Data Minimization

GDPR mandates collecting only personal data necessary for the specific purpose. Financial institutions must regularly assess data collection to avoid excessive customer profiling, which increases breach risk or regulatory scrutiny.