Data Minimisation Under GDPR: Why “Just in Case” Data Collection Is a Risk

Date: 02/09/2026

Data minimisation under GDPR — collect only what you actually need

More data isn’t safer — it’s riskier

It’s tempting to collect as much as possible: date of birth “just in case,” a phone number “just in case,” an extra address field “for later.” Under GDPR, that instinct is backwards. Article 5(1)(c) requires personal data to be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed — the principle known as data minimisation.

Minimisation sits alongside storage limitation (Article 5(1)(e)) as one of the core principles in Article 5. Privacy by design and by default is the separate obligation in Article 25 to actually build those principles into your systems — and Article 25(1) names data minimisation explicitly as an example of what should be designed in.

Every extra field you collect is data you now have to secure, data a breach could expose, and data you must be able to justify — Article 5(2) makes the controller responsible for demonstrating compliance with all of it.

What “necessary” actually means

The test isn’t “would this be useful” — almost anything could theoretically be useful. The test is whether you actually need it for the specific purpose you’re processing data for right now.

  • Running an online store? You need a delivery address. You don’t need date of birth unless you’re selling age-restricted products.
  • Running a newsletter sign-up? You need an email address. You don’t need a phone number.
  • Taking a booking? You need contact details and the booking specifics. You don’t need to ask someone’s occupation “for our records.”

If you can’t articulate a specific reason tied to the purpose at hand, the honest answer is usually that you don’t need the field.

The “just in case” trap

The most common way minimisation gets violated isn’t malicious — it’s habit. Sign-up forms grow extra fields over time because someone thought it might be useful for marketing segmentation, or a template came with fields nobody removed, or a previous product idea needed a field that’s now obsolete. None of that is a valid basis for keeping the field live today.

A useful discipline: every time you’re tempted to add a field to a form, ask what specific decision or action depends on that answer. If nothing does, leave it out — you can always add it later if a real need appears.

What this means for existing systems, not just new ones

Minimisation isn’t only about new forms. It’s worth periodically auditing what you already collect:

  1. List every field in your CRM, sign-up forms, and booking systems.
  2. For each one, name the specific purpose it serves right now.
  3. Anything without a clear purpose is a candidate to stop collecting — and, under the storage limitation principle in Article 5(1)(e), personal data should not be kept in a form that identifies people for longer than the purpose requires, subject to any legal retention requirement.
  4. Check your forms aren’t marking optional fields as required by default. Article 25(2) requires that, by default, only the personal data necessary for each specific purpose are processed — and that obligation covers the amount of data collected, the extent of the processing, how long it is stored, and who can access it.

A quick self-check for any new form or tool

  • Does every field serve a specific, current purpose?
  • Are optional fields actually optional, not disguised as mandatory?
  • If a regulator asked “why do you collect this,” could you answer in one sentence?
  • Would removing this field actually break anything you do today?

If the answer to that last question is no, it’s a field worth cutting.

The upside

Minimisation isn’t just a compliance obligation — shorter forms convert better, smaller databases are cheaper to secure and easier to audit, and a breach involving less data is a smaller incident by definition. Collecting less is one of the few GDPR principles that’s genuinely good for the business case too, not just the compliance one.

It also makes the rest of GDPR easier. Fewer fields means less to hand over when someone asks to see or correct their data, and less to track down when someone asks you to delete it.

Not sure which fields on your forms you actually need? Let’s Talk GDPR.

Related reading


References

  1. GDPR Article 5(1)(c) — data minimisation: personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
  2. GDPR Article 5(1)(e) — storage limitation.
  3. GDPR Article 5(2) — accountability: the controller must be able to demonstrate compliance with the Article 5(1) principles.
  4. GDPR Article 25(1) — data protection by design, which names data minimisation as a principle to be built in.
  5. GDPR Article 25(2) — data protection by default.
Latest Articles & Insides