# Data minimization

> Collecting and keeping only the data the job needs — the GDPR principle that is also the cheapest security control: what you do not hold cannot leak.

Every field you store is a liability you carry forever: storage, backups, breach exposure, deletion requests. Asking 'do we actually need the customer's birth year for a newsletter' before the form ships is cheaper than answering it in a breach report later.

In practice it means designing for subtraction: forms that skip optional fields nobody uses, logs that pseudonymize IPs, retention schedules that actually delete, analytics that count events rather than hoard profiles. Data you never collected is data you never have to defend.

## Related terms

- https://dfieldsolutions.com/en/glossary/gdpr.md
- https://dfieldsolutions.com/en/glossary/least-privilege.md
- https://dfieldsolutions.com/en/glossary/encryption-at-rest.md

---

Source: https://dfieldsolutions.com/en/glossary/data-minimization
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
