Data Minimisation Review
GDPR Principle: Collect only necessary data
GDPR Article 5(1)(c): Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ("data minimisation").
Essential Data
4 categories
Required for core functionality
Needs Review
3 categories
May contain excessive fields
Recommendations
5
Actions to minimize data
Data Collection Audit
Core User Data
Required for authentication and account management
Subscription Data
Required for billing and access control
Investor CRM Data
User-generated investor contact data
Analytics & Tracking
User behavior and page view tracking
Compliance Documents
KYC/AML verification documents
Error Logs
Technical error tracking
Admin Activity Logs
Administrator action tracking
Action Plan
Remove Low-Value Investor Fields
Job title and average response time provide minimal value. Consider removing from Investor entity schema.
Action Required:
Update entities/Investor.json - Remove job_title and avg_response_time_hours
Impact: Reduces data collection by 2 fields per investor
Limit Enriched Data Storage
enriched_data object in Investor entity may contain excessive third-party data. Implement strict field limitations.
Action Required:
Define specific fields allowed in enriched_data (e.g., only company size, industry)
Impact: Prevents storage of unnecessary third-party data
Reduce Analytics Retention
PageView data retained indefinitely. Implement automatic deletion after 90 days.
Action Required:
Create scheduled task to delete PageView records older than 90 days
Impact: Reduces database size and minimizes historical tracking
Remove Session Tracking
session_id in PageView entity provides limited value for analytics.
Action Required:
Remove session_id field from PageView entity
Impact: One less tracking field per page view
Implement Error Log Auto-Deletion
Error logs should be automatically deleted after 30 days.
Action Required:
Create scheduled task to purge ErrorLog records older than 30 days
Impact: Ensures error data is not retained longer than necessary
Implementation Notes
- • Entity Schema Changes: Backup database before removing fields from entity schemas
- • Data Deletion: Create scheduled tasks for automatic deletion of old data
- • User Communication: Notify users of any changes to data collection practices
- • Privacy Policy Update: Update privacy policy to reflect data minimisation efforts
- • Ongoing Review: Conduct quarterly data minimisation audits