---
term: "Data minimisation"
category: "Consent and data rights"
url: https://agenticopenfinance.com/glossary/data-minimisation
source: AgenticOpenFinance glossary
---

# Data minimisation

> Using personal data that is adequate, relevant and limited to what is necessary for the purpose.

Data minimisation is the GDPR principle that personal data must be adequate, relevant and limited to what is necessary for the purposes for which it is processed. For an agent, it means requesting the narrowest access that does the job, such as one account instead of all of them or a date range instead of full history, and not passing more context to a model or tool than the step requires. Minimisation also reduces what can leak through prompt injection or logs.

Related terms: [Purpose limitation](https://agenticopenfinance.com/glossary/purpose-limitation.md), [Personal data](https://agenticopenfinance.com/glossary/personal-data.md), [OAuth scope](https://agenticopenfinance.com/glossary/oauth-scope.md), [Sensitive information disclosure](https://agenticopenfinance.com/glossary/sensitive-data-leakage.md)
