
Data minimization is a simple idea: only collect and keep the data you need, and nothing more. It sounds obvious. But most government programs collect more data than they use, often without meaning to. Following this principle lowers risk and builds trust. People are more willing to apply for services when they trust their data won’t be used for other things.
CalData is part of the Office of Data and Innovation (ODI). We help departments build data infrastructure and establish governance best practices. This lets them make better business decisions and improve their services. Earlier this year, we built a toolkit and training to help any department in California do this work well. Here’s how we built it, and what happened after we published it.
Why this matters right now
In May 2025, the federal government asked the states for personal data on everyone in SNAP. This food assistance program serves over 42 million people. They asked for names, Social Security numbers, home addresses, and immigration status. The stated reason was reducing fraud. But advocates pointed out the data could serve another purpose: immigration enforcement. This is an example of what’s called purpose creep. It’s when data collected for one reason gets reused for a different (and in this case riskier) reason.
The request made one thing clear. California departments needed guidelines for how to respond to requests like this. Not just whether to say yes or no, but how to route them through the right channels and meet legal requirements. The Governor’s Executive Order N-5-26 asked our team to build something that could help.
“Data minimization is more than a technical standard; it is a fundamental commitment to Californians. ODI has given state departments a resource designed to help them collect, store, and share information safely and responsibly. It aims to build trust in government by ensuring we only collect and retain the data truly necessary for our programs,” said ODI Director Jeffery Marino.
Building the toolkit
We started with research, not writing. We looked at existing best practices and privacy law. We talked to the people who’d use this guidance day to day. They included privacy experts, legal staff, and state staff.
We wanted to avoid making a toolkit people read once and never use. Each section uses plain language and includes checklists instead of long policy text. We made a live training that includes two exercises so people can practice how to apply it in their own work.
The result is a public toolkit, live now on California’s Innovation Hub. It’s organized around 5 tasks:
- Data minimization 101
- How to put best practices into action
- How to run a risk and necessity assessment
- How to safely share data and handle outside requests
- How to review vendor contracts
What happened next
In the months since launch, we’ve trained over 350 leaders across 65 state departments. The toolkit has over 2,000 views.
One comment from a training attendee stood out. They planned to bring the training back to their agency because they store a lot of sensitive data. Much of this data is about people who are especially vulnerable and at risk. That’s the outcome we hoped for. None of this matters if people don’t actually use it.
The Department of General Services also used our toolkit to update Exhibit E. It’s the state’s standard confidentiality and data-safeguard language for non-IT contracts. These principles are now built into how California writes vendor contracts, whether or not someone took the training.
The bigger picture
California has some of the strongest privacy rules in the country:
- In 2023, the Delete Act was signed into law. It lets Californians ask data brokers to delete their personal info with a single request. They no longer have to ask each company one by one.
- Web browsers must give Californians a one-click way to stop companies from selling their data.
- Social media sites must make deleting an account quick and easy.
- State executive orders set rules for using artificial intelligence. It must be used responsibly while protecting people’s privacy and rights.
ODI’s data minimization toolkit sits at the intersection where policy meets action. A legal or political concern doesn’t just get written up in a memo. It gets turned into something departments can actually use.
Our office continues to support departments with sensitive data collection as they put the toolkit into practice. If you want to learn more or request training, you can find the full toolkit on ODI’s Innovation Hub or email caldata@innovation.ca.gov.