The principle of 'data minimisation' under GDPR requires that personal data must be what?
- A.Collected only with explicit consent, citing Recital 26, which states that anonymisation is achieved whenever data is stored on an encrypted server
- B.Encrypted at all times, under Article 5(1)(f), which requires that all personal data be stored exclusively within the EU regardless of security measures taken
- C.Anonymised before processing, and the rule caps fines at one percent
- D.Adequate, relevant, and limited to what is necessary for the purpose
Why D is correct
Data minimisation (Article 5(1)(c)) requires that personal data be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
Know someone studying for GDPR? Send them this one.