

The age-old idiom “less is more” is gaining traction in the privacy sphere. Data minimisation is a thing and is quickly rising to the top of lots of privacy ‘must-do’ lists. And because it brings significant business benefits, like risk mitigation, better customer relations, and decreased costs of compliance, we aren’t surprised to see increasing interest. But many businesses aren’t accessing these benefits, opting to collect more data than ever and relying on more complex privacy policies and disclosures instead of genuine attempts to minimise data collection.
This article will outline what data minimisation looks like in practice and why it’s a good idea plus some tips on how your business can achieve it.
Data minimisation is the practice of limiting the collection, processing, and storing of all information but especially personal information, limiting to that which is adequate, relevant and necessary to accomplishing the specified purpose.
This means you should understand what you want to do with the data you are collecting and then collect only the data that you need to achieve that purpose – no more, no less. And you shouldn’t keep it once that purpose has been achieved.
Data minimisation became part of data protection law when it was included in Article 5(1)(c) of Europe’s General Data Protection Regulation (GDPR). This Article requires that personal data collected be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed”. The principle is the same under the UK’s law.
Although a thread that has traditionally be included in privacy principles, it was given it’s own special place as a stand-alone principle, in recognition of the importance of the concept.
For example, in Australia, APP 3 (which still uses the more traditional privacy principles), refers to limited collection, and requires covered entities to only collect personal information when it is “reasonably neccessary” for the entity’s functions or activities.
The OAIC provides the following examples of where the collection of personal information was not reasonably necessary:
The Australian Privacy Act Review proposed a number of changes relating to data retention, including:
On the topic of data minimisation more broadly, the Privacy Act Review report highlighted the importance of data minimisation but did not go as far as introducing a specific data minimisation principle.
The more information you hold about a person, the more identifiable they are – and the greater the risk to the individual in the event of a data breach. By minimising the amount of personal information data your business holds, you minimise risk of damage to your reputation from a data breach and your legal risk too.
Some other compelling reasons for adopting a more minimalistic approach to data collection:
Your company should make business decisions with data minimisation in mind. In practice, this requires you to ask a series of questions before you start to collect personal information:
The earlier in the product development or project cycle these questions are asked, the better.
Bear in mind that data minimisation comes with significant business benefits. You aren’t collecting and storing data without purpose – which can result in an oversupply of data and reduced access to valuable insights. Instead, you’re collecting the data you need and will use. This starting point allows you to really focus on data points that will move the needle for your business.
We regularly see examples of companies collecting low value and high risk data. This category of data includes any personal or sensitive information that offers very little advantage for businesses, but is given at a high risk to the customer. For example:
In every case, it’s helpful to ask “is there a way I can achieve the same means without collecting personal information?”. If the answer is yes, opt to not collect it.
Signal is a free, privacy-focused messaging and video chat app. Instead of collecting data or pushing ads, it relies on donations from users to fund the app.
The app only requires individuals to provide their phone number to sign up. Users can voluntarily add their name and photograph if they wish.
Contrast this with the Meta-owned Whatsapp messaging service, which requires users to share information with the other Meta companies. The categories of data Whatsapp shares with Meta include (but aren’t limited to) your phone number, transaction data, information about how you interact with businesses, and your IP address.
If you can achieve what you need to achieve with de-identified data, you should implement processes to do so at the earliest possible stage.
You might consider some of the following deidentification techniques: anonymisation, pseudonymisation, generalisation, or differential privacy.
A taxi company in Denmark was fined under the GDPR because it retained customer phone numbers for longer than the specified period. The company had deleted other personal information but retained the phone numbers because it used them as an account identifier. The fine was levied (partially) on the basis that the phone number could easily be substituted with another account number and achieve the same purpose.
If you’ve adopted lazy data management because de-identifying the data you hold is difficult, consider updating your processes.
The longer you store data, the less likely it is that the data is accurate and the more likely it is that your customers will be upset if that data is breached. Plus you will have breached your Privacy Act obligation to ensure it is accurate and up-to-date.
Some Examples of Data Retention Gone Wrong
Your company should implement policies and processes to ensure that data is stored only while it is needed and either deleted, reduced, or updated at regular intervals.
Your business can benefit from reducing the amount of data you hold and creating a culture of data minimisation. Privacy108 will work with you to design and implement programs to uplift your privacy maturity including governance, policies, training and privacy assessments.
We use Privacy by Design Principles when developing your business privacy program:
Privacy by design principles
Contact us to discover how this can benefit your business.
"*" indicates required fieldsResource - Donor Data & Privacy eBook
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.