Data Minimisation
Data minimisation is the principle that an organisation should only collect and keep the personal data it actually needs to achieve a specific purpose, and no more. In practice, this means identifying the minimum amount of information required and avoiding gathering or retaining anything beyond that. It is a core idea in data protection regimes, though how it is applied can vary by jurisdiction.
Data minimisation is a data protection principle requiring that personal data be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Under the UK GDPR, as interpreted by the ICO, controllers should identify and hold the minimum amount of personal data needed to fulfil a specified purpose, and no more; where services deliver distinct elements, the assessment of what is necessary may be made per element. The concept is increasingly reflected in privacy frameworks beyond the EU, sometimes framed in terms of collection, use, and transfer being 'reasonably necessary and proportionate,' but the precise formulation, thresholds, and enforcement expectations differ by regime and are subject to regulator interpretation. Application to a specific processing activity generally depends on the identified purpose and may require legal or professional advice.
Why it matters
Data minimisation is one of the foundational principles of modern data protection regimes, and its significance extends beyond mere regulatory box-ticking. By limiting the personal data an organisation collects and retains to what is genuinely necessary for a specified purpose, the principle directly reduces an organisation's risk surface. Data that is never collected cannot be breached, misused, or subject to an access or erasure request, so minimisation operates as both a compliance obligation and a practical risk-reduction measure.
Under the UK GDPR, as interpreted by the ICO, personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Failing to observe this principle can expose a controller to regulatory scrutiny, particularly where excessive collection or indefinite retention cannot be justified against a clearly identified purpose. The principle is increasingly reflected in privacy frameworks beyond the EU, sometimes framed in terms of collection, use, and transfer being 'reasonably necessary and proportionate,' though the precise formulation and enforcement expectations differ by regime.
For compliance teams, the principle matters because it shapes decisions across the data lifecycle, from designing intake forms to setting retention schedules. Because what counts as 'necessary' is tied to the identified purpose and is subject to regulator interpretation, minimisation is not a one-time exercise but an ongoing assessment that generally requires documentation and, in complex cases, legal or professional advice.
Who it's relevant to
Inside Data Minimisation
Common questions
Answers to the questions practitioners most commonly ask about Data Minimisation.

