Data minimization is difficult in legacy systems because teams cannot identify which fields are actually used. A code scanning approach can identify unused data fields by tracing their paths through the codebase, creating an evidence-based shortlist for removal decisions rather than relying on room consensus.