Data minimisation is the third of the seven core principles of the UK GDPR. It requires organisations to collect, use, share and retain only the personal data that are adequate, relevant and limited to what is necessary for the purposes for which they are processed.
At first glance, this may sound straightforward. However, data minimisation is one of the most misunderstood GDPR principles. Many organisations assume it simply means collecting less information. In reality, the principle is about collecting the right amount of information—enough to achieve a legitimate purpose, but no more.
Every piece of personal data an organisation collects creates responsibilities. Personal data must be protected, kept accurate, retained appropriately, made available to individuals exercising their rights, and ultimately disposed of securely. The more information an organisation holds, the greater the cost, complexity and risk associated with managing it.
Data minimisation encourages organisations to think carefully before collecting personal data by asking a simple question:
What personal data do we genuinely need to achieve this purpose?
By collecting only the information that is necessary, organisations reduce privacy risks, improve operational efficiency and demonstrate compliance with the GDPR.

The Text of the Principle
Article 5(1)(c) of the UK GDPR states that personal data must be:
“adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.”
This requirement is known as the data minimisation principle.
Although the wording is relatively brief, it has significant implications for how organisations design services, collect information and manage personal data throughout its lifecycle.
What Does Data Minimisation Mean?
Data minimisation requires organisations to process **no more—and no less—than the personal data needed to achieve a legitimate purpose.
The principle does not require organisations to collect the smallest possible amount of information if doing so would prevent them from delivering a service or meeting a legal obligation. Equally, it does not allow organisations to collect additional information simply because it may prove useful in the future.
The GDPR establishes three tests.
Adequate
Organisations should collect enough information to achieve the purpose of the processing.
For example, a payroll department requires sufficient information to pay employees accurately and meet tax obligations.
Collecting too little information may prevent the organisation from meeting its objectives.
Relevant
The information collected must relate directly to the purpose for which it is being processed.
For example, collecting an applicant’s qualifications during recruitment is relevant. Collecting information about unrelated hobbies or political opinions is unlikely to be.
Limited to What Is Necessary
Only personal data that are genuinely required should be collected and processed.
The key question is not:
“Could this information be useful?”
Instead, organisations should ask:
“Is this information necessary for the purpose we have identified?”
Why Data Minimisation Matters
Data minimisation benefits both organisations and the individuals whose information they process.
Better Protection of Privacy
The less personal data an organisation holds, the lower the risk that individuals’ privacy will be affected by inappropriate use, accidental disclosure or cyber attacks.
Collecting only necessary information also helps individuals understand why their information is needed and reassures them that the organisation is handling their data responsibly.
Reduced Security Risk
Every additional piece of personal data increases the potential impact of a data breach.
If unnecessary information is never collected, it cannot be lost, stolen, disclosed or misused.
Smaller datasets are also easier to secure and monitor.
Improved Efficiency
Collecting, storing and maintaining personal data requires time, technology and staff resources.
Reducing unnecessary information often results in:
- simpler forms
- faster processing
- lower storage costs
- improved record management
- reduced administrative burden
Better Data Quality
Collecting fewer data fields often improves accuracy.
People are more likely to complete shorter forms accurately, and organisations have fewer records to update and maintain over time.
Supporting Compliance
Data minimisation underpins many other GDPR obligations.
Organisations that collect only necessary information generally find it easier to:
- comply with subject access requests
- respond to erasure requests
- maintain accurate records
- apply retention schedules
- protect personal data appropriately
Data Minimisation Throughout the Information Lifecycle
Many organisations assume data minimisation only applies when collecting information.
In reality, it applies throughout the entire information lifecycle.
Collection
Only request information that is necessary for the identified purpose.
Avoid asking for information “just in case.”
Use
Use only the personal data required to complete the task.
Staff should avoid accessing information that is not relevant to their work.
Sharing
Share only the minimum information necessary with third parties or colleagues.
Ask whether every recipient genuinely needs every piece of information.
Access
Access to personal data should be based on business need.
Role-based permissions help ensure employees only access information required for their responsibilities.
Retention
As organisational needs change, review whether personal data remain necessary.
If information is no longer required, it should be deleted or anonymised in accordance with the organisation’s retention policy.
Data Minimisation and Other GDPR Principles
The GDPR principles are designed to work together.
Purpose Limitation
Knowing why information is being collected helps determine what information is genuinely necessary.
Purpose limitation therefore provides the foundation for effective data minimisation.
Lawfulness, Fairness and Transparency
Organisations should be open about what information they collect and why.
Collecting unnecessary personal data may undermine fairness and transparency.
Storage Limitation
Information that is no longer required should not continue to be retained.
Integrity and Confidentiality
Smaller datasets reduce security risks and make personal data easier to protect.
Accountability
Organisations should be able to explain and justify why every category of personal data is collected.
Data Minimisation and Privacy by Design
Data minimisation is one of the most practical ways of implementing privacy by design.
Before introducing a new process, service or technology, organisations should ask:
- What information do we actually need?
- Could we achieve the same objective with fewer data?
- Can some information be anonymised?
- Does every user need access to every data field?
- Have we designed forms and systems to collect only what is necessary?
Considering these questions during the design stage is much easier than trying to remove unnecessary information later.
Data Minimisation in Practice
Online Retail
An online retailer collects a customer’s name, delivery address and payment details to fulfil an order.
Requesting information such as marital status or employer would generally be unnecessary unless it serves a clearly defined purpose.
Recruitment
An employer collects contact details, qualifications and employment history to assess applicants.
Information about health or criminal convictions should normally only be requested where there is a lawful reason and genuine business need.
Healthcare
Healthcare providers often need extensive personal information to deliver safe and effective treatment.
However, clinicians should still ensure that only information relevant to diagnosis and treatment is collected and recorded.
Newsletter Sign-Up
A newsletter subscription generally requires only an email address.
Requesting a postal address, date of birth and telephone number may be difficult to justify unless there is a clear purpose for doing so.
Common Mistakes
Many organisations unintentionally collect more information than necessary.
Common mistakes include:
Collecting Information “Just in Case”
Future usefulness is rarely sufficient justification.
Reusing Old Forms
Forms often accumulate additional questions over time without anyone reviewing whether they remain necessary.
Asking for Information Too Early
Collect information only when it is genuinely required.
For example, sensitive information may not be needed until later stages of recruitment.
Giving Excessive Access
Not every employee requires access to every record.
Access controls should reflect business need.
Assuming Storage Is Cheap
Although digital storage costs have fallen, the cost of securing, maintaining and governing personal data remains significant.
Demonstrating Compliance
Data minimisation is closely linked to the accountability principle.
Organisations should be able to demonstrate that they have considered what personal data are genuinely required.
Useful evidence may include:
- Records of Processing Activities (ROPAs)
- data flow maps
- Data Protection Impact Assessments (DPIAs)
- privacy notices
- information asset registers
- system specifications
- form reviews
- retention schedules
- access control reviews
Periodic reviews of forms, databases and business processes can help identify opportunities to reduce unnecessary data collection.
Practical Data Minimisation Checklist
Before collecting personal data, ask:
- Why do we need this information?
- Is every data field necessary?
- Could we achieve the same objective with less information?
- Are we collecting anything “just in case”?
- Who genuinely needs access?
- How long will the information be needed?
- Can we justify every item of personal data we collect?
If these questions cannot be answered confidently, the organisation should reconsider its approach before processing begins.
Conclusion
Data minimisation is one of the cornerstones of responsible data protection. It encourages organisations to collect, use and retain only the personal data they genuinely need, reducing privacy risks while improving efficiency and strengthening trust.
Importantly, data minimisation is not about collecting as little information as possible. It is about collecting the right information for clearly defined purposes and ensuring that personal data continue to be managed proportionately throughout their lifecycle.
Organisations that regularly review the personal data they collect, challenge unnecessary processing and embed data minimisation into the design of their systems and processes will not only strengthen GDPR compliance but also improve information governance, reduce operational costs and build greater confidence among customers, employees and other stakeholders.
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: