Security & governance · Glossary term
What is Purpose Limitation?
For personal data, collecting and using it only for specified, explicit purposes unless a new use has an appropriate compatible or authorized basis.
Why does Purpose Limitation matter?
Data that was acceptable for one workflow can create privacy and governance risk when silently reused for model training, evaluation, personalization, or unrelated analytics.
Purpose Limitation in practice
Record the purpose with each dataset, check new pipelines against it before access, separate incompatible uses, and require a documented decision when the purpose changes.
What is the common confusion about Purpose Limitation?
Purpose limitation governs why data is used. Data minimization governs how much data that purpose actually requires.
Learn Purpose Limitation in the course
No lesson links to this term yet. Search the course catalog for it.
Related terms
- Data MinimizationFor personal data, limiting what is collected, processed, exposed, and retained to what is necessary for a specified purpose.
- Data ClassificationAssigning data to documented sensitivity or impact classes so handling, access, retention, sharing, and incident rules follow the…
- AI Risk AssessmentA documented analysis of how an AI system can affect people, organizations, and environments, including context, hazards, likelihood,…
- Audit LogA durable, access-controlled record of security- or accountability-relevant events, including who or what acted, what changed, when it…
Sources
More terms in Security & governance
- AI Risk Assessment
- Audit Log
- Content Provenance
- Data Classification
- Data Exfiltration
- Data Lineage
- Data Minimization
- Datasheet for Datasets
- Defense in Depth
- Indirect Prompt Injection
- Jailbreak
- Membership Inference
- Provenance Attestation
- Red Teaming
- Separation of Duties
- Software Bill of Materials (SBOM)
- Threat Model
- Trust Boundary
- Zero Trust
This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.