A/HRC/39/29 the Global Network Initiative (the GNI Principles)63 and the Telecommunications Industry Dialogue Guiding Principles. 64 For example, the GNI principles specifically state that participating companies “will employ protections with respect to personal information” and “will respect and work to protect the privacy rights of users when confronted with government demands, laws or regulations that compromise privacy in a manner inconsistent with internationally recognized laws and standards”. 49. The Ranking Digital Rights Corporate Accountability Index evaluates a number of Internet, mobile and telecommunications companies specifically on their disclosed commitments and policies affecting freedom of expression and privacy. 65 That can be a useful tool for holding companies accountable for their impact on users’ rights. VI. Remedies 50. Victims of privacy violations or abuses committed by States and/or business enterprises must have access to an effective remedy. States not only have obligations to ensure accountability and remedy for human rights violations committed by State actors, they must also take appropriate steps to ensure that victims of business-related human rights abuse have access to an effective remedy (see pillar III of the Guiding Principles on Business and Human Rights). Depending on the nature of a particular case or situation, victims should be able to achieve remedies through effective judicial or non-judicial Statebased grievance mechanisms (A/HRC/32/19, Corr. 1 and Add. 1 and A/HRC/38/20 and Add. 1). Relevant State-based non-judicial mechanisms in the ICT context include independent authorities with powers to monitor State and private sector data privacy practices, such as privacy and data protection bodies. 51. Under the Guiding Principles, where business enterprises determine that they have caused or contributed to adverse human rights impacts, they should provide for or cooperate in the remediation of any adverse human rights impacts that they may have caused or contributed to through legitimate processes. 66 For any non-judicial mechanism to be effective, it should be legitimate, accessible, predictable, equitable, rights-compatible, transparent, a source of continuous learning and, for operational level grievance mechanisms, based on dialogue and engagement.67 52. Where an enterprise has not caused or contributed to an adverse impact, but where the impact is directly linked to its operations, products or services by a business relationship, the appropriate action is elaborated in Guiding Principle 19. It may include using any leverage the enterprise may have over its business partner or client to seek to influence it to provide for remediation.68 53. The Guiding Principles also highlight the role that operational-level grievance mechanisms can have in addressing grievances directly. Such mechanisms can potentially take a range of forms, which will depend on the type of company concerned, the needs of its stakeholders and the company’s human rights risk picture. To identify how those mechanisms may be designed and work in the ICT sector in practice, further discussion within the sector and with stakeholders is necessary. 54. In practice, there are significant gaps and obstacles when it comes to providing access to remedial avenues for privacy infringements. The transnational nature and effects of surveillance, communications interceptions and the many forms of processing of personal data pose legal and practical challenges (see A/HRC/34/60, para. 34). In addition, 63 64 65 66 67 68 14 Available from https://globalnetworkinitiative.org/gni-principles/. See also the Global Network Initiative, submission for the present report. Available from www.telecomindustrydialogue.org/about/guiding-principles/. See https://rankingdigitalrights.org/index2018/. Guiding Principle 22. Guiding Principle 31. Guiding Principle 19 and its commentary. See also OHCHR, “The corporate responsibility to respect human rights: an interpretive guide”, pp. 48–52.

Select target paragraph3