---
title: "Purpose limitation"
description: "The GDPR principle that personal data collected for a specified purpose may not be further processed in an incompatible way; Article 6(4) sets the compatibility test."
canonical: https://aigovernanceengineer.com/glossary/purpose-limitation
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Purpose limitation

The GDPR principle that personal data collected for a specified purpose may not be further processed in an incompatible way; Article 6(4) sets the compatibility test [1]. Enforced in AI pipelines by purpose tags on datasets and a policy that denies runs whose declared purpose does not match.

- Developed in: [ch. 19, Purpose limitation and function creep](https://aigovernanceengineer.com/bok/privacy-and-ai#purpose-limitation-and-function-creep)
- Chapters: [ch. 19, Privacy & AI](https://aigovernanceengineer.com/bok/privacy-and-ai)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-purpose-limitation

## Sources

[1] Regulation (EU) 2016/679 (General Data Protection Regulation) (Arts. 4(1), 4(5), 4(7), 4(8), 4(12), 4(14), 5, 6, 9, 12(3), 22, 25, 28(2) and 28(4), 30, 33, 35; Recital 26). Publications Office of the EU (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
