Purpose limitation (purpose specification)
The privacy principle that personal data is collected for specified, explicit and legitimate purposes, and is not later used in ways incompatible with those purposes.
Purpose limitation requires an organisation to decide and state why it is collecting personal data before it collects it, and then to keep its use of the data within that purpose. GDPR Article 5(1)(b) sets it out as collection for specified, explicit and legitimate purposes, with no further processing that is incompatible with them. Further processing for archiving in the public interest, scientific or historical research, or statistical purposes is not treated as incompatible, subject to safeguards. The idea predates the GDPR: the 1980 OECD Privacy Guidelines express it as a Purpose Specification Principle and a Use Limitation Principle.
Purpose limitation anchors several other principles. The stated purpose sets how much data is adequate under data minimisation, how long it may be kept under storage limitation, and which lawful basis applies. It also supports collection limitation. A common failure is function creep: data gathered for one reason, such as delivering orders, is later reused for an unrelated one, such as marketing profiles, without a fresh assessment or basis.
Exam relevance: a scenario may describe data collected for one reason and reused for another, and ask which principle is at risk. Candidates are expected to identify purpose limitation, and to recognise that the purpose is set before collection rather than justified afterwards.