IDEF Data Minimization, v1.0

Specifies requirements in accordance with Identity Ecosystem Framework (IDEF) requirement PRIVACY-1: DATA MINIMIZATION.

Assessment Steps (3)

1
Data Limited to Transaction Purpose and Related Legal Requirements (DataLimitedtoTransactionPurposeandRelatedLegalRequirements)
Does the entity limit the collection, use, transmission and storage of personal information to the minimum necessary to fulfill that transaction's purpose and related legal requirements?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
2
Claims and Attributes Data Limited to What Is Requested (ClaimsandAttributesDataLimitedtoWhatIsRequested)
When providing claims or attributes, does the entity provide no more personal information than what is requested? Indicate "Not Applicable" (N/A) if the entity does not provide claims or attributes.
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
3
Technical Mechanisms for Information Requests of Variable Granularity (TechnicalMechanismsforInformationRequestsofVariableGranularity)
When acting in the role of identity provider and where feasible, does the entity support data minimization by providing technical mechanisms to accommodate information requests of variable granularity? Indicate "Not Applicable" (N/A) if the entity is not an identity provider.
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Data Minimization
Entities MUST limit the collection, use, transmission and storage of personal information to the minimum necessary to fulfill that transaction's purpose and related legal requirements. Entities providing claims or attributes MUST NOT provide any more personal information than what is requested. Where feasible, identity providers MUST provide technical mechanisms to accommodate information requests of variable granularity, to support data minimization.
Citation
IDEF
Page 9