A/HRC/39/29 rights law to the greatest extent possible and mitigate as much as possible any adverse impact, for example by interpreting government demands as narrowly as possible. 57 45. The responsibility to respect human rights requires business enterprises to have in place policies and processes appropriate to their size and circumstances, including: (a) Making a publicly available policy commitment at the most senior level and embedding responsibility to respect human rights throughout operational policies and procedures;58 (b) Carrying out human rights due diligence processes, which entails: (i) Conducting human rights impact assessments to identify and assess any actual or potentially adverse human rights impacts; (ii) Integrating those assessments and taking appropriate action to prevent and mitigate adverse human rights impacts that have been identified; (iii) Tracking the effectiveness of their efforts; (iv) Reporting formally on how they have addressed their human rights impacts;59 (c) Providing remediation or cooperating in remediation of abuse where the company identifies adverse impacts that it has caused or to which it has contributed. 60 46. According to the Guiding Principles, all companies have a responsibility to undertake human rights due diligence to identify and address any human rights impacts of their activities. Taking a concrete example, companies selling surveillance technology should carry out, as part of their due diligence, a thorough human rights impact assessment prior to any potential transaction. Risk mitigation should include clear end-use assurances being stipulated in contractual agreements with strong human rights safeguards that prevent arbitrary or unlawful use of the technology and periodic reviews of the use of technology by States.61 Companies collecting and retaining user data need to assess the privacy risks connected to potential State requests for such data, including the legal and institutional environment of the States concerned. They must provide for adequate processes and safeguards to prevent and mitigate potential privacy and other human rights harms. Human rights impact assessments also need to be conducted, as part of the adoption of the terms of service and design and engineering choices that have implications for security and privacy, and decisions taken to provide or terminate services in a particular context (see A/HRC/32/38, para. 11). 47. As part of the human rights due diligence process, the Guiding Principles stipulate that business enterprises should account for how they address their human rights impacts and be prepared to communicate that externally, particularly when concerns are raised by or on behalf of affected stakeholders. 62 In the digital environment, that entails disclosing which personal data are collected, how long they are stored for, for what purpose, how they are used and with whom and under what circumstances they are shared. That includes requests received by States for access to user data. In instances where national laws and regulations hinder such reporting, companies should use to the greatest extent possible any leverage they may have and are encouraged to advocate for the possibility to release such information. 48. As part of the operationalization of their policy commitments under the Guiding Principles, the ICT sector has developed guidance on how to implement human rights policies. Such initiatives include the Principles on Freedom of Expression and Privacy of 57 58 59 60 61 62 Guiding Principle 23. Guiding Principle 16. Guiding Principles 17– 21. Guiding Principle 22 and section VI of the present report. See Privacy International, submission to the Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression (January 2016), available at www.ohchr.org/Documents/Issues/Expression/PrivateSector/PrivacyInternational.pdf. Guiding Principle 21. 13

Select target paragraph3