Data Minimisation is a privacy principle and GDPR requirement (Article 5(1)(c)) mandating that personal data collection and processing be limited to what is adequate, relevant, and necessary for specified purposes, reducing privacy risks by avoiding accumulation of excessive data that could be misused, breached, or enable function creep.

Semantic Classification

Content

0426 Data Minimisation — content pending enrichment.

Current Landscape (2026)

  • Data minimisation has become the pivotal battleground for AI training: the EDPB’s Opinion 28/2024 (adopted 17-18 December 2024) held that models trained on personal data cannot always be treated as anonymous, and required that training data be adequate, relevant and necessary — checking first whether synthetic or anonymised data could achieve the purpose.
  • National regulators have softened the operational reading for large models: the CNIL’s two AI-and-GDPR recommendations (7 February 2025) confirmed that minimisation “does not prevent the use of large training datasets”, provided data is selected and cleaned to strip unnecessary personal data, while the EDPS issued revised Generative AI orientations for EU institutions on 28 October 2025.
  • The EU’s Digital Omnibus package, unveiled 19 November 2025, proposes the most consequential shift: a new Article 88c GDPR putting ML training on a legitimate-interests footing (with documented LIAs, right to object and minimisation safeguards), a relative/entity-specific redefinition of “personal data” in Article 4(1), an Article 41a pseudonymisation mechanism, and extension of the breach-notification deadline to 96 hours.
  • The EDPB and EDPS pushed back in Joint Opinion 2/2026 (adopted February 2026), recommending that the strict-necessity standard be retained for processing special-category data used in bias detection and correction for high-risk AI systems.
  • Enforcement continues to bite on the classic principle: the CJEU reinforced minimisation and purpose limitation in Schrems v Meta (C-446/21, judgment 4 October 2024), ruling that indefinite large-scale processing for behavioural advertising cannot be justified merely because some data was public; regulators such as Romania’s ANSPDCP have levied fresh fines (15,000 euros against Continental Automotive, early 2026) for minimisation breaches.
  • Privacy-enhancing technologies are being positioned as the practical route to minimisation: the ICO maintains dedicated PETs guidance and, in a March 2026 report on agentic AI, urged privacy-by-design with narrow purposes to avoid “open-ended” access; the Israeli DPA published an English-language PETs technical guide in early 2026.
  • In the UK, the Data (Use and Access) Act 2025 and a 2026 DSIT call for evidence on “data regulation in the age of AI” are reopening how minimisation applies to data-intensive systems, with the frontier challenge being how to reconcile the principle with foundation-model scale, memorisation and re-identification risk, and emerging agentic architectures.

References

Provenance