Privacy Principles
What is Purpose Limitation?
Purpose limitation is the privacy principle — GDPR Article 5(1)(b) — that personal data must be collected for specified, explicit, and legitimate purposes and not further processed in ways incompatible with those purposes.
Purpose limitation has two halves. Specification: the purpose must be defined and disclosed at collection time — 'to fulfill your order,' 'to send marketing you signed up for' — not discovered retroactively. Compatibility: later uses must be compatible with the original purpose; anything incompatible needs a fresh legal basis, typically new consent. Vague catch-alls ('to improve our services,' 'for business purposes') fail specification because they authorize nothing in particular and therefore everything.
The compatibility assessment weighs the link between original and new purpose, the context and relationship, the nature of the data, consequences for individuals, and safeguards applied. GDPR deems archiving, research, and statistics compatible with appropriate safeguards. The classic incompatible move is repurposing: data collected for security used for marketing, delivery addresses shared for ad targeting, support transcripts mined to train models — each a purpose the individual never saw coming at collection.
The principle is why privacy notices enumerate purposes and why consent must be granular by purpose: agreeing to order fulfillment is not agreeing to profiling. It also structures data internally — modern architectures increasingly tag data with its collection purpose so downstream systems can enforce what it may feed, which is purpose limitation implemented as access control.
US law is adopting the frame: the CPRA requires that processing be compatible with the disclosed context and demands notice before materially different uses, and FTC enforcement has treated retroactive repurposing — quietly amending the policy to bless new uses of old data — as a deceptive practice.
Why it matters for eCommerce
The typical eCommerce violation is quiet repurposing: emails collected for order receipts sliding into marketing lists, or purchase histories collected for fulfillment feeding ad-platform audiences without disclosure. Map each data flow to the purpose disclosed when the data was collected — where a new use appears, disclose it and, where required, get consent rather than editing the policy after the fact.
Frequently asked questions
- Can we use customer data for a new purpose later?
- Only if the new purpose is compatible with the original one, or you obtain a fresh legal basis — usually consent — and update your notices first. Repurposing data under a silently amended privacy policy is a well-established enforcement pattern.
- Are broad purposes like 'improving our services' acceptable?
- Regulators treat them as failing the 'specified and explicit' requirement when used to justify concrete processing like profiling or sharing. State purposes at the level a user could genuinely anticipate: what data, for what outcome.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
Run a free scan