A recent decision by Hungary’s Data Protection Authority (NAIH) offers a deceptively modest outcome, a €5,000 fine, but sends a much stronger signal on the evolving expectations around data minimization under the GDPR and ultimately, the US State Privacy laws. The decision reflects a strict, controller-centric approach, making clear that the key question in a data minimization analysis is whether the data actually retained by the controller is necessary and proportionate to the stated purpose . not whether individuals were given the opportunity to limit what they submitted.