Law & regulation

Data minimisation

The principle of collecting and keeping only the data strictly necessary, and the best answer to the impossibility of erasing.

Definition

Data minimisation is a GDPR principle according to which an organisation must collect and keep only the data strictly necessary for the purpose pursued. Faced with the right to be forgotten made approximate by the absorption of data into models, it constitutes the most solid answer, shifted upstream, for the best protection against an erasure request remains never having absorbed the data that would be its object. It is accompanied by pseudonymisation, aggregation and privacy-preserving learning techniques that limit the personal footprint in the model. It reflects a shift of data governance, from content toward life cycle, where compliance is conceived from the origin rather than as a capacity to delete after the fact.

Example

Rather than training its model on named data it may later have to erase, an insurer aggregates and pseudonymises them upstream, reducing its exposure to the right to be forgotten.

Related terms
Also known as

minimisation, sobriété des données, data minimisation