A/HRC/39/29
and they should be required to keep records of all surveillance measures taken.52 Oversight
processes must also be transparent and subject to appropriate public scrutiny and the
decisions of the oversight bodies must be subject to appeal or independent review.
Exposing oversight bodies to divergent points of view, for example through expert and
multi-stakeholder consultations (see for example A/HRC/34/60, para. 36), is particularly
important in the absence of an adversarial process: it is essential that “points of friction” —
continual challenges to approaches and understandings — be built in.53
Principle of transparency
41.
State authorities and oversight bodies should also engage in public information
about the existing laws, policies and practices in surveillance and communications
interception and other forms of processing of personal data, open debate and scrutiny being
essential to understanding the advantages and limitations of surveillance techniques (see
A/HRC/13/37, para. 55). Those who have been the subject of surveillance should be
notified and have explained to them ex post facto the interference with their right to
privacy. They also should be entitled to alter and/or delete irrelevant personal information,
provided that information is not needed any longer to carry out any current or pending
investigation (see A/HRC/34/60, para. 38).
V. Responsibilities of business enterprises
42.
Pillar II of the Guiding Principles on Business and Human Rights provides an
authoritative blueprint for all enterprises, regardless of their size, sector, operational
context, ownership and structure, for preventing and addressing all adverse human rights
impacts, including the right to privacy. 54 It outlines the responsibility of business
enterprises to respect all internationally recognized human rights, meaning that they should
avoid infringing on the human rights of others and address adverse human rights impacts
with which they are involved. 55 The responsibility to respect applies throughout a
company’s activities and business relationships. It is of particular relevance in the digital
space that the responsibility to respect applies, regardless of where the people affected are
located. The responsibility to respect exists independently of whether the State meets its
own human rights obligations.
43.
Meeting the responsibility to respect human rights requires that business enterprises
(a) avoid causing adverse impacts through their own activities; (b) avoid contributing to
adverse impacts through their own activities, either directly or through some outside entity
(Government, business or others); and (c) seek to prevent or mitigate adverse human rights
impacts directly linked to their operations, products or services by their business
relationships, even if they have not contributed to those impacts.56 For example, a company
that provides data about users to a Government that then uses the data to trace and
prosecute political dissidents will have contributed to such human rights abuses, including
of the right to privacy. Companies that manufacture and sell technologies used for unlawful
or arbitrary intrusions will also be contributing to adverse human rights impacts.
44.
If there are conflicting demands between respect for international human rights law
and obligations under national law, companies should strive to respect international human
52
53
54
55
56
12
See European Court of Human Rights, Kennedy v. United Kingdom, application No. 26839/05,
judgment of 18 May 2010, para. 165, and Roman Zakharov v. Russia, para. 272.
See Human Rights, Big Data and Technology Project, Human Rights Centre, University of Essex,
submission for the present report.
The Guiding Principles were unanimously endorsed by the Human Rights Council in its resolution
17/4.
Guiding Principle 11.
Guiding Principle 13. See also OHCHR, “The corporate responsibility to respect human rights: an
interpretive guide” (2012).