Data minimisation
Using personal data that is adequate, relevant and limited to what is necessary for the purpose.
Data minimisation is the GDPR principle that personal data must be adequate, relevant and limited to what is necessary for the purposes for which it is processed. For an agent, it means requesting the narrowest access that does the job, such as one account instead of all of them or a date range instead of full history, and not passing more context to a model or tool than the step requires. Minimisation also reduces what can leak through prompt injection or logs.
Agent Minute explains this term on 2 December 2026.
Related terms
Purpose limitationCollecting personal data for specified, explicit and legitimate purposes and not reusing it in incompatible ways.Personal dataAny information relating to an identified or identifiable living person.OAuth scopeA value in an OAuth request naming the range of access a client asks for; the server may grant all, part or none of it.Sensitive information disclosureAn AI system revealing personal, confidential or security data through its outputs, logs or tool calls.