A/HRC/39/29 28. There is a growing global consensus on minimum standards that should govern the processing of personal data by States, business enterprises and other private actors. International instruments and guidelines reflecting this development include the 1990 Guidelines for the Regulation of Computerized Personal Data Files; the Council of Europe 1981 Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data and its modernized version, which sets a global high level of protection; 35 the 1980 Organization for Economic Cooperation and Development Privacy Guidelines, updated in 2013; the 2014 African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention); the Madrid resolution of the International Conference of Data Protection and Privacy Commissioners; and the 2015 Asia-Pacific Economic Coordination Privacy Framework, among others. Those standards, particularly the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, have informed the data privacy frameworks of many States and can direct the design of adequate policy instruments. 36 29. The instruments and guidelines mentioned above contain a range of key principles, rights and obligations that ensure a minimum level of protection of personal data. First, processing of personal data should be fair, lawful and transparent. The individuals whose personal data are being processed should be informed about the data processing, its circumstances, character and scope, including through transparent data privacy policies. In order to prevent the arbitrary use of personal information, the processing of personal data should be based on the free, specific, informed and unambiguous consent of the individuals concerned, or another legitimate basis laid down in law. 37 Personal data processing should be necessary and proportionate to a legitimate purpose that should be specified by the processing entity. Consequently, the amount and type of data and the retention period need to be limited, data must be accurate and anonymization and pseudonymization techniques used whenever possible. Changes of purpose without the consent of the person concerned should be avoided and when undertaken, should be limited to purposes compatible with the initially specified purpose. Considering the vulnerability of personal data to unauthorized disclosure, modification or deletion, it is essential that adequate security measures be taken. Moreover, entities processing personal data should be accountable for their compliance with the applicable data processing legal and policy framework. Finally, sensitive data should enjoy a particularly high level of protection. 38 30. In all the instruments and guidelines mentioned above, it is recognized that certain rights need to be afforded to the persons whose data is being processed. At a minimum, the persons affected have a right to know that personal data has been retained and processed, to have access to the data stored, to rectify data that is inaccurate or outdated and to delete or rectify data unlawfully or unnecessarily stored. Newer instruments have added important additional rights, in particular, a right to object to personal data processing, at least for cases where the processing entity does not demonstrate legitimate, overriding grounds for the processing. 39 States should pay particular attention to providing strong protection against interference with the right to privacy by means of profiling and automated decisionmaking. The rights described above should also apply to information derived, inferred and predicted by automated means, to the extent that the information qualifies as personal data. It is important that the legal framework ensures that those rights do not unduly limit the 35 36 37 38 39 In addition to the 47 member States of the Council of Europe, the Convention has been ratified by Mauritius, Senegal, Tunisia and Uruguay, and several other States are in the process of accession. For detailed guidance, see https://privacyinternational.org/advocacy-briefing/2165/guide-policyengagement-data-protection and Access Now, “Creating a data protection framework: a do’s and don’ts guide for lawmakers. Lessons from the EU general data protection regulation” (2018). See article 5 (2) of the modernized Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data; article 13 (1) of the Malabo Convention; and principle 12 of the Madrid resolution. See article 6 of the modernized Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data. Ibid., art. 9 (1) (d). See also article 21 of the general data protection regulation and article 18 (1) of the Malabo Convention. 9

Select target paragraph3