Data minimization
Minimization reduces privacy risk, security exposure, storage cost, and governance complexity. It should be applied before collection by questioning each field, limiting precision, shortening retention, restricting access, and removing data that no longer supports the purpose. Collecting data “just in case” makes future compliance and incident response harder and can reduce user trust.
What is Data minimization?
Data minimization is the practice of collecting, using, and retaining only the data that is necessary for a clearly defined purpose.
Why it matters
Minimization reduces privacy risk, security exposure, storage cost, and governance complexity. It should be applied before collection by questioning each field, limiting precision, shortening retention, restricting access, and removing data that no longer supports the purpose. Collecting data “just in case” makes future compliance and incident response harder and can reduce user trust.
Example
An analytics team records a broad region rather than precise location because regional reporting is sufficient for the product decision.