Data minimisation is the UK GDPR principle that you should collect and use only the personal data you actually need for a stated purpose, and nothing more. In marketing it applies to forms, CRMs and email lists, and just as much to what analytics tools, pixels and tags collect in the background.
How data minimisation works
Article 5 of the UK GDPR says personal data must be “adequate, relevant and limited to what is necessary” for the purposes it is processed for. Adequate means enough to do the job; limited means no extra. The test always starts with purpose: decide why you need data, then work out the least you can collect to achieve it.
For tracking, that question applies to every field, setting and parameter:
- Does your analytics need a visitor’s precise location, or is the region enough?
- Does an enquiry form need a date of birth, or just a name and a way to reply?
- Do session recording tools such as Hotjar need to capture what people type, or only where they click and scroll?
- Does your Meta Pixel need automatic advanced matching, which sends hashed form details, for the campaigns you actually run?
Why it matters
Every extra piece of personal data you hold is something you must protect, explain in your privacy notice, hand over in response to a subject access request and report if it leaks. Collecting less shrinks all of that. The ICO, as the UK regulator, expects organisations to be able to justify each item they collect.
Analytics is where this goes wrong most often, because nobody decides to collect the data; it leaks in. A form that submits by GET puts the visitor’s email address in the page URL, which GA4 then records as part of the page location. A thank-you page with the customer’s name in its address does the same. Google’s terms prohibit sending personally identifiable information to Google Analytics, so a leak like this breaks both the law and the platform’s rules.
There is a commercial argument too. A shorter enquiry form containing only the questions you actually use is easier to complete, so the same discipline that keeps you compliant often helps conversion.
Common mistakes
- Asking for a phone number, address and company size on a newsletter sign-up “in case it is useful later”.
- Leaving email addresses or names in URLs, so they flow into GA4, ad platforms and server logs.
- Sending user IDs, postcodes or free-text form answers to analytics as custom dimensions.
- Switching on every data-sharing and matching option in Google and Meta by default, without deciding whether each one is needed.
- Recording full sessions, including typed text, on pages with forms.
- Collecting data for a sound purpose and then keeping it indefinitely, which turns a minimisation question into a data retention problem.
How to act on it
List everything your site collects: each form field, each tag in Tag Manager, each analytics and pixel setting. Write the purpose next to each item. Anything without a purpose comes out.
Then use the controls the tools already provide. At the time of writing (October 2026), GA4 lets you switch off granular location and device data collection by region, and its data redaction setting can strip email addresses and named URL parameters before data is stored. Session recording tools such as Hotjar and Microsoft Clarity mask typed input in their standard settings, so check masking is still switched on. Change forms to submit by POST, so details never appear in a URL.
Finally, make sure your privacy notice describes what you actually collect once the clean-up is done. Reviewing a tracking setup through this lens is part of how I set up measurement for performance marketing, because a lean setup is easier to keep accurate and easier to defend.
