Learn
What Is Data Minimization?

Data minimisation is the principle that an organisation should collect, process, and retain only the personal data that is necessary for a specific, stated purpose. If a service needs your email address to send you notifications, it should collect your email address. If it does not need your phone number, date of birth, or home address to provide that service, it should not ask for them.
The idea is straightforward, and it is codified in law in many jurisdictions. In practice, most of the software people use every day ignores it.
Where the principle comes from
Data minimisation has roots in privacy frameworks that predate the internet. The Fair Information Practice Principles, developed in the 1970s, included concepts of purpose limitation and collection limitation that are closely related. The OECD's 1980 privacy guidelines formalised the idea that personal data collection should be limited to what is relevant.
The principle gained legal teeth with the European Union's General Data Protection Regulation, which took effect in 2018. Article 5(1)(c) of the GDPR states that personal data shall be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed." This is not a suggestion. Organisations that process the personal data of EU residents are legally required to practise data minimisation, and violations can result in substantial fines.
Similar principles appear in other regulations. Brazil's LGPD, California's CCPA (as amended by the CPRA), and various other data protection laws include requirements around limiting data collection to what is necessary. The direction of regulation globally is toward requiring minimisation, not away from it.
Privacy-by-design, a framework developed by Ann Cavoukian and now embedded in the GDPR, treats minimisation as a foundational principle. The idea is that privacy protections should be built into systems from the start, not added after the fact. Collecting minimal data is one of the most effective privacy protections available because it reduces risk at the source.
Why most apps collect more than they need
If data minimisation is both a legal requirement and a sound principle, why do so many applications ignore it? The reasons are largely economic.
Data has value beyond its immediate purpose. A social media app needs your name and email to create an account. But your location history, browsing habits, contact list, and app usage patterns have value for advertising, analytics, and product development. The marginal cost of collecting additional data points is low, and the potential value is high. This creates an incentive to collect everything available, even if most of it is never used.
The "collect now, figure out the use later" mentality is widespread in technology companies. Data that has no current use might become valuable for a future product, a machine learning model, or a business pivot. Storing data is cheap. Deciding in advance what you will and will not need requires discipline and foresight that run counter to the prevailing culture of rapid iteration.
AI training has intensified the incentive. Large language models and other AI systems require vast quantities of data. Companies that have accumulated large datasets of user behaviour, content, and preferences have a competitive advantage in building AI products. This has made user data more valuable than ever, which makes minimisation more costly from a business perspective, even as it becomes more important from a privacy perspective.
Advertising-driven business models depend on detailed user profiles. The more a platform knows about you, the more precisely it can target advertising, and the more it can charge advertisers. Data minimisation is fundamentally at odds with this model, which is why advertising-funded services tend to be the worst offenders.
Third-party SDKs and analytics tools embedded in applications often collect data independently of the app's own stated purposes. A developer might include an analytics library that tracks user behaviour in ways the developer does not fully understand or control. The result is data collection that the app's privacy policy may not adequately describe.
Examples of unnecessary data collection
The gap between what an app needs and what it collects is often striking.
A torch app that requests access to your contacts and location is collecting data that has no connection to turning on your phone's LED. This example sounds absurd, but it was common enough in the early years of mobile app stores that it became a standard illustration of the problem.
More contemporary examples are subtler but more consequential. A note-taking app that requires access to your camera roll, microphone, and location to function. A weather app that tracks your precise location history and sells it to data brokers. A fitness app that collects your health data and shares it with insurance companies. A messaging app that scans your messages to build advertising profiles.
Even services that are not obviously exploitative often collect more than necessary. A productivity tool that asks for your name, email, phone number, company name, job title, team size, and industry when all it needs is an email address. A cloud storage service that scans the contents of your files for its own purposes. A search engine that retains your complete search history indefinitely.
The pattern extends to permissions. Mobile operating systems have improved their permission models, but many apps still request broad permissions on first launch. An app that requests contacts access "to help you find friends" may retain your entire contact list permanently, even if you never use that feature.
How minimisation relates to security
Data minimisation is often discussed as a privacy principle, but its security implications are equally important. The relationship is direct: data that is not collected cannot be exposed in a breach.
When an organisation collects and stores personal data, it takes on the responsibility of protecting that data. Every additional data point increases the potential impact of a breach. If a service stores only email addresses and hashed passwords, a breach exposes limited information. If that same service also stores phone numbers, dates of birth, physical addresses, and payment card details, the same breach becomes far more damaging.
The National Public Data breach in 2024 illustrated this starkly. A data broker that most affected individuals had never heard of had accumulated billions of records containing names, addresses, and Social Security numbers. The data was collected and aggregated for commercial purposes, and when the breach occurred, the consequences fell on the individuals whose data had been collected without their knowledge or consent.
Zero-knowledge encryption and end-to-end encryption can mitigate the impact of breaches, but they work best in combination with minimisation. Encrypting a minimal dataset is more secure than encrypting a maximal one, because the attack surface is smaller and the consequences of any failure are limited.
For organisations building software, the calculus is clear. Every piece of data you collect is a liability as well as an asset. Collecting less means less to protect, less to lose, less to explain to regulators, and less damage if something goes wrong.
What to look for in privacy-respecting tools
Not every service that claims to respect privacy does so in practice. There are some indicators worth checking.
Read the privacy policy, or at least the data collection section. A privacy-respecting service should clearly state what data it collects, why it collects it, and what it does with it. Vague language about "improving our services" or "enhancing your experience" often covers broad data collection. Specificity is a good sign.
Check what permissions the app requests and whether they correspond to its function. A cloud storage service that requests file access is reasonable. A cloud storage service that requests microphone access is not.
Look for services that offer encryption by default, particularly end-to-end or zero-knowledge encryption. If the provider cannot read your data, they have less incentive to collect metadata about it.
Consider the business model. Services funded by subscriptions have less incentive to monetise your data than services funded by advertising. This is not a universal rule, but it is a useful heuristic. A service that charges you a transparent price for a clear set of features is more likely to treat your data as something to protect than as something to extract value from.
Check whether the service supports data portability. A service that makes it easy to export your data and leave is signalling confidence in its product and respect for your autonomy. A service that makes leaving difficult may be relying on lock-in rather than quality.
Look at whether the service uses your data to train AI models. Many cloud and productivity services have updated their terms to allow the use of customer data for AI training. A service that explicitly does not train on your data, as Fabric states in its privacy and security practices, is applying the minimisation principle to one of the most consequential uses of personal data today.
Practical steps for individuals
You cannot control how every organisation handles your data, but you can reduce your exposure and make more deliberate choices.
Audit your app permissions periodically. On both iOS and Android, you can review which apps have access to your location, contacts, camera, microphone, and other sensitive capabilities. Revoke access for any app that does not need it for its core function. Most apps will continue to work normally without the broad permissions they request.
Reduce the number of accounts you maintain. Every account is a data relationship with an organisation. Deleting accounts for services you no longer use removes data from their servers (assuming they honour deletion requests, which regulations like the GDPR require). Understanding what happens to your data when you leave a service helps you make informed decisions about which accounts to keep.
Consolidate where you can. Having files in a dozen different cloud services means a dozen organisations hold your data. A centralised workspace that connects to your existing services and brings your data into one encrypted, searchable place reduces the number of separate data relationships you maintain. This aligns with the concept of a personal data vault, which applies minimisation at the individual level by consolidating data into fewer, more controlled locations.
Use privacy-focused alternatives where they exist. Privacy-respecting search engines, browsers, email providers, and messaging apps are available and have matured significantly. The trade-offs in features and convenience have narrowed.
Be deliberate about what you share when signing up for services. If a field is optional, leave it blank. If a service requires information that seems disproportionate to its function, consider whether you want to use it. The data you do not provide is the data that cannot be collected, sold, or breached.
Read the data practices section of privacy policies for services that handle sensitive information. You do not need to read every policy for every service, but for the tools that hold your most important files and information, understanding how they handle your data is worth the time.
Fabric's approach
Fabric collects the data needed to provide the service: account information, the files and content you store, and the metadata required for features like search and AI assistance. It does not use customer data to train AI models. It supports encryption and offers options for controlling where your data is stored. This is not presented as exceptional. It is what the principle of data minimisation, applied consistently, looks like in a cloud workspace.
Frequently asked questions
Is data minimisation a legal requirement?
In the European Union, yes. Article 5(1)(c) of the GDPR requires that personal data be "limited to what is necessary." Similar requirements exist in Brazil's LGPD, California's CPRA, and other data protection laws. Enforcement varies by jurisdiction, but the legal trend is toward stricter minimisation requirements.
How does data minimisation relate to GDPR?
Data minimisation is one of the GDPR's core data processing principles. Organisations must collect only the data necessary for a specific, stated purpose, retain it only as long as needed, and be able to justify each data point they collect. Non-compliance can result in fines of up to four percent of global annual revenue.
Can a company still provide a good service while minimising data collection?
Yes. Many services that collect minimal data provide excellent functionality. The misconception that more data collection equals better service is driven more by advertising-funded business models than by technical necessity. A search feature can work well on the data you choose to store without requiring access to your contacts, location, or browsing history.
What is the difference between data minimisation and data anonymisation?
Data minimisation means collecting less data. Anonymisation means processing data to remove identifying information. They are complementary techniques: minimisation reduces what is collected, and anonymisation reduces the sensitivity of what remains. Both reduce risk, but minimisation is more fundamental because anonymous data can sometimes be re-identified.
How do I know if an app is collecting more data than it needs?
Check the app's permissions on your device and compare them to its stated function. Review the privacy policy's data collection section. If an app with a simple purpose collects a wide range of personal data or requests broad device permissions, it is likely collecting more than it needs.
Does data minimisation apply to files I store in the cloud?
Data minimisation as a legal principle applies to organisations collecting your personal data, not to your own storage choices. But the underlying logic applies at a personal level too: storing sensitive files in fewer, more secure locations reduces your exposure. A personal data vault approach applies this thinking to your own data management.
Why do free apps tend to collect more data?
Free apps are often funded by advertising, which relies on detailed user profiles for targeting. Your data is the product being sold. This creates a structural incentive to collect as much data as possible. Paid services that derive revenue from subscriptions have less reason to monetise user data, though a subscription model does not guarantee minimisation.
Can data minimisation prevent data breaches?
It cannot prevent breaches from occurring, but it limits their impact. An organisation that stores only email addresses and hashed passwords exposes far less in a breach than one that also stores phone numbers, addresses, financial data, and behavioural profiles. Less data collected means less data at risk.
What should I do if a service requires too much personal information?
Consider whether the service is worth using given what it asks for. If it is, provide only the required fields and leave optional fields blank. If the required data seems disproportionate to the service's function, look for alternatives that collect less. Services that respect data portability make it easier to switch if you find a better option.
How does data minimisation interact with AI features?
AI features often benefit from more data, which creates tension with minimisation. The resolution depends on architecture. An AI assistant that processes your data within an encrypted environment, without sending it to external services or using it for training, can provide useful AI features while respecting minimisation principles. The key question is whether the AI processing happens within the security boundary you control.