In 2025, a major European bank was fined €4.4 million for collecting identity documents beyond what data minimization rules required. That fine was a clear signal: data minimization has moved from compliance aspiration to legal baseline, and regulators are actively enforcing it. Global privacy frameworks — the GDPR, CCPA, and a growing stack of U.S….