Purpose Limitation
What is Purpose Limitation?
Purpose Limitation is a data-protection principle that mandates personal data be collected for specific, explicit and legitimate purposes. This ensures that data is not collected or used in a manner incompatible with those purposes.
The UK Information Commissioner's Office (ICO) explains that the principle of purpose limitation requires organisations to identify, document and communicate the purposes for which personal data are collected before processing begins. Data must be collected only for specified, explicit and legitimate purposes, and any subsequent processing must either be compatible with the original purpose or be supported by a separate lawful basis where required. The guidance emphasises that clearly defining processing purposes promotes transparency, accountability and compliance with other data protection principles, including data minimisation and lawfulness. It also serves as an important safeguard against function creep, preventing organisations from gradually expanding the use of personal data beyond what individuals could reasonably expect. Where controllers intend to reuse personal data for a different purpose, they must assess whether the new purpose is compatible with the original one, taking into account factors such as the relationship between the purposes, the reasonable expectations of data subjects, the nature of the personal data, the consequences of the new processing, and any appropriate safeguards. The ICO further stresses that organisations should periodically review their processing activities and update their privacy information if processing purposes evolve over time.
"Why do we need to specify our purposes? You must specify your purposes. Doing so ensures that you’re clear and open about your reasons for collecting personal information and that what you do with people’s information is in line with their reasonable expectations. Specifying your purposes from the outset helps you remain accountable for your processing and helps you avoid ‘function creep’. It also helps people: understand how you’ll use their information; make decisions about whether they’re happy to share their information; and exercise their data protection rights over their information, where appropriate. It is fundamental to building public trust with people, who are more likely to agree to you using their information if they can see what you intend to use it for."
Official Definition of Purpose Limitation
Digital Personal Data Protection Act [India][2023]
The legislation[1] reiterated the principle of purpose limitation in its definition of 'specified purpose'. Section 2(za) read with Section 6(1) of the Act mandates that the data collected from a person must strictly be limited to what is necessary for the purposes specified in the notice consented to.
Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules [India][2011]
In the Rules[2], Rule5(5) mandates that organisations that collect information must use the information only for the purpose for which it was collected. The rules prevent repurposing or selling user date for unrelated or unstated business uses without obtaining specified content for the same from the user. The rules aim to implement the purpose limitation principle without expressly mentioning it verbatim.
As Defined in Official Government Reports
A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians [Committee of Experts on Data Protection Framework for India][2018]
Under this policy document[3], Purpose Limitation means personal data must only be used for the specific purposes for which it was originally collected, preventing uncontrolled repurposing of data and preserving the individual's autonomy over personal information.
The purpose limitation principle has been the bedrock of data protection regimes for the last three decades.182 It contains two sub-principles: first, that the purpose for which the personal data is processed must be clearly specified to the data principal (purpose specification); second, the processing must be limited to such purposes, or other compatible purposes (use limitation). Implicit in each of these sub-principles are two assumptions: first, that specification of purpose must meet a certain standard of specificity — simply specifying purposes in a vague manner will not be sufficient. Second, any unspecified use will be determined from the point of view of whether the processing is fair and reasonable in light of the purpose that was specified.
International Experience
The Algorithm in the Courtroom: How Artificial Intelligence is Reshaping Justice and the Rule of Law Across Asia and the Pacific [UNDP][2026]
The United Nations Development Programme's report examines the rapid integration of artificial intelligence across justice systems in the Asia-Pacific region and its implications for the rule of law. It analyses the deployment of AI in judicial administration, legal research, case management, language translation and decision-support systems while evaluating the associated risks to judicial independence, due process, transparency and public trust. The glossary of terms defines Purpose Limitation as below:
Purpose Limitation[4] A data protection principle requiring that personal data be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
EU-US Data Privacy Framework [EU][2023]
The document[5] incorporates the Purpose Limitation Principle by requiring participating organisations to process personal information only in ways that are compatible with the purposes for which it was originally collected or subsequently authorised by the individual. Where processing materially changes or extends beyond the original purpose, organisations must provide appropriate notice and, where necessary, obtain fresh consent. This framework demonstrates that purpose limitation continues to govern cross-border data transfers by ensuring that transferred data are not repurposed inconsistently with the expectations of the data subject.
Personal Information Protection Law [China][2021]
The legislation[6] adopts purpose limitation as a central principle governing personal information processing. Article 6 provides that personal information processing must have a clear and reasonable purpose, be directly related to that purpose, and be conducted in a manner that has the minimum impact on individuals' rights and interests. The provision also requires that the collection of personal information be limited to the minimum scope necessary for achieving the stated purpose, thereby closely linking purpose limitation with the principle of data minimisation. Unlike the GDPR, which permits compatibility assessments for certain subsequent uses, the PIPL adopts a comparatively stricter approach by requiring that any change in processing purpose generally be accompanied by renewed notice and, where applicable, separate consent from the individual. This reflects China's emphasis on limiting function creep and strengthening individual control over the subsequent use of personal information.
Article 6 Processing of personal information shall be for a definite and reasonable purpose, shall be directly related to the purpose of processing, and shall be processed in a manner that has the least impact on individual rights and interests. Collection of personal information shall be limited to the minimum scope for the purpose of processing and excessive collection of personal information shall not be allowed.
General Data Protection Regulation [EU][2016]
The EU legislation[7] defines purpose limitation categorically under Article 5(1)(b). GDPR mandates that organizations must clearly define why they collect personal data, and they cannot later use that data for unrelated purposes without lawful justification.
Principles relating to processing of personal data 1. Personal data shall be: (b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);
The explanation to Article 5(1)(b) as stated by the UK Information Commissioner's Office (ICO) is as follows:
"This means that you must: be clear from the outset about why you’re collecting personal information and what you intend to do with it; document your purpose for collecting the information; tell people why you’re collecting their information; and ensure that if you plan to reuse personal information for a different purpose from the originally specified purpose, the new use is compatible with the original."
Guidelines Governing the Protection of Privacy and Trans-border Flows of Personal Data [OECD][2013]
An understanding of Purpose Limitation can be discerned from the guidelines[8] and its definition of 'Purpose Specification' and 'Use Limitation'. It says personal data must be collected for a clearly identified purpose, and later use of that data must remain confined to that purpose unless a compatible new purpose is identified and communicated.
Purpose Specification Principle 9.The purposes for which personal data are collected should be specified not later than at the time of data collection and the subsequent use limited to the fulfilment of those purposes or such others as are not incompatible with those purposes and as are specified on each occasion of change of purpose.
Act on the Protection of Personal Information [Japan][2003]
Japan's legislation[9] incorporates purpose limitation through a series of interconnected obligations. Under Article 17, business operators handling personal information must specify the purpose of utilisation as clearly as possible before or at the time of collection. Article 18 requires that personal information be used only within the scope necessary to achieve the specified purpose of utilisation, while Article 19 prohibits processing beyond that scope unless authorised by law or supported by the individual's consent.
The APPI therefore adopts a lifecycle approach to purpose limitation by requiring organisations to (i) clearly identify the purpose of processing, (ii) notify or publicly disclose that purpose, and (iii) restrict subsequent processing to activities reasonably connected with the original purpose. Any substantial alteration of the purpose of utilisation must remain reasonably related to the original purpose or be accompanied by appropriate notification and, where required, fresh consent. The Japanese approach illustrates how purpose limitation promotes transparency and predictability throughout the processing lifecycle while permitting carefully regulated flexibility for legitimate business and public interests.
(Specifying the Purpose of Use) Article 17 (1)In handling personal information, the business handling personal information must specify as much as possible the purpose for which it uses that information (hereinafter referred to as the "purpose of use"). (2)When altering the purpose of use, businesses handling personal information must not alter it beyond the extent that can be appreciably linked to what it was before the alteration.
Variations
Slight differences and nuances in the concept
Use Limitation
The OECD guidelines[8] and its definition of 'Use Limitation' is synonymous to how purpose limitation is understood. It says personal data must be collected for a clearly identified purpose, and later use of that data must remain confined to that purpose unless a compatible new purpose is identified and communicated.
Use Limitation Principle 10.Personal data should not be disclosed, made available or otherwise used for purposes other than those specified in accordance with Paragraph 9 except: a)with the consent of the data subject; or b)by the authority of law.
Collection Limitation
Collection limitation[3] requires that only personal data that are adequate, relevant and necessary for a clearly defined processing purpose should be collected. The principle prohibits excessive or indiscriminate collection of personal data by ensuring that data controllers limit collection to the minimum amount required to achieve the specified purpose. Read together with the principle of purpose limitation, it ensures that personal data are not only collected in a proportionate manner but are also processed solely for the purposes for which they were originally collected, or for purposes that are compatible with those original objectives.
The principle of collection limitation mandates that only such data should be collected that is necessary for achieving the purposes specified for such processing. Thus, the minimum data necessary for achieving a purpose could be collected, and such data used only for the specified purpose and other compatible purposes and no other. Taken together, these are designed to lead to data minimisation that in turn, allows greater granular control for the data principal.
Research that engages with ‘Purpose Limitation’
Updating Purpose Limitation for AI: A normative approach from law and philosophy [2024]
The paper[10] argues that traditional purpose limitation doctrine cannot adequately regulate modern AI as AI systems tend to derive value from open-ended secondary use of data, meaning future regulation ought to move beyond controlling data collection and towards regulation of the permissible purposes and capabilities of AI.
The Purpose and Limitations of Purpose Limitation [2020]
The research[11] argues that purpose limitation is the organising principle of European data protection law, ensuring that personal data are collected and processed only for specific, explicit and legitimate purposes, while preventing incompatible subsequent uses. Rather than viewing the principle merely as a restriction on further processing, it demonstrates that purpose limitation performs multiple functions throughout the data processing lifecycle. It promotes transparency by informing individuals why their data are collected, limits the exercise of data controller discretion, reinforces accountability, facilitates the application of related principles such as data minimisation and storage limitation, and protects individuals from function creep. At the same time, the thesis recognises that purpose limitation is increasingly challenged by developments in artificial intelligence, big data analytics and machine learning, where future uses of data are often unknown at the time of collection. Therefore, it contends that the principle should not be abandoned but interpreted alongside complementary safeguards including compatibility assessments, accountability obligations and contextual evaluation to ensure that technological innovation remains consistent with the fundamental objective of protecting informational self-determination and preventing unforeseen or excessive uses of personal data.
Purpose Limitation By Design As A Counter To Function Creep And System Insecurity In Police Artificial Intelligence [2020]
This paper[12] argues that traditional legal rules on purpose limitation are insufficient when applied to AI systems, especially police AI, because once data-intensive AI infrastructures are deployed, systems tend naturally toward “function creep.” It proposes a system of 'Purpose Limitation by Design' in the context of AI.
The Keys to Data Protection- Part 3 [Privacy International][2018]
The document[13] culls out major principles in data protection law. Purpose Limitation is a principle that mandates personal data be processed for a specified, explicit and legitimate purpose. The said purpose must be stated at the point of collection, and all further processing ought to be compatible with this purpose.
Challenges and Way Forward
Across the literature, legislation and policy documents surveyed, several recurring challenges emerge in applying the traditional principle of purpose limitation to contemporary AI systems. While purpose limitation remains one of the foundational principles of data protection law, the rise of machine learning, foundation models and large-scale data analytics has exposed significant doctrinal and practical limitations.
Challenges
Incompatibility between traditional purpose limitation and AI development
Traditional data protection regimes assume that the purpose for processing personal data can be identified before collection and remain relatively stable throughout the processing lifecycle. AI systems operate differently. Modern machine learning models frequently rely on broad, continuously expanding datasets whose future uses cannot always be anticipated at the point of collection. Training datasets are often reused to improve model performance, fine-tune algorithms or develop entirely new applications, making it difficult to define one fixed processing purpose. This creates tension between innovation and compliance with purpose limitation. Research has therefore questioned whether conventional purpose limitation can effectively regulate AI without significant reinterpretation.
Function creep and secondary use of personal data
One of the principal objectives of purpose limitation is to prevent "function creep", where data collected for one purpose are gradually reused for unrelated objectives without the knowledge or reasonable expectations of the data subject. AI systems significantly increase this risk because data often possess continuing value beyond their original purpose. Organisations may subsequently use existing datasets for predictive analytics, behavioural profiling, model retraining or commercial research without obtaining renewed consent or conducting meaningful compatibility assessments. This progressively weakens individual autonomy and undermines transparency, contrary to the core objectives of purpose limitation.
Technical limitations of machine learning systems
Purpose limitation presumes that data controllers retain meaningful control over the lifecycle of personal data. In AI systems, however, personal information may become embedded within trained models, model parameters or learned representations. Once a model has been trained, removing the influence of particular datasets or complying with requests for deletion may be technically difficult without retraining the model altogether. Consequently, traditional mechanisms for enforcing purpose limitation become significantly less effective once data have contributed to model development.
Vague and overly broad specification of processing purposes
Many organisations rely on broad descriptions such as "service improvement", "research", "security" or "product development" when collecting personal data. Although these statements technically identify a purpose, they provide little practical limitation on subsequent processing. Broad purpose statements diminish the effectiveness of compatibility assessments, reduce transparency for data subjects and create opportunities for expansive secondary uses that would otherwise require additional consent or legal justification.
Balancing purpose limitation with competing regulatory objectives
Strict adherence to purpose limitation may sometimes conflict with other principles of responsible AI governance. AI systems often require diverse and representative datasets to minimise algorithmic bias, improve fairness and enhance accuracy. Restricting processing too narrowly may inadvertently reduce dataset diversity and impair model performance. Regulators therefore face the challenge of balancing purpose limitation with data minimisation, fairness, accountability and innovation rather than treating these principles as operating independently.
Weak enforcement and regulatory uncertainty
Although purpose limitation appears prominently across major data protection frameworks—including the GDPR, DPDP Act, PIPL and APPI—its practical enforcement remains inconsistent. Supervisory authorities often encounter difficulties identifying impermissible secondary uses, particularly where organisations internally reuse data for analytics or AI model improvement without making such processing externally visible. The absence of AI-specific regulatory guidance further contributes to uncertainty regarding compatibility assessments, retraining practices and lawful secondary processing.
Way Forward
The comparative analysis demonstrates that purpose limitation remains an indispensable safeguard against excessive processing and function creep, but its application requires recalibration for AI-driven environments rather than abandonment.
First, legislators should develop AI-specific guidance explaining how purpose limitation applies throughout the AI lifecycle, including data collection, model training, validation, deployment, fine-tuning and continuous learning. Rather than treating AI training as a single processing activity, regulators should distinguish between successive processing stages and clarify the lawful purposes applicable to each.
Second, purpose specification should be made substantially more granular. Organisations should avoid generic processing descriptions and instead identify distinct purposes for data collection, model development, product improvement, research, security and commercial deployment. Such specificity would strengthen transparency and make compatibility assessments more meaningful.
Third, compatibility assessments should become a mandatory and documented exercise whenever personal data are proposed to be reused for AI model improvement or secondary processing. These assessments should evaluate the relationship between the original and new purposes, the reasonable expectations of individuals, the sensitivity of the data involved, the risks posed by further processing and the technical safeguards adopted by the organisation. This approach is consistent with the broader accountability framework reflected in the GDPR and the ICO's guidance.
Fourth, technical measures should increasingly complement legal obligations. Privacy-enhancing technologies including privacy-preserving machine learning, federated learning, differential privacy, secure multiparty computation and machine unlearning techniques can reduce reliance on unrestricted reuse of identifiable personal data while preserving AI functionality. Embedding "purpose limitation by design" into AI system architecture can minimise opportunities for unauthorised secondary processing from the outset.
Fifth, regulators should strengthen organisational accountability by requiring controllers to maintain detailed records of AI training datasets, document subsequent uses of personal data, periodically review whether processing remains compatible with the original purpose and publish meaningful information regarding AI data governance. Independent audits and algorithmic impact assessments should also evaluate compliance with purpose limitation alongside fairness, transparency and explainability obligations.
Finally, judicial interpretation will play an increasingly important role in adapting purpose limitation to AI. Courts can develop jurisprudence clarifying the meaning of compatible processing in machine learning contexts, define reasonable expectations of data subjects where AI training is involved and ensure that technological innovation does not erode the fundamental objective of purpose limitation namely, preserving individual autonomy, preventing function creep and maintaining public trust in data-driven technologies.
Overall, the comparative materials indicate that purpose limitation remains central to modern data protection law. However, its continued effectiveness will depend upon moving from a static, collection-focused principle towards a dynamic, lifecycle-based framework capable of regulating the iterative and evolving nature of artificial intelligence while preserving the underlying values of transparency, accountability and informational self-determination.
- ↑ Digital Personal Data Protection Act 2023 (Act No 22 of 2023, India).
- ↑ Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 (GSR 313(E), India, 11 April 2011).<https://upload.indiacode.nic.in/showfile?actid=AC_CEN_45_76_00001_200021_1517807324077&type=rule&filename=GSR313E_10511(1)_0.pdf>
- ↑ 3.0 3.1 Joint Committee on the Personal Data Protection Bill, Committee Report on the Draft Personal Data Protection Bill, 2018 (Parliament of India, 2019)https://prsindia.org/files/bills_acts/bills_parliament/2019/Committee%20Report%20on%20Draft%20Personal%20Data%20Protection%20Bill,%202018_0.pdf
- ↑ United Nations Development Programme, Regional Bureau for Asia and the Pacific, The Algorithm in the Courtroom: How Artificial Intelligence Is Reshaping Justice and the Rule of Law Across Asia and the Pacific (UNDP RBAP 2026).
- ↑ European Commission, Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 pursuant to Regulation (EU) 2016/679 on the adequate level of protection of personal data under the EU–US Data Privacy Framework [2023] OJ L231/118.
- ↑ Personal Information Protection Law of the People's Republic of China 2021, arts 6–7.
- ↑ Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) [2016] OJ L 119/1.
- ↑ 8.0 8.1 Organisation for Economic Co-operation and Development, Recommendation of the Council concerning Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data (OECD/LEGAL/0188, 23 September 1980, revised 11 July 2013)<https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0188>
- ↑ Act on the Protection of Personal Information (Act No 57 of 2003, as amended), arts 17–19.
- ↑ Mühlhoff R and Ruschemeier H, ‘Updating Purpose Limitation for AI: A Normative Approach from Law and Philosophy’ (working paper, 22 January 2024)<https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4711621&__cf_chl_f_tk=.QxNjm1RHZGm2VJ9fSpycK7kaQ9nbhQbKKSMM8_dvpE-1782820418-1.0.1.1-A6..w2dKRXIoIRXRV5D6McuLnrvyttjjoZr0CoUQHdQ>
- ↑ Koning ME, The Purpose and Limitations of Purpose Limitation (PhD thesis, Radboud University Nijmegen 2020).https://merelkoning.nl/wp-content/uploads/2020/10/M.Koning_The-purpose-and-limitations-of-purpose-limitation_thesis.pdf
- ↑ Emanuilov I, Fantin S, Marquenie T and Vogiatzoglou P, ‘Purpose Limitation by Design as a Counter to Function Creep and System Insecurity in Police AI’ (SSRN Working Paper, 21 August 2020)<https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3679850>
- ↑ Privacy International,Part 3 – Data Protection Principles (The Keys to Data Protection series, August 2018)<https://privacyinternational.org/sites/default/files/2018-09/Part%203%20-%20Data%20Protection%20Principles.pdf>