By Rebaone Fame Ditlale
Data minimization is a fundamental principle of data protection that requires organizations to collect only the personal data that is necessary for a specific and lawful purpose. According to Section 21 of the Data Protection Act No.18 of 2025, it is explained as “Personal data shall be adequate, relevant and limited to what is necessary in relation to the purpose for which it is processed.” In simple terms, it says, if you do not need the information, do not collect it. Continue reading as we analyse the aforementioned principle.
What is the issue?
Collecting unnecessary data can lead to non-compliance with data protection laws, potentially resulting in regulatory penalties, reputational damage, and legal consequences. Every piece of personal data collected carries a responsibility to be protected from unauthorized access, loss, misuse, or disclosure. When organizations collect excessive information, they increase the amount of data that must be managed and secured. This expands the organization’s risk in the event of a data breach. For example, if a job applicant needs to provide a name, qualifications, experience and contact number for recruitment purpose, requesting additional information such as marital status, religion, or Omang details may be unnecessary and unjustifiable.
Implementing data minimization
Data minimization should be integrated into every stage of an organization’s data lifecycle. Finding the specific reason for collecting personal data is the first step. After defining the purpose, organisations should carefully consider what information is actually needed to accomplish that goal. To remove unnecessary data categories, entities should regularly examine application forms, recruitment processes, client onboarding procedures, and digital platforms. Every question asked during mentioned processes should have a clear justification.
The benefits of less data
Adopting a data minimization approach provides numerous benefits beyond regulatory compliance. It reduces the organization’s overall risk by limiting the amount of sensitive information that could be compromised during a data breach. Less data means fewer opportunities for misuse or unauthorized access. Additionally, data minimization strengthens customer trust; individuals are more likely to engage with organizations that demonstrate respect for their privacy and collect information responsibly. Transparency about data collection practices can enhance an organization’s reputation and foster stronger relationships with customers and employees.
Our services
The Data Protection Act (DP Act) mandates every organization to put strict safeguards regarding personal data and in that regard, we can assist with crafting Data Protection Policies in line with the said Act. Some organizations such as schools, hospitals, regulatory bodies, etc, are required to have full-time Data Protection Officers (DPO). If you cannot afford a full-time DPO, we can act as your organization’s DPO on a contract basis. If you need training for your staff on the provisions of the Data Protection Act and other business courses such as Leadership & Supervisory Skills, Customer Care, Team Building as well as secondments of Tax, HR and DPOs, contact us at: +267 76 213 233 or +267 393 9435 or skills@aupracontax.co.bw. This article is general, and written advice or training is recommended if decisions are to be made. If you require to join our free WhatsApp groups or to know more about our services, please send us a text/WhatsApp on the numbers above.