A/HRC/39/29
the Global Network Initiative (the GNI Principles)63 and the Telecommunications Industry
Dialogue Guiding Principles. 64 For example, the GNI principles specifically state that
participating companies “will employ protections with respect to personal information” and
“will respect and work to protect the privacy rights of users when confronted with
government demands, laws or regulations that compromise privacy in a manner
inconsistent with internationally recognized laws and standards”.
49.
The Ranking Digital Rights Corporate Accountability Index evaluates a number of
Internet, mobile and telecommunications companies specifically on their disclosed
commitments and policies affecting freedom of expression and privacy. 65 That can be a
useful tool for holding companies accountable for their impact on users’ rights.
VI. Remedies
50.
Victims of privacy violations or abuses committed by States and/or business
enterprises must have access to an effective remedy. States not only have obligations to
ensure accountability and remedy for human rights violations committed by State actors,
they must also take appropriate steps to ensure that victims of business-related human rights
abuse have access to an effective remedy (see pillar III of the Guiding Principles on
Business and Human Rights). Depending on the nature of a particular case or situation,
victims should be able to achieve remedies through effective judicial or non-judicial Statebased grievance mechanisms (A/HRC/32/19, Corr. 1 and Add. 1 and A/HRC/38/20 and
Add. 1). Relevant State-based non-judicial mechanisms in the ICT context include
independent authorities with powers to monitor State and private sector data privacy
practices, such as privacy and data protection bodies.
51.
Under the Guiding Principles, where business enterprises determine that they have
caused or contributed to adverse human rights impacts, they should provide for or
cooperate in the remediation of any adverse human rights impacts that they may have
caused or contributed to through legitimate processes. 66 For any non-judicial mechanism to
be effective, it should be legitimate, accessible, predictable, equitable, rights-compatible,
transparent, a source of continuous learning and, for operational level grievance
mechanisms, based on dialogue and engagement.67
52.
Where an enterprise has not caused or contributed to an adverse impact, but where
the impact is directly linked to its operations, products or services by a business
relationship, the appropriate action is elaborated in Guiding Principle 19. It may include
using any leverage the enterprise may have over its business partner or client to seek to
influence it to provide for remediation.68
53.
The Guiding Principles also highlight the role that operational-level grievance
mechanisms can have in addressing grievances directly. Such mechanisms can potentially
take a range of forms, which will depend on the type of company concerned, the needs of
its stakeholders and the company’s human rights risk picture. To identify how those
mechanisms may be designed and work in the ICT sector in practice, further discussion
within the sector and with stakeholders is necessary.
54.
In practice, there are significant gaps and obstacles when it comes to providing
access to remedial avenues for privacy infringements. The transnational nature and effects
of surveillance, communications interceptions and the many forms of processing of
personal data pose legal and practical challenges (see A/HRC/34/60, para. 34). In addition,
63
64
65
66
67
68
14
Available from https://globalnetworkinitiative.org/gni-principles/. See also the Global Network
Initiative, submission for the present report.
Available from www.telecomindustrydialogue.org/about/guiding-principles/.
See https://rankingdigitalrights.org/index2018/.
Guiding Principle 22.
Guiding Principle 31.
Guiding Principle 19 and its commentary. See also OHCHR, “The corporate responsibility to respect
human rights: an interpretive guide”, pp. 48–52.