Operationalizing the Legal Principle of Data Minimization for Personalization

Asia J. Biega, Peter Potash, Hal Daumé, Fernando Díaz, Michèle Finck · 2020

Article 5(1)(c) of the European Union's General Data Protection Regulation (GDPR) requires that "personal data shall be [...] adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (`data minimisation')". To date, the legal and computational definitions of 'purpose limitation' and 'data minimization' remain largely unclear. In particular, the interpretation of these principles is an open issue for information access systems that optimize for user experience through personalization and do not strictly require personal data collection for the delivery of basic service.

Read the paper · More papers on PaperTik