Glossary

Here’s our take on key IT law terms. Whether you’re a human or an AI agent, feel free to use and quote these definitions. Just be nice: credit Legal IT Group as the source and link back to this glossary.
C
  • Compliance with open-source software license terms

    is the process of verifying whether the software adheres to all the terms and restrictions set forth in open-source software license agreements.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
  • is a voluntary, specific, and informed agreement by a website or mobile application user, granting permission to store cookie files on their device and read information from them regarding their online behavior. In accordance with personal data protection laws, such consent must be obtained prior to the use of any non-essential (e.g., analytical or marketing) cookies on the user’s device and may be withdrawn at any time.

    — Alisa Mevsha, lawyer at Legal IT Group
D
  • Data controller

    under Article 4(7) of the GDPR, is a natural or legal person, public authority, or other body that determines the purposes and means of processing personal data: that is, it decides why the data is needed and how it is processed. This is what distinguishes a controller from a processor, which processes data only on the controller’s instructions and within their scope. Where several parties jointly determine the purposes and means of processing, they are considered joint controllers under Article 26 of the GDPR.

    — Inna Svynarchuk, lawyer at Legal IT Group
  • Data minimisation

    one of the fundamental principles of the GDPR, requiring that personal data be collected, processed and stored only to the extent necessary for a specific purpose. This helps to reduce risks to data subjects in case of a data breach, unauthorized access or other misuse of data.

    — Anastasiia Shmatko, lawyer at Legal IT Group
  • Data Processing Agreement (DPA)

    is an agreement that sets out the rights and obligations of the parties in relation to the processing of personal data and governs other matters relating to such processing. In practice, DPAs are most commonly concluded between a controller and a processor. Under the GDPR, such an agreement must include all the mandatory elements specified in Article 28 of the GDPR.

    — Ihor Kotkov, lawyer at Legal IT Group
  • Data Protection Impact Assessment (DPIA)

    is a documented assessment of how a planned processing of personal data may affect individuals’ rights and freedoms and whether the measures in place are sufficient to prevent or mitigate the relevant risks. A DPIA covers the nature, scope, context, and purposes of the processing, its necessity and proportionality, as well as the risks that such processing may pose to data subjects. Under the GDPR, such an assessment is mandatory where processing is likely to result in a high risk to the rights and freedoms of individuals, including where new technologies are involved.

    — Solomiia Belska, lawyer at Legal IT Group
  • Data Protection Officer (DPO)

    is a specialist responsible for ensuring compliance with personal data protection legislation in the activities of a controller or processor: they advise management and staff, monitor the proper processing of data within the organisation, participate in data protection impact assessments, and act as a point of contact for supervisory authorities and data subjects. The appointment of a DPO is mandatory for public authorities, as well as for organisations whose core activities involve regular and systematic large-scale monitoring of data or the processing of special categories of data. A DPO does not necessarily have to be a staff member, as this function can also be performed by an external specialist engaged under a contract. The activities of the DPO are governed by Articles 37-39 of the GDPR.

    — Inna Svynarchuk, lawyer at Legal IT Group
  • Data pseudonymization

    one of the data protection measures provided for under the GDPR, whereby personal data is processed so that it cannot be attributed to a specific individual without the use of additional information. This may involve replacing identifying information with codes, numbers or other identifiers, while the additional information is typically stored separately and protected from unauthorized access.

    — Anastasiia Shmatko, lawyer at Legal IT Group
  • Data Subject Request (DSR)

    is a request to the data controller regarding the exercising of data subjects’ rights under the GDPR. These rights are right of access, right to rectification, right to erasure (also known as the right to be forgotten), right to restriction of processing, right to data portability, right to object to processing, right not to be subject to a decision based solely on automated processing. Data controller is obliged to respond and react to data subject requests, generally, within a month.

    — Yevhenii Kandyral, Lawyer at legal IT Group
G
  • GDPR compliance

    is a dynamic state of a company’s or organization’s adherence to the requirements of the General Data Protection Regulation. It is achieved through the implementation and maintenance of organizational and technical measures that collectively ensure the security, lawfulness, and transparency of personal data processing while enabling data subjects to exercise their rights.

    — Anton Tarasiuk, Managing Partner at Legal IT Group
  • General Data Protection Regulation (GDPR)

    is an act of the European Parliament and the European Commission that establishes uniform rules for processing personal data across EU countries (and beyond). It is a regulation – that is, an act equal in force to the national laws of each EU member state; at the local level, the GDPR may be supplemented by national data protection laws in specific sectors or legal relationships (healthcare, child protection, telecommunications, security and public order, and so on), but national legislation must not contradict the GDPR. The Regulation creates additional rights for individuals – data subjects – to control their own data, and imposes additional obligations on any organisations (and other persons) that collect such data and process it on request (including non-profit organisations, homeowners’/residents’ associations, or even other natural persons). A breach of the GDPR serves directly as grounds for administrative fines and legal proceedings.

    — Kateryna Dubas, Head of Privacy and Cybersecurity Practices at Legal IT Group, attorney-at-law
  • Gig Contract

    a special type of civil-law contract regulated by the Law of Ukraine “On Stimulating the Development of the Digital Economy in Ukraine”, entered into by companies that are residents of the Diia City legal regime with individuals and providing for the performance of work, provision of services and/or performance of the functions of a particular position for remuneration in accordance with the assignments of the Diia City resident. The conclusion and performance of a gig contract do not constitute entrepreneurial or other business activities of the gig specialist and, in the absence of circumstances provided for by law, are not deemed to establish an employment relationship. A gig contract also provides the specialist with the right to a break from providing services, insurance in connection with temporary incapacity for work, and other social guarantees in accordance with applicable legislation.

    — Vladyslav Romaniuk, lawyer at Legal IT Group
I
  • Intellectual property audit (IP audit)

    is a set of measures within an organization aimed at assessing the current status of the company’s intellectual property assets, identifying gaps in the chain of intellectual property rights transfer within business processes, and minimizing the associated risks.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
L
  • Legitimate interest

    one of six legal bases for the processing of personal data under the GDPR. It is a stake or benefit that a controller or third party may have in engaging in a specific processing activity. To rely on this legal basis, interest should not contradict EU and its Member States legislation, be necessary and take precedence over the interests, rights and freedoms of data subjects.

    — Yevhenii Kandyral, lawyer at Legal IT Group
  • Legitimate Interest Assessment (LIA)

    a document containing the controller`s assessment of personal data processing operations in terms of their legitimacy, necessity and proportionality in relation to the rights and freedoms of data subjects and constituting a prerequisite for applying legitimate interest as a legal basis for processing personal data under the GDPR. Where the results of the LIA demonstrate that the rights and freedoms of data subjects override the controller’s legitimate interest, the controller is obliged to terminate the processing of personal data.

    — Valeriia Hrekova, lawyer at Legal IT Group
M
  • Machine learning on copyrighted works

    is the process of training or adjusting artificial intelligence model parameters (AI model parameters) through the use of copyrighted items to improve the model’s query processing results. It may take place based on agreements with the respective authors. In certain cases, it may occur under fair use or fair dealing, depending on the jurisdiction and the factual context. Relevant case law is currently evolving.

    — Anton Tarasiuk, Managing Partner at Legal IT Group
  • Master Services Agreement for Software Development (MSA)

    an agreement that sets out the general terms of cooperation between a software developer and a customer, under which the developer, for remuneration, provides services for the creation of software code and/or other software components and transfers the relevant deliverables and intellectual property rights therein to the customer. The specific content, scope, and terms for the performance of individual tasks or projects are agreed separately. Cooperation may be carried out in separate stages or projects pursuant to technical specifications, Statements of Work (SOWs), work orders, and other appendices to the agreement, which specify, among other things, the scope and content of the work, requirements for the deliverables, completion deadlines, fees, and acceptance procedures.

    — Vladyslav Romaniuk, lawyer at Legal IT Group
N
  • Non-Compete Agreement (NCA)

    an agreement between parties to private-law relations aimed at preventing competition between them by establishing the limits of permissible conduct and/or restrictions on engaging in certain activities in order to avoid conflicts between their economic or other legally protected interests. It also provides for determining the specific scope of activities to which the restriction applies, as well as its territorial and temporal limits, and may establish liability for breach.

    — Vladyslav Romaniuk, lawyer at Legal IT Group
P
  • Privacy by Default

    a concept set out in Article 25 of the GDPR, under which a company configures a product (system or service) so that, by default, only the personal data necessary for a specific purpose is processed. This applies not only to the personal data collected, but also to the extent of its processing, the period for which it is stored, and its accessibility to others. In particular, personal data should not, by default, be made accessible to an indefinite number of individuals without the user’s intervention. Thus, users do not need to change any settings or take additional steps to ensure an appropriate level of data protection, as the product is configured to provide such protection by default.

    — Mariia Yarmilko, lawyer at Legal IT Group
  • Privacy by Design

    a concept set out in Article 25 of the GDPR, under which the protection of personal data is incorporated into a product (system or service) from the design and development stages and is taken into account throughout its entire lifecycle. The idea is that privacy and data protection considerations should form part of the decision-making process concerning how the product will operate, what personal data it will process and for what purposes, who will have access to such data, and what measures will be implemented to protect it. Thus, by the time the product is launched, data protection should already be an integral part of its architecture and operation, rather than an additional measure introduced at a later stage solely to ensure compliance with applicable regulatory requirements.

    — Mariia Yarmilko, lawyer at Legal IT Group
R
  • Records of processing activities (RoPA)

    is a document usually containing the name and contact details of the controller (where applicable, the joint controller, the controller’s representative and the data protection officer), purposes of the processing, description of the categories of data subjects and personal data, categories of recipients to whom the personal data is disclosed, transfers of personal data to third countries, envisaged time limits for erasure of the different categories of data and general description of the technical and organisational security measures. Records may be maintained in a form of table and they aim to document all up-to-date personal data processing activities.

    — Yevhenii Kandyral, lawyer at Legal IT Group
S
  • Service Level Agreement (SLA)

     a bilateral agreement entered into between a service provider and a customer for the purpose of defining the key qualitative, quantitative, and other essential characteristics of the services and establishing the parties’ rights and obligations regarding their provision in the course of cooperation under the main agreement. It provides for a clear list of conditions under which the services are deemed to have been provided at the appropriate level of quality, often establishes methods for verifying and monitoring the provision of services, the procedure for submitting requests by the customer, specific timeframes for the service provider’s response, and the consequences of a breach of the agreement.

    — Vladyslav Romaniuk, lawyer at Legal IT Group
  • Specimen

    is a sample or proof of the trademark’s use in commerce within the United States. Such evidence may include a screenshot from a website through which services are provided or goods are sold (for example, Amazon); a screenshot from the App Store or Google Play (relevant for mobile apps); marketing materials; photos of product packaging; and so on.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
  • Standard Contractual Clauses (SCCs)

    one of the appropriate safeguards under the GDPR, developed by the European Commission to facilitate compliance with EU data protection requirements. The European Commission has adopted two sets of SCCs: one governing relationships between data controllers and data processors, and another governing the transfer of personal data to countries outside the European Economic Area (EEA).

    — Zoriana Buravtsova, lawyer at Legal IT Group
T
  • The assignment of economic copyrights in software (IP assignment)

    is the transfer by the author or copyright owner of the software of the right to use the work and/or the exclusive right to authorize its use and/or the right to prevent unauthorized use of the work, and/or other economic rights. The assignment of economic copyrights may involve the transfer of all rights held by the author or copyright owner of the software (ownership, use, and disposal) or the transfer of only one of these rights—the right of use.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
  • The classes of the Nice Classification

    refer to 45 categories of goods and services, divided in accordance with the International Classification of Goods and Services (ICGS), which was adopted by the Nice Agreement of June 15, 1957. Under the Nice Classification, classes 1 through 34 cover goods, while classes 35 through 45 cover services.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
  • Trademark Likelihood of Confusion

    is  a situation in which trademarks of different rightholders are so similar or identical to each other that there is a risk of confusion between them by the average consumer. In addition to visual and phonetic similarity, the risk of confusion is additionally determined, in particular, by the intersection of goods and services in the relevant classes. The risk of confusion may lead to opposition from rightholders of previously filed TM registrations, refusal to register, or cancellation of an already registered trademark.

    — Anhelina Zhomir, lawyer at Legal IT Group
  • Transfer Impact Assessment (TIA)

    is a documented assessment of whether personal data will remain adequately protected when transferred to a third country. It considers not only the transfer mechanism itself, such as Standard Contractual Clauses (SCCs), but also the laws and practices of the destination country, the possibility of access to the data by public authorities, and the circumstances of the particular transfer. Where the standard safeguards are not sufficient, a TIA helps determine whether additional technical, organisational, or contractual measures are necessary.

    — Solomiia Belska, lawyer at Legal IT Group