PRI1
Minimise disclosure
Raw data must not cross a trust boundary where a verifiable claim satisfies the relying party’s stated need: the proof — revealing nothing beyond the answer itself — is the default, and any raw-data disclosure is an explicit, authorised, logged exception.
Rationale
When only the answer crosses a boundary, your exposure shrinks: there is less data to breach, less to hold on another party’s behalf, and lighter data-protection liability on both sides of every exchange. Making the proof the default — rather than merely aiming to share less — gives partners, auditors and regulators a predictable rule they can rely on. This principle governs what may cross a boundary; Principle 3 governs who authorises it, and Principle 2 protects whatever data remains. Where a relying party’s stated need can be met by a proof, the proof takes precedence over sending the underlying data.
Implications
- Teams justify and record any exchange that sends raw data instead of a proof, so raw-data flows become deliberate, authorised exceptions rather than the path of least resistance.
- Each exchange is scoped in terms of exactly what the other party learns, which changes how integrations are designed and reviewed with your partners and legal teams.
- Because a commitment or proof crosses the boundary rather than the data itself, residency and data-sharing obligations attach to artifacts that reveal nothing — shrinking the compliance surface of every partner integration.