) flag, per-jurisdiction status, data subjects, minors, special categories, insurance. Versioned per project so a score can be reproduced.
In cybersecurity usage asset and loss factors. Factor Analysis of Information Risk (FAIR)'s names for the analogous inputs. See also: Exposure ceiling, LexLint Risk Score
- Extraterritorial reach
-
How far an instrument binds companies outside the jurisdiction. The General Data Protection Regulation (GDPR) reaches any controller offering goods or services to people in the EU or monitoring their behaviour; the AI Act reaches providers whose output is used in the EU; US state acts reach companies doing business in the state above a threshold.
In law usage territorial scope. The heading under which EU instruments state it (GDPR Art. 3, AI Act Art. 2). See also: Establishment, Jurisdiction
- Fair use and fair dealing
-
The US doctrine that permits copying a work without permission when the purpose, nature, amount, and market effect weigh in favour, and the narrower Commonwealth doctrine that permits copying only for listed purposes such as research, criticism, and news reporting.
United Kingdomfair dealing. Purpose-limited; the EU's closed list of exceptions in Directive 2001/29 works the same way.
Canadafair dealing. Canada's list includes research, private study, education, parody, and satire, read generously by the Supreme Court. See also: Text and data mining
- Free band
-
The corpus-only band shown on the Free tier: High, Medium, Low, or None, derived from the instrument's status, its private right of action, and its penalty structure, with no exposure input from the developer.
See also: LexLint Risk Score, Private right of action
- General-purpose AI
-
A model that can serve many different tasks, such as a large language model. The AI Act sets specific duties for providers of these models: technical documentation, a copyright policy that respects text-and-data-mining opt-outs, a training-data summary, and more for models with systemic risk.
In software usage foundation model, frontier model. Industry and US policy usage for the same class; the AI Act uses neither term. See also: Provider and deployer, Text and data mining
- High-risk AI system
-
The AI Act's category for AI used in the areas its Annex III lists (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice) or as a safety component of a regulated product. Providers owe conformity assessment and a quality system; deployers owe human oversight and monitoring.
United Stateshigh-risk artificial intelligence system. Colorado's AI Act borrows the phrase for systems making consequential decisions, with a different list and a duty of reasonable care rather than conformity assessment. See also: Provider and deployer, General-purpose AI, Automated decision-making
- Human oversight
-
Two different things under one name. A duty on whoever runs a system to keep a person able to understand it, intervene in it and stop it, which is the AI Act's Article 14; and a right of the person a decision is about to have a human review it, which is the General Data Protection Regulation (GDPR)'s Article 22 and its counterparts in other privacy acts.
In software usage human in the loop, human on the loop. Design patterns rather than duties. In the loop, a person must act before the agent proceeds; on the loop, a person watches and may act. Neither is by itself the oversight a statute asks for, which turns on whether the person can really intervene. See also: Automated decision-making, Kill switch, High-risk AI system
Sources: Agentic AI Foundation, Taxonomy and Landscape workstream
- In force
-
An instrument's status: enacted and effective, enacted but not yet effective, proposed, repealed, or struck down. Only an in-force duty raises a warning; the rest raise information findings so a reader can see what is coming.
European Unionentry into force, application. EU acts enter into force on a date and apply from a later one, sometimes years later and in stages; the applying date is the one that binds. See also: Instrument, Finding
- Instrument
-
One statute, regulation, ordinance, directive, or binding guidance document in the corpus, with its citation, status, effective date, the parties it binds, and its attributes. A lint finding cites an instrument, not a topic.
European Unionregulation, directive. A regulation binds directly in every Member State; a directive binds only once transposed into national law, so the national act is the instrument that reaches an app.
United KingdomAct, statutory instrument. Primary legislation and the secondary rules made under it; both are instruments in the corpus. See also: Legal area, Applies to, In force
- Jurisdiction
-
A body of law together with the authorities and courts that apply it. LexLint keys every law to one jurisdiction at one of four levels: supranational (the EU), national, subnational (a US state, a province, a Land), or local (a city).
European UnionMember State. An EU Member State is a national jurisdiction in LexLint's model, sitting under the EU's supranational rung, so an EU-wide regulation and a Member State's own act are two jurisdictions.
United Kingdomnation. England and Wales, Scotland and Northern Ireland are separate legal systems; LexLint keys UK-wide statutes to the national rung and does not yet split the nations. In software usage region. Cloud and CDN "regions" are data-center locations, not jurisdictions; where data sits is one input to which jurisdiction applies, never the answer. See also: Jurisdiction level, Competent authority, Venue
- Jurisdiction level
-
Where a jurisdiction sits in the hierarchy: supranational, national, subnational, or local. The level, not the label, is what the model reads, because "state" means a sovereign country in one regime and a subnational unit in another.
European UnionUnion, Member State, region. Regional and municipal law exists across the EU but reaches LexLint's corpus only where it binds software; the local rung is US-first today. See also: Jurisdiction, Own-level and consolidated
- Legal area
-
The corpus topic a finding belongs to: age, aggregation, AI, cybersecurity, privacy, or scraping. Derived from the app's declared activities and overridable with a reason.
In law usage practice area. A firm's practice areas are broader (privacy and data security, technology transactions); a legal area is one corpus topic. See also: Finding, Instrument, Software law
- LexLint Risk Score
-
Likelihood times impact on a one-to-twenty-five scale, banded, per finding and rolled up per app. LexLint supplies statutory magnitude and a published enforcement base rate as cited defaults; the developer supplies exposure; counsel adjusts likelihood and impact with a written justification. It is a modelled exposure under stated assumptions, never a prediction.
In cybersecurity usage risk score. A security register scores likelihood times impact on a system; the LexLint Risk Score (LRS) prices the same product in money and in legal terms, and the two should never be merged into one number. See also: Expected monetary value, Base rate, Exposure ceiling, Register row
- Maker
-
The party that makes the software: the developer or publisher whose name is on it, the provider of a model behind a feature, the suppliers of libraries, kits and tool interfaces, and the open-source projects whose code was taken in. One of the six parties the LexLint agents documents use, written there as the tag MAKER.
See also: Distributor, Operator, Agent
- Matter
-
A legal team's unit of work: a client question with a status, a practice area, a responsible attorney, stages, tasks, and documents. LexLint's legal view presents an app under review as a matter, using the field names practice-management tools already use.
- Memo
-
The written analysis of one risk scenario in the convention of legal writing: question presented, brief answer, facts, applicable law, analysis, recommendation.
- Minors
-
People below the age of majority, whom software law treats as a protected class at several thresholds: under 13 for the US children's privacy statute, under 16 for parental consent in the General Data Protection Regulation (GDPR)'s default, under 18 for most age-appropriate design and social-media laws.
United Stateschildren, teens. Children's Online Privacy Protection Act (COPPA) says children (under 13); the state acts add teens (13 to 17) with opt-in rules of their own. See also: Age assurance, Consent
- Monetary sanction
-
Money ordered or agreed as the outcome of a public enforcement action. LexLint records the kind: a fine, a civil penalty, a settlement, disgorgement, restitution, or an order with no money attached.
United Statescivil penalty. The Federal Trade Commission (FTC) cannot fine for a first violation of Section 5 and must sue for civil penalties under a rule or an existing order; state attorneys general have direct penalty authority under their consumer-protection acts.
European Unionadministrative fine. General Data Protection Regulation (GDPR) Art. 83 and AI Act Art. 99; imposed by the authority directly in most Member States, by a court in Denmark and Estonia.
United Kingdommonetary penalty. Issued by notice; appealable to the First-tier Tribunal. See also: Enforcement action, Penalty structure, Disposition
- Obligation class
-
What kind of duty an instrument imposes: a prohibition, a disclosure, a consent requirement, a process duty such as an assessment, a technical requirement, or a governance duty. The class shapes what a remediation looks like.
- Operator
-
The party that runs the software: the operator of a service, a self-hosting customer, the hosting and cloud providers, and the services on the request path. The party most statutes bind by default. One of the six parties the LexLint agents documents use, written there as the tag OPERATOR.
- Overseer
-
The party that oversees the software: regulators and courts, auditors and certifiers, standards bodies, and the platform rule-setters whose rules bind by contract. One of the six parties the LexLint agents documents use, written there as the tag OVERSEER.
See also: Operator, Counterparty
- Own-level and consolidated
-
Two scopes for reading an enforcement record. The own-level record of the United States counts federal authorities and courts only; the consolidated record counts every body at or below it, the states and cities included. The EU has the same pair.
In economics usage consolidation. Borrowed from group accounting, where a parent's consolidated statements fold in its subsidiaries. See also: Jurisdiction level, Public enforcement record
- Penalty structure
-
The statutory arithmetic of a fine: a fixed cap, a percentage of worldwide turnover, the rule for choosing between them (the higher of the two, or the lower for small and medium enterprises where the instrument says so), and any per-violation or per-person amount.
European Unionadministrative fine tiers. General Data Protection Regulation (GDPR) Art. 83 and AI Act Art. 99 set tiers as the higher of a fixed sum and a share of worldwide annual turnover; the AI Act gives small or medium-sized enterprises (SMEs) the lower of the two.
United Statescivil penalty schedule. US statutes set per-violation amounts, adjusted for inflation by rule, with the count of violations doing the work a turnover percentage does in the EU. See also: Monetary sanction, Exposure ceiling, Statutory damages
- Playbook
-
Per legal area or instrument class, the preferred position, the fallback, the escalation trigger, and the approver. Contract-review tools use the word the same way; LexLint's playbooks are inherited by shared profiles.
- Prior and evidence
-
The order LexLint reads likelihood in. An instrument's own enforcement record is the evidence and wins where it exists; the jurisdiction's enforcement climate is the prior, used where the instrument has none. The finding says which one it used, and a jurisdiction nobody has researched yields neither.
In software usage prior. Bayesian usage, where a prior is the belief before the data arrives; the climate plays that role for the instrument's own record. See also: Enforcement climate, Base rate, Enforcement record
- Private enforcement
-
Action by a private party under a private right of action: an individual's suit, a class action, a competitor's claim. The other half of the enforcement record, counted separately because it answers to different incentives than a regulator does.
See also: Public enforcement, Private right of action, Class action, Private enforcement record
- Private enforcement record
-
Every private action under software law venued in a jurisdiction, one row per suit with its court, instrument, plaintiff class, resolution, and any disclosed amount, aggregated over a rolling ten-year window. Undisclosed settlements are counted as filings and reported as undisclosed rather than dropped.
See also: Private enforcement, Venue, Class action
- Private right of action
-
A statutory right of a private party to sue for a breach of the instrument, as opposed to enforcement by a public body alone. Whether one exists is the single largest driver of private enforcement, and LexLint records it on every instrument.
In law usage standing. Standing is the separate question of whether this plaintiff may bring the claim, which in US federal court turns on a concrete injury even where the statute grants the right.
European Unionright to an effective judicial remedy and to compensation. General Data Protection Regulation (GDPR) Arts. 79 and 82 give every data subject a right to sue the controller or processor and to be compensated for material or non-material damage. See also: Private enforcement, Statutory damages, Class action
- Prosecution
-
A criminal proceeding brought by the state. In everyday speech "prosecute" covers any enforcement, and LexLint does not use it that way: an administrative fine is an enforcement action, not a prosecution, and the distinction matters because criminal exposure is its own risk attribute.
See also: Enforcement action, Criminal exposure
- Provider and deployer
-
The AI Act's two main roles: the provider develops an AI system or model and places it on the market under its name; the deployer uses it under its own authority. Distributors and importers have narrower duties. Most US laws say developer and deployer.
United Statesdeveloper and deployer. Colorado's and Utah's terms; the National Institute of Standards and Technology (NIST) AI Risk Management Framework speaks of actors across the lifecycle rather than fixing two roles. In software usage model provider, operator. Industry usage; an operator that fine-tunes and re-releases a model becomes a provider under the AI Act. See also: High-risk AI system, General-purpose AI
- Public enforcement
-
Action by a government body under an instrument: a regulator's administrative proceeding, an attorney general's civil suit, a prosecutor's criminal case. The law-and-economics term, used in LexLint for the government half of the enforcement record.
In software usage regulatory enforcement. Industry usage; the same thing, minus the contrast with private enforcement that the model needs. See also: Private enforcement, Enforcement action, Public enforcement record
- Public enforcement record
-
Every public enforcement action under software law in a jurisdiction, one row per action with its authority, instrument, respondent, proceeding type, monetary sanction, and disposition, aggregated over a rolling ten-year window.
See also: Public enforcement, Enforcement action, Enforcement record
- Quantitative legal risk analysis
-
Pricing a legal risk as a probability times a loss rather than as a label. LexLint's model follows ISO 31022, the guideline for managing legal risk, for its frame and borrows the frequency-times-magnitude structure of the Factor Analysis of Information Risk (FAIR) standard for its arithmetic.
In cybersecurity usage FAIR. Factor Analysis of Information Risk, the Open Group standard that decomposes cyber risk into loss event frequency and loss magnitude; LexLint uses the structure and its own legal inputs. See also: LexLint Risk Score, Expected monetary value, Base rate
- Register row
-
The risk-register entry behind a work item: likelihood and impact on one to five, inherent and residual scores, treatment, owner, justification, identification date, review date, and status. Shaped to export straight into a governance tool.
In cybersecurity usage risk register entry. ISO 31000 and the governance, risk, and compliance (GRC) tools use the same shape; LexLint keeps the field names so an export needs no mapping. See also: Work item, Treatment, Risk decision
- Regulatory outlook
-
Forward-looking signals about how a jurisdiction intends to enforce, scored by people from what legislators, ministers, commissioners, and agency heads say. History says what a jurisdiction did; the outlook says what it has announced. It can move a climate band one step at most.
See also: Enforcement climate
- Risk decision
-
The recorded acceptance of a residual risk: the scenario, the treatment, the role that decided, the justification, the review date, and the hash of the exposure profile it was decided against.
In law usage risk acceptance. ISO Guide 73's term for the decision itself. See also: Register row, Treatment
- Settledness
-
How much interpretation stands between an instrument's text and knowing whether it binds an app: whether official guidance exists, whether a court has construed it, whether it is under challenge, and what questions remain open. Banded as settled, developing, or unsettled, and the band routes a finding to counsel by rule.
- Software law
-
LexLint's name for the law it holds: the instruments that govern what software must do, across its six topics (AI, scraping, privacy, cybersecurity, age-gating, and news aggregation). The term names the collection; an individual law keeps its own name and kind, so a finding cites an Act, a regulation, a directive, or a privacy law, never "software law".
In law usage software law (licensing and IP). In general legal usage the phrase means the law of software as property, licences, copyright, patents and contracts. None of that is in the corpus; LexLint's sense is the law that binds what an application does. In law usage technology law, digital regulation. Practice-area and policy labels that reach further than the corpus, into telecom, e-commerce, platform and IP law. LexLint does not use them for its collection. See also: Legal area, Instrument, Applies to
- Statutory damages
-
A fixed sum per person or per violation set by the statute, owed without proof of actual loss. They are what make a class action under a privacy statute worth bringing, since the arithmetic is the class size times the amount.
European Unioncompensation for material or non-material damage. General Data Protection Regulation (GDPR) Art. 82 requires an infringement, damage, and a causal link; the Court of Justice has held there is no seriousness threshold but also no damages without damage, which is not statutory damages.
United Kingdomdamages for distress. Recoverable under the UK GDPR and the Data Protection Act 2018, assessed by the court on the facts. See also: Private right of action, Class action, Penalty structure
- Terms of service
-
The contract a site offers its users. Whether it binds a crawler depends on how it was presented: terms behind a link nobody clicked (browsewrap) rarely bind; terms accepted by an act such as creating an account (clickwrap) usually do.
In law usage browsewrap, clickwrap. US case-law labels for the two presentations; the corpus records enforceability of each per jurisdiction.
European Unionterms and conditions, unfair contract terms. Consumer-protection law limits what standard terms can impose on consumers, but a crawler is rarely a consumer. See also: Authorized access, robots.txt
- Text and data mining
-
Automated analysis of text or data to extract information or to train a model, including crawling pages to do it. Whether it is lawful without a licence turns on the jurisdiction's copyright exception, and on whether the rightsholder has opted out where opt-outs count.
United Statesfair use. The US has no text and data mining (TDM) exception; the question is whether the copying is a fair use, decided case by case on purpose, nature, amount, and market effect.
United Kingdomtext and data analysis for non-commercial research. The UK exception (s. 29A) covers non-commercial research only; a wider exception was proposed and withdrawn.
European UnionTDM exception with opt-out. Directive 2019/790 Art. 4 permits commercial TDM unless the rightsholder has reserved the right, machine-readably for online content.
JapanArticle 30-4. Japan's exception permits use for information analysis regardless of purpose, with no opt-out, which is why it is the widest in the corpus. See also: Fair use and fair dealing, robots.txt, General-purpose AI
- Treatment
-
What is done about a risk once it is assessed: avoid, modify, share, or retain, in ISO 31000's words. LexLint adds "not applicable (determined)" for a finding counsel has routed out on the facts.
In cybersecurity usage mitigate, transfer, avoid, accept. The governance, risk, and compliance (GRC) labels for the same four options. See also: Register row, Risk decision
- User
-
The party the software acts for or upon: the user as principal, the affected person reached by its output, the data subject whose personal data flows through it, and a minor, whom the law treats apart. One of the six parties the LexLint agents documents use, written there as the tag USER.
See also: Operator, Counterparty, Agent
- Venue
-
The jurisdiction whose court a private action was filed in. LexLint's private enforcement record is keyed by venue, because the court a defendant can be reached in is what decides where the risk sits.
In law usage forum, situs. Near-synonyms in US practice; "forum selection" is the contract clause that picks the venue in advance. See also: Private enforcement, Private enforcement record
§ · Software
- Agent
-
Software that pursues a goal by choosing and taking actions through tools, across more than one step, with limited human intervention between the steps. The software in the middle of the six parties in the LexLint agents documents, written there as the tag AGENT. The Agentic AI Foundation publishes no definition of its own; this one is written to sit inside its governance working group's phrase "agentic AI systems".
See also: Operator, User, Maker, Harness, Delegation
- AI bill of materials
-
An inventory of what an AI system is built from: models, datasets, tools, libraries and services, with where each came from. The software version, a software bill of materials, is what the EU Cyber Resilience Act asks the manufacturer of a product with digital elements to draw up.
Sources: Agentic AI Foundation, Taxonomy and Landscape workstream
- Attestation
-
A claim about who or what something is, or about what happened, made in a form others can verify. The law's nearest things are a declaration of conformity, a certification and an audit report, each of which a statute names and none of which the word alone implies.
See also: Overseer, Delegation
Sources: Agentic AI Foundation, Taxonomy and Landscape workstream
- Autonomy level
-
How much an agent may do without a person approving it, from suggesting an action to taking it alone. Laws do not grade autonomy. They tier by use and by risk, so the same level can be lawful in one use and prohibited in another.
See also: High-risk AI system, Human oversight
Sources: Agentic AI Foundation, Taxonomy and Landscape workstream
- Delegation
-
Granting an agent authority to act on behalf of a person, an organisation or a system, within a stated scope. An agent has no legal role of its own, so a duty lands on the party that delegated or the party that runs it, and the record of who authorised what is the evidence either will need.
See also: Agent, User, Operator, Attestation
Sources: Agentic AI Foundation, Taxonomy and Landscape workstream
- Finding
-
One obligation in one jurisdiction under one instrument, as a lint raises it against an app. Its severity is warn or info; its kind is obligation, posture, coverage, or pending. Numbers in the risk model live on the finding.
In law usage issue. A legal memo's "issues" are the questions presented; a lint finding is narrower, one duty against one declared fact about the app. See also: Work item, Register row, Obligation class
- Harness
-
The software control layer between a model and the outside world: it runs the loop, connects the tools, keeps state across steps and records what happened. Where a law asks for a record or a control while the software is running, the harness is usually where that has to live.
See also: Agent, Delegation, Kill switch
Sources: Agentic AI Foundation, Taxonomy and Landscape workstream
- Kill switch
-
A control that lets a person halt an agent at once, whatever it is doing. The EU AI Act asks for the legal equivalent on a high-risk system: a person must be able to interrupt it through a stop button or a similar procedure that brings it to a halt in a safe state.
See also: Human oversight, Harness
Sources: Agentic AI Foundation, Taxonomy and Landscape workstream
- robots.txt
-
A file at the root of a site stating which paths crawlers may fetch, under a convention that is a published standard but not a law. Its legal weight varies: evidence of a site's wishes everywhere, a machine-readable opt-out in the EU, and a factor in authorization in some US cases.
European Unionmachine-readable reservation of rights. Directive 2019/790 Art. 4(3) makes an opt-out expressed in a machine-readable way effective against commercial text and data mining (TDM); robots.txt is the common vehicle. See also: Text and data mining, Authorized access, Terms of service
- Work item
-
The developer's triage unit for a set of findings, in one of three lanes: code, documentation, or counsel. It carries the register row, so nothing is re-triaged for the legal view.
See also: Finding, Register row, Treatment
§ · Cybersecurity
- Incident
-
Any event that compromises the confidentiality, integrity, or availability of a system or its data. A security team counts incidents; privacy law counts the subset that are breaches of personal data. The two logs should agree on which is which.
See also: Breach
§ · Privacy
- Biometric identifier
-
Data derived from a person's physical characteristics that can identify them: a face geometry, a fingerprint, a voiceprint, an iris scan. Illinois requires written consent before collection and gives a private right of action with statutory damages per person, which is why it produces the most private enforcement of any US privacy law.
European Unionbiometric data. A special category under General Data Protection Regulation (GDPR) Art. 9 when processed to uniquely identify a person; the AI Act separately restricts remote biometric identification. See also: Special categories, Statutory damages
- Breach
-
In privacy law, a defined trigger: unauthorized access to, or disclosure or loss of, personal data, which starts notification clocks to the authority and to affected people. In everyday usage a breach is any violation of a duty, and LexLint says "breach of the instrument" for that meaning.
In cybersecurity usage incident. An incident is any event that compromises a system's security; only an incident that reaches personal data is a breach in the legal sense, and the notification duty attaches to the legal one.
United Statesbreach of the security of the system. The fifty state breach-notification statutes each define it; most exclude encrypted data where the key was not taken. See also: Personal data, Incident
- Consent
-
A freely given, specific, informed, and unambiguous indication of the data subject's wishes, in the General Data Protection Regulation (GDPR)'s formulation. It is one lawful basis among several and is often the weakest, because it can be withdrawn and because bundled or pre-ticked consent is invalid.
United Statesopt-in, affirmative authorization. Required for sensitive data under the state acts, for children's data under Children's Online Privacy Protection Act (COPPA), and for biometric identifiers under Illinois law. In software usage consent banner. The cookie banner is one consent mechanism, for one duty, and is not the same thing as a lawful basis for the processing behind it. See also: Lawful basis, Age assurance
- Controller and processor
-
The two roles personal-data law assigns: the controller decides why and how personal data is processed, the processor processes it on the controller's instructions. Most duties fall on the controller; a processor has its own, narrower set.
United Statesbusiness and service provider. California's terms under the California Consumer Privacy Act (CCPA); other state acts say controller and processor. In software usage data owner and vendor. Engineering and procurement usage that maps loosely; a vendor that decides what to do with the data is a controller whatever the contract calls it. See also: Personal data, Data subject
-
The competent authority for personal-data law in a jurisdiction, a data protection authority (DPA). The US has none at the federal level; the Federal Trade Commission (FTC) acts under its unfairness and deception authority and sector statutes, and California created a dedicated agency, the California Privacy Protection Agency (CPPA), in 2020.
European Unionsupervisory authority. One per Member State (Germany has one per Land plus a federal one); they coordinate through the European Data Protection Board. See also: Competent authority, One-stop-shop
- Data protection impact assessment
-
A written assessment of a processing operation's risks to the people whose data it uses, required by the General Data Protection Regulation (GDPR) before high-risk processing and by several US state acts for profiling, sale, and sensitive data. A data protection impact assessment (DPIA) is about harm to individuals, not to the company.
United Statesdata protection assessment, privacy impact assessment. The state acts say data protection assessment; US federal agencies have done privacy impact assessments under the E-Government Act since 2002, which is where the older privacy impact assessment (PIA) term comes from.
Canadaprivacy impact assessment. Required of federal institutions by Treasury Board policy and of private organizations by Quebec's Law 25. See also: Algorithmic impact assessment, Special categories
- Data subject
-
The person the personal data is about. The rights regimes grant (access, deletion, correction, portability, objection, opting out of sale or profiling) belong to the data subject.
United Statesconsumer. The state privacy acts say consumer, and several exclude employees and business contacts from the definition. In software usage user. A user is whoever operates the product; a data subject is whoever the data describes, which includes people who never used it. See also: Personal data, Controller and processor
- Lawful basis
-
The justification a controller must have before processing personal data. The General Data Protection Regulation (GDPR) lists six, of which consent, contract, legal obligation, and legitimate interests carry most software processing. US law mostly runs the other way: processing is permitted unless a statute restricts it or the consumer opts out.
United Statesnotice and choice, opt-out. The US default; sensitive data and minors' data are the places US law flips to opt-in consent. See also: Consent, Personal data
- One-stop-shop
-
The General Data Protection Regulation (GDPR)'s rule that a controller established in more than one Member State answers to a single lead supervisory authority, the one where its main establishment is. It is why so many actions against US technology companies run through Ireland.
See also: Data protection authority, Establishment
- Personal data
-
Any information relating to an identified or identifiable person, the definition most regimes now share. Identifiers, location data, online identifiers, and inferences all count. Biometric data, health data, and other special categories carry extra duties.
United Statespersonal information, personally identifiable information (PII). Personally identifiable information is the older, narrower US notion built around identifiers; the state privacy acts define "personal information" broadly enough to match the EU term. In cybersecurity usage PII. Security frameworks still use PII as a data classification label; it under-includes inferences and pseudonymous identifiers that privacy law covers. See also: Controller and processor, Data subject, Special categories
- Special categories
-
Personal data whose processing is restricted or needs an explicit lawful basis: health, biometrics used to identify, genetic data, racial or ethnic origin, political opinions, religion, trade-union membership, sex life or orientation. Minors' data is treated as a special case in most regimes without being a category.
United Statessensitive personal information. The California Consumer Privacy Act (CCPA)'s term, which adds precise geolocation, account credentials, and the contents of communications. See also: Personal data, Biometric identifier
§ · Economics
- Jurisdictional weight
-
The population, nominal GDP, and software value added behind a jurisdiction's law. Used to rank findings, to normalise the enforcement record, and to roll jurisdictions up; never used on its own as a likelihood.
See also: Enforcement intensity, Software value added
- Software value added
-
The gross value added by software and IT services in a jurisdiction, the size of the regulated sector itself. LexLint splits it into what is produced there and what is merely booked there, because turnover- based fines reach the booked figure while establishment follows the produced one.
In economics usage gross value added (GVA), International Standard Industrial Classification (ISIC) J62 and J63. Gross value added is output minus intermediate consumption; the sector is divisions J58.2, J62, and J63 of the international industrial classification, and North American Industry Classification System (NAICS) 5112, 5415, and 518 in North America. In economics usage modified gross national income, gross national income (GNI)*. Ireland's statistical office publishes GNI* to strip out the profit and intellectual property that multinationals route through the country, the canonical measure of the produced-versus-booked gap. See also: Jurisdictional weight
§ · Acronyms
Every acronym the site annotates, with the sentence its tooltip carries. The same sentence appears wherever the acronym does.
- ACCC Australian Competition and Consumer Commission
Australian Competition and Consumer Commission: the national consumer-protection and competition regulator, which also acts against software under the Australian Consumer Law.
- ADMT automated decision-making technology
Automated decision-making technology: the term California's privacy rulemaking uses for systems that make or substantially replace human decisions about people.
- AEDE
Asociación de Editores de Diarios Españoles, the Spanish newspaper publishers' association the 2014 press levy was named after.
- BIPA Biometric Information Privacy Act
Biometric Information Privacy Act: the Illinois statute that requires written consent before a biometric identifier such as a faceprint or voiceprint is collected, and gives the person a private right of action.
- CAI
Commission d'accès à l'information: Quebec's access-to-information and privacy regulator, the strongest of Canada's provincial commissioners since Law 25.
- CAPTCHA
A challenge a site shows to tell people from automated visitors; defeating one is the clearest example of circumventing a technical barrier.
- CCPA California Consumer Privacy Act
California Consumer Privacy Act: the state privacy law, amended by the CPRA in 2020, that the other US state acts are modelled on or written against.
- CFAA Computer Fraud and Abuse Act
Computer Fraud and Abuse Act: the main United States federal statute on unauthorised access to computer systems.
- COPPA Children's Online Privacy Protection Act
Children's Online Privacy Protection Act: the US federal statute requiring verifiable parental consent before collecting personal information from children under 13.
- CPPA California Privacy Protection Agency
California Privacy Protection Agency: the dedicated privacy regulator California created in 2020, the only one of its kind in the United States.
- CPRA California Privacy Rights Act
California Privacy Rights Act: the 2020 ballot measure that amended the CCPA and created the CPPA.
- CRA Cyber Resilience Act
Cyber Resilience Act: the EU regulation that makes the manufacturer of a product with digital elements, software included, responsible for its security, its vulnerability handling and its incident reporting.
- DMCA Digital Millennium Copyright Act
Digital Millennium Copyright Act: the United States statute whose section 1201 prohibits circumventing technological measures that control access to copyrighted works.
- DPA data protection authority
Data protection authority: the competent authority for personal-data law in a jurisdiction, called a supervisory authority in the GDPR.
- DPIA data protection impact assessment
Data protection impact assessment: the written risk assessment the GDPR requires before high-risk processing, about harm to the people whose data is used.
- DSA Digital Services Act
Digital Services Act: the EU regulation on online intermediaries, with the heaviest duties on very large online platforms and search engines.
- DSM Digital Single Market
Digital Single Market: the EU's 2019 copyright directive, whose Article 4 lets rightsholders reserve their works against text and data mining.
- ECOA Equal Credit Opportunity Act
Equal Credit Opportunity Act: the United States fair-lending statute whose adverse-action notice duty applies however a credit decision was made, including by a model.
- EDPB European Data Protection Board
European Data Protection Board: the EU body that issues guidance and binding decisions on how data protection law is applied across member states.
- EMV expected monetary value
Expected monetary value: likelihood times loss, summed over scenarios; the number the LexLint Risk Score is built on.
- FAIR Factor Analysis of Information Risk
Factor Analysis of Information Risk: the Open Group standard that prices cyber risk as loss event frequency times loss magnitude; LexLint borrows its structure.
- FTC Federal Trade Commission
Federal Trade Commission: the US consumer-protection regulator that enforces privacy and data security through its unfairness and deception authority and sector rules.
- GDPR General Data Protection Regulation
General Data Protection Regulation: the EU's data protection law, which governs any processing of personal data about people in the EU, wherever the processor is.
- GEMA
The German collecting society that licenses performance and reproduction rights in music on behalf of composers, lyricists and publishers.
- GLBA Gramm-Leach-Bliley Act
Gramm-Leach-Bliley Act: the United States statute whose safeguards rule governs how financial institutions protect customer data, with a breach-notification duty since 2024.
- GNI gross national income
Gross national income: GDP plus net income from abroad; Ireland's modified version, GNI*, strips out what multinationals route through the country.
- GPAI general-purpose AI
General-purpose AI: a model that can serve many different tasks, such as a large language model; the EU AI Act sets specific duties for providers of these models.
- GRC governance, risk, and compliance
Governance, risk, and compliance: the category of tool a risk register is exported to, and the vocabulary its fields are named in.
- GVA gross value added
Gross value added: an industry's output minus what it bought in, the measure LexLint uses for the size of a jurisdiction's software sector.
- HIPAA Health Insurance Portability and Accountability Act
Health Insurance Portability and Accountability Act: the United States statute whose privacy, security and breach-notification rules govern protected health information.
- ICO Information Commissioner's Office
Information Commissioner's Office: the United Kingdom's data protection authority, which also enforces the electronic-marketing rules.
- IETF Internet Engineering Task Force
Internet Engineering Task Force: the open standards body that develops the core protocols of the internet, published as numbered documents in the RFC series.
- ISIC International Standard Industrial Classification
International Standard Industrial Classification: the United Nations industry taxonomy whose divisions J62 and J63 are software and information services.
- LGPD
Lei Geral de Proteção de Dados: Brazil's general data protection law, in force since 2020, which includes a right to review of decisions made solely by automated processing.
- LLM large language model
Large language model: an AI model that reads and generates text, the kind behind coding agents and chatbots.
- LRS LexLint Risk Score
LexLint Risk Score: likelihood times impact on a one-to-twenty-five scale, banded, from cited corpus defaults and the app's own exposure inputs.
- MCP Model Context Protocol
Model Context Protocol: the open standard coding agents use to discover and call external tools such as LexLint.
- NAICS North American Industry Classification System
North American Industry Classification System: the US, Canadian, and Mexican industry taxonomy; software publishers are 5112 and computer systems design is 5415.
- NDJSON newline-delimited JSON
Newline-delimited JSON: a file holding one JSON record per line, so it can be streamed and filtered without loading the whole thing.
- NIS2
The second Network and Information Security Directive: the EU directive that sets cybersecurity risk-management and incident-reporting duties for essential and important entities.
- NIST National Institute of Standards and Technology
National Institute of Standards and Technology: the US standards body whose AI Risk Management Framework supplies the role names in AI governance.
- OAIC Office of the Australian Information Commissioner
Office of the Australian Information Commissioner: Australia's privacy regulator under the Privacy Act 1988.
- OSAA Open Secure AI Alliance
Open Secure AI Alliance: an industry coalition, a Linux Foundation directed fund since September 2026, working on the security of AI agent systems.
- PDPA Personal Data Protection Act
Personal Data Protection Act: Singapore's personal-data statute of 2012, enforced by the PDPC; Thailand and Malaysia have acts of the same name.
- PDPC Personal Data Protection Commission
Personal Data Protection Commission: Singapore's data protection authority, which publishes its enforcement decisions in full.
- PIA privacy impact assessment
Privacy impact assessment: the older, public-sector name for a data protection impact assessment, still the term in Canada and in US federal agencies.
- PII personally identifiable information
Personally identifiable information: the older US term for personal data, narrower than the legal definition because it is built around identifiers.
- QA quality assurance
Quality assurance: the testing that decides software is fit to ship.
- RFC Request for Comments
Request for Comments: the numbered document series in which internet standards are published.
- RSL Really Simple Licensing
Really Simple Licensing: an industry-consortium scheme, launched in 2025, for publishing machine-readable licence terms for AI use of web content.
- SAFE Shared AI Findings Exchange
Shared AI Findings Exchange: the Open Secure AI Alliance's proposed scheme for reporting and learning from AI incidents. A proposal, not law.
- SEC Securities and Exchange Commission
Securities and Exchange Commission: the United States regulator of listed companies, whose Form 8-K Item 1.05 makes a registrant disclose a material cybersecurity incident.
- SME small or medium-sized enterprise
Small or medium-sized enterprise: under the EU AI Act an SME pays the lower of a fine's fixed cap and its turnover percentage, not the higher.
- SOCAN Society of Composers, Authors and Music Publishers of Canada
Society of Composers, Authors and Music Publishers of Canada: the Canadian performing-rights society that licenses music on behalf of its members.
- SSE server-sent events
Server-sent events: a one-way stream from server to client over HTTP, used by the older MCP transport that streamable HTTP replaced.
- TCPA Telephone Consumer Protection Act
Telephone Consumer Protection Act: the United States statute on automated calls and texts, which the Federal Communications Commission has read to cover calls made with an AI-generated voice.
- TDM text and data mining
Text and data mining: automated analysis of text or data, such as crawling pages to extract information or to train a model.
- TLD top-level domain
Top-level domain: the last part of a domain name, such as .com or .ai.
- UETA Uniform Electronic Transactions Act
Uniform Electronic Transactions Act: the model United States state law under which a contract may be formed by the interaction of electronic agents, with no person reviewing the exchange.
- URN Uniform Resource Name
Uniform Resource Name: the permanent, location-independent name UnGovr assigns to every government entity, which stays valid even if the entity's page moves.
- VLOP very large online platform
Very large online platform: a platform the European Commission has designated as reaching 45 million or more monthly users in the EU, which the Digital Services Act gives extra duties.
- VLOSE very large online search engine
Very large online search engine: a search engine designated on the same 45 million user threshold as a very large online platform, and carrying the same extra Digital Services Act duties.
- WAMCA
The Dutch collective-action act of 2020 that allows opt-out damages claims by representative foundations, which made the Netherlands a preferred venue for EU-wide claims.