Data Minimization
What is Data Minimization?
A privacy principle requiring organizations to collect and process only the minimum amount of personal data necessary to fulfill a specific stated purpose.
Terms that appear alongside data minimization
Each of these is named in at least one of the same controls as data minimization. The number is how many controls name both.
- consent 9 shared controls
- purpose limitation 5 shared controls
- data protection 3 shared controls
- encryption 2 shared controls
- pdpa 2 shared controls
- compliance 2 shared controls
Frameworks that govern data minimization
What the standards actually require on data minimization
Requirements naming data minimization across 6 standards, quoted from the control text.
Security Dimension 8 Privacy per X.805 Clause 6.8: Privacy provides protection of information that might be derived from the observation of network activities.
X805-Dim8-Privacy-Identification-Network-Activity-Personal-Information-Confidentiality · ITU-T X.805 Security Dimension 8 - Privacy + Identification of Network Activity + Personal Information Confidentiality + Subscriber Anonymity + Pseudonymity + Anti-Tracking + Location Privacy + Data Minimization + GDPR/CCPA Alignment →Data minimization requirements. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Collection & Consent.
BH-PDPL-05 · Data minimization requirements →Collection of personal data must be adequate, relevant and limited to what is reasonably necessary for the specified purposes.
COPA-1308-MINIMIZATION · Duty of Data Minimization →Controllers must limit collection to what is adequate, relevant and reasonably necessary for the disclosed purposes.
CTDPA-42-520-PURPLIMIT · Purpose Limitation and Data Minimization →Minimizing PII processing to what is adequate, relevant, and not excessive for the specified purposes
29100-6.4 · Data minimization →STRONGEST US STATE DATA MINIMIZATION STANDARD: Section 14-4607 limits controller collection of personal data to what is REASONABLY NECESSARY AND PROPORTIONATE to provide or maintain the specific product or service requested by the consumer (unique dual reasona...
MD-MODPA-Sensitive-Data-Health-Biometric-Section-14-4607-Reasonably-Necessary-Proportionate-Data-Minimization · Maryland MODPA Data Minimization + Sensitive + Health + Biometric + Section 14-4607 + Reasonably Necessary + Proportionate →Questions people ask about data minimization
What is Data Minimization?
Why is Data Minimization important for compliance?
Which compliance frameworks address Data Minimization?
Where can I learn more about Data Minimization?
See how Data Minimization applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.