What Does Data Minimisation Look Like in Practice?
8th September 2025
Data minimisation is one of the 7 key principles of the UK GDPR, and is also one of the most misunderstood and overlooked. Put simply, organisations should only collect the personal data they need, use it for a defined purpose, and store it for no longer than necessary. This sounds good in theory, but how does this apply in practice? Data minimisation mainly concerns data collection, retention policies and systems – let’s take a look at each of these areas and how we can apply the data minimisation principle.
What is Data Minimisation?
Article 5 of the GDPR states that personal data should be:
“adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’)” Article 5(1)(c), GDPR
Data minimisation is the practice of limiting the amount of personal data you collect, and only processing what is relevant for your predetermined purpose, then safely and securely erasing it when it is no longer required. For example, if you are hiring for a role at your organisation, you will need a potential candidate’s employment history and contact details, but you won’t need their bank details until they are actually an employee.
Why is Data Minimisation Necessary?
Data minimisation is necessary for several important reasons, the main one being that data protection laws like the GDPR require it. Regulators like the ICO can fine organisations for collecting or holding unnecessary personal data. Data minimisation also helps to reduce the risks posed by a data breach – the less data you hold, the less there is to lose in a breach. It can also help increase customers’ trust in your organisation – people are more willing to share their details with organisations that don’t overreach with their data collection.
Data Collection Forms
Most organisations gather data through forms, whether via a contact form on their website, a job application, or a client intake form. To apply the principle of data minimisation at this stage, follow these steps.
- Ask only what you need. If you are inviting people to sign up to your newsletter, you only need a person’s name and email address – don’t collect postal addresses or anything else you don’t need for this purpose.
- Make the optional fields clear. If additional data may be helpful for your purposes but isn’t necessary, make sure that those fields are clearly marked as ‘optional’. This provides transparency and builds trust in your organisation.
- Review any old forms that are still in use. Some forms created years ago could still ask for excessive amounts of personal information. Updating these forms is a quick win for compliance and customer confidence.
One area of particular concern is requesting excessive amounts of special category or sensitive data. Many organisations still routinely ask employees to complete a medical or health questionnaire, including questions such as ‘how much alcohol do you drink a week? ’
Unless the question is directly relevant to an individual’s job function, for example, it would be perfectly acceptable to ask a lorry driver if they have a heart condition or epilepsy, but not a receptionist. Similarly, routine drug testing may be reasonable for construction workers operating in hazardous environments, but not if they are just driving a computer mouse. You must look at every situation on a case-by-case basis.
Data Retention Policies
Data minimisation isn’t just about what data you collect, but also how long you keep it. Many organisations have problems with storing excessive amounts of data that are no longer required. The following tips can help improve your data retention policy and ensure you are compliant.
- Define clear timelines for storing data. These timelines will depend on the type of data that is being stored – some will need to be kept longer than others. For example, it’s not necessary to keep unsuccessful job applications for more than 6 months, whereas invoices should be kept for 6 years to comply with tax laws.
- Automating the deletion of records can help you to comply with data minimisation – set up reminders or use systems that automatically delete or anonymise data when it is no longer needed. Just make sure you build in exceptions, as you may need to keep some specific records for legal or litigation purposes.
- Make sure you document the reasoning behind different retention periods. This can help you think objectively about how long you need to retain certain data, and regulators like the ICO will want to see why you have chosen certain retention periods – link them to legal, contractual or operational requirements.
Systems and Processes
Data minimisation needs to be built into the way your business runs beyond forms and policies. Consider how everyday tools and workflows handle data and follow these tips.
- Limit data access to people who actually need it. Not everyone in your organisation needs to see all data – restrict access by role so that only those who need to can see and access the data. This reduces the risk of a data breach and maintains control over sensitive information.
- When choosing new software, check that it supports data minimisation. For example, can you turn off unnecessary features and fields, anonymise records, and easily delete outdated information? Systems that don’t have this functionality can slow you down and add risk.
- Build data minimisation into workflows. Think about who needs to access data in their daily tasks – e.g. sales teams need to see client details, including order history and contact information, whereas HR don’t need this – instead, they should be the only ones handling payroll data and accessing other information about employees.
- Perform regular audits to find out what information is being stored, where, and why. This can include checking hard drives, CRM systems, and cloud storage to ensure they don’t become dumping grounds for unnecessary personal data.
- Include data minimisation in staff training. This can help staff to understand why data minimisation matters and how to apply it in their daily work.
Data minimisation offers benefits beyond compliance. It can also help by making your systems faster and easier to manage, saving you money on storage and software, improving your organisation’s decision-making by removing irrelevant data, and strengthening your reputation for responsible data handling. Data minimisation isn’t about collecting as little as possible – it’s about collecting just enough. Done well, it reduces risk, builds customer trust, and makes your systems leaner and easier to manage. If your data collection forms, retention policies and systems already reflect these principles, you are well on your way to compliance.
Another significant benefit of data minimisation is if/when a subject access request is received. Having to retrieve and process data will simplify access requests, but also, if you have followed the rules on data minimisation and accuracy in relation to recording opinions, you will prevent a whole world of pain and potential litigation.
Putting data minimisation into practice can feel complex, but you don’t have to tackle it alone. We can help businesses review forms, set retention policies, and streamline systems to stay compliant and build trust – get in touch with us here at Griffin House Consultancy or call us on 01673 885533.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.