unified
UC-GOV-26 — Enforce personal-data processing principles and minimization
Adopt and enforce policies and procedures requiring that personal data is processed lawfully, fairly, and transparently; collected for specified, explicit purposes; limited to what is necessary; kept accurate through defined quality-management checks and correction procedures; stored no longer than needed; and protected — with accountability demonstrable through documentation. Minimize or use de-identified personally identifiable information in testing, training, and research, applying documented techniques where full data is not required.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-26
- title
- Enforce personal-data processing principles and minimization
- statement
- Adopt and enforce policies and procedures requiring that personal data is processed lawfully, fairly, and transparently; collected for specified, explicit purposes; limited to what is necessary; kept accurate through defined quality-management checks and correction procedures; stored no longer than needed; and protected — with accountability demonstrable through documentation. Minimize or use de-identified personally identifiable information in testing, training, and research, applying documented techniques where full data is not required.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- gdpr
- control_id
- GDPR-Art5
- coverage
- partial
- delta
- operational enforcement of principles sits in data-protection, retention, and security controls
- relationship
- intersects_with
- framework
- nist-800-53
- control_id
- PT-1
- coverage
- partial
- delta
- PT-family policy governance of transparency mechanisms - consent, privacy notices, and system-of-records notices - satisfied by the companion notice and consent controls
- relationship
- intersects_with
- framework
- nist-800-53
- control_id
- PM-22
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PM-25
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-26 — Enforce personal-data processing principles and minimization maps_to PM-25 — Minimization of Personally Identifiable Information Used in Testing, Training, and Research
- framework
- nist-800-53
- control_id
- PM-25
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-26 — Enforce personal-data processing principles and minimization mitigates Litigation, investigation and enforcement exposure
- strength
- primary
- rationale
- Enforcing lawful, purpose-limited, minimized data processing (GDPR Art5) directly reduces data-protection enforcement exposure.
- UC-GOV-26 — Enforce personal-data processing principles and minimization maps_to PT-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- PT-1
- coverage
- partial
- delta
- PT-family policy governance of transparency mechanisms - consent, privacy notices, and system-of-records notices - satisfied by the companion notice and consent controls
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-26 — Enforce personal-data processing principles and minimization maps_to PM-22 — Personally Identifiable Information Quality Management
- framework
- nist-800-53
- control_id
- PM-22
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-26 — Enforce personal-data processing principles and minimization maps_to GDPR-Art5 — Principles relating to processing of personal data
- framework
- gdpr
- control_id
- GDPR-Art5
- coverage
- partial
- delta
- operational enforcement of principles sits in data-protection, retention, and security controls
- relationship
- intersects_with
- source_version
- Regulation (EU) 2016/679
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-26 — Enforce personal-data processing principles and minimization mitigates Stakeholder trust and social-license erosion
- strength
- related
- rationale
- Fair, transparent, minimized data handling sustains individual and stakeholder trust.
- Privacy Safeguards & Notice Management operates UC-GOV-26 — Enforce personal-data processing principles and minimization