Data minimisation means collecting, using and keeping only the data necessary for a purpose. It's a legal principle in many privacy laws and good practice for AI.
Why It Matters
- Less data means less exposure in breaches.
- Fewer privacy obligations and simpler compliance.
- Lower storage and processing costs.
- Reduced risk of models memorising sensitive information.
Applying It
- Question each field: does the model need it? Test whether removing it hurts performance.
- Aggregate or generalise: age ranges instead of birth dates; regions instead of addresses.
- Pseudonymise: replace identifiers with tokens.
- Redact personal data from text before indexing or training.
- Set retention periods and delete data when they expire.
- Limit logging of prompts and outputs.
Tension With AI
AI teams often want "all the data". Evaluation showing which data actually improves results supports proportionate choices.
Document Decisions
Record what data is used, why, and how long it's kept.