Sustainability Language
Data Minimisation
The principle that personal data collected and processed should be adequate, relevant and limited to what is necessary for a specified purpose.
Expert review openNo editor-accepted expert review yetDefinition
The principle that personal data collected and processed should be adequate, relevant and limited to what is necessary for a specified purpose.
Overview
“The safest unnecessary data is the data never collected. ”
Data collection expands easily. A survey form has space for another question. A platform can store another identifier. A project team imagines that a field might be useful later, and the cost of adding it appears small. The cost becomes visible only when people must answer, systems must protect the information and the organisation must justify why it exists.
Article 5(1)(c) of the General Data Protection Regulation requires personal data to be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Data minimisation is not a preference for incomplete evidence. It is a discipline that connects every field, level of precision and retention decision to a real and specified need. Purpose comes first.
An organisation mapping farm boundaries for deforestation assessment may need location data.
It does not automatically need the national identity number, ethnicity, health history and names of every household member. Collecting them because the system can, because another project once requested them or because they may be useful later is not the same as demonstrating necessity. Adequacy also matters. Minimisation does not mean collecting too little to make a fair decision.
A programme evaluating gendered access to finance may need sex-disaggregated data and evidence about control of accounts. Removing relevant fields can make exclusion invisible. The principle asks for enough information to serve the purpose, no more and no less. Precision should be tested. Exact farm coordinates may be necessary for a plot-level land-use check.
A regional planning analysis may need only an aggregated grid or municipality. Date of birth may be unnecessary where an age band meets the purpose.
Reducing granularity can preserve analytical value while lowering re-identification and misuse risk. Collection burden is a sustainability issue. Farmers and workers repeatedly provide the same information to buyers, schemes and projects, often without payment or explanation. Long questionnaires consume time and can damage trust.
Minimisation should include reuse of reliable existing data where lawful and appropriate, rather than shifting the cost of organisational fragmentation to respondents. Default fields deserve scrutiny. Software vendors may offer standard profiles containing phone, email, address, gender, age, identification and location. A default is not a purpose.
Privacy by design requires organisations to configure systems around their actual need rather than accept maximum collection as the convenient setting. Derived data also count. Risk scores, inferred household status and behavioural profiles can affect people even where the original input seems ordinary.
Minimisation asks whether the inference is necessary, whether a less intrusive method exists and whether the result is retained or shared beyond the decision for which it was created. Retention is governed by a separate storage-limitation principle but follows the same logic. Data necessary during enrolment may not remain necessary after a contract ends.
Keeping every version indefinitely can increase breach and discrimination risk. Retention schedules should reflect purpose, legal obligations and legitimate evidence needs. Minimisation can improve quality.
Shorter instruments reduce fatigue, missing responses and inconsistent interpretation. Fewer critical fields make validation and stewardship more realistic. The objective is not simply a smaller database; it is a more intentional one. The discipline is to require a field-level answer. What purpose does this data element serve? Why is this level of detail necessary?
Who uses it, for how long and what happens if it is not collected? If no accountable person can answer, the field should not survive by habit.
Practical application
Create a data inventory linking each personal-data field to purpose, legal basis, necessity, users, precision and retention. Remove duplicate and speculative collection. Use aggregation, ranges, optional fields or local processing where they meet the decision need. Review forms and system defaults with field teams and data subjects. Test whether fewer fields improve completion and quality.
Reassess necessity when purposes change, and prevent downstream teams from reusing data merely because access is technically possible.
Why it matters
Unnecessary data create burden, privacy risk, security cost and opportunities for function creep. Minimisation protects people and improves focus by ensuring that evidence collection remains proportionate to the decision.
Common misconception
Data minimisation is often described as collecting the smallest possible dataset. The requirement is to collect data that are adequate and relevant while limiting them to what is necessary for the specified purpose.
Connections
Consent and Legitimate Interest address legal bases, but neither removes the minimisation obligation. Privacy by Design implements the principle in system architecture. Data Governance and retention controls determine whether unnecessary fields remain accessible or are deleted.
A question worth asking
Which personal-data field in your current farmer or worker dataset would be hardest to justify if the person asked exactly why it was necessary for the decision being made?
Selected references
European Union. 2016. Regulation (EU) 2016/679, Article 5(1)(c). European Data Protection Board. 2020. Guidelines 4/2019 on Article 25 Data Protection by Design and by Default. European Data Protection Board. 2024. Opinion 28/2024 on Certain Data Protection Aspects Related to the Processing of Personal Data in the Context of AI Models. OECD. 2013.
Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data. International Organization for Standardization. ISO/IEC 27701:2019. Privacy Information Management.
Review
Public comments appear only after editor acceptance. Draft comments stay in the review queue.
Reviewers choose the definition or an overview paragraph, leave a comment or replacement, and attach evidence or a source link.
Editors compare reviewer cards side by side. AI may help find agreement, conflicts, unsupported claims and possible source issues.
Only an editor-accepted synthesis changes the public page. Reviewer identities are shown only with consent and verification.
Submitted reviews stay private until accepted.
Loading verified endorsements… Endorsements are not votes and never determine publication.
Endorse this definition
Endorse the exact version shown here. This is not a vote, and publication remains an editorial decision.
Review board
Comment on a specific line. Each reviewer stays separate until an editor accepts a merged draft.
Each person comments on the definition or overview in their own draft card, with role, evidence and suggested wording kept together.
AI can compare comments against the current text, flag conflicting claims, surface missing evidence and identify where reviewers agree.
An editor merges compatible suggestions into a draft change, checks sources, records disagreements and decides what can be published.