Collect only the data you actually need for the job, and don't keep it longer than necessary.
Collect only the data you actually need for the job, and don't keep it longer than necessary.
Data minimisation is enshrined in Article 5(1)(c) of the GDPR and is also relevant to EU AI Act requirements on training data governance. In AI contexts, minimisation creates tension with the common assumption that more training data yields better models — organisations must document a legitimate basis for the breadth of data collected and must consider whether synthetic data or aggregated datasets can substitute for personal data. Minimisation also applies to inference: AI systems that collect user data at inference time must justify collection against the purposes declared in privacy notices.
AI teams must work with privacy counsel to establish data minimisation policies for training datasets — particularly for models processing health, financial, or biometric data where GDPR and sector regulations overlap.
Like only collecting the identity documents strictly required for a background check — taking a full passport copy when only a date of birth is needed violates the spirit and letter of minimisation.
Collect only the data you actually need for the job, and don't keep it longer than necessary.
Data minimisation is enshrined in Article 5(1)(c) of the GDPR and is also relevant to EU AI Act requirements on training data governance. In AI contexts, minimisation creates tension with the common assumption that more training data yields better models — organisations must document a legitimate basis for the breadth of data collected and must consider whether synthetic data or aggregated datasets can substitute for personal data. Minimisation also applies to inference: AI systems that collect user data at inference time must justify collection against the purposes declared in privacy notices.
AI teams must work with privacy counsel to establish data minimisation policies for training datasets — particularly for models processing health, financial, or biometric data where GDPR and sector regulations overlap.