%% You should probably cite draft-arkko-iab-data-minimization-principle-05 instead of this revision. @techreport{arkko-iab-data-minimization-principle-04, number = {draft-arkko-iab-data-minimization-principle-04}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-arkko-iab-data-minimization-principle/04/}, author = {Jari Arkko}, title = {{Data minimization among protocol participants}}, pagetotal = 12, year = 2023, month = mar, day = 13, abstract = {Communications security has been at the center of many security improvements in the Internet. The goal has been to ensure that communications are protected against outside observers and attackers. Privacy has also been a key focus area, and understanding the privacy implications of new Internet technology is an important factor when IETF works on such technologies. One key aspect of privacy is minimization of data disclosed to other parties. This document highlights the need for a particular focus with respect to data minimization. Avoiding data leakage to outside parties is of course important, but it can also be necessary to limit it among the primary protocol participants. This is because is necessary to protect against endpoints that are compromised, malicious, or whose interests simply do not align with the interests of users. It is important to consider the role of a participant and limit any data provided to it according to that role.}, }