Every field you store is a liability you carry forever: storage, backups, breach exposure, deletion requests. Asking 'do we actually need the customer's birth year for a newsletter' before the form ships is cheaper than answering it in a breach report later.
In practice it means designing for subtraction: forms that skip optional fields nobody uses, logs that pseudonymize IPs, retention schedules that actually delete, analytics that count events rather than hoard profiles. Data you never collected is data you never have to defend.
Related terms
GDPR
The EU's data-protection regulation — consent before collection, rights to access and deletion, breach notification in 72 hours, fines up to 4% of turnover.
Least privilege
Every user, service and process gets only the access the job requires — nothing more, so a compromise has a small blast radius.
Encryption at rest
Encrypting data where it is stored — disks, databases, backups — so a stolen drive or leaked dump is ciphertext, not data.
