DOI: 10.69554/ubki3139 ISSN: 2398-5119

Data minimisation: A crucial pillar of cyber security

Paul Luehr, Brandon Reilly
As data security threats mount, businesses should not lose sight of a fundamental but powerful tool to mitigate risk: data minimisation. Businesses across industries should recognise the potentially devastating security, operational and compliance risks that arise from keeping old and unreliable data. Helpfully, the latest generation of privacy laws are increasingly mandating data minimisation, purpose limitation and other measures designed to protect individual privacy. Such measures have the additional benefit of shrinking the surface area for cyberattacks and other threats to the confidentiality, integrity and availability of data. Leveraging new laws and technology, companies should maximise the value of their information by focusing on sound data governance, ensuring that it is not just an ‘IT issue’. Then businesses should use new tools to map their data and determine its age and sensitivity and start minimising their retention and use of data that no longer meets current business or compliance requirements. Businesses can use a variety of techniques to slim their data profile, eg destruction, de-identification, tighter retention policies, privacy-enhancing technology. In the end, these minimisation actions will be well worth the effort. Businesses will unlock their data’s true value, increase their productivity and avoid the serious privacy and information security risks that come from housing data they no longer need.

More from our Archive