Minimization
Minimization is the act of ensuring that the data being gathered is only what is needed for the purpose intended and what the subject consented to, without gathering any unnecessary additional information.
Article 5 of the GDPR, Principles relating to the processing of personal data, states in Item 1 the following: “Personal data shall be: (c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimization’).”
Figure 12.1: The fields we don’t require are redacted
In this chapter, we’re going to look at the privacy regulations that should be observed with regard to limiting data collected to only that necessary for the task at hand (minimization) by your systems.
As with the chapter on privacy in this chapter and the other TRIM chapters, the references used will be the GDPR, CCPA, CPRA, and OECD documents that have had a strong influence...