Collection limitation
The privacy principle that personal data is collected only as far as needed, by lawful and fair means, and where appropriate with the knowledge or consent of the person it concerns.
Collection limitation is the first of the eight basic principles in the OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data (1980, revised 2013). It says there should be limits to the collection of personal data, that data should be obtained by lawful and fair means, and that the data subject should know about it or consent where appropriate. The principle governs the moment of collection, and the ISC2 outline lists data collection among the data lifecycle topics under objective 2.4.
The GDPR carries the same idea without using the OECD name. Article 5(1)(a) requires processing to be lawful, fair and transparent, and Article 5(1)(c) sets out data minimisation: personal data must be adequate, relevant and limited to what is necessary for the purpose. Collection limitation is closely tied to purpose limitation, because the purpose defines what counts as necessary, and to lawful basis, because each collection needs one.
Exam relevance: a scenario is likely to describe a form, application or project gathering more personal data than its stated purpose needs. Candidates are expected to prefer limiting collection at the source over protecting or deleting the excess later, and to link it to storage limitation at the other end of the lifecycle.