Consent and data rights

Data minimisation

Using personal data that is adequate, relevant and limited to what is necessary for the purpose.

Data minimisation is the GDPR principle that personal data must be adequate, relevant and limited to what is necessary for the purposes for which it is processed. For an agent, it means requesting the narrowest access that does the job, such as one account instead of all of them or a date range instead of full history, and not passing more context to a model or tool than the step requires. Minimisation also reduces what can leak through prompt injection or logs.

Agent Minute explains this term on 2 December 2026.

Related terms