Laws · GDPR ·art-5-par-1-pnt-c EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);
How it connects
Cited by
- Belgian DPA: Employer unlawfully disclosed employee health data to colleagues (115/2022)
- Guidelines 05/2020 on consent under Regulation 2016/679
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020
- Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them
- Guidelines 3/2019 on processing of personal data through video devices
All 105
- Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679
- Guidelines 02/2022 on the application of Article 60 GDPR
- Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR
- LUXEMBOURG DPA: Non-compliance with general data processing principles
- Mercadona S.A.: Insufficient legal basis for data processing
- Rhodes Municipal Transport Company: Insufficient fulfilment of data subjects rights
- AMPUDIA DIAZ, S.L.: Non-compliance with general data processing principles
- Régie autonome des transports parisiens: Non-compliance with general data processing principles
- HvJ EU 9 januari 2025, C‑394/23 (Mousse).
- hier
- EDPB Annual Report 2024
- EDPB comments on European Commission's Guidelines on Art. 28 DSA
- Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH
- Guidelines 3/2025 on the interplay between the DSA and the GDPR
- Opinion 2/2026 on the Proposal for a Directive amending Directives (EU) 2016/2341 and 2016/97 as regards the strengthening of the framework for occupational retirement provision
- Cass.Civ. - 15625/2026
- AG at CJEU: Facebook must "minimize" personal data for ads in EU
- EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (
- The Right to Be Forgotten in The Context of Mobile Number Recycling
- Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU
- Garante per la protezione dei dati personali (Italy) - 382/2026
- Garante per la protezione dei dati personali (Italy) - 385/2026
- BGH - VI ZR 375/2
- Generative AI and data protection
- Garante per la protezione dei dati personali (Italy) - 471/2026
- Garante per la protezione dei dati personali (Italy) - 10192784
- AEPD (Spain) - EXP202102529
- Garante per la protezione dei dati personali (Italy) - 10128005
- OVG Saarlouis - 2 A 165/24
- AEPD (Spain) - EXP202103746
- HDPA (Greece) - 32/2020
- EDPB Annual Report 2025
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- Statement 2/2024 on the financial data access and payments package
- Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR)
- EDPB Annual Report 2023
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- EDPB Annual Report 2022
- Opinion 25/2022 regarding the European Privacy Seal (EuroPriSe ) certification criteria for the certification of processing operations by processors
- EDPB Annual Report 2021
- EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)
- Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications
- Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects
- WhatsApp Ireland Ltd v European Data Protection Board
- Maximilian Schrems v Meta Platforms Ireland Limited
- Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens
- HTB Neunte Immobilien Portfolio geschlossene Investment UG & Co. KG and Ökorenta Neue Energien Ökostabil IV geschlossene Investment GmbH & Co. KG v Müller Rechtsanwaltsgesellschaft mbH and Others
- UF and AB v Land Hessen
- Norra Stockholm Bygg AB v Per Nycander AB
- VS v Inspektor v Inspektorata kam Visshia sadeben savet
- WhatsApp Ireland Ltd v European Data Protection Board
- WM and Sovim SA v Luxembourg Business Registers
- Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság
- Komisia za zashtita na lichnite danni and Tsentralna izbiratelna komisia v Koalitsia „Demokratichna Bulgaria - Obedinenie“
- OT v Vyriausioji tarnybinės etikos komisija
- SIA 'SS' v Valsts ieņēmumu dienests
- Data Protection Regulation and International Arbitration: Can There Be Harmonious Coexistence (with the GDPR Requirements Concerning Cross-Border Data Transfer)?
- CJEU - C‑209/23 - RRC Sports
- Garante per la protezione dei dati personali (Italy) - 457/2026
- Hoge Raad - ECLI:NL:PHR:2023:935
- DSB (Austria) - 2025-0.950.759
- OLG München - 36 U 1054/25 e
- AEPD fines El Español for publishing video of minor assailant without anonymization
- Garante per la protezione dei dati personali (Italy) - 462/2026
- Garante fines Lusha Systems Inc. over unauthorized B2B contact database
- DSB (Austria) - 2025-1.049.138
- Austrian FAC rules on publishing full court judgment naming witness on social media
- Finnish DPA: requesting address, ID number and strong authentication for access request
- APDCAT sanctions Madremanya City Council for inadequate redaction of sensitive data in
- BAC (Bulgaria) - 7890/2026
- Garante per la protezione dei dati personali (Italy) - 476/2026
- ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.
- Garante per la protezione dei dati personali (Italy) - 10273026
- VG Berlin: DPA correctly found residential video surveillance for property protection
- DSB: Retailer must grant full access and delete data after third-party fraud order
- UODO reprimands mayor for disclosing data subject's data to company without legal basis
- Finnish DPA examines anti-doping organization's GDPR compliance over public suspension
- Federal Administrative Court: retention of job applicant data for potential legal claims
- Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car
- AEPD: Continuous workplace audio recording violates GDPR data minimisation principle
- BVwG - W137 2334047-1
- Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on
- Persónuvernd (Iceland) - 2025010364
- CJEU - C-798/24 - Jautiva
- Italian DPA sanctions Top Secret Investigazioni for unjustified email forwarding after
- BVwG - W292 2298015-1
- AEPD: CaixaBank requested excessive inheritance documentation from heirs
- Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste
- Cyprus Court upholds DPA finding that Sigma TV unlawfully disclosed financial data
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- CJEU - C-458/25
- Finnish DPA finds 12-year retention of rental applicant data violates minimisation
- Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary
- DSB (Austria) - 2026-0.690.562
- Austrian Federal Administrative Court: address publisher's data transfer and Article 15
- Italian DPA: Municipality of Aprilia unlawfully disclosed whistleblower data to employer
- Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools
- ANSPDCP (Romania) - TIP TOP FOOD INDUSTRY SRL
- AEPD (Spain) - ps-00287-2025
Related across sources
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design
Guidelines 10/2020 restrictions under Article 23 GDPR Guidelines Oct 13, 2021 GDPR Subject-Matter and Objectives Right to Restriction Data Portability
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines Jul 7, 2021 Controllers Processors IP Address
Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines Jan 28, 2020 Personal Data Privacy by Design & Default Processing
Guidelines 01/2022 data subject rights - Right of access Guidelines Apr 17, 2023 Right of Access Personal Data Right to Rectification
2018 Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) Guidelines on transparency Apr 11, 2018 Transparency Information Provision Modalities and Communication Methods Fairness & Transparency