Security & governance · Glossary term
What is Data Minimization?
For personal data, limiting what is collected, processed, exposed, and retained to what is necessary for a specified purpose. Teams can apply the same discipline to sensitive non-personal data as an engineering control.
Why does Data Minimization matter?
Every unnecessary field placed in a prompt, trace, cache, or tool call increases privacy exposure and the possible impact of misuse or compromise.
Data Minimization in practice
Define the required fields before collection, redact or aggregate at the earliest boundary, set retention limits, and verify that optional context improves a measured task outcome before keeping it.
What is the common confusion about Data Minimization?
Minimization does not mean keeping no data. It means being able to justify each data element, use, recipient, and retention period against the stated purpose.
Learn Data Minimization in the course
No lesson links to this term yet. Search the course catalog for it.
Related terms
- Purpose LimitationFor personal data, collecting and using it only for specified, explicit purposes unless a new use has an appropriate compatible or…
- Data ClassificationAssigning data to documented sensitivity or impact classes so handling, access, retention, sharing, and incident rules follow the…
- Least PrivilegeGiving a model, agent, tool, or user only the permissions required for the current task, for only as long as those permissions are needed.
- Context EngineeringDesigning the full information environment supplied to a model at each step, including instructions, selected files, retrieved evidence,…
- Membership InferenceAn attack that estimates whether a particular record or example was included in a model's training data by observing model outputs or…
Sources
More terms in Security & governance
- AI Risk Assessment
- Audit Log
- Content Provenance
- Data Classification
- Data Exfiltration
- Data Lineage
- Datasheet for Datasets
- Defense in Depth
- Indirect Prompt Injection
- Jailbreak
- Membership Inference
- Provenance Attestation
- Purpose Limitation
- Red Teaming
- Separation of Duties
- Software Bill of Materials (SBOM)
- Threat Model
- Trust Boundary
- Zero Trust
This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.