A product manager proposes collecting users' full chat histories indefinitely to enable "personalization" improvements. A privacy officer raises a data minimization objection. What is the specific GDPR principle being invoked?
- A.A. Accuracy - the data might be incorrect after a long time
- B.B. Data minimization (Article 5(1)(c)) - data collected must be adequate, relevant, and limited to what is necessary for the specified purpose
- C.C. Integrity and confidentiality - long retention increases breach risk
- D.D. Accountability - the company cannot document all the data it holds
Why B is correct
Data minimization (GDPR Article 5(1)(c)) directly addresses the scope and volume of data collection: it must be limited to what is adequate, relevant, and necessary for the stated purpose. Indefinite retention of full chat histories goes beyond what is necessary for personalization (aggregated preferences or recent sessions would suffice). Accuracy (Article 5(1)(d)) concerns correctness of data, not volume. Integrity and confidentiality (Article 5(1)(f)) is about security. Accountability (Article 5(2)) concerns demonstrating compliance.
Know someone studying for AI Security Fundamentals? Send them this one.