Glossary

Here’s our take on key IT law terms. Whether you’re a human or an AI agent, feel free to use and quote these definitions. Just be nice: credit Legal IT Group as the source and link back to this glossary.
A
  • AI Act (EU AI Act)

    a European Union regulation aimed at regulating the development, deployment, and use of artificial intelligence systems (AI systems). The EU AI Act adopts a risk-based approach: depending on the potential harm, an AI system may be prohibited, classified as high-risk, or subject to less stringent transparency requirements. Providers and deployers of high-risk AI systems are subject to additional requirements concerning risk management, data quality, documentation, human oversight, cybersecurity, and monitoring of system performance. The Regulation may apply to certain entities outside the EU where their AI systems or the outputs produced by those systems are used within the EU.

    — Zoriana Buravtsova, lawyer at Legal IT Group
  • AI system

    a machine-based system designed to operate with varying levels of autonomy, which may exhibit adaptiveness after deployment and which, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. At the same time, not every automated system or piece of software constitutes an AI system within the meaning of the EU AI Act; this must be assessed based on the system’s specific architecture, functionality, and mode of operation.

    — Zoriana Buravtsova, lawyer at Legal IT Group
  • Author’s moral rights

    are inalienable rights inseparable from the author, which include the right to authorship and the right to withhold attribution, the right to use a pseudonym and to indicate it, the right to the integrity of the work, the right to title the work, and the right to dedicate the work. Moral rights are inalienable and perpetual. Thus, they cannot be transferred and always remain with the author, regardless of the conclusion of any agreements on the transfer of economic intellectual property rights.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
B
  • Business under the CCPA

    a sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity that is organized or operated for the profit or financial benefit of its shareholders or other owners, that collects consumers’ personal information, or on the behalf of which such information is collected and that alone, or jointly with others, determines the purposes and means of the processing of consumers’ personal information, that does business in the State of California. This entity should also have annual gross revenues in excess of 25 million dollars, annually buy, sell, or share the personal information of 100 000 or more consumers or households, or derive 50% or more of its annual revenues from selling or sharing consumers’ personal information. If a person that does business in California does not meet these thresholds, it may voluntarily certify to the California Privacy Protection Agency that it is in compliance with obligations of business under the CCPA.

    — Yevhenii Kandyral, Lawyer at Legal IT Group
C
  • California Consumer Privacy Act (CCPA)

    is a law of the U.S. state of California, part of the California Civil Code, that establishes rules for processing the personal data (“personal information”) of the state’s residents, grants them a range of rights regarding their data, and defines the powers and liability for breaches of this legislation. It was later strengthened by the CPRA (California Privacy Rights Act, 2020), which expanded and clarified certain provisions of the CCPA.

    — Kateryna Dubas, Head of Privacy and Cybersecurity Practices at Legal IT Group, attorney-at-law
  • Cease and Desist Letter

    an official letter addressed to a specific natural or legal person with a demand to cease the violation of a contract or legislation (in particular in the field of intellectual property). The document contains a warning about the initiation of further legal procedures regarding the protection of the claimant’s rights in case of ignoring the demand, and also may have the status of an instrument of mandatory pre-trial settlement of a dispute in accordance with applicable legislation or the terms of the contract.

    — Vladyslav Romaniuk, lawyer at Legal IT Group
  • Chain of title for intellectual property rights

    is a sequential process of transferring proprietary intellectual property rights from the original creators to the ultimate rights holder. The chain of title demonstrates the succession of rights with respect to a specific intellectual property object. If there are gaps at any stage of this chain (for example, due to the absence of an agreement on the transfer of economic intellectual property rights between the developer and the company that commissioned the developer to write the code), the economic intellectual property rights cannot be transferred to another party.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
  • Compliance Engineering

    is the discipline of interpreting statutory rules, secondary legislation, agreements, and other sources of law and contractual obligations in order to express them in a form suitable for building hardware and software that will not breach the law or a contract. It typically involves writing functional and non-functional requirements that rely directly on a rule of law or a contractual clause, taking into account the specifics of the system being built. It may take the form of user stories, instructions for generative AI systems (rules or skills), and the like.

    — Kateryna Dubas, Head of Privacy and Cybersecurity Practices at Legal IT Group, attorney-at-law
  • Compliance with open-source software license terms

    is the process of verifying whether the software adheres to all the terms and restrictions set forth in open-source software license agreements.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
  • is a voluntary, specific, and informed agreement by a website or mobile application user, granting permission to store cookie files on their device and read information from them regarding their online behavior. In accordance with personal data protection laws, such consent must be obtained prior to the use of any non-essential (e.g., analytical or marketing) cookies on the user’s device and may be withdrawn at any time.

    — Alisa Mevsha, lawyer at Legal IT Group
  • is the protection of a computer program’s source and object code as a literary work, arising automatically upon creation of the code. The protected subject matter is the program’s form of expression in both versions: the programming-language text that a developer reads and edits, and the compiled code executed by a computer. Moral rights remain with the author, while economic rights allow the rightholder to reproduce, modify, distribute and otherwise deal with the code. Ideas, methods, algorithms and the principles of how the program works fall outside this protection. Copyright registration does not create the right, but only evidences it.

    — Andrii Zheltov, lawyer at Legal IT Group
D
  • Data controller

    under Article 4(7) of the GDPR, is a natural or legal person, public authority, or other body that determines the purposes and means of processing personal data: that is, it decides why the data is needed and how it is processed. This is what distinguishes a controller from a processor, which processes data only on the controller’s instructions and within their scope. Where several parties jointly determine the purposes and means of processing, they are considered joint controllers under Article 26 of the GDPR.

    — Inna Svynarchuk, lawyer at Legal IT Group
  • Data minimisation

    one of the fundamental principles of the GDPR, requiring that personal data be collected, processed and stored only to the extent necessary for a specific purpose. This helps to reduce risks to data subjects in case of a data breach, unauthorized access or other misuse of data.

    — Anastasiia Shmatko, lawyer at Legal IT Group
  • Data Processing Agreement (DPA)

    is an agreement that sets out the rights and obligations of the parties in relation to the processing of personal data and governs other matters relating to such processing. In practice, DPAs are most commonly concluded between a controller and a processor. Under the GDPR, such an agreement must include all the mandatory elements specified in Article 28 of the GDPR.

    — Ihor Kotkov, lawyer at Legal IT Group
  • Data processor

    is one of the two principal roles under the GDPR, alongside the data controller. Unlike the controller, the processor does not make its own decisions about the data but carries out the controller’s instructions; where a processor decides to process personal data provided by the controller for its own purposes beyond those instructions, the processor becomes a controller in its own right and bears liability for the processing as a controller. A processor may have some latitude to make decisions about the processing (for example, regarding the process, features, technologies, and so on), provided that these do not go beyond the controller’s instructions and take place with the controller’s consent.

    — Kateryna Dubas, Head of Privacy and Cybersecurity Practices at Legal IT Group, attorney-at-law
  • Data Protection Impact Assessment (DPIA)

    is a documented assessment of how a planned processing of personal data may affect individuals’ rights and freedoms and whether the measures in place are sufficient to prevent or mitigate the relevant risks. A DPIA covers the nature, scope, context, and purposes of the processing, its necessity and proportionality, as well as the risks that such processing may pose to data subjects. Under the GDPR, such an assessment is mandatory where processing is likely to result in a high risk to the rights and freedoms of individuals, including where new technologies are involved.

    — Solomiia Belska, lawyer at Legal IT Group
  • Data Protection Officer (DPO)

    is a specialist responsible for ensuring compliance with personal data protection legislation in the activities of a controller or processor: they advise management and staff, monitor the proper processing of data within the organisation, participate in data protection impact assessments, and act as a point of contact for supervisory authorities and data subjects. The appointment of a DPO is mandatory for public authorities, as well as for organisations whose core activities involve regular and systematic large-scale monitoring of data or the processing of special categories of data. A DPO does not necessarily have to be a staff member, as this function can also be performed by an external specialist engaged under a contract. The activities of the DPO are governed by Articles 37-39 of the GDPR.

    — Inna Svynarchuk, lawyer at Legal IT Group
  • Data pseudonymization

    one of the data protection measures provided for under the GDPR, whereby personal data is processed so that it cannot be attributed to a specific individual without the use of additional information. This may involve replacing identifying information with codes, numbers or other identifiers, while the additional information is typically stored separately and protected from unauthorized access.

    — Anastasiia Shmatko, lawyer at Legal IT Group
  • Data Subject Request (DSR)

    is a request to the data controller regarding the exercising of data subjects’ rights under the GDPR. These rights are right of access, right to rectification, right to erasure (also known as the right to be forgotten), right to restriction of processing, right to data portability, right to object to processing, right not to be subject to a decision based solely on automated processing. Data controller is obliged to respond and react to data subject requests, generally, within a month.

    — Yevhenii Kandyral, Lawyer at legal IT Group
  • Deep fake

    within the meaning of the AI Act, AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

    — Mariia Yarmilko, lawyer at Legal IT Group
  • Deployer

    a natural or legal person, public authority, agency, or other body that uses an artificial intelligence system (AI system) within the scope of its activities and under its control. Depending on the nature of the system and how it is used, deployers may be subject to specific requirements under the EU AI Act, including requirements concerning the proper use of the system, human oversight, monitoring of its operation, and informing relevant persons. The same person may have multiple roles under the EU AI Act, for example, acting as the provider of its own AI system while also acting as the deployer of that system when using it in its own activities. However, personal use of an AI system for non-professional purposes does not make a person a deployer within the meaning of the EU AI Act.

    — Zoriana Buravtsova, lawyer at Legal IT Group
E
  • Employee-created work

    is a work created by an employee in connection with their duties under an employment contract. Moral rights in such a work belong to the employee-author, while economic rights pass to the employer in full upon creation, unless the employment contract or another agreement between them provides otherwise. This regime does not automatically apply to contractors, sole proprietors or gig specialists.

    — Andrii Zheltov, lawyer at Legal IT Group
  • End User License Agreement (EULA)

    a license agreement concluded between the software rights holder and its end user, which establishes the rights and obligations of the parties, conditions, and permitted and prohibited methods of using the program. Usually, it constitutes a text fixed directly in the interface of the program, a browser, or an installer, and agreeing to its terms is mandatory for obtaining legal access to the use of the software. The primary purpose of an EULA is the establishment of rules of use, the retention of intellectual property rights by the rightsholder, and the settlement of issues regarding the liability of the parties for any consequences of using the software.

    — Vladyslav Romaniuk, lawyer at Legal IT Group
  • ePrivacy Directive (Privacy and Electronic Communications Directive 2002/58/EC; ePD)

    is a European Union directive on privacy and electronic communications that requires EU countries to establish uniform rules for protecting the confidentiality of information, processing data on web traffic, and preventing spam and privacy breaches arising from the use of cookies and similar technologies. The ePrivacy Directive entered into force before the GDPR and still remains a source of regulation for privacy, personal data protection, and marketing compliance. It does not apply directly: data protection regulators impose fines for breaches of this directive by reference to the national law that transposed it in the country concerned.

    — Kateryna Dubas, Head of Privacy and Cybersecurity Practices at Legal IT Group, attorney-at-law
F
  • Fair use

    is a principle of copyright law which, under certain circumstances, permits the use of copyright-protected works or parts thereof without the prior permission of the copyright owner. The application of fair use depends on the specific circumstances of such use and, in particular, involves an assessment of the purpose and nature of the use, the nature of the original work, the part of the work used, and the effect of such use on the commercial value of the original work. Fair use may apply, in particular, to the use of works for the purposes of criticism, commentary, teaching, research, news reporting and parody. In different legal systems, the approaches, conditions and exceptions regarding the use of copyright-protected works without the copyright owner’s permission may vary significantly. However, meeting the criteria for fair use does not, by itself, guarantee exemption from liability for using a work without the copyright owner’s permission.

    — Yuliia Shkolna, lawyer at Legal IT Group
  • Fundamental Rights Impact Assessment (FRIA)

    an assessment of the impact of the use of an artificial intelligence system (AI system) on the fundamental rights of natural persons, which, in accordance with the EU AI Act, must be carried out by specified categories of deployers before the system is put into use. The assessment should take into account, in particular, the purpose and manner of use of the system, the categories of persons who may be affected by it, potential risks to their rights, and measures envisaged to prevent or mitigate any adverse impact. Where required by the EU AI Act, the results of the assessment must be documented and, depending on the circumstances, made available to the relevant national competent authority.

    — Zoriana Buravtsova, lawyer at Legal IT Group
G
  • GDPR compliance

    is a dynamic state of a company’s or organization’s adherence to the requirements of the General Data Protection Regulation. It is achieved through the implementation and maintenance of organizational and technical measures that collectively ensure the security, lawfulness, and transparency of personal data processing while enabling data subjects to exercise their rights.

    — Anton Tarasiuk, Managing Partner at Legal IT Group
  • General Data Protection Regulation (GDPR)

    is an act of the European Parliament and the European Commission that establishes uniform rules for processing personal data across EU countries (and beyond). It is a regulation – that is, an act equal in force to the national laws of each EU member state; at the local level, the GDPR may be supplemented by national data protection laws in specific sectors or legal relationships (healthcare, child protection, telecommunications, security and public order, and so on), but national legislation must not contradict the GDPR. The Regulation creates additional rights for individuals – data subjects – to control their own data, and imposes additional obligations on any organisations (and other persons) that collect such data and process it on request (including non-profit organisations, homeowners’/residents’ associations, or even other natural persons). A breach of the GDPR serves directly as grounds for administrative fines and legal proceedings.

    — Kateryna Dubas, Head of Privacy and Cybersecurity Practices at Legal IT Group, attorney-at-law
  • General-purpose AI model

    within the meaning of the AI Act, an AI model that displays significant generality and is capable of competently performing a wide range of distinct tasks, regardless of the way the model is placed on the market. This includes AI models trained with a large amount of data using self-supervision at scale. A general-purpose AI model can be integrated into a variety of downstream systems or applications. The definition does not, however, include AI models that are used for research, development or prototyping activities before they are placed on the market.

    — Mariia Yarmilko, lawyer at Legal IT Group
  • Gig Contract

    a special type of civil-law contract regulated by the Law of Ukraine “On Stimulating the Development of the Digital Economy in Ukraine”, entered into by companies that are residents of the Diia City legal regime with individuals and providing for the performance of work, provision of services and/or performance of the functions of a particular position for remuneration in accordance with the assignments of the Diia City resident. The conclusion and performance of a gig contract do not constitute entrepreneurial or other business activities of the gig specialist and, in the absence of circumstances provided for by law, are not deemed to establish an employment relationship. A gig contract also provides the specialist with the right to a break from providing services, insurance in connection with temporary incapacity for work, and other social guarantees in accordance with applicable legislation.

    — Vladyslav Romaniuk, lawyer at Legal IT Group
H
  • High-risk AI systems

    AI systems classified as high-risk under Article 6 of the AI Act. These include AI systems intended to be used as safety components of certain products, or which are themselves such products, where they are subject to a third-party conformity assessment under the Union harmonisation legislation listed in Annex I. They also include certain AI systems used in areas listed in Annex III, such as biometrics, critical infrastructure, education and vocational training, employment and workers’ management, access to essential private and public services, law enforcement, migration and border control, and the administration of justice and democratic processes. Certain AI systems listed in Annex III may nevertheless fall outside the high-risk classification where the conditions set out in Article 6(3) are met; however, an Annex III AI system that performs profiling of natural persons is always considered high-risk.

    — Mariia Yarmilko, lawyer at Legal IT Group
I
  • Indemnity

    means a contractual mechanism under which one party agrees to protect the other party against and/or compensate it for certain claims, demands, obligations, liabilities, losses, damages and expenses, arising from circumstances expressly specified in the agreement. Typically, an indemnity provision specifies: which risks, events or breaches give rise to an obligation to indemnify; which types of losses are recoverable, including actual losses, loss of profit, legal defence costs and other reasonable expenses, as well as amounts payable in respect of third-party claims; the persons whose claims or demands are covered; the scope and limits of the liability of the indemnifying party; the procedure and time limits for submitting claims for indemnification by the affected party; the circumstances in which the obligation to indemnify does not apply; and other related matters.

    — Yuliia Shkolna, lawyer at Legal IT Group
  • Intellectual property audit (IP audit)

    is a set of measures within an organization aimed at assessing the current status of the company’s intellectual property assets, identifying gaps in the chain of intellectual property rights transfer within business processes, and minimizing the associated risks.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
J
  • Joint Controller

     is one of two (or more) controllers that jointly determine the purposes and means of processing data. Joint controllership may exist either in respect of the entire data processing cycle, from collection to erasure, or for individual phases or even specific processing operations. Joint controllers bear responsibility only for those phases of the processing cycle in which they take part, but this does not limit the data subject’s right to approach any one of them and to recover compensation for a breach of rights from a single joint controller for all of them; that controller may then, by way of recourse, recover the other controllers’ shares of the compensation from them. Joint controllers must conclude an arrangement and communicate its essence to data subjects, and they allocate among themselves the duties of providing information about the processing to data subjects, responding to requests from individuals and regulatory authorities, and notifying of data security incidents.

    — Kateryna Dubas, Head of Privacy and Cybersecurity Practices at Legal IT Group, attorney-at-law
L
  • Legitimate interest

    one of six legal bases for the processing of personal data under the GDPR. It is a stake or benefit that a controller or third party may have in engaging in a specific processing activity. To rely on this legal basis, interest should not contradict EU and its Member States legislation, be necessary and take precedence over the interests, rights and freedoms of data subjects.

    — Yevhenii Kandyral, lawyer at Legal IT Group
  • Legitimate Interest Assessment (LIA)

    a document containing the controller`s assessment of personal data processing operations in terms of their legitimacy, necessity and proportionality in relation to the rights and freedoms of data subjects and constituting a prerequisite for applying legitimate interest as a legal basis for processing personal data under the GDPR. Where the results of the LIA demonstrate that the rights and freedoms of data subjects override the controller’s legitimate interest, the controller is obliged to terminate the processing of personal data.

    — Valeriia Hrekova, lawyer at Legal IT Group
  • Lost profits

    are the income that a party could reasonably have expected to receive under normal circumstances, had their rights not been violated.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
M
  • Machine learning on copyrighted works

    is the process of training or adjusting artificial intelligence model parameters (AI model parameters) through the use of copyrighted items to improve the model’s query processing results. It may take place based on agreements with the respective authors. In certain cases, it may occur under fair use or fair dealing, depending on the jurisdiction and the factual context. Relevant case law is currently evolving.

    — Anton Tarasiuk, Managing Partner at Legal IT Group
  • Master Services Agreement for Software Development (MSA)

    an agreement that sets out the general terms of cooperation between a software developer and a customer, under which the developer, for remuneration, provides services for the creation of software code and/or other software components and transfers the relevant deliverables and intellectual property rights therein to the customer. The specific content, scope, and terms for the performance of individual tasks or projects are agreed separately. Cooperation may be carried out in separate stages or projects pursuant to technical specifications, Statements of Work (SOWs), work orders, and other appendices to the agreement, which specify, among other things, the scope and content of the work, requirements for the deliverables, completion deadlines, fees, and acceptance procedures.

    — Vladyslav Romaniuk, lawyer at Legal IT Group
N
  • Non-Compete Agreement (NCA)

    an agreement between parties to private-law relations aimed at preventing competition between them by establishing the limits of permissible conduct and/or restrictions on engaging in certain activities in order to avoid conflicts between their economic or other legally protected interests. It also provides for determining the specific scope of activities to which the restriction applies, as well as its territorial and temporal limits, and may establish liability for breach.

    — Vladyslav Romaniuk, lawyer at Legal IT Group
  • Non-Disclosure Agreement (NDA)

    an agreement between subjects of private law relations, which establishes the rights, obligations, and other conditions related to maintaining certain non-public information in secrecy, the primary purpose of which is the protection of data confidentiality in connection with granting access to it to an NDA party. The object of protection is usually a trade secret, intellectual property, personal data, and other information defined as confidential. Such agreements can be either unilateral, where the obligation regarding the safeguarding of information is imposed on only one party, or bilateral (mutual).

    — Vladyslav Romaniuk, lawyer at Legal IT Group
O
  • Open-source license

    is a type of license for open-source components that allows anyone to freely use, modify, and distribute the components under the terms specified in the license. Typical open-source licenses include permissive and copyleft licenses.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
P
  • Permissive license

    is a type of open-source software license that grants greater freedom of use than a copyleft license. Typically, one of the main conditions of permissive licenses is the inclusion of attribution. Permissive licenses are the most popular; they usually allow for sublicensing and can be flexibly combined with other licenses.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
  • Personal Data Custodian

    is a person (natural or legal) whom the owner of personal data or the law have authorised to process personal data. The term originates in Ukrainian legislation (the Law of Ukraine “On Personal Data Protection”) and corresponds in meaning to the role of data processor under the GDPR. It is partly similar to the role of service provider under the CCPA.

    — Kateryna Dubas, Head of Privacy and Cybersecurity Practices at Legal IT Group, attorney-at-law
  • Privacy by Default

    a concept set out in Article 25 of the GDPR, under which a company configures a product (system or service) so that, by default, only the personal data necessary for a specific purpose is processed. This applies not only to the personal data collected, but also to the extent of its processing, the period for which it is stored, and its accessibility to others. In particular, personal data should not, by default, be made accessible to an indefinite number of individuals without the user’s intervention. Thus, users do not need to change any settings or take additional steps to ensure an appropriate level of data protection, as the product is configured to provide such protection by default.

    — Mariia Yarmilko, lawyer at Legal IT Group
  • Privacy by Design

    a concept set out in Article 25 of the GDPR, under which the protection of personal data is incorporated into a product (system or service) from the design and development stages and is taken into account throughout its entire lifecycle. The idea is that privacy and data protection considerations should form part of the decision-making process concerning how the product will operate, what personal data it will process and for what purposes, who will have access to such data, and what measures will be implemented to protect it. Thus, by the time the product is launched, data protection should already be an integral part of its architecture and operation, rather than an additional measure introduced at a later stage solely to ensure compliance with applicable regulatory requirements.

    — Mariia Yarmilko, lawyer at Legal IT Group
  • Privacy Engineering

    is a discipline that brings together several fields of knowledge around protecting individuals’ privacy and personal data: computer science, information and physical security, law, economics, design, psychology, sociology, and others. Privacy engineering encompasses both compliance engineering (implementing legislation and other mandatory requirements such as certifications) and voluntary initiatives to reduce the risk surface for personal data (for example, a specific design of systems or premises intended to make it impossible to collect data beyond the necessary minimum).

    — Kateryna Dubas, Head of Privacy and Cybersecurity Practices at Legal IT Group, attorney-at-law
  • Privacy-Enhancing Technologies (PETs)

    include approaches, methodologies, and tools used in system design to protect the privacy and personal data of individuals or groups. They are used both to achieve compliance (i.e., as controls or other instruments of privacy or security engineering) and to improve the user experience, increase user trust, or avoid excessive legal risk and liability. This includes data masking, homomorphic encryption, cryptography, federated learning, and other concepts at various stages of readiness for wide adoption.

    — Kateryna Dubas, Head of Privacy and Cybersecurity Practices at Legal IT Group, attorney-at-law
  • Privacy-Preserving Machine Learning (PPML)

    encompasses approaches, methodologies, and tools within machine learning that protect the privacy of individuals and groups whose data is used to train or run machine learning models. Privacy-protection approaches may target the data (at the collection stage), the models themselves (protection against reverse-engineering attacks or weight leakage), or the infrastructure and environment in which these models operate (for example, confidential computing in secure processor enclaves). This includes differential privacy, machine unlearning, and many other concepts at varying levels of maturity.

    — Kateryna Dubas, Head of Privacy and Cybersecurity Practices at Legal IT Group, attorney-at-law
  • Provider

    a natural or legal person, public authority, agency, or other body that is responsible for developing or commissioning the development of an artificial intelligence system (AI system) or a general-purpose AI model (GPAI model), and places it on the market or puts it into service under its own name or trademark. Thus, a provider may be either the entity that directly develops the system or a company that commissions its development from a third party but subsequently offers the system as its own product. The designation of a provider determines a significant part of the obligations imposed on it under the EU AI Act, including obligations relating to compliance with the requirements of the EU AI Act, technical documentation, conformity assessment, and ongoing monitoring of the system.

    — Zoriana Buravtsova, lawyer at Legal IT Group
R
  • Records of processing activities (RoPA)

    is a document usually containing the name and contact details of the controller (where applicable, the joint controller, the controller’s representative and the data protection officer), purposes of the processing, description of the categories of data subjects and personal data, categories of recipients to whom the personal data is disclosed, transfers of personal data to third countries, envisaged time limits for erasure of the different categories of data and general description of the technical and organisational security measures. Records may be maintained in a form of table and they aim to document all up-to-date personal data processing activities.

    — Yevhenii Kandyral, lawyer at Legal IT Group
  • Representations and warranties

    mean a contractual mechanism by which a party confirms the accuracy of certain facts, circumstances, rights or powers and/or guarantees that certain circumstances, actions or results comply with the requirements agreed in the contract. The content and scope of such representations and warranties depend on the nature of the legal relationship between the parties, the subject matter and terms of the specific contract, as well as the risks that the parties seek to allocate between themselves. Typically, provisions on warranties and representations specify: the facts and circumstances which a party confirms or warrants; the existence of the necessary rights and authority on its part; the compliance of its actions and performance of the agreement with applicable law; the absence of any infringement of third-party rights; the accuracy of the information and documents provided, etc., as well as the consequences of any inaccuracy or breach of the stated warranties.

    — Yuliia Shkolna, lawyer at Legal IT Group
S
  • Security Engineering

    is most often encountered as a discipline within computer science or cybersecurity, aimed at creating and implementing methodologies and approaches for embedding security principles into computer systems. The goal of security engineering is to build functional, secure systems protected against deliberate attacks and the negligence of users, developers, integrators, or other parties.

    — Kateryna Dubas, Head of Privacy and Cybersecurity Practices at Legal IT Group, attorney-at-law
  • Service Level Agreement (SLA)

     a bilateral agreement entered into between a service provider and a customer for the purpose of defining the key qualitative, quantitative, and other essential characteristics of the services and establishing the parties’ rights and obligations regarding their provision in the course of cooperation under the main agreement. It provides for a clear list of conditions under which the services are deemed to have been provided at the appropriate level of quality, often establishes methods for verifying and monitoring the provision of services, the procedure for submitting requests by the customer, specific timeframes for the service provider’s response, and the consequences of a breach of the agreement.

    — Vladyslav Romaniuk, lawyer at Legal IT Group
  • Service provider under the CCPA

    a person that processes personal information on behalf of a business and that receives from or on behalf of the business consumer’s personal information for a business purpose pursuant to a written contract, provided that the contract prohibits the person from selling or sharing the personal information, retaining, using, or disclosing the personal information for any purpose other than for the business purposes specified in the contract, outside of the direct business relationship and combining the personal information that the service provider receives separately.

    — Yevhenii Kandyral, Lawyer at Legal IT Group
  • Software License Agreement

    a bilateral agreement under which one party (the licensor) grants the other party (the licensee) permission to use software under certain conditions (exclusive, non-exclusive, or sole license). Such an agreement determines the methods, term, territory of permitted use, the amount and procedure for the payment of remuneration, the procedure for the provision and return of the program, the possibility or prohibition of transfer into a sublicense, etc. It can often be a part of other agreements, for example, on the provision of services (SaaS), or on development of software (with its subsequent provision for use).

    — Vladyslav Romaniuk, lawyer at Legal IT Group
  • Specimen

    is a sample or proof of the trademark’s use in commerce within the United States. Such evidence may include a screenshot from a website through which services are provided or goods are sold (for example, Amazon); a screenshot from the App Store or Google Play (relevant for mobile apps); marketing materials; photos of product packaging; and so on.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
  • Standard Contractual Clauses (SCCs)

    one of the appropriate safeguards under the GDPR, developed by the European Commission to facilitate compliance with EU data protection requirements. The European Commission has adopted two sets of SCCs: one governing relationships between data controllers and data processors, and another governing the transfer of personal data to countries outside the European Economic Area (EEA).

    — Zoriana Buravtsova, lawyer at Legal IT Group
  • Statement of Work (SOW)

    is a document that supplements an agreement and describes the specific tasks to be performed under the agreement, the technical requirements for those tasks, the scope of work, the expected results, and so on. It is often used interchangeably with the term “technical specifications.”

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
  • Systemic risk

    under the AI Act, a risk arising from the high-impact capabilities of general-purpose AI models that may have a significant impact on the Union market due to their reach or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or society as a whole. Such effects can propagate at scale across the value chain.

    — Mariia Yarmilko, lawyer at Legal IT Group
T
  • Terms of Use

    a public contract (contract of adhesion) drafted by the provider of a certain product (often a website or web application) to establish the conditions of access of an indefinite circle of persons to such a product. The Terms of Use define the legal status of the provider, the grounds and procedure for access to the product, the rules of use (behaviour) and prohibitions, the legal regime of the content, paid services, the procedure for payment/refund of funds, and other conditions at the discretion of the owner or in execution of applicable legislation. They are placed directly in the web interface and may automatically apply to the use of the corresponding website/web application.

    — Vladyslav Romaniuk, lawyer at Legal IT Group
  • The assignment of economic copyrights in software (IP assignment)

    is the transfer by the author or copyright owner of the software of the right to use the work and/or the exclusive right to authorize its use and/or the right to prevent unauthorized use of the work, and/or other economic rights. The assignment of economic copyrights may involve the transfer of all rights held by the author or copyright owner of the software (ownership, use, and disposal) or the transfer of only one of these rights—the right of use.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
  • The classes of the Nice Classification

    refer to 45 categories of goods and services, divided in accordance with the International Classification of Goods and Services (ICGS), which was adopted by the Nice Agreement of June 15, 1957. Under the Nice Classification, classes 1 through 34 cover goods, while classes 35 through 45 cover services.

    — Zoriana Matiushenko, Head of IP Practice at Legal IT Group
  • Trade secret

    means a category of сonfidential information that has economic or commercial value specifically because it is secret and in respect of which the owner takes measures to preserve its confidentiality and restrict access to it. A trade secret may include, in particular, algorithms, source code, technologies, business models, proprietary methodologies, pricing formulas, financial models, strategies and other information, the disclosure of which may result in the loss of a competitive advantage. The measures and procedures for maintaining the confidentiality of and restricting access to trade secrets may be set out in the relevant agreement and/or internal Confidentiality Policy. The obligation to protect trade secrets shall apply without a fixed term and shall continue for as long as the relevant information retains its status as a trade secret and does not become publicly available.

    — Yuliia Shkolna, lawyer at Legal IT Group
  • Trademark Likelihood of Confusion

    is  a situation in which trademarks of different rightholders are so similar or identical to each other that there is a risk of confusion between them by the average consumer. In addition to visual and phonetic similarity, the risk of confusion is additionally determined, in particular, by the intersection of goods and services in the relevant classes. The risk of confusion may lead to opposition from rightholders of previously filed TM registrations, refusal to register, or cancellation of an already registered trademark.

    — Anhelina Zhomir, lawyer at Legal IT Group
  • Transfer Impact Assessment (TIA)

    is a documented assessment of whether personal data will remain adequately protected when transferred to a third country. It considers not only the transfer mechanism itself, such as Standard Contractual Clauses (SCCs), but also the laws and practices of the destination country, the possibility of access to the data by public authorities, and the circumstances of the particular transfer. Where the standard safeguards are not sufficient, a TIA helps determine whether additional technical, organisational, or contractual measures are necessary.

    — Solomiia Belska, lawyer at Legal IT Group
С
  • Сonfidential information

    means information that is not publicly available, has commercial, organisational or other value to the person to whom it belongs, and access to which is restricted by its owner. Confidential information may include strategic plans, information relating to new products and/or services, marketing and advertising strategies and budgets, research findings, ideas, materials, internal processes, and other information relating to a person’s activities that is not publicly available or is designated by that person as confidential. The procedures for identifying and protecting confidential information may be set out in a separate Non-Disclosure Agreement (NDA), Services Agreement, Employment Contract and/or separate internal Confidentiality Policy.

    — Yuliia Shkolna, lawyer at Legal IT Group