DAT-007 Data Minimisation and Purpose Limitation
Description
Only the minimum personal data required to fulfil a specific, documented purpose is collected and retained. Data is not used for purposes incompatible with those disclosed at collection. Processing purposes are reviewed when product capabilities change. Where personal data is to be used for a purpose that was not disclosed at collection, a compatibility assessment is recorded before that processing starts, covering the link between the original and the new purpose, the context of collection and the relationship with the individual, the nature of the data including any special category or criminal offence data, the consequences for individuals and the safeguards applied.
Rationale
Collecting more data than necessary increases breach impact and creates regulatory exposure, and purpose limitation prevents data being repurposed in ways that undermine individual rights. The compatibility assessment is the step teams skip: the conclusion that a new purpose is compatible gets made informally and never written down, so there is nothing to review when the purpose is challenged. Training a model on data collected for service delivery is the case this clause is most often needed for.
Applicability (9 profiles)
Framework Mappings (11)
| DSP-07 | Data Protection by Design and Default | informative |
| DSP-12 | Limitation of Purpose in Personal Data Processing | full |
| DSP-07 | Data Protection by Design and Default | informative |
| DSP-12 | Limitation of Purpose in Personal Data Processing | full |
| GDPR-Art.5.1b | Purpose Limitation | full |
| GDPR-Art.5.1c | Data Minimisation | full |
| GDPR-Art.6.4 | Compatibility Test for Further Processing | full |
| PT-2 | Authority to Process Personally Identifiable Information | informative |
| PT-3 | Personally Identifiable Information Processing Purposes | full |
| P3.1 | Collection of Personal Information | full |
| P4.1 | Use of Personal Information | full |
Evidence (3)
Data minimisation and purpose limitation policy or procedure documenting the requirement to collect only necessary personal data and restrict use to declared purposes.
Example: Data Minimisation Procedure (Confluence), approved by DPO, specifying the privacy-by-design review gate for new data collection fields, the requirement to document collection justification, and the process for reviewing purposes when product capabilities change
Test: Request the data minimisation policy or procedure. Verify: (1) explicitly prohibits collection of personal data without a documented purpose, (2) includes a review or sign-off step when new data fields are added to products, (3) defines the process for reviewing and updating purposes when product features change, (4) is approved by the DPO or equivalent authority within 24 months.
Completed data minimisation reviews or privacy design review records showing that data collection fields were evaluated against necessity for specific product features.
Example: Privacy design review sign-off tickets (Jira) for the last 3 significant product releases, each showing: data fields collected, stated purpose, DPO or privacy engineer sign-off, and outcome (approved / fields removed)
Test: Request the design review or privacy sign-off records for the last three product releases that changed personal data collection. Verify: (1) a review is recorded for each of those releases, (2) every data field added in those releases carries a recorded processing purpose, (3) every field added carries the name of the privacy approver who accepted it, (4) a field added without a recorded purpose is either removed or carries a recorded exception with an expiry date, (5) each review is dated before the release it covers.
Compatibility assessments recorded for each use of personal data for a purpose that was not disclosed at collection.
Example: Compatibility assessment, model training on support transcripts, 2026-04-22
Test: Request the compatibility assessments. Verify: (1) an assessment exists for every further-processing use identified in the records of processing, (2) each assessment is dated before the further processing began, (3) each addresses the link between purposes, the collection context and the relationship with the individual, the nature of the data, the consequences for individuals and the safeguards, rather than recording a conclusion alone, (4) where an assessment concluded the new purpose was incompatible, the processing did not proceed or a separate lawful basis is recorded, (5) uses relying on consent or on a statutory route are identified as such rather than assessed under the wrong test.
Questions (3)
Does your organisation have a documented policy or procedure requiring that only the minimum personal data necessary for a specific, documented purpose is collected?
The policy should explicitly prohibit collection of personal data without a documented purpose and require review when product capabilities change. It should be approved by the DPO or equivalent authority.
How does your organisation enforce data minimisation and purpose limitation in practice?
A mandatory review gate in the development process (e.g. a privacy design review ticket) is the most effective control. Selecting multiple overlapping mechanisms indicates a mature programme.
Is a compatibility assessment recorded before personal data is used for a purpose that was not disclosed when it was collected?
The assessment covers the link between the old and new purposes, the context of collection, the nature of the data, the consequences for individuals and the safeguards applied. Answer yes only where the assessment is written down and dated before the new processing started. A decision recorded in a meeting note without those five elements is not one.