Data Minimization (Article 5(1)(c) GDPR)
Data minimization as a principle of the GDPR: relevance, necessity and adequacy of data processing; differences from the earlier principle of data economy; practical areas of application.
The principle of data minimization requires that personal data be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed." The provision is an expression of the principle of proportionality and consistently builds on purpose limitation (Article 5(1)(b) GDPR).
Key takeaways
- Data minimization imposes three purpose-related requirements: relevance, necessity and adequacy (the three tiers of proportionality).
- It does not set an absolute upper limit on the volume of data, but rather a review geared to the purpose of the processing.
- It replaces the earlier principle of data economy (§ 3a of the German Federal Data Protection Act (BDSG), old version); the objective of pure data avoidance has thus been abandoned.
- Its areas of application are in particular pseudonymous/anonymous use, big data and limiting mandatory fields in forms.
- A breach renders the processing unlawful and is subject to administrative fines; Article 25(1) GDPR implements the principle in technical and organizational terms.
1 Overview
1.1 Three requirements: three tiers of proportionality
Data minimization breaks down into three requirements that mirror the three tiers of the proportionality test:
- Relevance ("relevant"): the data must be suitable for the purpose pursued.
- Necessity ("limited to what is necessary"): the processing must be limited to what is necessary.
- Adequacy ("adequate"): the processing must be proportionate in the narrower sense.
All three requirements are geared to the purpose of the processing. They do not impose an absolute limit on the permissible volume of data, but rather a purpose-related proportionality review.
1.2 Legal consequence and systematic context
A breach of data minimization renders the processing unlawful and is subject to administrative fines. The principle also serves as a standard for interpreting individual provisions: Article 25(1) GDPR obliges the controller to provide for technical and organizational measures implementing data minimization as early as the selection and design of its processing systems.
1.3 Relationship to the earlier principle of data economy
The GDPR replaces the former principle of data economy (§ 3a BDSG, old version). Whereas data economy pursued the objective of data avoidance and already covered the design and organization of processing operations, data minimization is geared solely to the purpose of the processing. It contains no normative limitation on the extent of the processing beyond the purpose-related assessment.
2 The three requirements in detail
2.1 Relevance
The data processed must make a relevant contribution to achieving the purpose of the processing. Data that bear no connection to the purpose may not be processed. This assessment corresponds to the suitability tier of the general proportionality test.
2.2 Necessity
The processing must remain limited to what is necessary for the purpose. In this respect, the wording of the GDPR is narrower than the predecessor provision in Directive 95/46/EC, which merely required that the data be "not excessive." Processing is not necessary where the purpose can be achieved just as effectively with a lesser interference with the rights of the data subject, that is, where a less intrusive alternative exists.
Necessity is already contained as a statutory criterion in most of the legal bases under Article 6(1) GDPR (with the exception of consent, point (a)). The principle of data minimization reaffirms and clarifies this requirement, but does not extend it beyond Article 6 GDPR.
2.2.1 Examples of application
Typical constellations in which necessity is assessed are:
- Identification: for many online services, it is not necessary for the user to identify herself by her real name. Pseudonymous or anonymous forms of use must regularly be examined and provided for as a matter of priority.
- Big data: even with large volumes of data, it must be critically examined whether a link to an identified person is actually needed. Anonymous or pseudonymous datasets can often be used in a manner appropriate to the purpose without individual data subjects being identified.
- Mandatory fields: forms and registration screens may only include as mandatory those fields that are genuinely needed for the specific purpose.
2.3 Adequacy
The processing of data must also be adequate in the narrower sense ("adequate"). This criterion calls for an evaluative assessment of whether the extent of the processing bears a reasonable relationship to the purpose pursued. Adequacy is a separate tier; it may render processing unlawful even where the conditions of a legal basis under Article 6(1) GDPR (including consent) are met. Processing may be inadequate in particular where it is excessive from an objective perspective or is carried out for purely hypothetical purposes for which there is no foreseeable occasion at the time of collection.
3 Assessment in the individual case
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Purpose Limitation (Article 5(1)(b) GDPR)
Purpose limitation as a principle of the GDPR: the duty to specify the purpose, the prohibition of incompatible further processing, exceptions for archiving, research and statistical purposes, and the relationship to Article 6(4) GDPR.
Accuracy (Article 5(1)(d) GDPR)
Accuracy and up-to-dateness of personal data: proactive rectification, profiling and AI, the treatment of time-related data, and obligations where data have been passed on to third parties.