Data Minimisation: The Third GDPR Privacy Principle

Data minimisation is the third of the seven core principles of the UK GDPR. It requires organisations to collect, use, share and retain only the personal data that are adequate, relevant and limited to what is necessary for the purposes for which they are processed.

At first glance, this may sound straightforward. However, data minimisation is one of the most misunderstood GDPR principles. Many organisations assume it simply means collecting less information. In reality, the principle is about collecting the right amount of information—enough to achieve a legitimate purpose, but no more.

Every piece of personal data an organisation collects creates responsibilities. Personal data must be protected, kept accurate, retained appropriately, made available to individuals exercising their rights, and ultimately disposed of securely. The more information an organisation holds, the greater the cost, complexity and risk associated with managing it.

Data minimisation encourages organisations to think carefully before collecting personal data by asking a simple question:

What personal data do we genuinely need to achieve this purpose?

By collecting only the information that is necessary, organisations reduce privacy risks, improve operational efficiency and demonstrate compliance with the GDPR.

 

Periodic Table of the GDPR

 

The Text of the Principle

Article 5(1)(c) of the UK GDPR states that personal data must be:

“adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.”

This requirement is known as the data minimisation principle.

Although the wording is relatively brief, it has significant implications for how organisations design services, collect information and manage personal data throughout its lifecycle.

What Does Data Minimisation Mean?

Data minimisation requires organisations to process **no more—and no less—than the personal data needed to achieve a legitimate purpose.

The principle does not require organisations to collect the smallest possible amount of information if doing so would prevent them from delivering a service or meeting a legal obligation. Equally, it does not allow organisations to collect additional information simply because it may prove useful in the future.

The GDPR establishes three tests.

Adequate

Organisations should collect enough information to achieve the purpose of the processing.

For example, a payroll department requires sufficient information to pay employees accurately and meet tax obligations.

Collecting too little information may prevent the organisation from meeting its objectives.

Relevant

The information collected must relate directly to the purpose for which it is being processed.

For example, collecting an applicant’s qualifications during recruitment is relevant. Collecting information about unrelated hobbies or political opinions is unlikely to be.

Limited to What Is Necessary

Only personal data that are genuinely required should be collected and processed.

The key question is not:

“Could this information be useful?”

Instead, organisations should ask:

“Is this information necessary for the purpose we have identified?”

Why Data Minimisation Matters

Data minimisation benefits both organisations and the individuals whose information they process.

Better Protection of Privacy

The less personal data an organisation holds, the lower the risk that individuals’ privacy will be affected by inappropriate use, accidental disclosure or cyber attacks.

Collecting only necessary information also helps individuals understand why their information is needed and reassures them that the organisation is handling their data responsibly.

Reduced Security Risk

Every additional piece of personal data increases the potential impact of a data breach.

If unnecessary information is never collected, it cannot be lost, stolen, disclosed or misused.

Smaller datasets are also easier to secure and monitor.

Improved Efficiency

Collecting, storing and maintaining personal data requires time, technology and staff resources.

Reducing unnecessary information often results in:

  • simpler forms
  • faster processing
  • lower storage costs
  • improved record management
  • reduced administrative burden

Better Data Quality

Collecting fewer data fields often improves accuracy.

People are more likely to complete shorter forms accurately, and organisations have fewer records to update and maintain over time.

Supporting Compliance

Data minimisation underpins many other GDPR obligations.

Organisations that collect only necessary information generally find it easier to:

  • comply with subject access requests
  • respond to erasure requests
  • maintain accurate records
  • apply retention schedules
  • protect personal data appropriately

Data Minimisation Throughout the Information Lifecycle

Many organisations assume data minimisation only applies when collecting information.

In reality, it applies throughout the entire information lifecycle.

Collection

Only request information that is necessary for the identified purpose.

Avoid asking for information “just in case.”

Use

Use only the personal data required to complete the task.

Staff should avoid accessing information that is not relevant to their work.

Sharing

Share only the minimum information necessary with third parties or colleagues.

Ask whether every recipient genuinely needs every piece of information.

Access

Access to personal data should be based on business need.

Role-based permissions help ensure employees only access information required for their responsibilities.

Retention

As organisational needs change, review whether personal data remain necessary.

If information is no longer required, it should be deleted or anonymised in accordance with the organisation’s retention policy.

Data Minimisation and Other GDPR Principles

The GDPR principles are designed to work together.

Purpose Limitation

Knowing why information is being collected helps determine what information is genuinely necessary.

Purpose limitation therefore provides the foundation for effective data minimisation.

Lawfulness, Fairness and Transparency

Organisations should be open about what information they collect and why.

Collecting unnecessary personal data may undermine fairness and transparency.

Storage Limitation

Information that is no longer required should not continue to be retained.

Integrity and Confidentiality

Smaller datasets reduce security risks and make personal data easier to protect.

Accountability

Organisations should be able to explain and justify why every category of personal data is collected.

Data Minimisation and Privacy by Design

Data minimisation is one of the most practical ways of implementing privacy by design.

Before introducing a new process, service or technology, organisations should ask:

  • What information do we actually need?
  • Could we achieve the same objective with fewer data?
  • Can some information be anonymised?
  • Does every user need access to every data field?
  • Have we designed forms and systems to collect only what is necessary?

Considering these questions during the design stage is much easier than trying to remove unnecessary information later.

Data Minimisation in Practice

Online Retail

An online retailer collects a customer’s name, delivery address and payment details to fulfil an order.

Requesting information such as marital status or employer would generally be unnecessary unless it serves a clearly defined purpose.

Recruitment

An employer collects contact details, qualifications and employment history to assess applicants.

Information about health or criminal convictions should normally only be requested where there is a lawful reason and genuine business need.

Healthcare

Healthcare providers often need extensive personal information to deliver safe and effective treatment.

However, clinicians should still ensure that only information relevant to diagnosis and treatment is collected and recorded.

Newsletter Sign-Up

A newsletter subscription generally requires only an email address.

Requesting a postal address, date of birth and telephone number may be difficult to justify unless there is a clear purpose for doing so.

Common Mistakes

Many organisations unintentionally collect more information than necessary.

Common mistakes include:

Collecting Information “Just in Case”

Future usefulness is rarely sufficient justification.

Reusing Old Forms

Forms often accumulate additional questions over time without anyone reviewing whether they remain necessary.

Asking for Information Too Early

Collect information only when it is genuinely required.

For example, sensitive information may not be needed until later stages of recruitment.

Giving Excessive Access

Not every employee requires access to every record.

Access controls should reflect business need.

Assuming Storage Is Cheap

Although digital storage costs have fallen, the cost of securing, maintaining and governing personal data remains significant.

Demonstrating Compliance

Data minimisation is closely linked to the accountability principle.

Organisations should be able to demonstrate that they have considered what personal data are genuinely required.

Useful evidence may include:

  • Records of Processing Activities (ROPAs)
  • data flow maps
  • Data Protection Impact Assessments (DPIAs)
  • privacy notices
  • information asset registers
  • system specifications
  • form reviews
  • retention schedules
  • access control reviews

Periodic reviews of forms, databases and business processes can help identify opportunities to reduce unnecessary data collection.

Practical Data Minimisation Checklist

Before collecting personal data, ask:

  • Why do we need this information?
  • Is every data field necessary?
  • Could we achieve the same objective with less information?
  • Are we collecting anything “just in case”?
  • Who genuinely needs access?
  • How long will the information be needed?
  • Can we justify every item of personal data we collect?

If these questions cannot be answered confidently, the organisation should reconsider its approach before processing begins.

Conclusion

Data minimisation is one of the cornerstones of responsible data protection. It encourages organisations to collect, use and retain only the personal data they genuinely need, reducing privacy risks while improving efficiency and strengthening trust.

Importantly, data minimisation is not about collecting as little information as possible. It is about collecting the right information for clearly defined purposes and ensuring that personal data continue to be managed proportionately throughout their lifecycle.

Organisations that regularly review the personal data they collect, challenge unnecessary processing and embed data minimisation into the design of their systems and processes will not only strengthen GDPR compliance but also improve information governance, reduce operational costs and build greater confidence among customers, employees and other stakeholders.