Data Dictionary

Purpose limitation

What is purpose limitation?

Purpose limitation is the rule that you decide why you are collecting personal data before you collect it, say so plainly, and then do not quietly reuse that data for something unrelated later. Data gathered to ship an order is for shipping the order, not for training a recommendation model or building an advertising audience, unless you can show the new use genuinely fits the original one.

It is one of the six data-protection principles at the heart of the GDPR, sitting alongside data minimisation, accuracy, and storage limitation.

What the GDPR requires

Article 5(1)(b) says personal data must be "collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes." Three words in that sentence do the work.

Specified means you name the purpose before collecting, not "for business reasons" but something a person could recognise, like "to deliver your order and handle returns".

Explicit means the purpose is written down and communicated, not left implied.

Legitimate means it rests on a lawful basis and does not conflict with other law.

Under the accountability principle in Article 5(2), you also have to be able to demonstrate all of this, so the purpose usually lives in a record: a processing register, a privacy notice, or a data governance catalogue entry with a named owner.

The compatible-use test

Purpose limitation does not freeze data forever. It bars processing that is incompatible with the original purpose, which is a softer bar than identical. If you want to reuse data for a new purpose, you weigh how close the new use is to the old one, what people would reasonably expect, the nature of the data, and the possible impact on them.

The GDPR names one built-in exception. Further processing for archiving in the public interest, scientific or historical research, or statistics is not treated as incompatible, provided you apply the safeguards in Article 89(1). So a hospital analysing treatment records for research stands on firmer ground than the same hospital selling patient data to an insurer.

Purpose limitation versus data minimisation

These two principles are often mentioned together and they lean on each other, but they answer different questions. Data minimisation asks how much data you may collect: only what the purpose needs. Purpose limitation asks what you may do with it once collected: only the purpose you named. One caps the volume, the other caps the use.

They meet at the point of reuse. The moment you consider a new use for data you already hold, purpose limitation makes you check compatibility, and minimisation makes you check whether that new use even needs all the fields you kept.

What to watch out for with purpose limitation

Purpose creep. The classic failure. Data collected for support tickets slowly ends up feeding marketing, then a model, then a partner integration, each step small and none of them the stated purpose. Name purposes narrowly and review new uses against them.

Vague catch-all notices. "We may use your data to improve our services" is not a specified purpose. It reads as permission for anything, which in practice means permission for nothing in particular.

Analytics as a blank cheque. Labelling a reuse "analytics" does not make it compatible. Repurposing PII into a new dataset is still further processing and still needs the test.

Forgetting the end date. A clear purpose also has a finish line. Once the purpose is met, keeping the data becomes a data retention problem even if the original collection was clean. Purpose and retention schedule belong together.

Last Updated: July 17, 2026 Back to Dictionary
Keywords
purpose limitation GDPR data minimisation data governance data retention PII privacy data protection governance personal data