Data minimisation: the principle that does the most work
Of all the principles in privacy law, one does most of the practical work: collect only the data the purpose actually requires. Every other safeguard โ encryption, access control, contracts, deletion โ protects data that exists; minimisation shrinks what needs protecting. It's the difference between guarding a vault and not filling one, and for children's data the arithmetic is decisive: breaches disclose what was held, never less, and the harm ceiling of any incident was set years earlier, at collection time, by whoever decided what to ask for.
It's law, not aspiration
The principle recurs across every regime a school deals with: Australia's APP 3 โ collect personal information only if reasonably necessary for the entity's functions (with special hurdles for sensitive information) โ mirrored for government schools by the state principles (Victoria's IPP 1, and equivalents per state); GDPR Article 5(1)(c) โ "adequate, relevant and limited to what is necessary," plus purpose limitation in 5(1)(b) (data collected for one purpose can't drift to another); COPPA ยง312.7 โ operators may not condition a child's participation on disclosing more information than reasonably necessary to participate; the UK Children's Code standard 8 โ collect and retain the minimum. The pattern is worth noticing: regulators keep converging on the same idea from different directions, because it's the one control that works before anything goes wrong.
The test that operationalises it
For every field a product collects, ask: "why do you have this?" โ and require an answer phrased as this feature fails without it, not it's useful. Almost everything fails the strict version: birth dates (an age band would do โ or nothing), full names (a pseudonym serves the function), email addresses for children (the master-key identifier, rarely necessary), gender (necessary for approximately nothing an edtech product does), photos, location. What survives the test in a learning product is mostly learning state: progress, mastery evidence, the things the teaching actually runs on. The gap between what survives the test and what the median product collects is the industry's minimisation debt โ documented at scale by the Human Rights Watch and Internet Safety Labs audits.
Two corollaries schools should apply: retention is collection stretched over time โ data kept past its purpose fails the same test (deletion in practice); and derived data counts โ behavioral profiles and inferences are collected-by-computation, and purpose limitation applies to them with extra force (the "improve our products" clause is where drift lives).
What minimisation doesn't mean
- It doesn't mean no data โ a mastery curriculum genuinely needs progress records (what remains is game state); minimisation is a ratio of data to purpose, not an absolute.
- It doesn't excuse under-delivery โ "we collect nothing" plus "we can't help you recover your account" done badly is just cost-shifting; honest minimised design pays its UX costs deliberately (the ledger).
- It doesn't replace the other safeguards โ what you do hold still needs APP 11-grade security; minimisation sets the stakes, not the locks.
In practice (for schools)
- Make it the first procurement filter (the guide): run why-do-you-have-it on the sign-up form before reading a single policy page โ products failing at the form fail everywhere.
- Minimise your own asks: school-built forms, spreadsheets and newsletters collect plenty; the test applies at home too.
- Teach it โ data minimisation is a child-facing idea in disguise: "before you type it in, ask why they need it" is the consent-gate curriculum in one sentence, and children who apply it to apps become adults who apply it to everything.
References
- Australian Privacy Principle 3 (and APP 11 on retention/destruction); OAIC APP Guidelines.
- GDPR Articles 5(1)(b)โ(c); UK ICO Age Appropriate Design Code, standard 8.
- COPPA Rule, 16 CFR ยง312.7 โ the anti-conditioning provision.
- Human Rights Watch (2022); Internet Safety Labs (2022) โ the audits measuring the sector's distance from the principle.
ยฉ Glu IO Pty. Ltd. โ Wiz Kids (wiz.kids). Link freely; republication requires permission โ see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.