Data minimization and your GDPR rights, in plain English
The safest piece of data is the one a company never collects. It cannot be breached, sold, subpoenaed, or leaked by a careless employee, because it does not exist. That plain idea sits at the centre of the GDPR under the name data minimization, and it is closely tied to a set of rights you hold over any personal data an organisation does keep. This guide explains what those words mean, why the principle is stronger than any promise, and how to act on your rights.
What "personal data" actually means
Personal data is any information that relates to an identified or identifiable person. That is broader than most people expect. It covers the obvious — name, email address, home address — but also an account id, an IP address, a device fingerprint, or a usage log that could be tied back to you. If a piece of information can single you out, on its own or combined with other data, it counts.
Once you see how wide the definition is, the appeal of collecting less becomes obvious. Every field a service stores is a small ongoing liability: something to secure, to disclose, to hand over on request, and to delete when its purpose ends. Minimization is the quiet hero of the GDPR precisely because it reduces that liability at the source rather than trying to manage it forever.
The minimization principle — Article 5(1)(c)
The GDPR lists a set of principles that govern all processing of personal data. One of them, in Article 5(1)(c), is data minimization: personal data must be adequate, relevant, and limited to what is necessary in relation to the purpose it is collected for. In plain terms, a company may collect only what it genuinely needs to do the specific thing it told you it would do — and nothing extra "just in case".
The word doing the heavy lifting is necessary, and it is a high bar. Necessary does not mean useful, convenient, or potentially valuable later. It means the stated purpose cannot be achieved without that data. A newsletter needs an email address. It does not need your date of birth, your phone number, or your precise location. When you notice a form asking for more than its purpose can justify, you are watching minimization being ignored.
Why minimization beats promises
A privacy policy is a promise about behaviour: we will not misuse your data. Minimization is a fact about architecture: the data is not here to misuse. The second is far stronger, because promises depend on the company staying honest, staying solvent, staying uncompromised, and staying in control of every employee and sub-contractor forever. Data that was never collected has none of those dependencies.
Consider what can go wrong with data a company holds. It can be stolen in a breach. It can be sold if the business is acquired or goes bankrupt. It can be demanded by a court order. It can be copied by an insider acting in bad faith. None of these risks apply to information that does not exist in the first place. A privacy claim backed by design is testable and durable; a claim backed only by policy asks you to trust that nothing will ever change.
Your rights over your data
When an organisation does hold your personal data, the GDPR gives you a set of rights over it. Each one is short to state, and most are found in Articles 15 to 21.
- Access (Article 15). You can ask what personal data an organisation holds about you and get a copy of it, along with an explanation of why it is held.
- Rectification (Article 16). You can have inaccurate data about you corrected and incomplete data completed.
- Erasure (Article 17). Often called the "right to be forgotten", you can ask for your data to be deleted when there is no good reason to keep it.
- Portability (Article 20). You can receive the data you provided in a common, machine-readable format and move it to another service.
- Restriction (Article 18). You can ask an organisation to pause its use of your data while a dispute or check is resolved, without deleting it.
- Objection (Article 21). You can object to certain processing, such as direct marketing, and it must stop.
Sitting alongside these is the right to complain to a supervisory authority — an independent regulator in your country — if you believe an organisation has mishandled your data. You do not have to resolve the matter with the company first.
Rights are the safety net; minimization is the reason you rarely need it. If a company never held your file names, your message content, or your location, then an access or erasure request over those things returns almost nothing — because there was almost nothing to return. Fewer fields collected means fewer places anything can go wrong.
Controllers, processors, and sub-processors
The GDPR splits responsibility into two roles. A controller decides why and how personal data is processed — it is the organisation you are dealing with. A processor handles data on the controller's instructions, such as a hosting provider or a payment company. When a processor brings in its own vendors, those are sub-processors, and they matter to you because your data may pass through their systems even though you never chose them directly.
A concrete example: MAIN OÜ, an Estonian private limited company (registry code 11272196), is the controller for classified. Its sub-processors are Cloudflare (hosting, storage, email delivery, and the Turnstile anti-abuse challenge), Google (advertising with certified consent, and optional Google sign-in), and Paddle (payments, acting as merchant of record). A minimized service keeps this list short and each role narrow, so that the fewest parties touch the least data.
What a minimized service looks like in practice
Principles are easiest to judge against a real design. classified shares end-to-end encrypted notes and files that self-destruct after a single view or download, and it illustrates minimization at each layer:
- No content, no file names. Notes and files are encrypted in your browser. The servers receive only an encrypted blob and an opaque id; the key never reaches them, there is no content logging, and file names are never received. There is nothing readable to store.
- Minimal metadata. If you make an account, the record is deliberately thin: email, an optional display name, a salted password hash (or a Google sign-in id), verification status, usage counts, and a share audit log holding each share's size, creation, expiry, download time, and status — never file names or content.
- Short retention. Shares are ephemeral: deleted on first view or download, or auto-expired at a chosen time-to-live between five minutes and twenty-four hours. Edge request logs are kept only briefly, for security. Data that is not needed does not linger.
- Delete anytime. Account data is kept only while the account exists and is deleted when you delete the account, which you can do at any time. Billing records are the one exception, kept by Paddle and MAIN OÜ for as long as tax law requires.
You can also use the tool with no account at all, on a free allowance — which is minimization taken to its natural end, since a service that needs no identity to work has almost nothing to collect.
How to exercise your rights
Acting on your rights is usually simple. You make a request to the controller — in writing is best, so there is a record — stating which right you want to use and enough detail to identify your data. The organisation should respond within a month, free of charge in ordinary cases, and either comply or explain in plain terms why it cannot. For some rights, the fastest route is built into the product: with classified, for example, you delete your account yourself and the associated data goes with it.
If you are not satisfied, you can escalate to a supervisory authority. For MAIN OÜ that authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon); in your own country it will be the equivalent regulator. To reach MAIN OÜ with a request or question, use the contact reveal on the mainly.art home page. The smoother a company makes these steps, the more seriously it tends to take the principle behind them.
- Data minimization (Article 5(1)(c)) means collecting only what is strictly necessary for a stated purpose.
- Data never collected cannot be breached, sold, subpoenaed, or leaked — architecture beats promises.
- Your core rights are access, rectification, erasure, portability, restriction, and objection, plus the right to complain to a regulator.
- A minimized service, like classified, stores no content or file names, keeps thin metadata, retains it briefly, and lets you delete your account anytime.
classified puts minimization into practice: no account required, no content or file names stored, and shares that delete themselves after one view. The less it holds, the less there is to protect.
Try classified free