Data minimisation is the requirement to collect and keep only the personal data that a stated purpose actually needs, and to stop keeping it once that purpose ends. Article 5(1)(c) of the General Data Protection Regulation (GDPR) puts the standard in a single clause: personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Each word carries separate weight. Adequate sets a floor, since data too thin to deliver the service fails as well. Relevant demands a rational connection between a field and the purpose. Limited to what is necessary removes everything else, including fields captured in case they prove useful later.

The principle exists because collection is the only stage at which risk is eliminated rather than managed. A field never captured cannot leak, cannot be sold on and cannot be repurposed years later by a different team. Two features make it awkward for advertising: naming a purpose in a privacy notice does not license the collection, and the rule runs independently of the legal basis, so a consent banner does not switch it off.

How the test works

Purpose comes first. Until a controller specifies why it is processing, there is nothing to measure necessity against. Recital 39 of the regulation sets the bar above usefulness, stating that personal data should be processed only where the purpose cannot reasonably be fulfilled by other means. The operative question is whether the same result could be reached with less, not whether an extra field helps.

The Court of Justice of the European Union applied that reading to a single form field on January 9, 2025. In Case C-394/23, the association Mousse challenged the practice of French rail operator SNCF Connect, which required ticket buyers to select Monsieur or Madame. According to the judgment, collecting title data is not objectively indispensable, particularly where the aim is to personalise commercial communication. Convention in commercial correspondence did not survive a necessity test.

Two further provisions push the principle into system design. Article 25 requires data protection by design and by default, so that only data necessary for each specific purpose is processed unless a setting is changed. Article 5(2) adds accountability, which places the burden of proof on the controller: documented field justifications, retention schedules, and impact assessments for higher-risk processing.

Enforcement shows what that looks like inside a file. Poland's supervisory authority fined McDonald's Polska 3.89 million euros over a scheduling system that used national identification numbers and passport details as employee identifiers, treating the later switch to internal numbers as evidence that the original fields had never been required. France's highest administrative court cut a penalty against Amazon France Logistique from 32 million to 15 million euros while upholding the minimisation finding, because the company could not justify retaining every warehouse productivity indicator for 31 days.

Where it lands in the advertising chain

Real-time bidding broadcasts a structured message to every invited buyer, turning each field into a separate minimisation question. A bid request can carry the page URL, store bundle, user agent, IP address, device model, the mobile advertising identifier, latitude and longitude with an accuracy value in metres, cookie and third-party identifiers, audience segments and regulatory flags. The Electronic Privacy Information Center and the Irish Council for Civil Liberties, filing with the Federal Trade Commission on January 16, 2025, described one such system as operating across 35.4 million websites, 91 per cent of Android apps and 75 per cent of iOS apps, with 2,365 certified recipients on a published list.

The most codified example concerns children. Once the coppa flag in the regulatory object is set to 1, standard guidance directs exchanges to suppress the hashed device identifiers didmd5 and didsha1, truncate the ip field by its lowest 8 bits and the ipv6 field by its lowest 32, drop the latitude and longitude coordinates along with metro, city and zip, and remove the user object's id, buyeruid, year of birth and gender. Prebid Server enforces that rounding in core rather than leaving it configurable, according to the project's notes. Nothing here is anonymised. Precision is removed at defined offsets.

Adult traffic gets the same arithmetic through defaults. Removing the fourth octet of an address collapses resolution from a specific block to a broader subnet, costing buyers city-level targeting, data centre detection and household frequency management. An AdSense control passing the full address to three demand channels launched switched off on June 1, 2026 and stays blocked on non-personalised, limited and restricted-data-processing requests. A federal judge approved a settlement on March 26, 2026 requiring a user-facing control that strips encrypted user identifiers, device advertising identifiers and IP addresses from bid requests, with implementation due within 30 days of final approval.

Duration is the other axis, and platform windows have swung hard. Google set an 11-year retention period for Ads reporting data from November 13, 2024, then capped granular access at 37 months from June 1, 2026, keeping the longer window only for monthly, quarterly and annual aggregates. Customer Match membership has been limited to 540 dayssince April 7, 2025, with longer lists truncated retroactively.

Origin and evolution

The vocabulary arrived long before the web. Privacy guidelines issued by the Organisation for Economic Co-operation and Development on September 23, 1980 stated a collection limitation principle at paragraph 7. Council of Europe Convention 108, opened for signature in January 1981, required stored data to be adequate, relevant and not excessive, and Directive 95/46/EC of October 24, 1995 carried that wording into Community law at Article 6(1)(c).

Germany went further first, with a provision headed Datenvermeidung und Datensparsamkeit, roughly data avoidance and data thrift, directing that processing and system design aim at using as little personal data as possible. Until September 1, 2009 it reached only the design and selection of processing systems; an amending act of August 14, 2009 extended it to every use of personal data.

The GDPR, applicable from May 25, 2018, replaced not excessive with limited to what is necessary. That edit moved the question from whether collection was disproportionate to whether it was required at all, and gave the principle the name now used across the industry.

Why it matters for the marketing community

Consent is not a cure. On October 4, 2024 the Court of Justice ruled that Article 5(1)(c) precludes a platform from aggregating personal data for targeted advertising without restriction as to time or distinction as to type, whether that data was gathered on the platform or off it, and confirmed that the principle applies whatever the legal basis. Katharina Raabe-Stuppnig, the lawyer representing complainant Max Schrems, said that only a small part of the accumulated pool would remain usable for advertising after the ruling, even where users had agreed. A second holding narrowed Article 9(2)(e): a public statement about a sensitive characteristic does not authorise processing other data about it.

United States law is arriving from a different angle. Maryland limits collection to what is reasonably necessary and proportionate to provide or maintain a specific product or service the consumer requested, bans the sale of sensitive data outright and permits sensitive data processing only where strictly necessary. Signed on May 9, 2024 and effective from October 1, 2025, it applies to processing from April 1, 2026. Targeted advertising is not a requested service under that wording. Connecticut took a softer route in June 2025, adding proportionality but tying it to disclosed purposes, effective July 1, 2026. The federal SECURE Data Act, introduced on April 21, 2026, would impose minimisation obligations while pre-empting every state statute.

Where the principle is contested

The standard resists auditing. Assessing a German certification scheme in 2025, the European Data Protection Board found its minimisation criterion too general for effective auditing and asked for precise, testable wording. A comparative study of 19 regulatory guidelines on artificial intelligence training placed minimisation at the least convergent end of the spectrum: guidance instructs developers to process only what is strictly necessary, enforcement rarely penalises over-collection, and benchmarks are absent.

Industry objects to the cost of that ambiguity rather than to the principle. The small-business coalition Internet for Growth backed the federal bill while naming minimisation standards and sensitive data definitions as the unresolved items driving compliance expense. Consumer groups fight the opposite battle in the states, where Consumer Reports and EPIC opposed a Maryland bill replacing the requested-service test with a disclosure-based one, arguing it would reward broadly drafted notices.

The quieter threat is definitional. The European Commission's Digital Omnibus, presented on November 19, 2025, would narrow what counts as personal data and create an explicit legitimate interest basis for AI training; the Board and the European Data Protection Supervisor rejected key elements in a joint opinion on February 10, 2026. Less data inside the definition means less data inside Article 5(1)(c).

Not the same as

Purpose limitation, at Article 5(1)(b), fixes what data may be used for. Minimisation asks how much is needed once that purpose is set, which is why the two are almost always cited together.

Storage limitation, at Article 5(1)(e), governs how long identifiable data may be kept. Retention cuts are routinely called minimisation and formally belong next door.

Pseudonymisation reduces linkability without reducing volume. Records stay personal data even when the reversal key sits elsewhere, so hashing an identifier is not equivalent to not collecting it.

Selective disclosure is a delivery technique. Mobile document standards let a verifier confirm an age threshold without receiving an address or a document number, which satisfies minimisation at the point of presentation rather than at the point of collection.

Timeline

  • September 23, 1980: OECD privacy guidelines state the collection limitation principle at paragraph 7
  • January 28, 1981: Council of Europe Convention 108 opens for signature, requiring data to be adequate, relevant and not excessive
  • October 24, 1995: Directive 95/46/EC carries that wording into Community law at Article 6(1)(c)
  • September 1, 2009: Germany broadens its Datensparsamkeit provision beyond system design to every use of personal data
  • May 25, 2018: The GDPR becomes applicable, replacing "not excessive" with "limited to what is necessary"
  • May 9, 2024: Maryland enacts the strictest state minimisation standard in the United States
  • October 4, 2024: The Court of Justice rules that minimisation limits targeted advertising regardless of legal basis
  • November 13, 2024: An 11-year retention window takes effect for Google Ads reporting data
  • January 9, 2025: The Court of Justice rules in Case C-394/23 that collecting customer titles is not objectively indispensable
  • January 16, 2025: EPIC and the ICCL file a complaint over the scale of real-time bidding data sharing
  • April 7, 2025: A 540-day cap takes effect on Customer Match list membership
  • June 2025: Connecticut adds proportionality to its minimisation test, effective July 1, 2026
  • October 1, 2025: The Maryland act takes effect
  • November 19, 2025: The European Commission presents the Digital Omnibus package
  • February 10, 2026: The EDPB and EDPS reject key elements of that package
  • March 26, 2026: A federal judge approves the settlement creating an identifier-stripping bidding control
  • April 1, 2026: Maryland enforcement begins to apply to processing activities
  • April 21, 2026: The SECURE Data Act is introduced in the US House
  • June 1, 2026: Granular Google Ads reporting access falls to 37 months

Summary

Who. Controllers and processors under European law, state attorneys general in the United States, and every participant in a programmatic supply chain that decides which fields leave a server. The standard is applied by national supervisory authorities, the European Data Protection Board and the Court of Justice of the European Union.

What. A binding requirement that personal data be adequate, relevant and limited to what is necessary for the purpose it was collected for, tested at the level of individual fields, precision and duration rather than at the level of disclosure.

When. Stated in international guidance from 1980, binding in European law from 1995, tightened by the GDPR in 2018, and applied to targeted advertising by the Court of Justice on October 4, 2024.

Where. In bid request objects, tag configurations, retention settings, audience size thresholds and serving modes, alongside privacy notices and records of processing.

Why. Collection that cannot be justified against a purpose is unlawful regardless of consent, and the consequences now arrive as product changes: stripped identifiers, truncated addresses, shorter retention windows and controls that ship switched off.