# Data minimisation · Glossary
The principle that an organisation should collect and process only the personal data that is adequate, relevant and limited to what is necessary for a stated purpose.
[Glossary](/glossary) · Data privacy and security

# Data minimisation

     The principle that an organisation should collect and process only the personal data that is adequate, relevant and limited to what is necessary for a stated purpose. It is one of the core data protection principles in UK GDPR.

## Why it matters

     Every extra field collected is one more thing to secure, justify, retain and potentially disclose in a breach. Minimisation reduces risk and often simplifies systems, because less data means fewer integrations and fewer edge cases.

     In AI projects the temptation is to include everything in case it helps the model. Minimisation asks teams to justify each input, which usually improves both compliance and model robustness.

## In practice

     For example, a UK retailer building a returns-fraud model might find that postcode district and order history perform as well as full address and date of birth. It can then drop the more sensitive fields from the training pipeline entirely.

## Where Rodan fits

     Rodan applies minimisation when designing data flows for AI and analytics in [AI and Decision Systems](https://rodan.io/what-we-build/ai-decision-systems) and documents the reasoning so it can be reviewed.

## Related terms

- [Personally identifiable information (PII)](/glossary/personally-identifiable-information)

- [Data retention](/glossary/data-retention)

- [Data protection impact assessment (DPIA)](/glossary/data-protection-impact-assessment)

- [Pseudonymisation](/glossary/pseudonymisation)

- [Responsible AI](/glossary#responsible-ai)
HTML: https://rodan.io/glossary/data-minimisation
