Ace of minimization
You have found a piece of personal data that we can technically do without.
Threat |
|
You’re collecting data that isn’t relevant to the purpose of your activity; this is just exposing you to greater risk for no additional gain. Chapter 2, Article 5. 1 (c), Data Minimization, of the GDPR states that collection should be limited to what is necessary for the purpose it was intended. |
|
GDPR |
Chapter 2, Art. 5 – 1 (c) |
CCPA and CPRA |
CCPA 1798.100. General Duties of Businesses that Collect Personal Information (a)(1) |
OECD |
Part 2, 7. Collection Limitation Principle |
Mitigations |
|
... |