I recently posted a new paper draft co-authored with Professor Woodrow Hartzog: Meaningful Data Minimization. You can download it here for free. We welcome your feedback.
We argue that data minimization is one of the most important parts of privacy laws, and we explain why it is a crucial antidote to our data maximalist world.
Short synopsis:
Without meaningful data minimization, data privacy laws have little impact, and the data minimization in most laws is far from meaningful. This Article provides a roadmap for how to give data minimization the rigor it needs to do its essential work.
Here’s a longer abstract:
Data minimization—the requirement that entities should collect, process, or transfer only personal data that is necessary and proportionate to a particular purpose—is the heart and soul of privacy law. Most privacy laws include a data minimization principle, which in theory should reduce the amount of data collected and used to only what is needed and justified. Unfortunately, data minimization frequently ends up being meaningless in practice and rarely has any impact. Instead, the opposite of data minimization is occurring—entities are engaging in data maximization by collecting vaster quantities of personal data, processing it in a wide range of ways, and transferring it liberally.
In this Article, we unpack the promise and failure of data minimization. We argue that meaningful data minimization is the most indispensable data privacy protection. Without data minimization, it is impossible to bring even a semblance of order and responsibility to out-of-control surveillance capitalism. Although most laws mandate data minimization, it is often not meaningful. To be effective, privacy laws must take a different and more rigorous approach to data minimization.
Data minimization is woefully undertheorized. In this Article, we develop a robust theory of data minimization by explaining its origins, conceptual development, key components, and why it matters. Privacy laws take various approaches to data minimization, all of which include two basic prongs—purpose and tailoring. Purpose involves the reason for collecting and processing data and tailoring involves how closely connected the data activities are to the purpose. Most laws are far too open-ended on how they address purpose, which enables entities to evade data minimization by stating many broad and vague purposes. Most laws are also too loose on tailoring, requiring only that data activities be “reasonably necessary” for disclosed purposes.
We contend that to be meaningful, data minimization must specify a list of permissible and impermissible purposes and must require data activities to be strictly necessary for each purpose. We also argue that laws must include several other dimensions to make data minimization meaningful.
Simply put, without meaningful data minimization, data privacy laws have little impact, and the data minimization in most laws is far from meaningful. This Article provides a roadmap for how to give data minimization the rigor it needs to do its essential work.
You can download the paper here.
* * * *
Daniel J. Solove is the Bernard Professor of Intellectual Property and Technology Law at the George Washington University Law School. He is the founder of TeachPrivacy, a company that provides workforce privacy, cybersecurity security, and AI training to companies and organizations around the world. He is the author of 10+ books and 100+ articles.
You can follow his events, writings, training, cartoons, and resources by subscribing to his free weekly newsletter.
Subscribe to Solove’s Free Substack
A supplement to Solove’s regular newsletter with more in-depth discussions