Skip to content
Schweizersoftware

6 min read

Data minimisation in a small business: collect less, manage less

What proportionality and purpose limitation mean in the Swiss Data Protection Act, and how they look in the everyday life of a small business.

Cover on a green background: “Data minimisation in everyday business”. Beside it a customer file in which date of birth, occupation and notes are struck through and marked as removed; name, email and appointment remain, six fields become three.

A hair salon in St. Gallen has kept a customer file for years. It began with name and phone number. Then came the address for the Christmas card, the date of birth for a birthday discount, the occupation because someone thought it might be useful, and a “notes” column that now also records who is pregnant and who has a skin condition. Nobody planned it that way. Every column once had a reason.

This is how data collections grow in small businesses: not by intention, but by opportunity. The Swiss Federal Act on Data Protection (FADP) sets one idea against that, and in everyday life it is surprisingly liberating — only as much as the purpose needs.

What the FADP means by proportionality

The principles are set out in Art. 6 FADP, and three of them work together.

Proportionate. Processing must be carried out in good faith and be proportionate (Art. 6 para. 2 FADP). The Federal Data Protection and Information Commissioner (FDPIC) explains the principle in a fact sheet like this: collect no more data than necessary and use it no more than necessary. It applies to both collecting and using.

Purpose-bound. Personal data may only be collected for a specific purpose that is recognisable to the person concerned, and may only be processed in a way compatible with that purpose (Art. 6 para. 3 FADP).

Time-limited. It is destroyed or anonymised as soon as it is no longer needed for the purpose of processing (Art. 6 para. 4 FADP).

One more duty is often overlooked: whoever processes data must make sure it is accurate and take appropriate measures so that inaccurate or incomplete data is corrected or deleted (Art. 6 para. 5 FADP). Every extra column is also a column that has to be right.

The word “data minimisation” does not appear in the Swiss act as such. It is shorthand for what these three paragraphs mean together.

Collect less: asking what for

The easiest place for data minimisation is the moment data comes into being: the form, the customer card, the registration sheet. The FDPIC gives a clear example in its fact sheet on patient forms. Systematically collecting details such as maiden name, marital status, nationality, work phone, occupation and employer’s name is, in principle, not necessary. That does not mean such details may never be asked for — occupation can be relevant for back pain. What is problematic is collecting them systematically.

This distinction carries over to any business. For every field, one question helps: what do we need this for, and do we need it from everyone?

Field in the file Typical reason The question behind it
Phone number Rescheduling appointments Is it needed, or is the email address enough?
Postal address Christmas card Does the person want post, or is it simply recorded?
Date of birth Birthday discount Are day and month enough, and only if they are interested?
Occupation “might be useful” Is there a concrete, recognisable purpose?
Free-text notes A memory aid What is written there, and would the person be happy with it?

The last row deserves attention. Free-text fields often collect details the law classes as sensitive, such as data about health (Art. 5 let. c FADP). Nobody decided to collect such data — it is simply there. A free-text field is therefore the one most worth reading through now and then.

Keep it no longer than needed

The second place is the end. Data whose purpose has been fulfilled is destroyed or anonymised (Art. 6 para. 4 FADP). The act sets no deadline, because the deadline depends on the purpose.

Where other laws require retention, they apply. The best known is in the Swiss Code of Obligations: business books and accounting records, together with the annual report and the audit report, must be kept for ten years (Art. 958f para. 1 CO). The invoice to a customer falls under this; her favourite hair colour does not.

In practice, retention easily becomes indiscriminate: because the accounts stay for ten years, everything stays for ten years. The reverse question helps — what has to stay for a particular reason, and for how long? Everything else has an expiry date, even if nobody has set it yet.

Use less: default settings and access

Data minimisation is not only about which data exists, but also about who sees it and what it is used for. The FADP requires the controller to ensure, through suitable default settings, that processing is limited to the minimum needed for the intended purpose, unless the person concerned decides otherwise (Art. 7 para. 3 FADP). And it should take this into account from the planning stage (Art. 7 para. 1 FADP).

In a small business, this means for example:

  • A newsletter box stays empty until the person ticks it themselves.
  • The temp at the front desk sees appointments and names, but not the notes.
  • An export delivers the columns needed for the purpose, not the whole table.

Employers know the same idea. In its FAQ, the FDPIC refers to Art. 328b CO, under which only processing of personal data that concerns the employee’s suitability for the job or is needed to perform the employment contract is permitted — the employer should process only the personnel data that is necessary.

Less data, less effort

Data minimisation is often seen as a restriction. For a small business it is closer to the opposite, because almost every duty in the FADP grows with the amount of data.

Data security. Controllers ensure data security appropriate to the risk (Art. 8 para. 1 FADP). What is not stored does not need protecting.

Access requests. Anyone can ask whether data about them is being processed (Art. 25 para. 1 FADP). A lean file is quicker to search and easier to explain.

Accuracy. Every detail must be correct or corrected (Art. 6 para. 5 FADP). Fewer details, less upkeep.

Data security breaches. If something is lost or reaches unauthorised people, whether a report to the FDPIC is needed depends on whether it is likely to result in a high risk for the persons concerned (Art. 24 para. 1 FADP). A list of names and appointments is one thing; a list with health notes is another.

Where to start

Tidying a customer file is rarely a project; more like an hour with a cup of coffee. The salon in St. Gallen could go about it like this:

  1. List the fields of the file and write the purpose next to each. Fields without a purpose go.
  2. Read through the notes and remove anything the work does not need — especially health details nobody consciously collected.
  3. Decide for each kind of data how long it stays, keeping the accounts separate from customer care.
  4. Adjust the registration sheet or online form so it only asks for what is left.

For individuals, the idea works the other way round: when a form asks for a lot of details, it is fair to ask what for. Mandatory fields that have nothing to do with the matter are a reason to ask.

We build our apps on the same principle: collect only what an app needs for its job. It is one of the reasons each of our apps does exactly one job.

Sources

  1. 1.Bundesgesetz über den Datenschutz (DSG, SR 235.1) (checked on 24 September 2026)
  2. 2.Obligationenrecht (OR, SR 220), namentlich Art. 958f (checked on 24 September 2026)
  3. 3.EDÖB: Merkblatt «Erläuterungen zu Patientenformularen für ärztliche und therapeutische Konsultationen» (checked on 24 September 2026)
  4. 4.EDÖB: FAQ Datenschutz (checked on 24 September 2026)

Follow our ideas

Look at our ideas and ask to be told once when one of them becomes an app. Or write to us – about an idea, about a task that deserves an app, or just to say hello.

Choose a language

This page opens in the language you choose.