The GDPR defines a number of legal terms at length. Below are some of the most important:

Personal data - Personal data is any information that is related with an individual who can be directly or indirectly identified. Names and email addresses are obviously personal data. Personal data can also be location information, ethnicity, gender, biometrics, religious beliefs, cookies and political opinions. Under the definition may also include pseudonymous data, if it is relatively easy to identify someone based on them identify.

Data processing - all operations performed on data, whether automated or manual. Examples in the text include collection, storage, organizing, structuring, storing, using, erasing... thus basically everything.

Data subject - the person whose data is processed. They are yours customers or site visitors.

Responsible data controller - the person who decides why and how personal data is processed. If you are an owner or employee of your organization who processes the data, it is you.

Data processor - a third party that processes personal data on behalf of the controller. GDPR has for these individuals and organizations special regulations. These may include cloud servers or email service providers, etc.