A/HRC/39/29
Rights (OHCHR). More generally, efforts should be made to develop sector-specific
guidance tools on business responsibilities to respect the right to privacy.
61.
The High Commissioner recommends that States:
(a)
Recognize the full implications of new technologies, in particular datadriven technologies for the right to privacy but also for all other human rights;
(b)
Adopt strong, robust and comprehensive privacy legislation, including
on data privacy, that complies with international human rights law in terms of
safeguards, oversight and remedies to effectively protect the right to privacy;
(c)
Ensure that data-intensive systems, including those involving the
collection and retention of biometric data, are only deployed when States can
demonstrate that they are necessary and proportionate to achieve a legitimate aim;
(d)
Establish independent authorities with powers to monitor State and
private sector data privacy practices, investigate abuses, receive complaints from
individuals and organizations, and issue fines and other effective penalties for the
unlawful processing of personal data by private and public bodies;
(e)
Ensure, through appropriate legislation and other means that any
interference with the right to privacy, including by communications surveillance and
intelligence-sharing, complies with international human rights law, including the
principles of legality, legitimate aim, necessity and proportionality, regardless of the
nationality or location of the individuals affected, and clarify that authorization of
surveillance measures requires reasonable suspicion that a particular individual has
committed or is committing a criminal offence or is engaged in acts amounting to a
specific threat to national security;
(f)
Strengthen mechanisms for the independent authorization and oversight
of State surveillance and ensure that those mechanisms are competent and adequately
resourced to monitor and enforce the legality, necessity and proportionality of
surveillance measures;
(g)
Review laws to ensure that they do not impose requirements of blanket,
indiscriminate retention of communications data on telecommunications and other
companies;
(h)
Take steps in order to enhance transparency and accountability in the
acquisition of surveillance technologies by States;
(i)
Fully implement their duty to protect against abuses of the right to
privacy by business enterprises in all relevant sectors, including the ICT sector, by
taking appropriate steps to prevent, investigate, punish and redress such abuse
through effective policies, legislation, regulations and adjudication;
(j)
Ensure that all victims of violations and abuses of the right to privacy
have access to effective remedies, including in cross-border cases.
62.
The High Commissioner recommends that business enterprises:
(a)
Make all efforts to meet their responsibility to respect the right to
privacy and all other human rights. At a minimum, business enterprises should fully
operationalize the Guiding Principles on Business and Human Rights, which implies
conducting effective human rights due diligence across their operations and in
relation to all human rights, including the right to privacy, and taking appropriate
action to prevent, mitigate and address actual and potential impacts;
(b)
Seek to ensure a high level of security and confidentiality of any
communications they transmit and personal data they collect, store or otherwise
process. Conduct assessments on how best to design and update the security of
products and services on an ongoing basis;
(c)
Comply with the key privacy principles referred to in paragraphs 29–31
of the present report and ensure the greatest possible transparency in their internal
policies and practices that implicate the right to privacy of their users and customers;
16