What is “data minimization” under the GDPR?

The GDPR's data minimization principle requires organizations to process only the personal data that is adequate, relevant, and necessary for a specific purpose. Learn how to determine what is truly necessary, when additional data may be justified, and how this principle applies in practice.

What is “data minimization” under the GDPR?
ChatGPT modified from - IABI — Image from page 540 of “St. Nicholas [serial]” (1873)

There are seven basic data protection principles under EU data protection law. The third principle is the principle of “data minimization” (GDPR Article 5 (1) (c)).


GDPR Article 5

“1. Personal data shall be:

(c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimisation)”


The data minimization principle requires entities to process only ‘adequate, relevant and limited’ personal data that is ‘necessary’. EU data protection law does not define what ‘adequate, relevant and limited’ means but states that the assessment of what is ‘necessary’ must be done in relation to the purposes for processing.

Because the assessment of what data is needed should be based on the purposes of the processing itself, a controller or processor should never have more data than what it needs to achieve the purposes of the processing.

Example: A debt collection agency is engaged to find a particular debtor. It collects information on several people with a similar name to the debtor. During the enquiry some of these people are discounted. The agency should delete most of those records, keeping only the minimum data needed to form a basic record of a person they removed from their search. It is appropriate to keep this small amount of information so that these people are not contacted again about debts which do not belong to them.

Example: A recruitment agency places workers in a variety of jobs. It sends applicants a general questionnaire, which includes specific questions about health conditions that are only relevant to particular manual occupations. It would be irrelevant and excessive to obtain such information from an individual who applied for an office job.

Example: An employer holds details of the blood groups of some employees. These employees do hazardous work and the information is needed in case of accident. The employer has safety procedures to help prevent accidents, so the blood group data may never be needed, however it still needs to hold this information in case of emergency. If the employer holds the blood groups of the rest of the workforce, though, such information is likely to be irrelevant and excessive as they do not engage in the same hazardous work.

If achieving the purpose of the processing is not possible, because the personal data is insufficient, then the data is not ‘adequate’ and additional collection may be required. Data may also be inadequate if making decisions about someone is based on an incomplete understanding of the facts. In particular, if an individual asks that the information be supplemented (right to rectification), this could indicate that the data might be inadequate for the purpose.

Example: A group of individuals set up a club. At the outset the club has only a handful of members, who all know each other, and the club’s activities are administered using only basic information about the members’ names and email addresses. The club proves to be very popular and its membership grows rapidly. It becomes necessary to collect additional information about members so that the club can identify them properly, and so that it can keep track of their membership status, subscription payments etc.

A record of an opinion is not necessarily inadequate or irrelevant just because the individual disagrees with it or thinks it has not included information they think is important.

However, in order to be adequate, the record should make clear that it is opinion rather than fact. The record of the opinion (or of the context it is held in) should also contain enough information to enable a reader to interpret it correctly (i.e. state the date and the author’s name and position).

Example: A GP’s record may hold only a letter from a consultant and it will be the hospital file that contains greater detail. In this case, the record of the consultant’s opinion should contain enough information to enable detailed records to be traced.

ICO Checklist

The Information Commissioner’s Office website includes a helpful Checklist that summarizes this principle:

Consequences of non-compliance

Failure to comply with data protection principles may lead to substantial fines. Article 83(5)(a) of GDPR states that infringements of the basic principles for processing personal data are subject to the highest tier of administrative fines. This could mean a fine of up to €20 million, or 4% of your total worldwide annual turnover, whichever is higher.

NOTES:

Recitals - (39) Principles of Data Processing (74) Responsibility and Liability of the Controller

Additional relevant provisions include Article 16 (right to rectification) and Article 17 (right to erasure)

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe