Purpose Limitation

The principle of Purpose-Limitation is a fundamental pillar of Data-Privacy law, most notably defined under the General-Data-Protection-Regulation (GDPR). As outlined in Article 5(1)(b), personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.

This principle requires Data-Controllers to be precise about their intentions at the point of collection. This transparency allows Data-Subjects to make informed decisions about their Personal-Data. If an organization wishes to use the data for a new, incompatible purpose, they generally must obtain fresh Consent or identify a new Lawful-Basis, unless the new purpose is required by law.

According to guidelines from the European-Data-Protection-Board and the Information-Commissioners-Office, the specification of purpose must be clear and documented. This prevents 'function creep,' a scenario where data usage expands beyond the initial scope without oversight. Compliance with Purpose-Limitation ensures that organizations maintain trust and adhere to the Accountability-Principle.