unified
UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary
Identify and document the specific purposes for which personal data is processed, and restrict use and disclosure to those purposes or documented compatible ones. Apply the minimum-necessary standard so only the least data required is used, disclosed, or requested for each purpose. Obtain new authority or consent before processing for any new purpose.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Data Protection & Privacy
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-DATA-03
- title
- Limit personal-data use to stated purposes and minimum necessary
- statement
- Identify and document the specific purposes for which personal data is processed, and restrict use and disclosure to those purposes or documented compatible ones. Apply the minimum-necessary standard so only the least data required is used, disclosed, or requested for each purpose. Obtain new authority or consent before processing for any new purpose.
- domain
- Data Protection & Privacy
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PT-3
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- P4.1
- coverage
- full
- relationship
- superset_of
- framework
- hipaa
- control_id
- HIPAA-164.502
- coverage
- partial
- delta
- required disclosures to HHS, personal-representative and business-associate limits not addressed
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary mitigates Illegal processing of personal or sensitive data
- strength
- related
- rationale
- Requiring new authority/consent before any new purpose keeps processing within lawful bounds.
- UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary maps_to HIPAA-164.502 — Uses and disclosures of PHI (permitted/required uses, minimum necessary)
- framework
- hipaa
- control_id
- HIPAA-164.502
- coverage
- partial
- delta
- required disclosures to HHS, personal-representative and business-associate limits not addressed
- relationship
- intersects_with
- source_version
- 45 CFR Parts 160/164 (Security, Privacy, Breach Notification)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary maps_to P4.1 — The entity limits the use of personal information to the purposes identified in the entity's objectives related to privacy.
- framework
- soc2
- control_id
- P4.1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary maps_to PT-3 — Personally Identifiable Information Processing Purposes
- framework
- nist-800-53
- control_id
- PT-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary mitigates Absence of privacy-by-design and default
- strength
- related
- rationale
- The minimum-necessary/data-minimization requirement is a core privacy-by-default principle reducing over-collection and exposure.
- Privacy Program Operations (Consent, Complaints & Sharing) operates UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary
- UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary mitigates Excessive collection, purpose creep and secondary use
- strength
- primary
- rationale
- Purpose limitation plus the minimum-necessary standard directly restricts over-use/over-disclosure and blocks secondary use without new authority.
- UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary mitigates Excessive surveillance, appropriation and induced disclosure
- strength
- related
- rationale
- Restricting use/disclosure to documented purposes limits monitoring and appropriation of data beyond its stated purpose.
- SOC 2 Privacy Criteria Assessment tests UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary