Glossary · Security & governance
Data Minimization
For personal data, limiting what is collected, processed, exposed, and retained to what is necessary for a specified purpose. Teams can apply the same discipline to sensitive non-personal data as an engineering control.
Why it matters
Every unnecessary field placed in a prompt, trace, cache, or tool call increases privacy exposure and the possible impact of misuse or compromise.
In practice
Define the required fields before collection, redact or aggregate at the earliest boundary, set retention limits, and verify that optional context improves a measured task outcome before keeping it.
Common confusion
Minimization does not mean keeping no data. It means being able to justify each data element, use, recipient, and retention period against the stated purpose.
Related terms
Sources
Browse the learning paths to see this term in context — every lesson is free to read.