Skip to content

Data Minimisation

What is Data Minimisation?

The principle that organisations should collect and process only the personal data that is strictly necessary for the specified purpose. Data minimisation is a core principle of GDPR (Article 5) and most modern privacy regulations.

Privacy

Each of these is named in at least one of the same controls as data minimisation. The number is how many controls name both.

What the standards actually require on data minimisation

Requirements naming data minimisation across 6 standards, quoted from the control text.

Standard 3 per Section 21 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be adequate + relevant + and necessary in relation to the purposes for which they are processed (Data Minimisation Principle).

JM-DPA2020-Standard3-Adequacy-Relevance-Necessity-Sec21-Data-Minimisation-No-Excess-Processing · Jamaica DPA 2020 Standard 3 - Adequacy + Relevance + Necessity + Section 21 + Data Minimisation + No Excess Processing + Proportionality + Privacy by Default + Field-Level Restraint + Granular Permissions
India DPDP Act2 controls

Sections 4-7 of DPDP Act 2023 establish the foundational lawful processing framework. Section 4 Grounds for Processing Personal Data: a person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful...

DPDP-Scope-2023-Sec5-NoticeConsent-LawfulProcessing-PurposeLimitation-DataMinimisation · DPDP Act Sections 4-7 + Notice + Consent + Lawful Processing + Purpose Limitation + Data Minimisation + Legitimate Uses + Sec 4 Lawful Use + Sec 5 Notice + Sec 6 Consent + Sec 7 Legitimate Uses

Articles 16-19 of UU PDP establish the foundational lawful processing framework. Article 16: lawful basis for processing personal data limited to (a) explicit valid consent of the Data Subject for one or more specific purposes;

IDPdp-LawfulBasis-Notice-Consent-PurposeLimitation-DataMinimisation-Art16to19-ExplicitConsent · Indonesia PDP Articles 16-19 + Lawful Basis + Notice + Explicit Consent + Purpose Limitation + Data Minimisation + 6 Lawful Bases + Withdrawal + Transparency

Apply data minimisation + purpose limitation + retention + secure deletion per Oman PDPL Articles 7 + 9 + 10. Data minimisation requires collecting only personal data necessary for the documented lawful purpose + with periodic review of necessity.

OMANPDPL-3 · Data Minimisation, Purpose Limitation, Retention, Secure Deletion

Apply data minimisation + purpose limitation + retention per Oregon OCPA per ORS 646A.578(2). Data Minimisation and Purpose Limitation requires (a) limiting collection of personal data to what is adequate + relevant + and reasonably necessary in relation to sp...

OREGONCPA-6 · Data Minimisation, Purpose Limitation, Retention

Per AADC: high-privacy default settings + data minimisation + no sharing without compelling reason.

UKAADC-3 · Default Settings, Data Minimisation, Sharing

Questions people ask about data minimisation

What is Data Minimisation?
The principle that organisations should collect and process only the personal data that is strictly necessary for the specified purpose. Data minimisation is a core principle of GDPR (Article 5) and most modern privacy regulations.
Why is Data Minimisation important for compliance?
Data Minimisation is a key concept in Privacy. Understanding data minimisation helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Data Minimisation?
Data Minimisation appears in the requirement text of Jamaica Data Protection Act 2020, India DPDP Act, Indonesia PDP Law, Oman Personal Data Protection Law (Royal Decree 6/2022), Oregon Consumer Privacy Act. Across these standards we have identified 14 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Data Minimisation?
Explore our compliance framework pages to see how data minimisation applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Data Minimisation applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.