Data Minimization and Storage Limitation: Curbing the over Retention of Personal Data
43 questions
43 questions on data minimization and storage limitation, answered and cited by the UpLaw editorial team.
- Can we anonymize data instead of deleting it?
- Does California law require data minimization?
- Does California require businesses to disclose how long they keep personal information?
- Does HIPAA set a retention period for medical records?
- Does the GDPR apply to a U.S. company with no European offices?
- Do state privacy laws outside California require minimization?
- Has the FTC's authority to police data practices under Section 5 been upheld?
- How does over-retention make a data breach worse?
- How does the FTC regulate data retention without a general privacy statute?
- How do minimization rules apply to employee and HR data?
- How do third-party SDKs in a mobile app create minimization problems?
- How do you handle deletion in backups?
- How long should we keep personal data?
- Is data minimization compatible with training AI models?
- Is data minimization legally required in the United States, or just a best practice?
- What about personal data in logs and free-text fields that nobody meant to collect?
- What are the actual costs of keeping personal data too long?
- What are the components of a data minimization and retention program?
- What are the penalties for violating California's minimization and retention rules?
- What are the penalties for violating GDPR data minimization or storage limitation?
- What does COPPA require about retaining children's data?
- What does GDPR Article 5 say about data minimization and storage limitation?
- What does privacy by design mean in practice?
- What does the FCRA Disposal Rule require?
- What does the GDPR's accountability principle require for retention?
- What does the GLBA Safeguards Rule require about disposing of customer information?
- What has the FTC required in its data retention enforcement orders?
- What is algorithmic disgorgement, and when has the FTC ordered it?
- What is data minimization?
- What is data protection by design and by default under GDPR Article 25?
- What is defensible deletion?
- What is purpose limitation and how does it relate to minimization?
- What is the difference between data minimization and storage limitation?
- What is the difference between pseudonymized and anonymized data under the GDPR?
- What makes a deletion process actually work?
- What retention schedule does Illinois's BIPA require for biometric data?
- What should a data retention schedule contain?
- What two questions should we ask about every category of personal data we hold?
- Where did the idea of data minimization come from?
- Who in an organization should own data retention?
- Why classify personal data by sensitivity rather than applying one rule?
- Why does a data minimization program have to start with a data map?
- Won't deleting data hurt us in litigation?