Privacy & regulation · also called Data minimisation
Data minimization
Data minimization is the privacy principle that organisations should collect and keep only the personal data that is adequate, relevant and necessary for a specific, stated purpose.
The simplest way to protect data is not to collect it. Data minimization asks every system: do you really need this field, this precise location, this full birth date, and for how long? It is written into GDPR Article 5(1)(c), and appears in California's CCPA / CPRA regulations, India's India DPDP Act and other laws.
In advertising, minimisation might mean passing coarse location instead of GPS coordinates in bid requests, truncating IP addresses, limiting the data fields shared with each bidder, shortening retention of logs, or using aggregated reporting instead of user-level exports. The bidstream has been criticised by regulators for broadcasting more data to more parties than necessary.
There is a genuine tension with fraud detection, which benefits from rich signals. The practical answer is purpose-specific processing: collect the signals needed to detect invalid traffic, use them only for that purpose, secure them, and delete them when no longer needed. Minimisation is also a business advantage: less data means less breach risk and fewer compliance obligations.
Think of it like this
Data minimization is like packing for a trip with only what you will use, rather than bringing your entire wardrobe just in case.
An example
An SSP in Europe changes its bid requests to send only city-level location and truncated IPs to most bidders, keeping full IPs only for its accredited fraud-detection partner.
Related terms
GDPR
The GDPR (General Data Protection Regulation) is the European Union's data protection law, applying since May 2018, which governs how organisations collect and use personal data about people in the EU.
PII (personally identifiable information)
PII (personally identifiable information) is information that identifies, or can be used to identify, a specific person, such as a name, email, phone number or government ID number.
Pseudonymous data
Pseudonymous data is personal data where direct identifiers are replaced with a code, such as a hashed email or random ID, so it cannot identify someone without additional information kept separately.
Bidstream
The bidstream is the continuous flow of bid requests and responses exchanged in real-time bidding, and the data they carry about sites, apps, devices, locations and users.
India DPDP Act
India's Digital Personal Data Protection (DPDP) Act 2023 is the country's main data protection law, with Rules notified in November 2025 that bring its obligations into force in phases.
Sources: GDPR Article 5: principles, California Attorney General: CCPA regulations