Data must not be used for purposes undisclosed at collection
Aliases: use limitation · purpose specification · incompatible use
What it is
Purpose limitation confines personal data to the explicit, specific purposes established when it was collected. It governs why processing occurs, not merely who can access a dataset. Lawful possession by the same team does not by itself authorize incompatible advertising, scoring, or model-training uses. Elastic phrases such as “improve services” fail to create a testable boundary.
Why it happens
Disclosure decisions depend on an expected exchange: what information is given, for which function, and with what possible consequences. Function creep changes that exchange while exploiting cheap copying and sunk collection costs. If new uses inherit old permissions automatically, organizations can redirect data toward evolving commercial or technical goals while people lose the chance to assess risk before disclosure. A specific purpose gives flows, access, and outputs a common constraint.
Studying it
Researchers can code collection screens, policy versions, and requirements into a purpose inventory, then reconcile it with query logs, model features, sharing interfaces, and product outcomes. Measures include processing without a declared mapping, specificity of purpose language, renewed-choice rates after changes, and users' ability to predict consequences. Technical similarity is not contextual compatibility: two tasks consuming the same field are not necessarily perceived as the same purpose.
Where it stops holding
Purpose limitation does not prohibit every later operation. Security response, legal obligations, properly governed public-interest research, or processing demonstrably compatible with the original purpose may rest on another basis. Compatibility depends on collection context, sensitivity, new consequences, and safeguards. Truly anonymous data may change the object of risk, but pseudonymization or simple de-identification does not automatically remove the constraint.
Applying it
- State purposes at collection as observable user outcomes and record prohibited uses, avoiding departmental goals or generic benefits.
- Attach purpose metadata to datasets, fields, and access requests so queries, exports, and training jobs are checked before execution.
- Trace every proposed new output back to its original notice; pause unmatched processing instead of rewriting copy to ratify an accomplished use.
- Send marked test records through the pipeline and verify that they reach only declared functions, logs, and recipients; report unexplained destinations at release review.