Data minimisation
The principle that personal data collected and kept should be adequate, relevant and limited to what is necessary for the stated purpose, as set out in GDPR Article 5(1)(c).
Data minimisation holds that an organisation should collect, keep and expose only the personal data it actually needs for a defined purpose. GDPR Article 5(1)(c) states it as a processing principle: personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed. Article 25 carries the idea into design: by default, only the personal data necessary for each specific purpose is processed. Earlier privacy frameworks express a similar idea, notably the collection limitation principle in the OECD Privacy Guidelines of 1980.
Purpose limitation fixes why data may be processed, minimisation limits how much data that purpose justifies, and storage limitation limits how long it is kept. Collection limitation is the closest older equivalent. For security, minimisation shrinks what a breach can expose and reduces aggregation risk, because data that was never collected cannot be combined, leaked or demanded by a third party. Where data cannot be removed entirely, pseudonymisation and data masking reduce exposure.
Exam relevance: a scenario is likely to describe a form, system or data set that gathers more personal data than the task requires. Candidates are expected to recognise that collecting less tends to be a stronger control than protecting data that did not need to be collected at all.