Use Limitation
Use limitation is the idea that personal data collected for a particular reason should generally not be used later for a different, incompatible reason. In practice, organisations are expected to be clear from the outset about why they are collecting personal data and to stick to those stated purposes. It is closely related to, and often discussed as part of, the purpose limitation principle.
Use limitation, commonly framed in data protection guidance as the purpose limitation principle, requires that personal data be collected for specified, explicit purposes and not subsequently processed in a manner incompatible with those purposes. Under UK data protection guidance from the ICO, this obligation entails being clear from the outset about the reason for collecting personal data. Comparable framing exists under the CCPA, where, in its simplest form, personal information collected for one purpose may not later be used for an incompatible purpose; however, the specific scope, exceptions, and compatibility assessments differ between regimes and should not be treated as interchangeable. This entry does not address related principles such as data minimisation or storage limitation in detail, nor does it cover lawful bases for processing, cross-border transfer mechanics, retention rules, or enforcement. Note also that the term 'field-of-use limitation' in patent licensing is a distinct concept and is out of scope here.
Why it matters
Use limitation, most commonly discussed as the purpose limitation principle, is foundational to building trust in how personal data is handled. When an organisation is clear from the outset about why it is collecting personal data and confines its processing to those stated purposes, individuals have a reasonable basis for understanding and anticipating what will happen to their information. Where data collected for one reason is quietly repurposed for an incompatible one, that expectation breaks down, and the organisation may find itself unable to defend its processing against scrutiny from regulators or affected individuals.
The principle also acts as a practical constraint on scope creep. Data gathered for a narrow, legitimate reason can accumulate value over time and become tempting to reuse for analytics, marketing, or other secondary aims. Purpose limitation requires organisations to assess whether a new use is compatible with the original purpose before proceeding, rather than treating already-collected data as a free resource. Under UK data protection guidance from the ICO, being clear about the reason for collection is central to this discipline; comparable framing exists under the CCPA, though the specific scope, exceptions, and compatibility assessments differ between regimes and should not be treated as interchangeable.
Because the details of what counts as an incompatible purpose vary by regime, the same repurposing decision may be assessed differently in the UK than under the CCPA. This entry does not address lawful bases for processing, retention rules, cross-border transfer mechanics, or enforcement, all of which bear on whether a given secondary use is ultimately permissible in a particular jurisdiction.
Who it's relevant to
Inside Use Limitation
Common questions
Answers to the questions practitioners most commonly ask about Use Limitation.