Skip to content

Glossary

Data minimisation

Holding only what the purpose actually requires, which is a legal principle and the cheapest reduction in exposure available.

In plain terms

Do not keep what you do not need. It is the rare rule that is simultaneously a legal requirement, a security improvement and a cost saving, and it is also the one AI tools give an organisation a constant reason to ignore.

01

Why it matters

Because these tools work better with more material, and that creates steady pressure in exactly the opposite direction from the principle. A search deployment improves as it reaches further, an assistant answers better with more context, and every one of those improvements is an argument for holding more than the purpose requires.

02

How it works

The test is necessity for a stated purpose rather than usefulness in general. Material that might be handy later fails it, because later is not a purpose, and the discipline of the principle is that it forces the purpose to be named before the collection is justified.

It applies to what is kept as much as to what is gathered. Data collected legitimately becomes a minimisation question once its purpose is served, which is why retention is where organisations most often fall short of a principle they believe they are following.

It is the cheapest security control available and is rarely counted as one. Material that was never collected cannot be exposed, cannot be requested, and costs nothing to protect, so every reduction removes work permanently rather than adding a control that has to be maintained.

AI adoption pulls directly against it, and pretending otherwise helps nobody. The genuine improvement from giving a tool more to work with is real, so the tension is not between the principle and a bad idea; it is between the principle and something that works.

The useful question is whether the additional material changes an outcome or only feels safer. Reaching further usually improves a tool somewhat, and the honest version asks whether that improvement changes a decision anybody makes, which is a much narrower claim than more is better.

Two reasons to hold more

Two reasons to hold moreThe reason to separate these is that the right-hand column never announces itself. Nobody writes down that the scope was set wide because narrowing it required a conversation with three teams, so the arrangement that results looks identical to one arrived at deliberately. That is also why the principle is unusual among privacy requirements in being genuinely easy to satisfy once somebody engages with it: the question is short, it can be asked about any particular field or source, and a specific answer usually exists. Can somebody name a case where this material changes what the tool concludes. Where the answer is yes, the material is necessary and the principle is satisfied by including it. Where the answer is a general feeling that more is better, what has been described is the right-hand column, and the honest cost of narrowing it is a conversation somebody did not want to have rather than any loss of capability. The AI-specific difficulty is that the left-hand column is frequently true in a small way, so the exercise is not separating necessary from useless but deciding how much marginal improvement justifies holding somebody's material.Changes an outcomeThe answer is wrong without it.A decision would differ.Somebody can name the case.Feels saferIt might be useful later.Narrowing it takes effort.Nobody wanted to decide.Both columns produce the sameinstruction, which is to includeeverything, and only the leftone is a reason. The right-handcolumn is what the default lookslike when no decision was made.
The reason to separate these is that the right-hand column never announces itself. Nobody writes down that the scope was set wide because narrowing it required a conversation with three teams, so the arrangement that results looks identical to one arrived at deliberately. That is also why the principle is unusual among privacy requirements in being genuinely easy to satisfy once somebody engages with it: the question is short, it can be asked about any particular field or source, and a specific answer usually exists. Can somebody name a case where this material changes what the tool concludes. Where the answer is yes, the material is necessary and the principle is satisfied by including it. Where the answer is a general feeling that more is better, what has been described is the right-hand column, and the honest cost of narrowing it is a conversation somebody did not want to have rather than any loss of capability. The AI-specific difficulty is that the left-hand column is frequently true in a small way, so the exercise is not separating necessary from useless but deciding how much marginal improvement justifies holding somebody's material.
03

Seen in the wild

  • Scoping a search deployment to the material a question genuinely needs rather than everything reachable.

    Glean
  • Uploading a whole archive to an assistant because it might help, rather than the part that answers the question.

    ChatGPT
  • An automation copying entire records where three fields would have done.

    Make
04

Common misconceptions

People assume

It is about collecting less at the start.

In fact

It applies equally to what is kept afterwards. Material gathered for a purpose that has been served is now held without a purpose, and retention is where most organisations fall short of a principle they genuinely believe they follow.

People assume

More context always makes an AI tool better.

In fact

It usually makes it somewhat better, which is not the same claim. The question worth asking is whether the improvement changes an outcome anybody acts on, because that is a much narrower thing than a general preference for more.

05

Questions

How does this square with AI tools needing context?
It does not square neatly, and the tension is real rather than a misunderstanding. More material genuinely helps, so the principle is competing with something that works, and the honest resolution is asking whether the extra changes a decision rather than whether it improves an answer.
Why is it described as a security control?
Because material that was never collected cannot be exposed, cannot be requested and cannot leak, and it costs nothing at all to protect. Every other control has to be built and then maintained indefinitely, whereas a reduction removes that work permanently, which makes it unusually good value.
Where do organisations most often fall short?
Retention rather than collection. Deciding not to gather something is a visible choice that somebody makes at a particular moment, while continuing to hold material whose purpose has been served is the absence of a decision, and nothing in an ordinary week prompts anybody to make it.
06

Key takeaways

  • The test is necessity for a stated purpose, not usefulness in general.
  • It governs what is kept as much as what is collected.
  • It is the only control that removes work rather than adding it.
  • AI tools pull against it, and the pull comes from something that genuinely works.
08

Tools that use this

  • Glean

    Scoping to what a question needs rather than everything reachable.

  • ChatGPT

    Uploading a whole archive where the relevant part would do.

  • Make

    Copying entire records where three fields would have done.

Last checked August 2026

All glossary terms