Adequate, relevant and limited to what is necessary is a test applied to every field, not to the dataset as a whole.
Why it matters when the plan changes
Assessment tools invite over-collection because more data feels like more insight, and legacy templates carry fields that nobody has revisited. The principle, set out in Article 5 of the GDPR, turns that instinct around: each item collected has to earn its place against the stated purpose, not against what might be convenient to report later. Data that might be interesting later is data collected without a purpose, and it is also data that has to be secured, retained correctly and eventually deleted, which is a cost with no corresponding benefit.
The tension is with the desire to learn. A supplier improving its method wants everything it can get; a controller applying the principle wants the least that answers the question. The workable position, consistent with giving each role only what its purpose requires, is to separate the two purposes and give the second one its own basis and its own consent, rather than smuggling it inside the first.
In practice
A platform collects date of birth, nationality and tenure alongside a behavioural assessment because the fields were already in the template. None of the three is used for the decision the assessment informs. When a works council asks why they are collected, the honest answer is that nobody removed them, which is not a purpose.
Evidence
Personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
Article 5, General Data Protection Regulation (2016)
What it cannot tell you
Data minimisation tests necessity against a stated purpose; it does not tell you whether the purpose itself is legitimate or proportionate, nor does it govern accuracy or fairness. A dataset can be minimal and still measure the wrong thing, or measure the right thing in a way that produces poor decisions.
Questions
Field by field, against the purpose stated under Article 5 of the GDPR (2016). For each item, the question is whether the decision the data informs could be made without it. If so, the item is not necessary and should not be collected, however routine it is to request.
No, but it separates the purposes. Using assessment data to improve the instrument is a different purpose from informing a decision about a team, and it needs its own basis, its own transparency and usually its own consent or aggregation, rather than riding on the original collection.
It has to meet the same test. Data that turns out not to be necessary should be deleted rather than kept in case, because retention beyond the purpose is itself a breach of the principle and a liability. Periodic review of what is held is part of applying minimisation.
Truly anonymous data falls outside the regulation defined in the GDPR (2016). Aggregated data that could still identify individuals remains subject to Article 5's requirement that data be adequate, relevant and limited to what is necessary. The threshold for anonymity is higher than most organisations assume, so treat the principle as still applying.
The instrument itself should collect only what the constructs it measures require, and the surrounding record only what the decision needs. Demographic fields are the usual failure, gathered for reporting convenience rather than for the decision, and they are the first thing a works council notices.