Data Minimization Privacy: The Cheapest Control Nobody Uses Under PIPEDA and Law 25
The most expensive data you own is the data you never needed. Collecting less is the privacy control that saves you money and keeps the OPC and CAI off your back.
By Valdra Team
A Vancouver e-commerce shop I talked to last year had a breach. Nothing exotic. An old marketing database, sitting on a server somebody forgot about, got scraped by a credential-stuffing bot over a long weekend. The painful part wasn't the attack. It was what the attackers walked away with: full names, addresses, dates of birth, and partial payment histories for roughly 40,000 people, most of whom hadn't bought anything since 2019.
The shop didn't need any of that. The dates of birth were collected for a "birthday discount" feature that had been killed two years earlier. The full purchase histories were retained because nobody had ever decided to delete them. Every record in that database was a liability the business carried for free, right up until the moment it became very, very expensive.
That's the thing about personal data. It feels like an asset on the way in. It behaves like hazardous material once you're holding it.
The control that costs nothing and gets skipped anyway
Most privacy spending in this country goes toward protecting data: encryption, access controls, monitoring, breach insurance, the occasional six-figure consultant. All of that matters. But it defends a perimeter around a pile that, in most organizations, is two or three times bigger than it needs to be.
Data minimization is the only control that shrinks the pile itself. You can't lose, leak, or be sued over data you never collected. It can't be subpoenaed, scraped, or sold off in a bankruptcy. It has no attack surface. And unlike almost every other security measure, it doesn't cost money to deploy. It costs discipline, which is admittedly harder to buy.
This isn't a fringe idea. It's written into the law you're already subject to.
What PIPEDA actually requires
Under the federal Personal Information Protection and Electronic Documents Act, the relevant principle is Limiting Collection (Principle 4.4 in Schedule 1). The wording is plain: collection of personal information "shall be limited to that which is necessary for the purposes identified by the organization," and information "shall be collected by fair and lawful means."
Necessary. Not useful. Not "might come in handy." Necessary for a purpose you've actually identified and can defend.
There's a companion principle most people forget exists. Principle 4.5, Limiting Use, Disclosure, and Retention, says personal information "shall be retained only as long as necessary for the fulfilment of those purposes." Principle 4.5.3 goes further: information no longer required to fulfil its purpose "should be destroyed, erased, or made anonymous." Retention is collection's quiet twin. Data you gathered legitimately in 2019 becomes an unjustified holding in 2026 once the purpose expires and you never throw it out.
The Office of the Privacy Commissioner has been consistent on this in its investigation findings for years. When the OPC reviews a breach or a complaint, one of the first questions is whether the organization was even entitled to be holding the data. Over-collection turns a security incident into a compliance failure stacked on top of it. You don't just have a breach. You have a breach of data you couldn't justify keeping, which is a separate problem with its own consequences.
Quebec went further, and added teeth
If PIPEDA nudges, Quebec's Law 25 shoves. The province's modernized private-sector privacy regime, enforced by the Commission d'accès à l'information (CAI), phased in through September 2023 and 2024, and it treats minimization as a default state rather than a polite suggestion.
Two pieces matter here.
First, collection must be limited to what is necessary for the serious and legitimate purpose you've defined, and that necessity has to be demonstrable. The CAI is not interested in your aspirations for future product features.
Second, and this is the one that catches people, Law 25 introduced privacy by default for any technological product or service that collects personal information. The highest-privacy settings have to be on out of the box, without the user lifting a finger. If your sign-up form pre-checks "share my data with partners," you're offside. The whole orientation of the law runs one direction: collect less, by default, unless someone affirmatively opts into more.
The penalties are not theoretical. Administrative monetary penalties under Law 25 reach $10 million or 2% of worldwide turnover, whichever is greater. Penal fines climb to $25 million or 4% of worldwide turnover, and can be doubled for repeat offences. For a Quebec business, or any business serving Quebec residents, "we collected it just in case" is now a line item with a price tag attached.
Collecting personal data you don't need isn't ambition. It's storing someone else's risk on your own balance sheet, unpaid.
"But we might want it later" is not a purpose
I hear this constantly, and I understand the instinct. Data analysts love rich datasets. Marketing teams want every field they can get. Engineers build flexible schemas with room to grow. The future feels full of opportunities you'll regret not having data for.
Here's the reframe that tends to land: every optional field on your intake form is a future incident report you've pre-written. The phone number you collect "for support" but never dial is a notification obligation waiting to happen. Under Law 25's mandatory breach reporting and PIPEDA's, the volume and sensitivity of what you held drive what you owe affected individuals and the regulator when something goes wrong.
A few concrete moves I'd push any small or mid-sized Canadian business to make:
- Audit your forms. Walk through every signup, checkout, and contact form and ask, field by field, what specific purpose justifies it. If nobody can name one, delete the field. One afternoon, permanent reduction in liability.
- Set retention periods and actually enforce them. "Indefinitely" is not a retention period. Pick a number tied to the purpose: support tickets, a year or two; marketing leads who never converted, shorter. Then automate the deletion, because manual cleanup never happens.
- Stop free-text fields from swallowing sensitive data. An open "notes" box on a customer record is where health information, immigration status, and other special-category data go to hide. You collected it without meaning to, and now you're holding it without protection.
- Separate "nice to know" from "need to operate." If a field only feeds analytics, ask whether aggregate or anonymized data would do the same job. Often it would, and properly anonymized data falls largely outside these laws.
Data minimization privacy starts with seeing what you hold
Here's the catch that trips up nearly everyone who gets religious about this: you cannot reduce data you don't know you have. The Vancouver shop didn't keep that birthday database on purpose. They lost track of it. The fields nobody can justify are almost always the fields nobody remembers collecting.
Most over-collection isn't a decision. It's an accumulation. A field added here, an integration there, a spreadsheet export that became a permanent shadow copy, a third-party tool quietly logging more than anyone reads. Real minimization starts with an honest inventory of what personal information actually lives in your systems, where it sits, and which purpose, if any, still justifies it. Everything after that is deletion.
That inventory is genuinely hard to do by hand, which is exactly why so few businesses do it, and why the cheapest control on the books stays the least used. If you want to find the data you forgot you were holding before an attacker does, Valdra maps the personal information hiding across your systems.
AI governance and privacy compliance, simplified.
Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.
Try Valdra