In 2025, a major European bank was fined €4.4 million for collecting identity documents beyond what data minimization rules required. That fine was a clear signal: data minimization has moved from compliance aspiration to legal baseline, and regulators are actively enforcing it.
Global privacy frameworks — the GDPR, CCPA, and a growing stack of U.S. state laws — all converge on the same core principle: collect only what you need, use it only for what you said, and delete it when you’re done. For financial services organizations running KYC and AML workflows, the margin for over-collection is shrinking fast.
Decentralized identity reframes the problem. Rather than collecting and centralizing raw identity documents, it issues cryptographically verified credentials that users control. The result is a structural reduction in data collected, transmitted, and retained at every verification touchpoint.
This guide breaks down what data minimization actually requires under each major framework and how decentralized identity infrastructure directly addresses those obligations.
What Is Decentralized Identity?
Decentralized identity is a user-controlled model in which cryptographically secured credentials are stored in a digital wallet rather than in a centralized database controlled by a single organization. No single entity holds or controls the underlying identity data — a fundamental departure from traditional identity architectures.
The W3C formalized decentralized identifiers (DIDs) as an open standard, and in March 2026, W3C advanced DID v1.1 to Candidate Recommendation, reinforcing the standard’s trajectory toward global adoption.
Jumio’s approach anchors decentralized credentials to a government-issued ID and a biometric selfie check. Once that verification is complete, a digital certificate is issued to the user’s wallet and becomes reusable across services. Re-verification requires only a selfie, with no re-submission of government ID, and no re-collection of sensitive documents. Each subsequent identity verification transaction carries a smaller data footprint than the original verification.
What Is Data Minimization and Why Is It Important?
Data minimization is the principle that organizations should collect only the data strictly necessary for a defined, documented purpose. Regulators no longer treat excess data collection as a best practice lapse. They treat it as a compliance failure.
For identity-intensive industries, the stakes are compounded. Over-collection creates regulatory exposure, expands breach liability, and inflates the potential damage from any single incident. Enforcement is accelerating and is coordinated across jurisdictions. For example, in April 2025, the California Privacy Protection Agency (CPPA) and nine state attorneys general formed a coordinated privacy enforcement body.
Core Principles of Data Minimization
Data minimization operates through three distinct obligations that together define what compliant data handling looks like in practice.
1. Obtain User Consent
Consent must be informed, specific, and tied to a defined processing purpose — not blanket permission. Under GDPR Article 7, consent must be freely given and as easy to withdraw as it was to grant. Decentralized identity wallets embed consent controls directly into the credential exchange, so users see exactly what they’re sharing and can revoke access at any time.
2. Collect Only Required Data
Each data field must map to a specific, documented business or compliance purpose before collection begins. Identity proofing for KYC doesn’t require storing a full document scan when a verified attribute will suffice. Jumio’s verifiable credential model enables attribute-level disclosure, which allows users to share verified credentials, like proof of age, without revealing identifying information, like date of birth.
3. Delete Data After Use
The CPRA was the first U.S. law to codify storage limitation as a distinct legal obligation, not just a policy guideline. Retention schedules must align with the purpose for which data was collected, and when data is no longer needed for its stated purpose, it must go. Automated deletion workflows are the practical mechanism for meeting that standard, and they double as documented evidence of compliance intent for regulators.
Data Minimization and Risk Mitigation
Every unnecessary data field is a potential attack vector. Minimization structurally reduces the breach surface, and the financial consequences of getting it wrong are steep. GDPR penalties can reach €20 million or 4% of global annual turnover, whichever is higher. Decentralized identity limits what’s transmitted and stored, directly narrowing the scope of any compliance audit or breach notification obligation.
Benefits to Consumers
Users gain meaningful control under data minimization frameworks. With reusable, user-owned credentials, individuals decide what gets disclosed to whom — and can revoke that access at any time without contacting the organization that originally verified them.
This selective disclosure means consumers can confirm they meet an age threshold without handing over their full date of birth. Or they can verify residency without exposing their complete address history. And because credentials are portable, there’s no need to re-submit a passport or driver’s license every time a new platform requires identity verification.
The downstream security benefit is equally concrete. Every organization that doesn’t store a full identity record is one fewer target for credential theft. Identity thieves depend on over-retained data sets, but minimization structurally reduces what’s available to exploit.
Data Minimization Requirements in Practice
Privacy obligations don’t exist in a single jurisdiction, and for organizations operating across borders, that means managing a layered stack of data minimization requirements simultaneously. The frameworks below represent the most consequential regulatory obligations currently in force — and in the case of pending federal legislation, the clearest signal of where compliance requirements are heading.
European Union: The General Data Protection Regulation (GDPR)
Article 5(1)(c) of the GDPR codifies data minimization as one of six core data processing principles. Data must be “adequate, relevant and limited to what is necessary” relative to the stated processing purpose. The five companion principles — lawfulness and transparency, purpose limitation, accuracy, storage limitation, and integrity and confidentiality — collectively define how personal data can be used throughout its lifecycle.
Purpose limitation under Article 5(1)(b) prohibits repurposing data beyond its original stated collection intent. Biometric data used in identity verification is classified as a Special Category under Article 9, requiring explicit consent. That provision directly applies to any KYC workflow that captures a facial image or liveness check.
Jumio’s reusable identity model aligns with both the GDPR’s data minimization and purpose limitation obligations. Attribute-level sharing means organizations never receive data beyond what a specific transaction requires. Jumio’s platform also supports GDPR-compliant KYC and AML workflows across all relevant processing activities.
The American Data Privacy and Protection Act (ADPPA)
The ADPPA advanced through the House Energy and Commerce Committee in 2022 with a bipartisan 53-2 vote but expired without reaching a floor vote. It would have been the first U.S. federal law to impose universal data minimization requirements on all businesses.
Under its framework, organizations would have been required to process only the minimum data necessary for a specific, documented purpose. Entities with $250 million or more in revenue that also process data on 5 million or more individuals — or sensitive data on 200,000 or more individuals — would have faced additional privacy impact assessment obligations.
The American Privacy Rights Act (APRA)
The APRA followed in April 2024, building on the ADPPA with a stronger focus on data minimization and proportionality. Collection and processing would have been required to be “necessary and proportionate” to providing the requested service. The APRA also added explicit consent requirements for biometric and genetic data — a direct implication for KYC and AML workflows relying on facial recognition and liveness detection.
Its enforcement architecture was set to be among the most aggressive of any U.S. privacy law. FTC oversight, state attorney general enforcement, and a private right of action for consumers would have created three independent liability channels simultaneously. For identity verification workflows processing biometric data at scale, that combination would have represented material litigation and regulatory exposure.
The APRA expired when the 118th Congress ended in January 2025 and has not been reintroduced.
Neither bill became law, but both have shaped the direction of federal thinking. Identity verification vendors operating as service providers would have fallen within scope of both frameworks — and organizations should anticipate that any future federal bill will follow similar lines. Meanwhile, individual states have enacted their own privacy laws, with California and Maryland being the strictest.
California: The California Consumer Privacy Act (CCPA)
No U.S. state has moved further on data minimization than California. The California Consumer Privacy Act (CCPA) went into effect in January of 2020. Later that year, the California Privacy Rights Act (CPRA)’s amendments to the CCPA converted minimization from a compliance guideline into an enforceable legal standard, requiring that collection and use be “reasonably necessary and proportionate” to the documented purpose.
The storage limitation obligation is equally firm. Data that no longer serves its stated purpose must be deleted, making automated deletion schedules a compliance necessity.
Enforcement is handled by the California Privacy Protection Agency (CPPA), which has broad authority to pursue violations. Fines reach $2,663 for non-intentional violations and $7,988 for intentional ones, adjusted for CPI as of January 2025. The CCPA applies to businesses meeting revenue, data volume, or data sale thresholds, catching most fintechs and banks.
In general, the law applies to for-profit businesses that:
- Have a gross annual revenue of $26.625 million or more
- Buy, sell, or share the personal information of 100,000 or more California residents
- Derive 50% or more of their revenue from selling or sharing that personal information
Biometric data collected during identity verification carries an additional classification as sensitive personal information under the CPRA, triggering heightened consent obligations. Decentralized identity addresses that directly, using one-time verification with reusable credentials that limits retention of raw biometric data after the verification event is complete.
Maryland Online Data Privacy Act (MODPA)
Maryland’s MODPA was signed in May 2024 and took effect October 1, 2025, with enforcement beginning April 1, 2026. It sets one of the strictest data minimization standards of any U.S. state law, requiring controllers to collect only data that is “strictly necessary” for the disclosed processing purpose — a higher bar than most state frameworks. Maryland’s approach aligns more closely with GDPR principles than with the softer language found in other U.S. laws.
MODPA applies to entities processing data on 35,000 or more Maryland consumers, or processing data on at least 10,000 consumers where data sales constitute more than 20% of gross revenue.
Controllers cannot process sensitive data without explicit consumer consent — a provision with direct implications for any KYC workflow that touches biometric data. The bill also authorizes the Office of the Attorney General of Maryland to request a data protection assessment from controllers to ensure compliance.
Organizations using Jumio’s decentralized identity tools can limit the data transmitted and retained per transaction to meet MODPA’s strict necessity standard.
Frequently Asked Questions
How do I choose software for unstructured data compliance and retention?
Prioritize platforms with automated data mapping, audit-trail generation, and configurable retention schedules that can accommodate multi-jurisdiction obligations — U.S. state laws, the GDPR, and sector-specific rules simultaneously. Look for integration with identity verification workflows to enforce minimization at the point of collection. Jumio’s platform provides compliance-ready infrastructure for KYC, AML, GDPR, and CCPA requirements.
Who is responsible for ensuring compliance with data protection legislation?
Compliance responsibility is assigned differently depending on which framework applies.
Under the GDPR, ultimate responsibility sits with the “data controller”: the entity that determines the purpose and means of processing. “Data processors” — including identity verification vendors — operate under contract and share compliance obligations with the controller.
The CCPA uses different terminology for the same structural relationship. The party making decisions about data collection and use is a business; the party processing data on that business’s behalf is a service provider.
Maryland’s MODPA takes a broader definitional approach. Rather than designating a named role like “controller” or “business,” MODPA places obligations on any person that conducts business in the state or provides products or services targeted to Maryland residents and meets the applicable processing thresholds.
In practice, DPOs, CCOs, and CISOs own day-to-day compliance program management.
What are the penalties for violating data minimization laws?
Penalty exposure varies significantly by jurisdiction. The GDPR’s ceiling sits at €20 million or 4% of global annual turnover for serious violations. The CCPA/CPRA carries fines of up to $7,988 per intentional violation, enforced by the California Privacy Protection Agency. And Maryland’s MODPA penalties are pursued by the state Attorney General. Across all three frameworks, per-incident fines compound quickly at the transaction volumes typical of KYC and AML workflows.
How does decentralized identity support KYC and AML compliance?
KYC and AML workflows are data-intensive by design, but decentralized identity reduces how much raw data those workflows actually require. Verification happens once; after that, a reusable credential replaces the need to re-collect a passport scan or government ID, with KYC attributes like verified name, date of birth, and residency status disclosed selectively per transaction.
Jumio’s platform automates AML screening and maintains compliance-grade records alongside identity checks.
Is biometric data subject to data minimization requirements?
Yes, biometric data is classified as sensitive or special category data under the GDPR, CCPA, and MODPA. Explicit consent is required for collection and processing in most jurisdictions, and data minimization principles require that biometric data not be stored beyond the verification purpose.
Jumio’s biometric liveness detection and facial matching processes are built to align with these elevated obligations.
How does data minimization reduce fraud risk?
Data minimization reduces fraud risk by shrinking the attack surface. Fewer records in circulation means less exposure when a breach occurs, and less value in targeting the organization in the first place. Decentralized identity eliminates the centralized repositories that credential thieves specifically seek out, while attribute-level disclosure prevents excess personal data from being harvested during the verification event itself.
Jumio’s identity intelligence platform applies data minimization principles without compromising fraud detection.
What is the difference between data minimization and purpose limitation?
Data minimization governs how much data is collected; purpose limitation governs how it can be used. Both are codified in GDPR Article 5 and reflected in the CCPA and MODPA. Together, they establish a three-part obligation: collect less, use only for stated purposes, and delete when no longer needed. Decentralized identity enforces both principles at the infrastructure level — not just the policy level.
Your Compliance Framework Starts With Smarter Identity Infrastructure
The GDPR, CCPA, MODPA, and the expanding body of state privacy laws are converging on the same core obligation: collect less, protect more. Financial services organizations that continue to over-collect identity data are accumulating both regulatory liability and breach exposure in parallel. The regulatory direction is consistent, and enforcement is accelerating.
Decentralized identity reduces data collection and embeds minimization into the verification architecture itself. That doesn’t mean centralization disappears entirely — it means it becomes accountable. What changes is not whether data is centralized somewhere, but how much, by whom, and under what obligations.
Data centralization and data minimization might seem like they’re mutually exclusive. But in reality, there is always going to be some data centralization, whether it’s a government agency that has issued your reusable digital ID or a third-party identity verification vendor. From a consumer perspective, the best approach is founded on three pillars:
- Verified Security: Your data is stored by an identity verification platform that adheres to bank-grade security practices and is regularly audited and certified for compliance.
- Purposeful Collection: The identity verification platform enables data minimization by providing only what’s needed for businesses to onboard you.
- Compatibility and Reduced Repetition: The majority of businesses you want to onboard with use that same identity verification vendor so you minimize repetition of your complete identity information with multiple vendors.
Jumio anchors digital identity credentials to a government-issued ID and a biometric selfie, verified once and reused everywhere — across over 200 countries and territories with complete GDPR, CCPA, KYC, and AML compliance. With Cross-Transaction Risk capabilities and the Jumio Identity Graph, compliance and fraud prevention operate from the same data-minimized foundation.
See how Jumio’s identity verification and decentralized identity capabilities help you minimize data collection while maximizing compliance, consumer confidence, and fraud detection. Explore Jumio’s platform today!