Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Data Minimisation (Art. 5.1.c)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 15/54 Part 2 — Core Principles Intermediate Reviewed 2026-08-23

Data Minimisation (Art. 5.1.c)

Controllers must only collect and process data that is adequate, relevant, and strictly limited to what is necessary for the specified purpose. Preemptive or speculative data harvesting is illegal.

Open in interactive reader
⚖️ Proportionality Standard 🏛️ Strict Necessity Doctrine

Data Minimisation (Art. 5.1.c)

⚡ In 30 seconds

Under Article 5(1)(c), personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Data collection must not be speculative or opportunistic. If a service can function without a phone number or date of birth, requesting those attributes violates the GDPR.

Adequate & Relevant

Data must be qualitatively sufficient to achieve the stated business objective without collecting tangential personal details.

Limited to Necessity

Quantitative limitation: minimize record count, attributes per user, access rights, and retention windows across all systems.

⚡ Key Takeaways
  • Need-to-know access controls inside the organization enforce minimisation.
  • Less data stored equals reduced exposure in the event of a security breach.
  • Granular consent forms must separate mandatory data from optional preferences.
⚠️ Common Pitfall

Recording full credit card numbers or government ID copies when simple payment authorization tokens suffice.

🛠️ In Practice

Review database schemas and remove unused legacy columns during sprint refactoring cycles.

⚖️ Official Sources: Art. 5(1)(c), 25(2) GDPR · Recital 39 · CJEU C-708/18 TK v Asociaţia ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Three cumulative requirements: adequate, relevant, and strictly necessary.
  • Minimisation applies at design stage (collection) and endures across time (pruning/retention).
  • Directly tied to the mandate of Data Protection by Default (Art. 25.2).

⚠ Common pitfall: Collecting excessive attributes 'just in case' they might be helpful for future marketing or AI initiatives.

→ Actionable practice: Audit registration forms and delete optional input fields that cannot be justified by core service functionality.

← The 6 Cardinal Principles of Processing (Art. 5.1) Anonymisation vs Pseudonymisation (Art. 4.5) →