A/HRC/39/29 and they should be required to keep records of all surveillance measures taken.52 Oversight processes must also be transparent and subject to appropriate public scrutiny and the decisions of the oversight bodies must be subject to appeal or independent review. Exposing oversight bodies to divergent points of view, for example through expert and multi-stakeholder consultations (see for example A/HRC/34/60, para. 36), is particularly important in the absence of an adversarial process: it is essential that “points of friction” — continual challenges to approaches and understandings — be built in.53 Principle of transparency 41. State authorities and oversight bodies should also engage in public information about the existing laws, policies and practices in surveillance and communications interception and other forms of processing of personal data, open debate and scrutiny being essential to understanding the advantages and limitations of surveillance techniques (see A/HRC/13/37, para. 55). Those who have been the subject of surveillance should be notified and have explained to them ex post facto the interference with their right to privacy. They also should be entitled to alter and/or delete irrelevant personal information, provided that information is not needed any longer to carry out any current or pending investigation (see A/HRC/34/60, para. 38). V. Responsibilities of business enterprises 42. Pillar II of the Guiding Principles on Business and Human Rights provides an authoritative blueprint for all enterprises, regardless of their size, sector, operational context, ownership and structure, for preventing and addressing all adverse human rights impacts, including the right to privacy. 54 It outlines the responsibility of business enterprises to respect all internationally recognized human rights, meaning that they should avoid infringing on the human rights of others and address adverse human rights impacts with which they are involved. 55 The responsibility to respect applies throughout a company’s activities and business relationships. It is of particular relevance in the digital space that the responsibility to respect applies, regardless of where the people affected are located. The responsibility to respect exists independently of whether the State meets its own human rights obligations. 43. Meeting the responsibility to respect human rights requires that business enterprises (a) avoid causing adverse impacts through their own activities; (b) avoid contributing to adverse impacts through their own activities, either directly or through some outside entity (Government, business or others); and (c) seek to prevent or mitigate adverse human rights impacts directly linked to their operations, products or services by their business relationships, even if they have not contributed to those impacts.56 For example, a company that provides data about users to a Government that then uses the data to trace and prosecute political dissidents will have contributed to such human rights abuses, including of the right to privacy. Companies that manufacture and sell technologies used for unlawful or arbitrary intrusions will also be contributing to adverse human rights impacts. 44. If there are conflicting demands between respect for international human rights law and obligations under national law, companies should strive to respect international human 52 53 54 55 56 12 See European Court of Human Rights, Kennedy v. United Kingdom, application No. 26839/05, judgment of 18 May 2010, para. 165, and Roman Zakharov v. Russia, para. 272. See Human Rights, Big Data and Technology Project, Human Rights Centre, University of Essex, submission for the present report. The Guiding Principles were unanimously endorsed by the Human Rights Council in its resolution 17/4. Guiding Principle 11. Guiding Principle 13. See also OHCHR, “The corporate responsibility to respect human rights: an interpretive guide” (2012).

Select target paragraph3