Ch.4 Managing Data, Information and Content Regulation 209 words

Data minimisation: the 'need-to-know' rule

Process only personal data that is adequate, relevant, and limited to what is necessary; the exam trap is confusing 'necessary' with 'useful'.

Audio

Listen to this page (beta)

Subtitles

Data minimisation under GDPR Article 5(1)(c) means you must collect only the personal data that is strictly needed for a specific purpose. For example, if you run a newsletter, an email address is enough—you do not need to ask for a passport scan or home address. The key contrast is between data that is essential for the task and data that is merely nice to have; the regulation demands the former, not the latter.

A common exam trick is to present a scenario where extra data seems helpful, like storing a customer's date of birth for a discount scheme when only their age range is needed. Remember that 'necessary' means you cannot achieve the purpose without it—if you can, the extra data is a violation. Another elimination hint: if a question lists multiple data fields, ask yourself which ones directly serve the stated goal; anything beyond that is likely non-compliant.

To test your understanding, imagine you are processing job applications: you need the applicant's name, contact details, and relevant qualifications, but not their marital status or hobbies. If you can mentally strip away any field and still complete the task, that field probably fails the minimisation test. This mental filter helps you spot violations quickly in any data-processing scenario.

Related flashcard

What does GDPR data minimisation require?

Process only personal data that is adequate, relevant, and limited to what is necessary.

Back to flashcard View all flashcards