Necessity and proportionality are the tests used to decide whether a data processing activity is justified and appropriately limited. Necessity asks whether the processing is needed for its stated purpose. Proportionality asks whether the scope, data use, and controls are reasonable compared with the privacy impact on individuals.
What the tests mean in practice
Necessity and proportionality are complementary legal and governance tests. Necessity asks whether a processing activity is genuinely needed to achieve a stated purpose, while proportionality asks whether the scope of collection, use, retention, and control measures are reasonable for the privacy impact involved.
Together, they force organisations to connect purpose, data volume, sensitivity, and safeguards. A process can be useful but still fail necessity if the same outcome can be achieved with less data, fewer recipients, or a narrower method.
How the tests are applied
Necessity is usually the first filter: define the purpose, then test whether each element of processing is essential to that purpose rather than merely convenient. Proportionality then asks whether the chosen design is no broader than needed, including whether the data categories, access patterns, sharing model, and retention period are justified.
In practice, this is why privacy assessments often move from a purpose statement to a more detailed review of data minimisation, access limitation, and retention controls. EU General Data Protection Regulation (GDPR) is a useful reference point because its principles and DPIA expectations reflect the same discipline of limiting processing to what is justified and necessary.
Why the distinction matters
Necessity and proportionality are not the same test. Necessity is about whether the activity should exist at all in its current form; proportionality is about whether its design is appropriately bounded. That distinction matters because an activity may be necessary in principle, yet still become excessive if it collects too much data, retains it too long, or exposes it to more people than required.
The tests also help explain why a technically lawful design can still be poor privacy practice if it ignores context. A small increase in data scope can be disproportionate when the data is sensitive, when individuals would not reasonably expect the processing, or when the control environment is weak.
Common failure modes
The most common mistakes are treating convenience as necessity, assuming “more data is better,” and writing broad purposes that make almost any processing look justified. Another failure mode is focusing only on collection, while ignoring the proportionality of storage, sharing, retention, and downstream reuse.
These failures often show up when teams copy a previous use case, expand an existing dataset for a new purpose, or keep data indefinitely “just in case.” For privacy governance, the real question is whether each additional element still has a defensible purpose and a bounded impact.
Risk and Threat Considerations
When necessity and proportionality are weak, organisations tend to accumulate unnecessary personal data, broader access, and longer retention than they can justify. That increases privacy exposure, enlarges the blast radius of a breach, and makes secondary use or internal misuse harder to control.
Failure mechanism: Over-collection, over-retention, and over-sharing create avoidable exposure because sensitive data exists in more systems, for longer periods, and with more potential recipients than the purpose requires.
Impact: The result can be greater regulatory scrutiny, higher breach impact, weaker user trust, and more difficulty defending the processing decision if challenged.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art. 5 — Principles Relating to Processing of Personal Data | Necessity and proportionality mirror GDPR's core processing principles. |
| Art. 25 — Data Protection by Design and by Default | Proportional design requires minimisation and privacy by default. | |
| Art. 35 — Data Protection Impact Assessment | DPIAs operationalise the necessity and proportionality review for higher-risk processing. | |
| Recommendation — Limit each processing activity to a defined lawful purpose and the minimum personal data needed. Build privacy limits into the design so default settings collect and expose the least data. Document why the processing is needed, what the privacy impact is, and how risks are reduced. | ||
| NIST SP 800-53 Rev 5 | PT-2 — Authority to Process Personal Data | PT-2 directly governs whether personal data processing is authorised and bounded by purpose. |
| PT-3 — Personally Identifiable Information Processing and Transparency | PT-3 requires explicit privacy-aware processing decisions and transparency around use. | |
| PT-5 — Privacy Notice | Notice supports proportional processing by making collection and use understandable to individuals. | |
| Recommendation — Define and constrain personal-data processing to the authorised purpose and approved scope. Specify what personal data is processed, why it is needed, and how individuals are informed. Publish clear notices that accurately describe the purpose and limits of data processing. | ||
| ISO/IEC 27001:2022 | A.5.34 — Privacy and Protection of PII | This Annex A control anchors privacy governance for justified and limited processing of personal data. |
| Recommendation — Apply privacy controls that limit personal-data use to the stated and justified purpose. | ||
Practitioner Guidance
What to watch for: Use these tests as a design checkpoint whenever a team proposes new data collection, a new purpose, or a retention extension. If the answer depends on “it might be useful later,” or if the same outcome can be achieved with less data, the case for necessity is weak.
Governance implication: Treat necessity and proportionality as an approval standard, not a wording exercise. The strongest submissions are specific about purpose, clearly limited in scope, and able to explain why each data element, recipient, and retention period is justified.
Related resources from NHI Mgmt Group
- What happens when organisations try to use facial recognition for retail crime prevention without a proportionality assessment?
- How should organisations balance age assurance with privacy and proportionality?
- What is the difference between strict necessity and consent-based cookie use?
- Why does behavioural advertising create compliance risk when teams rely on contractual necessity?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org