A/HRC/39/29 However, the obligations of States extend beyond the obligation to respect and also include “positive” measures to protect the enjoyment of rights. In the context of the right to privacy, that implies a duty to adopt legislative and other measures to give effect to the prohibition of and protection against unlawful or arbitrary interference and attacks, whether they emanate from State authorities or from natural or legal persons. 31 24. The duty to protect is reflected in pillar I of the Guiding Principles on Business and Human Rights, entitled the “State duty to protect human rights”, which elaborates on the implications of the duty of States to protect against adverse human rights impacts involving companies. Principle 1 of the Guiding Principles requires that appropriate steps be taken to prevent, investigate, punish and redress human rights abuses through effective policies, legislation, regulations and adjudication. The subsequent principles outline the different legal and policy areas in which States should adopt a “smart mix of measures” — national and international, mandatory and voluntary — to foster business respect for human rights. 32 Examples of the application of the approach stipulated in the Guiding Principles in relation to the ICT sector include sectoral guidance developed at the European Union level, which focuses on how ICT enterprises should deal with any detrimental impact of their activities. 25. The duty of States to protect against abuses of the right to privacy by companies and other third parties incorporated or domiciled within their jurisdiction has extraterritorial effects. For example, States should have in place export control regimes applicable to surveillance technology, which provide for assessing the legal framework governing the use of the technology in the destination country, the human rights record of the proposed end user and the safeguards and oversight procedures in place for the use of surveillance powers. Human rights guarantees need to be included in export licensing agreements. Furthermore, States have a duty to protect persons within their jurisdictions from extraterritorial interference with their rights to privacy, such as means of interception of communications or hacking. B. State responsibility to put in place adequate safeguards and effective oversight 26. Enjoyment of the right to privacy depends largely on a legal, regulatory and institutional framework that provides for adequate safeguards, including effective oversight mechanisms. In an era where a vast amount of personal data is accessible to States and business enterprises, and individuals have limited insight into and control over how information about them and their lives is being used, it is critical to focus on measures that mitigate the impact on human rights from such power and information asymmetries. 1. Overarching framework protecting against undue interference 27. One cornerstone of a State privacy protection framework should be laws setting the standards for the processing of personal information by both States and private actors. 33 While States have discretion in defining the smart mix of measures governing the corporate use of personal information, article 17 (2) of the International Covenant on Civil and Political Rights lays down the need to protect individuals by means of law. The increased interlinking of public and private data processing and the track record to date implying mass, recurrent misuse of personal information by some business enterprises confirm that legislative measures are necessary for achieving an adequate level of privacy protection. 34 31 32 33 34 8 See Human Rights Committee, general comments No. 16, paras. 1 and 9, and No. 31, para. 8. See Principle 2, commentary. See Human Rights Committee, general comment No. 16, para. 9, A/HRC/13/37, para. 61, and A/HRC/17/27, para. 56. For a global overview of data privacy legislation, see Graham Greenleaf, University of New South Wales, submission for the present report. In the present report “processing” is understood as encompassing any operation performed on personal data, including collection, retention, use, modification, erasure, disclosure, transfer and combination. See Human Rights Council resolutions 34/7, para. 5 (f), and 38/7, para. 17.

Select target paragraph3