Purpose Limitation: The Second GDPR Privacy Principle

Purpose limitation is one of the seven core principles of the General Data Protection Regulation (GDPR). It requires organisations to be clear about why they need personal data before they collect it and to ensure that information is not used in ways that are incompatible with those original purposes.

The principle exists to prevent organisations collecting personal data simply because it might be useful in the future. Instead, organisations must identify specific, legitimate reasons for processing personal data and ensure that any future use remains consistent with those reasons.

Purpose limitation is closely linked to several other GDPR principles, including lawfulness, fairness and transparency, data minimisation, and accountability. Together these principles help ensure individuals retain control over how their personal information is used.


The Text of the Principle

Article 5(1)(b) of the GDPR states that personal data must be:

“collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes.”

This requirement is commonly known as the principle of purpose limitation.

 

Periodic Table of the GDPR

 

What Is Purpose Limitation?

Purpose limitation requires organisations to identify and document why personal data are needed before they collect them.

In practice, this means organisations should be able to answer a simple question:

Why do we need this information?

The answer must be specific enough to explain how the information will be used and why the processing is necessary.

Purpose limitation prevents organisations from collecting personal data without a clear purpose and then deciding later how they might use it. Personal data should not be collected “just in case” it becomes useful in the future.

The principle also supports transparency. Individuals have a right to understand why their information is being collected and how it will be used. If an organisation does not understand its own purposes, it cannot explain them properly to data subjects.


What Does “Specified, Explicit and Legitimate” Mean?

The GDPR requires purposes to be specified, explicit, and legitimate.

Specified

The purpose must be clearly identified before personal data are collected.

For example:

  • Processing employee information to administer payroll.
  • Collecting customer details to fulfil an order.

Vague statements such as “business purposes” are unlikely to be sufficient.

Explicit

The purpose should be communicated clearly to individuals.

People should understand:

  • why information is being collected
  • how it will be used
  • who it may be shared with

This information is typically provided through privacy notices and other transparency measures.

Legitimate

The purpose must be lawful and appropriate.

Organisations cannot rely on purpose limitation to justify activities that are unlawful, unethical, or inconsistent with other GDPR requirements.


Why Purpose Limitation Matters

Without purpose limitation, organisations could reuse personal data for almost any activity once it had been collected.

This would undermine transparency and reduce individuals’ ability to understand or control how their information is used.

Purpose limitation helps to:

  • protect privacy
  • support transparency
  • reduce unnecessary processing
  • improve governance
  • strengthen trust between organisations and individuals

It also encourages organisations to think carefully about what information they genuinely need and why.


Purpose Limitation and Lawful Bases

Purpose limitation is closely linked to lawful processing.

Before processing personal data, organisations must identify both:

  • a specific purpose for processing
  • a lawful basis that permits that processing

The six lawful bases under the GDPR are:

  • consent
  • contract
  • legal obligation
  • vital interests
  • public task
  • legitimate interests

Identifying a lawful basis alone is not enough. Organisations must also ensure that personal data are used only for the purposes that have been specified and communicated to individuals.


Further Processing and Compatible Purposes

Organisations sometimes identify new uses for personal data after it has been collected.

The GDPR does not automatically prohibit this.

Instead, organisations must consider whether the new purpose is compatible with the original purpose for which the information was collected.

Factors that may be considered include:

  • the relationship between the original and new purposes
  • the context in which the data were collected
  • the nature of the personal data involved
  • the potential impact on individuals
  • any safeguards that have been implemented

Example of Compatible Processing

A retailer collects customer purchase information to fulfil orders and later analyses purchasing trends to improve stock management.

This may be compatible because the processing is closely related to the original purpose and is likely to align with customer expectations.

Example of Potentially Incompatible Processing

The same retailer sells customer information to third-party advertisers without informing customers.

This may be incompatible with the original purpose and could require a separate lawful basis and additional transparency measures.

Where organisations cannot demonstrate compatibility, they should reconsider the processing activity or identify an alternative lawful route before proceeding.


Purpose Limitation and Other GDPR Principles

Purpose limitation does not operate in isolation.

Lawfulness, Fairness and Transparency

Individuals should understand why their information is being collected and how it will be used.

Data Minimisation

Organisations should collect only the information required to achieve their stated purposes.

Storage Limitation

Personal data should not be retained indefinitely once the purpose has been fulfilled.

Accountability

Organisations must be able to demonstrate that they have identified purposes, assessed compatibility where necessary, and complied with their obligations.


Purpose Limitation in Practice

Online Shopping

An online retailer collects customer information to process orders and arrange delivery.

Using the same information for unrelated marketing activities without an appropriate lawful basis may breach the principle.

Healthcare Services

Healthcare providers process personal data to deliver treatment and maintain medical records.

Using that information for unrelated commercial activities would likely be incompatible with the original purpose.

Recruitment

Employers collect information to assess candidates and make recruitment decisions.

Using applicant information for unrelated marketing activities would generally fall outside the original purpose.


Common Mistakes

Collecting Data Before Defining the Purpose

Organisations should identify why they need personal data before collecting it.

Writing Vague Purpose Statements

Purposes should be specific and meaningful.

Assuming Data Can Be Reused Freely

The fact that information has already been collected does not mean it can be used for any purpose.

Failing to Assess New Processing Activities

New purposes should be assessed before processing begins.

Treating Consent as Open-Ended

Consent is linked to specific processing activities and specific purposes.


Demonstrating Compliance

Purpose limitation is closely linked to the accountability principle.

Organisations should be able to demonstrate:

  • why personal data are collected
  • what purposes have been identified
  • what lawful bases apply
  • whether compatibility assessments have been performed
  • how decisions have been documented

Useful evidence may include:

  • Records of Processing Activities (ROPAs)
  • privacy notices
  • Data Protection Impact Assessments (DPIAs)
  • legitimate interests assessments
  • policies and procedures

Many organisations are required to maintain Records of Processing Activities under Article 30 of the GDPR. Even where not strictly required, a ROPA is often one of the most useful tools for understanding and documenting processing activities.


Purpose Limitation and Privacy by Design

Purpose limitation works best when organisations identify their processing purposes during the design stage of a process, service, or system.

Understanding why information is needed before it is collected helps organisations:

  • reduce unnecessary processing
  • support transparency
  • improve compliance
  • reduce privacy risks

This is one of the reasons purpose limitation is closely linked to privacy by design and privacy by default.


Practical Compliance Checklist

Before collecting personal data, organisations should ask:

  • Why do we need this information?
  • Is the purpose specific and legitimate?
  • Have we explained the purpose clearly?
  • What lawful basis applies?
  • Could the purpose change in future?
  • How would we assess compatibility?
  • Can we demonstrate our reasoning?

If these questions cannot be answered confidently, further consideration may be required before processing begins.


Conclusion

Purpose limitation is one of the foundational principles of the GDPR. It requires organisations to identify why they need personal data before collecting it and to ensure that information is not used in ways that are incompatible with those original purposes.

By defining purposes clearly, communicating them transparently, and assessing any future processing carefully, organisations can improve compliance, strengthen governance, and build trust with the individuals whose information they process.

Ultimately, purpose limitation helps ensure that personal data are used because there is a genuine need to do so—not simply because the information is available.