← GDPR · Principles

Art.5(1)(b) — Purpose limitation

high data-minimisationlawful-basis

Requirement

Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
purposepurposes
Required element 2 — any one of
specifiedlimited tonot used forcompatiblesecondary use
Supporting terms — specificity signals
documented purposefurther processingcompatibility assessmentno repurposing

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
ISO 27001 A.5.34 Privacy and protection of personally identifiable information lawful-basis data-minimisation
NDPA 2023 s.24 Principles of data processing lawful-basis data-minimisation
CCPA/CPRA 1798.100(c) Purpose limitation and data minimisation data-minimisation
SOC 2 P1.1 Notice and communication of privacy commitments lawful-basis
PCI DSS 4.0.1 3.3 Sensitive authentication data is not stored after authorisation data-minimisation
COPPA 312.7 No conditioning participation on excess data data-minimisation
NDPA 2023 s.25 Lawful basis for processing lawful-basis
NDPA 2023 s.30 Sensitive personal data lawful-basis