Glossary · Security & governance

Data Minimization

For personal data, limiting what is collected, processed, exposed, and retained to what is necessary for a specified purpose. Teams can apply the same discipline to sensitive non-personal data as an engineering control.

Why it matters

Every unnecessary field placed in a prompt, trace, cache, or tool call increases privacy exposure and the possible impact of misuse or compromise.

In practice

Define the required fields before collection, redact or aggregate at the earliest boundary, set retention limits, and verify that optional context improves a measured task outcome before keeping it.

Common confusion

Minimization does not mean keeping no data. It means being able to justify each data element, use, recipient, and retention period against the stated purpose.

Related terms

Sources

Browse the learning paths to see this term in context — every lesson is free to read.