Data minimisation

Data protection glossary · 1 minute read

Data minimisation is the principle that only as much personal data may be processed as is necessary for the purpose in question.

Content of the principle

Personal data must be adequate, relevant and limited to what is necessary in relation to the purpose. This applies to the amount of data, the extent of the processing, the retention period and the group of people with access.

The German term Datensparsamkeit (data economy) comes from the former BDSG and is today used largely as a synonym.

Practical examples

Forms only ask for mandatory information that is actually needed. Log data is truncated or deleted after a short time. Wherever possible, pseudonymised or anonymised data is used.

Art. 5(1)(c) GDPR
Principle of data minimisation.
Art. 25 GDPR
Implementation through data protection by design and by default.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.