Direct Collection vs Minimum Disclosure

Back to thirdrailsystems.ee

Direct Collection vs Minimum Disclosure

Verified as of August 2026

How to cite this page

Cite individual sections by their stable anchor, e.g. thirdrailsystems.ee/architecture/direct-collection-vs-minimum-disclosure#the-alternative. Verified August 2026.

Before an enterprise delegates sensitive travel-risk data to a third party, or builds a minimum-disclosure architecture, most start somewhere simpler: HR or the travel-risk team just asks the traveller directly. A form, a self-disclosure survey, a conversation with a line manager. It feels like the lightest-touch option. It usually isn't.

What direct collection is for

Some direct disclosure is unavoidable and appropriate. Emergency contact details, allergy information relevant to first responders, an active medical condition requiring urgent accommodation, these need to reach a human quickly, and no architecture should stand between a traveller and help in a genuine emergency.

What it costs when applied to routine readiness

Article 9 of the GDPR does not treat health data, sexual orientation, or similar categories as ordinary information. Its default position is that processing them "shall be prohibited" (GDPR Article 9(1)) unless a specific lawful basis applies. The moment HR or a travel-risk team holds this data directly, for routine pre-travel screening rather than emergency response, that basis has to be established, documented, and defended, for every record, indefinitely.

Article 5(1)(c) sets the standard the whole regulation is built around: personal data must be "adequate, relevant and limited to what is necessary" for its purpose (GDPR Article 5). A standing HR record of an employee's disability, gender identity, or health history, collected once for a single trip and retained afterwards because deleting it is nobody's job, is difficult to defend as limited to what was necessary.

There is also a cost that shows up before any regulator gets involved. Research from the Williams Institute at UCLA found that 46% of LGBTQ employees are not open about their identity with their current supervisor, and that those who are out at work are three times as likely to report having experienced discrimination as those who are not (Williams Institute, LGBT People's Experiences of Workplace Discrimination and Harassment). A direct-disclosure system asks exactly the population most likely to be harmed by disclosure to be the one that discloses. The traveller who most needs an accurate readiness assessment is often the traveller with the strongest incentive to give an incomplete one.

The data, once collected, is a target regardless of intent

None of this requires bad faith on the enterprise's part. A well-run HR system that holds this data centrally is still a centralised store of exactly the category of information a breach is most damaging to lose. The global average cost of a data breach is now USD 4.99 million (IBM, 2026 Cost of a Data Breach Report), and that figure covers breaches in general, not specifically the reputational and legal exposure of a breach involving Article 9 data. Holding the data well is still holding the data.

The alternative

A minimum-disclosure architecture never asks the question in a form that produces a standing record. The assessment happens against the traveller's own device, the enterprise receives a Ready / Needs Review / Not Ready signal, and the underlying attribute, whatever it was, is never transmitted, never centrally stored, and never becomes a line in an HR file that someone forgot to delete.

The honest trade-off

Direct collection is the fastest to set up and the easiest to explain in a policy document. It is also the option that puts the most sensitive data in the most central, most exposed place, and asks the people least able to afford disclosure to be the ones who provide it.

Sources

Sources: GDPR Article 5, data minimisation (primary); GDPR Article 9, special categories (primary); Williams Institute, UCLA (primary, research institute's own study); IBM, 2026 Cost of a Data Breach Report (primary, first-party).

Request a diagnostic
60-minute structured conversation. Confidential. No HRIS integration required.

Third Rail Systems OÜ, "Direct Collection vs Minimum Disclosure", thirdrailsystems.ee, https://thirdrailsystems.ee/architecture/direct-collection-vs-minimum-disclosure.