Article · June 17, 2026

What is the PDPL data minimization principle?

Understand PDPL data minimization: collect only what's needed, cut risk and cost, with shorter-form examples and practical implementation.

consent.vn Editorial6 min read

Quick answer

Under the PDPL, the data minimization principle means businesses should collect only the personal data necessary for the specified purpose—no extra “just in case.” This approach reduces leakage risk, lowers storage costs, and makes it easier to demonstrate compliance during inspections.

What is the PDPL data minimization principle?

This is a critical operational requirement in personal data protection: collect, use, and retain only the amount of data sufficient to achieve the lawful purpose you have disclosed. Simply put, if a field does not directly serve the business process, consider removing it from the form, API, or internal workflow.

Real-world example: a newsletter signup form only needs an email address. If a business asks for ID number (CMND/CCCD), date of birth, or home address without a clear purpose, you are increasing legal and operational risk. For SMEs, this is often the most common mistake: the longer the form, the more “convenient for later,” but it creates surplus datasets that are hard to govern.

Legally, the Personal Data Protection Law is the Personal Data Protection Law (Law 91/2025/QH15), expected to take effect from 01/01/2026 and replace Decree 13/2023/ND-CP. When implementing, businesses should read this principle as “collect enough to use, not for convenience.” The enforcement authority is the Ministry of Public Security — Department of Cybersecurity and High-Tech Crime Prevention (A05).

Why does collecting less data reduce risk?

Collecting less data is not just about a “cleaner record” but also real cost savings. The more data you hold, the more:

  • the attack surface grows in a security incident;
  • complex internal access control becomes;
  • time it takes to fulfill requests to access/delete/rectify data increases;
  • backup, encryption, inventory, and deletion costs rise.

Example: an e-commerce marketplace that collects images of ID cards (CCCD) from all customers at the account creation step will have to protect a more sensitive data category than necessary. Meanwhile, if the current business only needs phone number, email, and shipping address, collecting CCCD is inconsistent with the data minimization principle.

If a leak occurs, the impact scope is also narrower when you store less data. This is important because data breach notifications must be made within 72 hours from discovery. Less data usually means faster containment, faster investigation, and reduced harm to users.

How should businesses reduce form fields?

The most effective approach is to review each field with the question: “Is this field mandatory to fulfill the stated purpose?” If the answer is not clear, remove it or make it optional.

  1. Define the purpose first:

    State clearly what the form is for: account creation, ordering, consultation, or recruitment. Each purpose should only come with a corresponding minimal dataset.

  2. Review each data field:

    For each field, ask: if this field is missing, can the process still run? If yes, make it optional or remove it.

  3. Separate required and optional fields:

    Only mark as required those truly necessary fields. Do not make everything “required” for the convenience of sales or customer support teams.

  4. Separate different purposes into different forms:

    A newsletter subscription form, a quote request form, and a recruitment form should not share the same field set.

  5. Check what actually lands in your systems:

    Many businesses trim forms but still collect extra data via logs, CRM, Excel files, or internal notes. Review the entire flow.

  6. Schedule periodic reviews:

    Each quarter or whenever the product changes, review data fields to prevent gradual “bloat” over time.

Sample fields for a B2B consultation signup form:

  • Company name
  • Contact person’s full name
  • Work email
  • Work phone number
  • Consultation needs

Do not collect by default:

  • date of birth;
  • ID number (CCCD);
  • home address;
  • family relationships;
  • headshot photo, unless there is a clear purpose and lawful basis for processing under the regulations.

How does this principle apply to websites, apps, and internal systems?

On websites and apps, data minimization typically shows up in three areas: forms, cookies/trackers, and system logs. For cookies/trackers, businesses should not collect data just because they “want to measure everything.” Enable only the tools that truly serve the disclosed purposes of analytics, advertising, or personalization, and provide a clear consent management mechanism.

Internally, this principle also applies to:

  • HR files: retain only what is necessary for recruitment, payroll, insurance, and tax;
  • CRM: do not casually note down sensitive customer data;
  • support tickets: avoid asking customers to send unnecessary data;
  • technical logs: do not over-log tokens, passwords, card numbers, or document images.

A common SME mistake is “copying a competitor’s form wholesale.” But each business has different processing purposes. If you are a SaaS company, a demo form only needs contact information and usage needs; if you are a clinic, health data may trigger higher protection obligations under the regulations.

Do you need to retain data longer “just in case”?

You should not retain data longer just for contingency. Data minimization is not only about collecting less but also retaining less; once the purpose ends, delete or anonymize according to internal policy. Retaining “for later” often leads to stale datasets that are hard to classify, complicates DSAR handling, and increases risk when incidents occur.

If your business is using forms, a CRM, or a consent management system, design from the start with the principles: collect only what is necessary, retain for the right period, and be able to evidence the reason for collection. For tough questions on legal bases, sensitive data, or cross-border transfers, seek legal counsel to finalize the implementation.

It means asking users to fill in only the fields truly necessary to fulfill the form’s purpose; for example, a newsletter form needs only an email address.
Lower leakage risk, reduced storage and access-control costs, and easier handling of requests to access/delete/rectify data.
You should not if there is no clear purpose under the regulations. Collect only the data needed for the current business process.
Review the processing purpose, stop further collection, assess retention periods, and delete or anonymize unnecessary parts as required.

If your business is reviewing forms, cookie banners, or mechanisms for retaining consent evidence, consent.vn can help you standardize data collection flows from the start to avoid heavy rework later.

Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP: thuvienphapluat.vn. Enforcement authority A05: bocongan.gov.vn

Get started — no account needed.

Ready to comply with PDPL?

Get started