Annex I Part I essential cybersecurity requirements – EU Cyber Resilience Act
EU Cyber Resilience Act Annex I Part I(2)(g): Data minimisation
The product must process only data, personal or other, that is adequate, relevant and limited to what is necessary for its intended purpose.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.