Skip to content
Legiscope
Menu
Data Privacy

GDPR Data Minimisation and Purpose Limitation: Official

GDPR data minimisation (Art 5(1)(c)) and purpose limitation (Art 5(1)(b)): official Commission text, EDPB guidance, cases, implementation.

In one sentence. GDPR Article 5(1)(b) purpose limitation requires that personal data be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes; Article 5(1)© data minimisation requires that data be adequate, relevant and limited to what is necessary in relation to those purposes. Together they form the collection-side core of GDPR compliance. Official text: Regulation (EU) 2016/679, Article 5 on EUR-Lex, reaffirmed in European Commission GDPR guidance.

These two principles are sanctioned under Article 83(5)(a) — the top tier (€20M / 4%). They are the most-invoked principles in CJEU rulings and DPA decisions because they govern what data may be collected at all.

Key takeaways

  • Purpose limitation = specified, explicit, legitimate + no incompatible further use.
  • Data minimisation = adequate, relevant, limited to what is necessary.
  • Both are principles (Article 5) — breach is among the most serious GDPR infringements.
  • Compatibility test (Article 6(4)) governs further processing.
  • Statistical, research and archiving purposes are deemed compatible (Article 5(1)(b) + Article 89).
  • Sanctions: Article 83(5)(a) — up to €20M or 4% of global turnover.

1. Article 5 official text (excerpts)

  1. Personal data shall be: (a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’); (b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’); © adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);

Source: EUR-Lex, European Commission.

2. Purpose limitation: three requirements

(a) Specified: precise enough to enable accountability — “marketing” is too vague; “monthly newsletter about product X” is acceptable. (b) Explicit: communicated to the data subject in a transparent privacy notice (Articles 13-14). © Legitimate: lawful under GDPR and EU/national law.

Plus: no incompatible further processing.

Purpose limitation is upstream of the lawful-basis analysis: you cannot pick a valid Article 6 lawful basis until the purpose is defined with precision, because the basis attaches to a specific purpose, not to the data in the abstract. A deeper treatment of the principle itself is in the purpose limitation explainer.

3. The Article 6(4) compatibility test

If a controller wants to process collected data for a new purpose, Article 6(4) sets a compatibility test:

  • Link between original and new purpose
  • Context of collection (relationship with data subject)
  • Nature of the data (special categories?)
  • Possible consequences for the data subject
  • Existence of appropriate safeguards (encryption, pseudonymisation)

A compatible further purpose can be pursued without a new legal basis. Incompatible = new consent or other Article 6 basis required. In practice, the safest reuse cases are analytics and internal quality improvement on data already held under contract; the most dangerous are onward disclosure to third parties and any repurposing that a reasonable data subject would not have expected at collection.

4. Data minimisation: three requirements

(a) Adequate: sufficient to fulfil the purpose (b) Relevant: linked to the purpose © Limited to what is necessary: nothing more

Common failures: collecting date of birth when only an age range is needed; storing full IP when last octet suffices; HR systems retaining CVs of rejected candidates indefinitely.

5. Necessity test (EDPB and CJEU)

EDPB Guidelines and CJEU consistently apply a strict necessity test:

  • The data must be objectively necessary for the purpose
  • “Useful” or “convenient” is not enough
  • The least intrusive option must be preferred (privacy by default — Article 25)

5a. Where minimisation fails in real systems

The gap between the principle and the deployment is almost always at the point of collection. Product and growth teams add form fields “in case they are useful later”; analytics SDKs capture full device fingerprints when a coarse segment would do; onboarding flows demand a date of birth where an age gate would suffice. Each of these is a minimisation breach waiting for an auditor. The data minimisation deep-dive sets out a field-by-field method: for every input, name the specific purpose it serves, and if no purpose survives the necessity test, remove the field. Special-category data raises the bar further — collecting health, biometric or ethnicity data “to be safe” is not merely disproportionate, it triggers the Article 9 conditions and a far higher enforcement risk. H&M’s €35.3M fine (HmbBfDI, 2020) is the canonical warning: it turned on managers recording employees’ health details and family circumstances that no legitimate HR purpose required.

6. Relationship with Article 25 (privacy by design)

Article 25 operationalises minimisation: technical and organisational measures must ensure that by default only data necessary for each specific purpose are processed. Privacy by design and by default is the enforcement hook that turns the abstract principle into a system requirement. This affects:

  • Default form fields (optional vs mandatory)
  • Default visibility settings
  • Default data retention
  • Default API field exposure

7. CJEU case law

  • C-291/12 Schwarz — biometric passport: even mandatory data must be minimised
  • C-13/16 Rīgas — necessity over usefulness
  • C-708/18 Asociaţia de Proprietari — CCTV minimisation
  • C-439/19 Latvijas — public data registers; purpose limitation extends
  • C-184/20 OT — special category data + purpose limitation

8. DPA enforcement — purpose limitation cases

  • Google (CNIL 2019): €50M — vague purposes for ads personalisation
  • H&M (HmbBfDI 2020): €35.3M — employee profiles beyond purpose
  • WhatsApp (Irish DPC 2021): €225M — transparency + purpose
  • Amazon (CNPD Luxembourg 2021): €746M — ad targeting purposes
  • Meta (Irish DPC 2023): €390M — behavioural ads basis + purpose

9. DPA enforcement — minimisation cases

  • Deutsche Wohnen (Berlin 2019): €14.5M — tenant data over-retention
  • Marriott (ICO 2020): £18.4M — passport scans beyond necessity
  • Discord (CNIL 2022): €800,000 — log retention disproportionate
  • Multiple HR cases — over-collection of medical data

10. Implementation checklist

11. Tooling

FAQ

What is purpose limitation under GDPR Article 5?

Personal data must be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes (Article 5(1)(b)). Compatibility for new purposes is tested under Article 6(4).

What does data minimisation require?

Article 5(1)© requires data to be adequate, relevant and limited to what is necessary for the purposes. EDPB and CJEU apply a strict necessity test, not mere usefulness.

Where is the official European Commission text?

European Commission — GDPR principles and the official Regulation on EUR-Lex.

Can I reuse data for a new purpose?

Only if compatible under Article 6(4) (link, context, nature, consequences, safeguards). Otherwise a new legal basis is required, typically consent.

What’s the sanction for breaching these principles?

Top tier: up to €20M or 4% of global turnover (Article 83(5)(a)). Amazon €746M (CNPD 2021) is the leading purpose-limitation sanction.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

GDPR Data Minimisation and Storage Limitation: Official

In one sentence. GDPR Article 5(1)(c) data minimisation and Article 5(1)(e) storage limitation are the two quantity-control principles: minimisation governs how much data is collected (only what is…

June 3, 2026
02Data Privacy

EUR-Lex GDPR Article 5 Storage Limitation: Official

In one sentence. GDPR Article 5(1)(e) storage limitation — the official text published on EUR-Lex Regulation (EU) 2016/679 — requires that personal data be kept in a form which permits identification…

June 3, 2026
03Data Privacy

GDPR Purpose Limitation: 7 Examples + Documentation Template

Definition. The GDPR purpose limitation principle (Article 5(1)(b)) requires that personal data be collected for specified, explicit, and legitimate purposes, and not further processed in a manner…

September 29, 2024
04Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
05Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

GDPR Article 46 lists multiple safeguards for international data transfers. Three dominate practice: Binding Corporate Rules (BCRs), Standard Contractual Clauses (SCCs), and the EU-U.S. Data Privacy…

April 30, 2026
06Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — so the software a DPO uses is now itself an accountability signal.

July 7, 2026
07Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
08Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026