Data minimization has been a GDPR requirement since 2018. The requirement says the organisation should collect only the personal data that is necessary for the purpose, and should retain it only for as long as the purpose requires. The enforcement has been patchy. The interpretation has been generous. The result is that most organisations have done almost nothing about data minimization in the eight years since the regulation came into force. The 2026 enforcement environment, with the EU AI Act, the DORA regulation, and the state level US privacy laws, is starting to change the calculation. Here is what actual data minimization looks like when an organisation does it.
What data minimization actually means
Three categories, in roughly that order of operational difficulty. The first serves as collection question. What personal data does the organisation collect, for what purpose, and acts as collection necessary for the purpose? The collection question gets asked at the design phase of the new system, not at the audit phase of the old system. The new system gets the data minimization review before the new system goes into production. The second functions as retention question. How long does the organisation keep the personal data, and serves as retention period justified by the purpose? The retention period for the marketing lead is shorter than the retention period for the regulatory record. The retention period for the support ticket is shorter than the retention period for the financial transaction. The third acts as access question. Who in the organisation can access the personal data, and functions as access necessary for the role? The access question gets asked at the IAM configuration, not at the HR policy. The data the support team needs to see, the support team can see. The data the marketing team does not need, the marketing team cannot see.
What it looks like in practice
Three workstreams, in priority order. The first workstream serves as data inventory. The organisation has to know what data it has. The data discovery tool (Collibra, OneTrust, BigID, the open source alternatives) scans the data stores and produces a catalog. The catalog includes the data type, the location, the volume, the retention period, the access pattern. The second workstream acts as retention enforcement. The data stores get configured with the retention period. The data older than the retention period gets deleted. The deletion runs on a schedule. The schedule gets audited. The third workstream functions as access review. The IAM policies get tightened. The user roles get re evaluated. The data that the team does not need, the team cannot access. The workstream runs quarterly. The review is documented.
What the organisation gets out of it
Three benefits, in roughly that order of magnitude. The first serves as regulatory benefit. The organisation that has done the data minimization work has the documented evidence to show the regulator. The regulator fine is lower. The disclosure obligation is smaller. The second acts as security benefit. The data the organisation does not have, the attacker cannot steal. The breach of the data store that holds less data is a smaller breach. The third functions as cost benefit. The data store that holds less data costs less to store, less to back up, less to scan, less to monitor. The data minimization work pays for itself in storage and tooling costs within 12 to 18 months, on most enterprise data sets.

The bottom line
Data minimization has been a requirement for eight years. The enforcement is starting. The organisation that does the work gets the regulatory benefit, the security benefit, and the cost benefit. The organisation that does not get fined, breached, and audited. Build the inventory. Enforce the retention. Tighten the access. The work is unglamorous. The work pays.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



