Data Minimization
Data minimization is a privacy principle holding that an organization should only collect, use, and keep the personal data that is genuinely necessary to accomplish a specific purpose. The goal is to avoid gathering or retaining more information than needed, which helps respect individual privacy and reduces the potential harm if a data breach occurs. It is a long-standing concept that is becoming more common across jurisdictions and subject to increasing enforcement.
As commonly defined, data minimization is the principle that entities should limit the collection, use, retention, and transfer of personal data to what is 'reasonably necessary and proportionate' to a stated purpose. In practice it constrains data handling across the lifecycle, favoring purpose limitation and retention limits so that data not required for the defined objective is not gathered or is deleted once no longer needed. The specific legal formulation and scope vary by jurisdiction and framework; the sources here indicate it is an increasingly global concept with rising enforcement, but this entry does not resolve how any particular statute defines or enforces the requirement. Out of scope: sector-specific or jurisdiction-specific obligations, and the precise legal tests applied in individual regimes.
Why it matters
Data minimization directly shapes an organization's exposure surface: the personal data an entity never collects, or deletes once it is no longer needed, is data that cannot be exposed in a breach, misused, or repurposed beyond its original justification. As a privacy principle, it links respect for individual privacy to concrete risk reduction, since limiting collection and retention narrows the volume of sensitive information that could be compromised. It is a long-standing concept, but the sources indicate it is becoming more common across jurisdictions and is subject to increasing enforcement, which raises the practical stakes for organizations that over-collect or retain data by default.
For AI and analytics contexts, data minimization is often in tension with the incentive to gather and keep as much data as possible for future modeling or feature development. Because the principle favors purpose limitation and retention limits, organizations that accumulate data speculatively may find that holdings are harder to defend against a minimization standard. It is worth noting that the specific legal formulation and enforcement tests vary by jurisdiction and framework; this entry does not resolve how any particular statute defines or applies the requirement, and organizations should not treat any single definition as authoritative across all regimes.
Who it's relevant to
Inside Data Minimization
Common questions
Answers to the questions practitioners most commonly ask about Data Minimization.