Operationalizing the Legal Principle of Data Minimization for Personalization
Asia J. Biega, Peter Potash, Hal Daumé III, Fernando Diaz, Michèle Finck
Abstract
Article 5(1)(c) of the European Union's General Data Protection Regulation (GDPR) requires that "personal data shall be [...] adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed ('data minimisation')". To date, the legal and computational definitions of 'purpose limitation' and 'data minimization' remain largely unclear. In particular, the interpretation of these principles is an open issue for information access systems that optimize for user experience through personalization and do not strictly require personal data collection for the delivery of basic service.
In this paper, we identify a lack of a homogeneous interpretation of the data minimization principle and explore two operational definitions applicable in the context of personalization. The focus of our empirical study in the domain of recommender systems is on providing foundational insights about the (i) feasibility of different data minimization definitions, (ii) robustness of different recommendation algorithms to minimization, and (iii) performance of different minimization strategies.We find that the performance decrease incurred by data minimization might not be substantial, but that it might disparately impact different users-a finding which has implications for the viability of different formal minimization definitions. Overall, our analysis uncovers the complexities of the data minimization problem in the context of personalization and maps the remaining computational and regulatory challenges.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 480e296e-7c52-4efb-aff9-ba3c610fe118Cited by top-tier papers9
- In-Context Unlearning: Language Models as Few-Shot UnlearnersMartin Pawelczyk, Seth Neel, Himabindu LakkarajuICML 2024 · 217 citations
- Auditing Black-Box Prediction Models for Data Minimization ComplianceBashir Rastegarpanah, Krishna P. Gummadi, Mark CrovellaNeurIPS 2021 · 24 citations
- Rescriber: Smaller-LLM-Powered User-Led Data Minimization for LLM-Based ChatbotsJijie Zhou, Eryue Xu, Yaoyao Wu, Tianshi LiCHI 2025 · 15 citations
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee et al.S&P 2024 · 11 citations
- From Principle to Practice: Vertical Data Minimization for Machine LearningRobin Staab, Nikola Jovanovic, Mislav Balunovic, Martin T. VechevS&P 2024 · 10 citations
Related papers
- "I'm not convinced that they don't collect more than is necessary": User-Controlled Data Minimization Design in Search EnginesTanusree Sharma, Lin Kyi, Yang Wang, Asia J. BiegaUSENIX Security 2024 · 5 citations
- POLICYCOMP: Counterpart Comparison of Privacy Policies Uncovers Overbroad Personal Data Collection PracticesLu Zhou, Chengyongxiao Wei, Tong Zhu, Guoxing Chen et al.USENIX Security 2023
- "It doesn't tell me anything about how my data is used": User Perceptions of Data Collection PurposesLin Kyi, Abraham Mhaidli, Cristiana Teixeira Santos, Franziska Roesner et al.CHI 2024 · 22 citations
- Algorithmic Data Minimization for Machine Learning over Internet-of-Things Data StreamsTed Shaowang, Shinan Liu, Jonatas Marques, Nick Feamster et al.VLDB 2025
- 'Transparency is Meant for Control' and Vice Versa: Learning from Co-designing and Evaluating Algorithmic News RecommendersElias Storms, Oscar Alvarado, Luciana Monteiro KrebsCSCW 2022 · 29 citations
