ParamergeParamerge

Practice Library

Governance patternstructural

Data minimization

Write less and keep less: the least data that does the job is the least there is to leak, to contaminate, and to purge later.

What it changes

dampenedAdopted failures documented into records(less written into the record)
dampenedFailures written directly into records(machine writes bounded and aged out)
dampenedClient data pasted into an unsanctioned tool(less identifiable data on hand to paste out)
dampenedModel runs on an ungoverned host with no privacy guardrails(less identifiable data reaching the vendor-hosted model)
dampenedRecords replicated outside the governed system(fewer records on hand to replicate out of the boundary)

Who can pull it

Data-protection officerDeploying organizationHarness builder

What it looks like institutionally

Every field written and every record retained is a liability with no expiry: it can be adopted as fact, retrieved into a model, replicated to a system nobody is watching, or pasted into a tool nobody vetted. Data minimization treats the record itself as the attack surface and shrinks it — collect only what the task needs, write only what must persist, and age out what no longer earns its place.

In a sociotechnical deployment this is not a one-time schema decision but a standing discipline on the write edges: what the model is allowed to commit to the record, what a worker documents from an AI draft, how long either survives. Bounding those flows lowers exposure everywhere downstream at once, because there is simply less identifiable material in motion — less to read and believe, less to retrieve back into the model, less to carry out of the building under time pressure. It also bounds the ways data crosses the system boundary: less identifiable material reaches a vendor-hosted model and less is left to replicate out to an ungoverned store. Minimization slows those exits — it does not close them; a data-processing agreement or self-hosting closes the model's path out, and connection authorization closes the record's.

The person who owns this is typically a data-protection officer: an accountable role scoped to the systems holding personal data, empowered to say what is written and kept and what is not. National-survey findings put the demand squarely here — concerns about client data privacy and security are the profession's most-reported barrier to AI use, and stronger privacy and confidentiality protection is the single most-requested improvement to the tools.

Two costs belong in the same paragraph as the protection, because the practice already carries both. Practitioners in the cited literature deliberately omit sexual-orientation and gender-identity data from client information systems to protect people from exposure, forced outing or violence — a considered deviation from data-completeness norms, not a recording error. And a record deliberately kept thinner supports less verification: minimising trades exposure against the evidence the correction loop itself runs on. The duty that travels with it is purpose limitation — consent obtained for one purpose does not cover reuse of that data to train a model for another — which is how the data-protection regulation states the two together. Direction only: none of these sources measures the size of either cost.

The discipline it must never collapse into: deleting records blind to buy the appearance of safety. Removing content by volume rather than by what it contains can strip the benign material that was diluting the harmful, and a documented PAN-run scenario shows exactly this backfire — the contaminated share of a record system rising after a content-blind purge. Minimize what is written and how long it is kept; correct what is already there by content, never by panic.

Addresses: Unsafe data flow / privacy & confidentiality · Contaminated records read as fact · Data pasted into unsanctioned tools · Data reaching a vendor-hosted model · Records replicated out of the boundary. Test a version of this lever in the PAN Lab.

Deciding whether this lever fits your deployment?

Which patterns matter, and in what order, depends on your system's actual shape. Ranking your options on evidence, with what can backfire stated, is engagement work.

Sources & Evidence

Claims made on this page and what supports them. The full registry lives in Evidence.

ScenarioIn the sociotechnical simulation, deleting records without reading them raised the contaminated share by strip…

In the sociotechnical simulation, deleting records without reading them raised the contaminated share by stripping out benign entries; only content-aware cleanup reliably reduced it.

From the sociotechnical simulation: PAN governance-lever audit.

EmpiricalIn the 2025–2026 University of Texas at Austin / NASW national survey of U.S. social workers, concerns about d…

In the 2025–2026 University of Texas at Austin / NASW national survey of U.S. social workers, concerns about data privacy and security were the most frequently reported challenge to using AI in practice (46.5% of respondents), and an increased focus on client privacy and confidentiality was the most requested improvement to AI tools for social work (50.4%).

isbanner2022AcademicSave

Isbanner, S., O'Shaughnessy, P., Steel, D., Wilcock, S., & Carter, S. (2022). The Adoption of Artificial Intelligence in Health Care and Social Services in Australia: Findings From a Methodologically Innovative National Survey of Values and Attitudes (the AVA-AI Study). Journal of Medical Internet Research, 24(8), e37611. https://doi.org/10.2196/37611

doi.org/10.2196/37611

Appears in: Evidence reverification (2026)

Topics: human-ai-interaction, public-benefits

EmpiricalThe LGBTQIA+ chapter documents a governance trade-off practitioners already make: social work professionals in…

The LGBTQIA+ chapter documents a governance trade-off practitioners already make: social work professionals intentionally omit sexual-orientation and gender-identity data from client information systems to protect people from exposure, forced outing or violence. The chapter frames this as a considered deviation from data-completeness norms rather than a recording error, reports it from the literature it reviews, and gives no prevalence figure.

downey2026AcademicSave

Downey, D. L., & Jenkins, D. A. (2026). AI in Supporting LGBTQIA+ Populations. In R. An & M. A. Lindsey (Eds.), Artificial Intelligence in Social Work: Bridging Technology and Humanity. Springer. https://doi.org/10.1007/978-3-032-18443-6_7

doi.org/10.1007/978-3-032-18443-6_7

Appears in: AI in Social Work (Springer, 2026)

Topics: lgbtqia, social-work

ConceptualMinimisation carries a cost the protective case usually leaves out: a record deliberately kept thinner is also…

Minimisation carries a cost the protective case usually leaves out: a record deliberately kept thinner is also a record that supports less verification, so minimising trades exposure against the evidence the correction loop itself runs on. The duty that travels with it is purpose limitation — consent obtained for one purpose does not cover reuse of that data to train a model for another — which is how the data-protection regulation states the two together. Direction only: none of these sources measures the size of either cost.

downey2026AcademicSave

Downey, D. L., & Jenkins, D. A. (2026). AI in Supporting LGBTQIA+ Populations. In R. An & M. A. Lindsey (Eds.), Artificial Intelligence in Social Work: Bridging Technology and Humanity. Springer. https://doi.org/10.1007/978-3-032-18443-6_7

doi.org/10.1007/978-3-032-18443-6_7

Appears in: AI in Social Work (Springer, 2026)

Topics: lgbtqia, social-work

an2026aAcademicSave

An, R., & Lindsey, M. A. (2026). Ethical Foundations of AI in Social Work. In R. An & M. A. Lindsey (Eds.), Artificial Intelligence in Social Work: Bridging Technology and Humanity. Springer. https://doi.org/10.1007/978-3-032-18443-6_2

doi.org/10.1007/978-3-032-18443-6_2

Appears in: AI in Social Work (Springer, 2026)

Topics: ai-ethics, social-work

europeanparliamentandcouncil2016GroundingRegulatorySave

European Parliament and Council of the European Union (2016). Regulation (EU) 2016/679 (General Data Protection Regulation), Article 5 — purpose limitation and data minimisation. https://eur-lex.europa.eu/eli/reg/2016/679/oj

https://eur-lex.europa.eu/eli/reg/2016/679/oj

Appears in: Evidence addition (2026)

Grounds: privacy law: purpose limitation and data minimisation (GDPR)