Purpose limitation

The GDPR principle that personal data collected for a specified purpose may not be further processed in an incompatible way; Article 6(4) sets the compatibility test 1. Enforced in AI pipelines by purpose tags on datasets and a policy that denies runs whose declared purpose does not match.

Developed in
ch. 19, Purpose limitation and function creep
Chapters
ch. 19, Privacy & AI
Source
1 numbered reference, listed below

Where it is used

3 chapters of the Body of Knowledge use the term. Each link opens the first section that does.

Patterns that use this term

One pattern page uses the term.

Sources

  1. [1] Regulation (EU) 2016/679 (General Data Protection Regulation) (Arts. 4(1), 4(5), 4(7), 4(8), 4(12), 4(14), 5, 6, 9, 12(3), 22, 25, 28(2) and 28(4), 30, 33, 35; Recital 26). Publications Office of the EU (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Purpose limitation. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/purpose-limitation. CC BY 4.0

BibTeX

@misc{aige2026purposelimitation,
  author  = {Jorge García Aibar},
  title   = {{Purpose limitation}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/purpose-limitation}
}