Collection Limitation Principle
The Collection Limitation Principle is a privacy principle stating that organizations should limit the amount of personal information they gather to what is actually needed. It is one of a set of foundational privacy principles and works alongside related ideas such as data minimization. It focuses specifically on the front-end step of collecting data, rather than how data is later used, stored, or secured.
The Collection Limitation Principle is one of the eight OECD privacy principles, alongside data quality, purpose specification, use limitation, security safeguards, and openness. It holds that the collection of personal data should be limited, and in practice this is applied in accordance with a data minimization approach that restricts collection to what is necessary for a given purpose. It is distinct from, but frequently paired with, purpose limitation (collecting data only for specified, explicit, and legitimate purposes) and use limitation (constraining later processing); the Collection Limitation Principle addresses the collection stage specifically and does not by itself govern downstream use, retention, or security, which are covered by separate principles. This entry is educational and not a substitute for professional or legal advice; the precise scope and force of these principles vary by applicable framework and jurisdiction and should be confirmed against primary sources.
Why it matters
The Collection Limitation Principle addresses the earliest and often most consequential stage of the data lifecycle: the decision about what personal information to gather in the first place. Data that is never collected cannot later be misused, breached, or over-retained. For compliance and ethics program managers, this makes the principle a foundational control point rather than a downstream remedy. It is one of the eight OECD privacy principles and, in practice, is applied in accordance with a data minimization approach that restricts collection to what is necessary for a given purpose.
The principle matters because it shapes the risk profile an organization carries. Excessive collection expands the volume of personal data that must be secured, governed, and eventually disposed of, and it can create friction with individuals' expectations about how their information is handled. It is important to note, however, that adhering to a collection limitation principle does not by itself guarantee compliance or protect against enforcement; it is one component within a broader set of privacy principles that includes data quality, purpose specification, use limitation, security safeguards, and openness. Its precise scope and force vary by applicable framework and jurisdiction.
Because the Collection Limitation Principle is frequently paired with purpose limitation and use limitation, program teams should be careful not to treat it as covering the full data lifecycle. It governs the collection stage specifically and does not by itself address downstream use, retention, or security, which are handled by separate principles. This glossary entry is educational and not a substitute for professional or legal advice, and the application of these principles to a specific program should be confirmed against primary sources and, where necessary, qualified counsel.
Who it's relevant to
Inside Collection Limitation Principle
Common questions
Answers to the questions practitioners most commonly ask about Collection Limitation Principle.