What is “data minimization” under EU Data Protection Law?

Golden Data Law
Golden Data
Published in
4 min readJan 22, 2019

--

IABI — Image from page 540 of “St. Nicholas [serial]” (1873)

There are seven basic data protection principles under EU data protection law. The principles lie at the heart of the law and, although they don’t give hard and fast rules, they embody the spirit of the regulatory framework. Therefore, compliance with the principles is a fundamental building block to any good data protection practice. The seven principles are:

  1. Lawfulness, fairness and transparency
  2. Purpose limitation
  3. Data minimization
  4. Accuracy
  5. Storage limitation
  6. Integrity and confidentiality (security)
  7. Accountability

The third principle is the principle of “data minimization” (GDPR Article 5 (1) (c)).

GDPR Article 5

“1. Personal data shall be:

(c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimisation)”

The principle of ‘data minimization’

The data minimization principle requires entities to process only ‘adequate, relevant and limited’…

--

--

Golden Data Law
Golden Data

Golden Data Law is a mission driven benefit corporation that provides legal services to the not-for-profit community and to governmental agencies.