concept

Data Minimisation

Collecting and retaining only the personal data actually necessary for the stated purpose, treated as an architectural constraint rather than a policy statement.

privacygdprdesign

Minimisation is the cheapest privacy control that exists, because data you never collected cannot be breached, cannot be misused, cannot be subject to an access request and costs nothing to store or delete.

It runs against a strong default instinct in engineering and analytics — capture everything, decide later — which produces schemas full of fields nobody uses and event streams recording every interaction against an identifiable user. The cost of that instinct is invisible until an incident, at which point the breach notification enumerates it precisely.

The architectural expressions of the principle are concrete. Do not log full request bodies on endpoints that carry personal data. Do not copy the whole customer table into the analytics environment when three columns are needed. Store a derived flag rather than the underlying sensitive attribute where the flag is what gets used — an age bracket rather than a date of birth, a verification result rather than the document. Truncate or hash identifiers in telemetry.

The most common violation is not a deliberate decision; it is a default. Debug logging left on, SELECT * in a pipeline, a full production copy in a test environment. Each was convenient, and each expands the estate's exposure permanently, because data that arrives somewhere tends to stay.