Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To apply data minimization, define a specific purpose for each business activity, collect only personal data adequate and relevant to that purpose, and set rules to review, delete, or anonymize data when it is no longer needed. Under the EU GDPR and UK GDPR, the purpose—not a blanket preference for collecting less—determines what information is necessary. The UK Information Commissioner’s Office (ICO) says its relevant guidance is under review following the Data (Use and Access) Act, so check current guidance for the rules that apply to your business.

What data minimization requires

Article 5(1)(c) of the GDPR says personal data must be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimisation).” The ICO reproduces this wording in its Principle (c): Data minimisation guidance.

In practice, this means neither collecting every potentially useful detail nor stripping away information needed to do the job. The amount and precision of data should fit a defined purpose. If a business grows or its activity changes, what is adequate may change too; the ICO gives the example of a growing organisation needing more membership and payment records to administer a substantially larger membership.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This article focuses on EU GDPR and UK GDPR guidance. These principles are not a substitute for checking the laws that apply in other jurisdictions or to your particular processing.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How to reduce collection without making data inadequate

1. Define the purpose before choosing fields

Write a clear purpose statement for each form, system, report, or service feature before deciding what information to request. For example, account administration, search, recommendations, and sharing may be distinct activities with different data needs. A purpose stated only as “improve the service” is unlikely to help teams determine which fields are genuinely needed.

Document the purpose in relevant privacy information and internal records. Purpose specification helps determine what data is needed and can reduce function creep: using information collected for one reason for a different, undeclared activity. The ICO explains the connection between purpose limitation and data minimization in its Principle (b): Purpose limitation guidance.

Rank #2
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

2. Justify each field against that purpose

Build a field inventory for each purpose. For every field, record why it is needed, how it is used, who can access it, and how long it is required. Ask whether the same result can be achieved with fewer fields, less precision, aggregation, or data that no longer identifies a person.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Keep a field when it is relevant and sufficient to achieve the documented purpose.
  • Make it optional or remove it when the purpose can still be achieved without it.
  • Reduce precision when a broader category, shorter location range, or less detailed record will work.
  • Use aggregated or anonymized information when the task does not require information about identifiable people.

Do not remove so much information that the remaining data is inadequate. The test is fit for purpose, not the smallest possible form.

Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

3. Consider identifiability as well as detail

Data minimization can involve collecting less detail, but it can also involve changing how information is handled after collection. Aggregated or anonymized data can support activities that do not require identifying individuals. Pseudonymisation can be useful when direct identification is no longer needed, but it is not a standalone solution: pseudonymized information may still be personal data.

The European Data Protection Board (EDPB) discusses these approaches in its February 2026 business-owner summary, Principles in practice: Key steps for business owners.

Rank #4
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

How to build minimization into forms and services

Apply data protection by design and by default before processing begins, then maintain it throughout the data lifecycle. The EDPB’s Guidelines 4/2019 on Article 25 Data Protection by Design and by Default explain this lifecycle approach.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Make mandatory only fields needed for the specific purpose.
  • Explain the purpose of optional fields so people can make an informed choice.
  • Assess separate service features independently instead of assuming the whole product needs the same data.
  • Set access and workflow defaults that expose information only to people who need it for their role.

For example, the information needed to administer an account may not be needed by a search feature or recommendation system. Treat each processing purpose as its own decision, rather than regarding an entire company or product as one undifferentiated activity. The EDPB’s Data protection guide for small business describes data protection by design and default for small businesses.

Best Value
Thetis BIOFP Plus FIDO2 Fingerprint Security Key Hardware Passkey with USB Type C/Biometric/FIDO Certified, 2FA / MFA Authenticator App Device, Works for Window, macOS, Linux, Gmail, Github
  • FIDO2 Certified Passkey Authentication: Officially FIDO2 certified for secure, passwordless login on supported platforms. Use modern passkeys with hardware-backed protection. Please verify your intended service supports FIDO2 hardware keys before purchase.
  • Precision Fingerprint Sensor: Built-in high-accuracy biometric fingerprint sensor ensures fast, convenient authentication while preventing unauthorized access. No PIN reuse, no shared secrets—only your fingerprint unlocks the key.
  • Strong Hardware 2FA/MFA Security: Enhances account protection with physical-presence and biometric verification, helping defend against phishing, credential theft, and account takeovers.
  • USB-C Wired Compatibility (No NFC): Designed for stable USB-C authentication on desktops and laptops, including Windows, macOS, and Linux systems. Ideal for users and enterprises that prefer wired-only security keys.
  • Durable Aluminum Shield, Portable Design: Features the same precision aluminum protective shield for long-term durability. Compact, lightweight, battery-free, and network-free-built for everyday carry and professional environments.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to review data already held

Compare existing records and fields with documented purposes. For each data store, identify information with no current use, records beyond their retention period, and data that could be aggregated or anonymized once identification is no longer needed. Assign an owner and recurring review schedule; then delete or anonymize data when appropriate.

There is no universal retention period established by the GDPR materials cited here. Set retention practices to match the purpose and applicable requirements, and record why each period is appropriate rather than keeping data indefinitely “just in case.”

How to document decisions and exceptions

Keep the reasoning behind each data category, retention period, and exception. The EDPB says organizations must be able to demonstrate compliance; records of processing and, in certain circumstances, a data protection impact assessment (DPIA) form part of that work. A DPIA is not automatically required for every data-minimization project: assess whether the particular processing meets the conditions for one.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A useful internal record connects each purpose to the fields used, their necessity, access, retention, and any less identifying or less detailed alternative considered. This makes it easier to revisit a decision if the service, audience, or processing changes.

When to check local guidance

Data-protection duties depend on the jurisdiction and processing involved. The ICO’s data-minimization guidance is marked as under review following the Data (Use and Access) Act. Check the regulator guidance currently applicable to your business, and do not assume that EU or UK guidance states the law everywhere.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.