Skip to content

GDPR data minimisation, applied to documents

Article 5(1)(c) GDPR in practice: what adequate, relevant and limited mean for files you share, store or feed to a tool. With three before-and-after cases.

By Alexis de ONYRIUpdated September 23, 2026

Data minimisation means a document should carry only the personal data its purpose needs. Article 5(1)(c) GDPR says personal data must be adequate, relevant and limited to what is necessary. For a file, that means: before you send, store or upload it, remove or mask what the reader or the tool does not need.

Take Jane Example, an office manager. A client's auditor asks for proof that her company paid its staff last quarter. She is about to email the full payroll export: forty names, salaries, bank details. A summary of the monthly totals would do. This guide is general information as of September 2026, not legal advice.

What does Article 5(1)(c) GDPR say?

Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’). (Article 5(1)(c) GDPR)

EU: the test starts from the purpose. Adequate: enough to fulfil it. Relevant: linked to it. Limited: no more than you need. Recital 39 GDPR adds that personal data should be processed only if the purpose could not reasonably be fulfilled by other means.

UK: the ICO reads the three words the same way. It says you must not collect personal data on the off-chance that it might be useful. As of September 2026, the ICO notes this guidance is under review after the Data (Use and Access) Act.

Why is minimisation harder with documents than with databases?

A database has fields. You decide field by field what to collect. A document is a bundle. It was written for one purpose, gets reused for another, and travels whole. It also carries data you do not see. Microsoft's documentation lists what the Document Inspector in Word can find: comments, tracked changes, document properties such as the author's name, and hidden text.

How does it apply when you share, store or process a file?

SituationQuestion to askWhat minimisation looks like
Sharing a file with a client, a supplier, an auditorWhat does this reader need to do their job?Send an extract or a masked copy. Remove third parties, ID numbers and contact details the reader has no use for.
Storing a file on a shared drive or in an archiveDo we still need it, in this detail, and who needs access?Set a deletion date. Delete duplicates. Restrict the folder.
Processing with a tool: AI assistant, online translator, converterMust the tool know who the people are?Mask or replace identifiers before the upload. Check what the provider keeps and reuses.

The European Data Protection Board (EDPB) gives the method in its Guidelines 4/2019 on Article 25: check whether the purpose can be achieved with less personal data, less detailed data, or none at all. And do not create more copies than necessary. On AI tools, France's CNIL advised in July 2024 never to share confidential information such as personal data with a consumer service.

How do Articles 25 and 32 fit in?

Article 25(1) asks controllers for technical and organisational measures, such as pseudonymisation, designed to implement principles such as data minimisation. Article 25(2) sets the default: only personal data necessary for each specific purpose are processed. It covers four dimensions: the amount of data collected, the extent of processing, the storage period and accessibility.

Article 32 is about security. It lists pseudonymisation and encryption among the measures to consider. The link is simple: what is not in the file cannot leak from it. A masked attachment sent to the wrong address exposes less than the full file.

What does it look like in practice? Three before-and-after examples

CaseBeforeAfter
Supplier due diligence: a client asks who owns and runs your companyFull passport scans of two directors, home addresses, the whole shareholder registerNames and roles, as the questionnaire asks. Passport numbers, photos and home addresses masked, unless the client shows why it needs them.
HR case: a complaint file goes to an outside investigatorThe whole personnel file: sick notes, salary history, every colleague named in the emailsOnly the documents about the complaint. Witnesses become Witness A, Witness B. Health and pay data removed.
Support ticket: a customer attaches a bank statement to prove a bugThe full statement, visible to every agent and kept for yearsMask the IBAN and the address on receipt. Delete the attachment when the ticket closes.
Illustrative cases. What is necessary depends on your own purpose.

Notice the word adequate. Minimisation does not mean sending as little as possible. It means enough, and no more. If the auditor needs the invoice amount, masking it makes the document useless.

How do you minimise a document, step by step?

  1. 1Write the purpose in one sentence. Example: prove that invoice 2026-114 was paid.
  2. 2List what the reader or the tool needs for that one job.
  3. 3Send an extract or one page if that is enough.
  4. 4Work on a copy. Mask the rest: other people's names, ID and bank numbers, addresses.
  5. 5Clean what you cannot see: comments, tracked changes, document properties.
  6. 6Check the result. Try to select and copy text under each mask.
  7. 7Set a deletion date for each copy. Note what you removed and why: Article 5(2) requires you to be able to demonstrate compliance.

On tools: the ICO warns that text under a simple black rectangle can be revealed by copying and pasting. Adobe's documentation says the Redact tool in Acrobat Pro permanently removes content, and that sanitizing removes comments, metadata and hidden layers. A browser-based option is ONYRI Sanitize: it masks a PDF, a Word file or a scan without uploading it, and exports flattened pages. No detector finds everything. Review each item yourself.

What does data minimisation not do?

  • It does not make a document anonymous. Under Recital 26, pseudonymised data that could be attributed to a person with additional information remain personal data.
  • It does not replace security. A minimised file still needs the right recipient, and encryption where the risk calls for it (Article 32).
  • It does not replace retention limits. Article 5(1)(e) is a separate principle: a lean file kept forever is kept too long.

Frequently asked questions

Is masking the names enough to make a document anonymous?
Usually not. Recital 26 GDPR says to take account of all the means reasonably likely to be used to identify a person. Context often does it: a role, a date, a rare event. Treat a masked document as personal data.
Does data minimisation apply to old files we already hold?
Yes. The EDPB says controllers should periodically consider whether the data are still adequate, relevant and necessary, or should be deleted or anonymised. Recital 39 asks for time limits for erasure or a periodic review.
Can we keep the full original if we share a masked copy?
Yes, if the original has its own purpose and retention period. Restrict who can open it: accessibility is one of the four dimensions of Article 25(2). And do keep it: a properly redacted copy cannot be turned back into the original.
Should we black out data or replace it with labels?
If the information is not needed at all, remove it: a black bar is final. If the reader must follow who did what, consistent labels such as Person A keep the text readable. That is pseudonymisation. The EDPB recommends it once directly identifiable data are no longer necessary. The result is still personal data.

Sources & references

Mask a document without uploading it

ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.

Read next