A controller instructs a processor to collect forty optional fields ‘for future unknown projects’ with no current necessity. What principle does that instruction primarily conflict with?
Select an answer to reveal the explanation.
Short Explanation
‘Grab forty extra fields in case we invent a project later’ is a shopping spree, not data protection. Minimisation wants the shopping list tied to today’s purpose. Unknown future projects are not a blank cheque for speculative collection.
Full Explanation
Data minimisation under Article 5(1)(c) requires personal data to be adequate, relevant, and limited to what is necessary for the purposes. Instructing a processor to harvest numerous optional fields solely for undefined future projects is classic speculative collection and conflicts with minimisation and purpose specification. Controllers should collect what current, specified purposes require—not warehouse fields against unspecified later ideas.