Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Necessity And Proportionality
Governance, Ownership & Risk

Necessity And Proportionality

← Back to Glossary
By NHI Mgmt Group Updated September 30, 2026 Domain: Governance, Ownership & Risk

Necessity and proportionality are the tests used to decide whether a data processing activity is justified and appropriately limited. Necessity asks whether the processing is needed for its stated purpose. Proportionality asks whether the scope, data use, and controls are reasonable compared with the privacy impact on individuals.

What the tests mean in practice

Necessity and proportionality are complementary legal and governance tests. Necessity asks whether a processing activity is genuinely needed to achieve a stated purpose, while proportionality asks whether the scope of collection, use, retention, and control measures are reasonable for the privacy impact involved.

Together, they force organisations to connect purpose, data volume, sensitivity, and safeguards. A process can be useful but still fail necessity if the same outcome can be achieved with less data, fewer recipients, or a narrower method.

How the tests are applied

Necessity is usually the first filter: define the purpose, then test whether each element of processing is essential to that purpose rather than merely convenient. Proportionality then asks whether the chosen design is no broader than needed, including whether the data categories, access patterns, sharing model, and retention period are justified.

In practice, this is why privacy assessments often move from a purpose statement to a more detailed review of data minimisation, access limitation, and retention controls. EU General Data Protection Regulation (GDPR) is a useful reference point because its principles and DPIA expectations reflect the same discipline of limiting processing to what is justified and necessary.

Why the distinction matters

Necessity and proportionality are not the same test. Necessity is about whether the activity should exist at all in its current form; proportionality is about whether its design is appropriately bounded. That distinction matters because an activity may be necessary in principle, yet still become excessive if it collects too much data, retains it too long, or exposes it to more people than required.

The tests also help explain why a technically lawful design can still be poor privacy practice if it ignores context. A small increase in data scope can be disproportionate when the data is sensitive, when individuals would not reasonably expect the processing, or when the control environment is weak.

Common failure modes

The most common mistakes are treating convenience as necessity, assuming “more data is better,” and writing broad purposes that make almost any processing look justified. Another failure mode is focusing only on collection, while ignoring the proportionality of storage, sharing, retention, and downstream reuse.

These failures often show up when teams copy a previous use case, expand an existing dataset for a new purpose, or keep data indefinitely “just in case.” For privacy governance, the real question is whether each additional element still has a defensible purpose and a bounded impact.

Risk and Threat Considerations

When necessity and proportionality are weak, organisations tend to accumulate unnecessary personal data, broader access, and longer retention than they can justify. That increases privacy exposure, enlarges the blast radius of a breach, and makes secondary use or internal misuse harder to control.

Failure mechanism: Over-collection, over-retention, and over-sharing create avoidable exposure because sensitive data exists in more systems, for longer periods, and with more potential recipients than the purpose requires.

Impact: The result can be greater regulatory scrutiny, higher breach impact, weaker user trust, and more difficulty defending the processing decision if challenged.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt. 5 — Principles Relating to Processing of Personal DataNecessity and proportionality mirror GDPR's core processing principles.
Art. 25 — Data Protection by Design and by DefaultProportional design requires minimisation and privacy by default.
Art. 35 — Data Protection Impact AssessmentDPIAs operationalise the necessity and proportionality review for higher-risk processing.
Recommendation — Limit each processing activity to a defined lawful purpose and the minimum personal data needed. Build privacy limits into the design so default settings collect and expose the least data. Document why the processing is needed, what the privacy impact is, and how risks are reduced.
NIST SP 800-53 Rev 5PT-2 — Authority to Process Personal DataPT-2 directly governs whether personal data processing is authorised and bounded by purpose.
PT-3 — Personally Identifiable Information Processing and TransparencyPT-3 requires explicit privacy-aware processing decisions and transparency around use.
PT-5 — Privacy NoticeNotice supports proportional processing by making collection and use understandable to individuals.
Recommendation — Define and constrain personal-data processing to the authorised purpose and approved scope. Specify what personal data is processed, why it is needed, and how individuals are informed. Publish clear notices that accurately describe the purpose and limits of data processing.
ISO/IEC 27001:2022A.5.34 — Privacy and Protection of PIIThis Annex A control anchors privacy governance for justified and limited processing of personal data.
Recommendation — Apply privacy controls that limit personal-data use to the stated and justified purpose.

Practitioner Guidance

What to watch for: Use these tests as a design checkpoint whenever a team proposes new data collection, a new purpose, or a retention extension. If the answer depends on “it might be useful later,” or if the same outcome can be achieved with less data, the case for necessity is weak.

Governance implication: Treat necessity and proportionality as an approval standard, not a wording exercise. The strongest submissions are specific about purpose, clearly limited in scope, and able to explain why each data element, recipient, and retention period is justified.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org