Purpose limitation prevents silent mission creep
Data collected for one purpose drifting into another, one small reasonable step at a time, is how most privacy problems actually arise.
Nobody decides to repurpose it. Somebody notices the data exists and builds something useful with it, then somebody else builds on that. Each step is defensible and the end state would never have been approved if proposed at the start. Fixing the purpose early is what stops the drift, because it forces the question each time.
More on Privacy engineering
- Anonymisation is about re-identification riskThe name was the easy part
- Differential privacy limits one person's influenceOne person cannot move the needle
- Consent interfaces can undermine genuine choiceBoth answers, very different distances
- Privacy by design moves decisions earlierA line on the plan, or a hole in the wall
- A privacy notice does not create permissionTelling is not asking
- Data subject rights depend on finding the dataThe right ends where the index does
