# TTC-104 — Everyday privacy and data minimization

Give an AI workflow only the data needed for the stated purpose, remove identifiers when possible, and define retention and access before sharing anything.

Level: beginner · Version: 1.0.0 · Last reviewed: 2026-10-03
Review status: reviewed

## Learning outcome
Minimize a fictional dataset for one task and justify every retained field against the purpose.

## Explanation
Start with purpose: what exact output is needed, and which fields are essential to produce it? Delete, mask, aggregate, or replace everything else with synthetic values. A name removed from a record may still be recoverable from dates, locations, or rare combinations, so consider indirect identification. Check the provider, storage location, retention, access, and deletion path before disclosure. Prefer a local summary or selected excerpt over a complete file. Record what was released and withheld. When the purpose changes, reassess it; prior access is not blanket permission for a new use.

## Worked fictional example
Fictional case: a bakery wants themes from staff survey comments. Jo removes names, email addresses, exact shift times, and references to medical leave; substitutes department codes only where comparison is needed; and supplies the comments in a temporary file. The receipt lists four released and four withheld fields.

## Reusable exercise
Take a synthetic ten-field record and a precise summarization purpose. Create a release table with keep, transform, or withhold for every field; produce the minimized input; then set an access and deletion rule. Repeat with a changed purpose and show why the release decision changes.

## Observable success criteria
- Every released field has a purpose-linked justification.
- Direct identifiers and unnecessary sensitive or linkable details are absent from the minimized input.
- The exercise records access, retention, deletion, and the fields deliberately withheld.

## Limitations
- Minimization reduces exposure but cannot guarantee anonymity or eliminate provider and recipient risk.
- Legal obligations depend on jurisdiction and context; this lesson is not legal advice.

## Next review
Privacy law, provider data handling, or the product's retention and deletion behavior changes.; A cited primary source is materially revised, replaced, or becomes unavailable.; Repeated learner results show that the exercise or success criteria are ambiguous.

## Copyable material
```text
# TTC-104 — Everyday privacy and data minimization
Objective: Release the smallest useful input for one declared purpose.
Procedure: Classify each field as keep, transform, or withhold; document access, retention, and deletion before use.
Required evidence: Produce a receipt listing purpose, released fields, withheld fields, transformations, and expiry.
Boundaries: A previous release does not authorize reuse; stop when identity or sensitivity cannot be reduced enough.
Completion test: The task remains possible with the minimized input and no retained field lacks a purpose.
Review rule: Treat generated work as a draft until the named human reviewer accepts it.
```

## Primary sources
- European Union: Regulation (EU) 2016/679 (General Data Protection Regulation) — https://eur-lex.europa.eu/eli/reg/2016/679/oj
- National Institute of Standards and Technology: NIST Privacy Framework — https://www.nist.gov/privacy-framework

Canonical URL: https://teachthecompany.com/school/everyday-privacy-and-data-minimization/
Related established guide: https://teachthecompany.com/ai-agent-security/