← Back to glossary
πŸ“₯

Data Collection

Data Management

Acquisition of personal data from users, devices, or third parties for defined purposes.

Definition

Data collection includes obtaining personal data directly (forms, sensors), indirectly (logs, telemetry), or from third parties (brokers/partners). Good practice limits collection to what is necessary and documents purposes and retention.

In plain English Acquisition of personal data from users, devices, or third parties for defined purposes.

Why this matters

Why it matters: Over-collection increases attack surface, compliance burden, and profiling potential.

Example

Example: Collect coarse location (city) instead of precise GPS when fine accuracy is not needed.