Skip to content
arrow_back
search
ISM-2021 policy ASD Information Security Manual (ISM)

Implement and Maintain Data Minimisation Practices

System owners should limit data collection and storage to what's necessary.

record_voice_over

Plain language

System owners should only collect and keep the data they truly need. This is important because storing unnecessary information makes an organisation more vulnerable to data breaches, which can lead to financial losses and harm to reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

System owners implement and maintain data minimisation practices for each of their systems.
policy ASD Information Security Manual (ISM) ISM-2021
priority_high

Why it matters

Excessive data retention increases the risk of data breaches, leading to potential financial loss and reputational damage.

settings

Operational notes

Regularly review what data is collected and retained, delete data no longer required, and record retention periods. Document and justify any exceptions to minimisation.

Mapping detail

Mapping

Direction

Controls