Purpose limitation
Process only the data required for the agreed delivery purpose.
ICSInternational Cyber SecurityPrinciples for defining purpose, access, retention, transfer, and deletion of data within a delivery scope.


Use these areas to confirm fit, dependencies, ownership, and the evidence required for acceptance.
Process only the data required for the agreed delivery purpose.
Record who can access data and under which conditions.
Retain information according to purpose, agreement, and legal requirements.
Close the scope with documented handover or disposal.
Contact ICS when your procurement or security team requires controlled documentation.

Give procurement and security reviewers a clear starting point before requesting scope-specific evidence.

Protect users and systems while enabling timely technical investigation.

Send the right evidence to the right reviewer without exposing sensitive implementation detail unnecessarily.
Principles for defining purpose, access, retention, transfer, and deletion of data within a delivery scope.
Discuss this scope