small-logo
ProfessionalsCapabilitiesInsights & NewsCareersLocations
About UsAlumniOpportunity & InclusionPro BonoCorporate Social Responsibility
Stay Connected:
facebookinstagramlinkedintwitteryoutube
  1. Insights & News

Article

Minimizing Privacy Risk With Data Minimization

  • PDFPDF
    • Email
    • LinkedIn
    • Facebook
    • Twitter
    Share this page
  • PDFPDF
    • Email
    • LinkedIn
    • Facebook
    • Twitter
    Share this page

Article

Minimizing Privacy Risk With Data Minimization

  • PDFPDF
    • Email
    • LinkedIn
    • Facebook
    • Twitter
    Share this page

1 Min Read

Related Locations

Houston

Related Topics

Data Privacy
Data Breach
Data Protection
Data Retention
Data Security

Related Capabilities

Privacy & Data Security
Trade Secrets, Non Competes & Restrictive Covenants
eDiscovery & Information Governance
Intellectual Property

Related Regions

North America

September 2, 2019

This article originally appeared in Corporate Counsel. Any opinions in this article are not those of Winston & Strawn or its clients. The opinions in this article are the author’s opinions only.

At a recent annual meeting of The Sedona Conference Working Group on Data Security and Privacy Liability, one key theme seemed to be on everyone’s mind. During the sessions, which covered breach notification laws, litigation, and other current issues impacting data privacy and security, the topic of data minimization came up again and again. While the practice of data minimization isn’t exactly new, we’re now seeing it resonate and discussed at the forefront of the legal industry for the first time.

The reason is that companies have never faced greater risk with respect to their data than they do today. The landscape is only growing more challenging and complex. Across the globe, stringent data protection laws have emerged, and several U.S. states are implementing legislation to introduce new regulations for how governments and businesses are permitted to handle personal data. Multinational corporations must navigate compliance requirements for the General Data Protection Regulation, China’s Information Security Technology–Personal Information Security Specification and Cybersecurity Law, Brazil’s General Data Privacy Law, the California Consumer Privacy Act, U.S. state-based breach notification laws and dozens of others.

The vector of risks introduced by data privacy laws grows exponentially when combined with cybersecurity threats, insider threats, and potential theft of intellectual property and trade secrets. Since it’s clear that the waters of data risk are going to be rough for the foreseeable future, corporations must start acting now to take steps that will narrow the scope of information they store. Data minimization is a critical strategy in that effort.

Read the full Corporate Counsel article for steps legal teams can take to implement a data ­minimization plan and maintain a reasonable retention and deletion policy long-term.

Logo
facebookinstagramlinkedintwitteryoutube

Copyright © 2025. Winston & Strawn LLP

AlumniCorporate Transparency Act Task ForceDEI Compliance Task ForceEqual Rights AmendmentLaw GlossaryThe Oval UpdateWinston MinutePrivacy PolicyCookie PolicyFraud & Scam AlertsNoticesSubscribeAttorney Advertising