Data Minimisation

GDPR principle requiring only necessary personal data to be collected and processed for the specific purpose.

A

B

C

D

Data minimisation is one of the core principles of the GDPR (Article 5(1)(c)), requiring that personal data collected and processed must be adequate, relevant and limited to what is strictly necessary for the stated purpose. This means organisations must critically evaluate each data field they collect and be able to justify why it is needed, rather than gathering data speculatively or "just in case".

In practice, data minimisation reduces an organisation's attack surface and limits the potential impact of a data breach, since less data means less exposure. It also simplifies compliance with other GDPR obligations such as storage limitation and data subject access requests, and builds trust with customers who are increasingly aware of how their data is used.

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

S

T

U

V

W

Z

Frequently asked questions

What is data minimisation under the GDPR?
Data minimisation is the GDPR principle that you should only collect and process the personal data that is actually necessary for your specified purpose.
Why is data minimisation important?
Collecting less data reduces privacy risk, limits the impact of a breach, and is a legal requirement under the GDPR.
How do you apply data minimisation?
Only ask for data you truly need, avoid collecting data just in case, and delete data once the purpose is fulfilled (which the GDPR addresses under the related storage-limitation principle).